Hacker News new | ask | show | jobs
by sergimansilla 1815 days ago
I think the problem here is with the definition of “secure system”. What is “secure enough”? Considering we’re talking about groups that have resources to buy 0-day exploits, if they want to get in, they’ll eventually will.

Sticking with your analogy, we could probably define a set of standards for baseline IT security for all IT systems…but it probably wouldn’t be very useful. Systems vary so wildly in complexity and scale that coming up with the equivalent of a “code” that fits most systems like we have with electrical installations is impossible.