Hacker News new | ask | show | jobs
by btmiller 2169 days ago
Oof yeah you're not wrong! It was well-intended for sure, but you've made a good point regarding regulatory capture. How can we achieve both a) increased security beyond a your basic acronym certificate* and b) democratized access to startups?

Which set of levers can we pull to achieve the best outcome for everyone, I have no idea. Is it fair to compare this to the current aviation dilemmas? I don't want just anyone building a passenger jet, slapping a compliance sticker on it, and hop on board; very high stakes system. Yet at the same time, it's clear to see how Boeing infected the FAA to simply get their way and lockout newcomers.

* are PCI, PII, SOX, et. al. really that trivial and meaningless?

1 comments

Knowing that absolute security is a myth, it makes more sense to assume all the systems are insecure and proceed from there, placing only the appropriate level of trust in any system.