Hacker News new | ask | show | jobs
by ChrisMarshallNY 2199 days ago
Weakest link.

That’s one of the issues an aggregate system (which describes any system of meaningful size, these days) has to deal with.

How many of the massive breaches we hear about, originate with dependencies or subcontractors?

1 comments

Speaking of, I always find it very telling that the knee-jerk reaction is to blame a dependency or subcontractor. That's the same mentality that says "paid for code must be better" when, last I checked, there aren't any more Windows phones, are there?

But there was a Windows password hash method in the early 2000s that could be brute forced on a single consumer grade CPU in less than 24 hours on their current-at-the-time flagship network server OS. So there's that...

I have no idea why you made that post.