TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Security Program Is Shit

76 点作者 ig0r0超过 1 年前

8 条评论

justin_oaks超过 1 年前
I&#x27;ve been the employee who describes what needs to be done to improve security, only to be ignored. And then some rando off the internet makes note of the security shortcoming in the product and suddenly the boss is going crazy. He says stuff like &quot;Why didn&#x27;t anyone tell me about this?!&quot; And fixing the issue needs to be done yesterday. No, no time to fix it properly, let&#x27;s slap together whatever we can and rush it out.<p>So glad I quit that job.
评论 #39220769 未加载
评论 #39230930 未加载
rsync超过 1 年前
This reminds me of something we wrote a few years ago about PCI compliance:<p><a href="https:&#x2F;&#x2F;rsync.net&#x2F;resources&#x2F;regulatory&#x2F;pci.html" rel="nofollow">https:&#x2F;&#x2F;rsync.net&#x2F;resources&#x2F;regulatory&#x2F;pci.html</a>
datadrivenangel超过 1 年前
The misaligned incentives for security is the core issue, so stronger regulation is needed. Breach happens? entire executive team ought to get most of their remuneration clawed back.
评论 #39323816 未加载
mmvasq超过 1 年前
No one disagrees. Consider project management; for example, which has had many failed projects, has evolved, is still incredibly imperfect. Health care services, have had many flaws, continue to evolve, are still incredibly imperfect. Marketing, has had many flaws, has advanced, is imperfect. Pick one or two problems and advance them. Try not to kill people in the process which is all too common in tech.
评论 #39217562 未加载
MattPalmer1086超过 1 年前
This may not not a popular opinion, but this honestly comes across to me as a sad rant that has nothing worthwhile to say about security.<p>Consultants get paid to come in and advise, and internal staff are ignored? Suck it up, it&#x27;s not a problem particular to security. I&#x27;ve seen it everywhere.<p>People don&#x27;t choose hospitals because of their security program? Well, duh. They don&#x27;t choose hospitals for all kinds of non medical reasons that are still vital for the damn thing to function. Get back to me when you&#x27;re in surgery and the whole hospital goes down in a ransomware attack.<p>Honestly, if I had to listen to this person on my team for more than 10 seconds, I&#x27;d be on the phone to Deloitte before you could blink.
thatfunkymunki超过 1 年前
Yeah, it&#x27;s basically true
toomuchtodo超过 1 年前
Shouting truth into the abyss. Great read. My CISO chuckled.
blakesterz超过 1 年前
I think the &quot;Your&quot; got dropped from this. Should read:<p>You Security Program Is Shit