|
|
|
|
|
by zelphirkalt
1220 days ago
|
|
Maybe internally. If done externally, extorting your users to update their stuff, then it is clearly overstepping the boundaries. Creating awareness is good and necessary, but insisting on another entity, be it a user or another company doing something, because it is in your company's security benchmark, is inappropriate. Quickly silly things, that have no security benefit at all make it into that benchmark and are tried to be forced upon other entities. Suddenly a company will be interested in how you internally handle your SSH keys. Do you make new ones every 3 months? No sorry, every 4 months is too long for our security benchmark. |
|
That’s always the tradeoff you have to make since you’re balancing the benefits to the user and cost of development - customers do benefit if you can ship better things faster because you’re not held back by discontinued browsers. <dialog> might not be there quite yet but it’s close and if you already don’t support IE11 there’s an obvious appeal.