Hacker News new | ask | show | jobs
by tptacek 1373 days ago
It's not actually that unusual to absorb security into engineering; if engineering is already doing most of software security, and engineering/ops is already handling IT security, then the rest of security might in fact be duplicative of stuff third parties can do just as well.

I have no inside knowledge as to whether this was the case at Patreon; no opinions about Patreon whatsoever. But re-orging security into and out of engineering is not unprecedented.

1 comments

You're right that having security report to engineering is not unusual. It's also not a great idea due to conflicts of interest, but not unusual.