Hacker News new | ask | show | jobs
by dmix 2503 days ago
I'm guessing Coinbase hiring a pentester and giving them 'employee level access' would be a needless formality?
1 comments

People do internal pentests even though everyone knows the pentesters will win; you still learn something from the experience.
You’ll never be able to prevent privileged insiders, or their accounts, from being able to cause damage. But I have worked with organisations where internal tests were not able to compromise the most critical assets, and where the outcome of the tests was those assets become even more well protected. Which is really the best outcome you could be hoping for with these kinds of engagements, imo.
Of course, I was just being cute.