Hacker News new | ask | show | jobs
by bobdole123456 2807 days ago
The difference here is that Google found this problem itself, and evaluated with high confidence that it was likely unknown to anyone outside that audit.

That means that Google was proactively checking it’s work to make sure it was secure, unlike your example where nobody was likely ever going to notice that bucket was misconfigured.

They’re the gold standard because they find and clean up their own shit, even when nobody is pressing them to do it.