Hacker News new | ask | show | jobs
by handrous 1641 days ago
> Because if not, aren't you just adding another attack vector onto all your employee/contractor laptops when you use 'Drata' to check a policy box on your SOC2 application?

I have bad news: gaining security certifications mostly through pointless or even harmful measures is the norm.