TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Security Program Is Shit

76 pointsby ig0r0over 1 year ago

8 comments

justin_oaksover 1 year ago
I&#x27;ve been the employee who describes what needs to be done to improve security, only to be ignored. And then some rando off the internet makes note of the security shortcoming in the product and suddenly the boss is going crazy. He says stuff like &quot;Why didn&#x27;t anyone tell me about this?!&quot; And fixing the issue needs to be done yesterday. No, no time to fix it properly, let&#x27;s slap together whatever we can and rush it out.<p>So glad I quit that job.
评论 #39220769 未加载
评论 #39230930 未加载
rsyncover 1 year ago
This reminds me of something we wrote a few years ago about PCI compliance:<p><a href="https:&#x2F;&#x2F;rsync.net&#x2F;resources&#x2F;regulatory&#x2F;pci.html" rel="nofollow">https:&#x2F;&#x2F;rsync.net&#x2F;resources&#x2F;regulatory&#x2F;pci.html</a>
datadrivenangelover 1 year ago
The misaligned incentives for security is the core issue, so stronger regulation is needed. Breach happens? entire executive team ought to get most of their remuneration clawed back.
评论 #39323816 未加载
mmvasqover 1 year ago
No one disagrees. Consider project management; for example, which has had many failed projects, has evolved, is still incredibly imperfect. Health care services, have had many flaws, continue to evolve, are still incredibly imperfect. Marketing, has had many flaws, has advanced, is imperfect. Pick one or two problems and advance them. Try not to kill people in the process which is all too common in tech.
评论 #39217562 未加载
MattPalmer1086over 1 year ago
This may not not a popular opinion, but this honestly comes across to me as a sad rant that has nothing worthwhile to say about security.<p>Consultants get paid to come in and advise, and internal staff are ignored? Suck it up, it&#x27;s not a problem particular to security. I&#x27;ve seen it everywhere.<p>People don&#x27;t choose hospitals because of their security program? Well, duh. They don&#x27;t choose hospitals for all kinds of non medical reasons that are still vital for the damn thing to function. Get back to me when you&#x27;re in surgery and the whole hospital goes down in a ransomware attack.<p>Honestly, if I had to listen to this person on my team for more than 10 seconds, I&#x27;d be on the phone to Deloitte before you could blink.
thatfunkymunkiover 1 year ago
Yeah, it&#x27;s basically true
toomuchtodoover 1 year ago
Shouting truth into the abyss. Great read. My CISO chuckled.
blakesterzover 1 year ago
I think the &quot;Your&quot; got dropped from this. Should read:<p>You Security Program Is Shit