Hacker News new | ask | show | jobs
by cm_silva 1258 days ago
Exactly this. Security is more about about defense-in-depth, incident response and recovery planning.

Personally, I assume the hardware is already compromised and plan for recovery accordingly, starting with the worse case scenario. Then, I ask myself "If this thing isn't compromised yet, how can I help it stay so?", starting probably with the network access, through firmware, all the way to the browser.