|
|
|
|
|
by acdha
1220 days ago
|
|
The possibility of something being done poorly doesn’t mean that it can’t be done more thoughtfully. For example, most banks will refuse to let you do online banking using IE6 or SSLv3 and pretty much everyone is okay with that because the risks are obvious. That’s always the tradeoff you have to make since you’re balancing the benefits to the user and cost of development - customers do benefit if you can ship better things faster because you’re not held back by discontinued browsers. <dialog> might not be there quite yet but it’s close and if you already don’t support IE11 there’s an obvious appeal. |
|
What I would proprose then is, that companies should state their minimum security requirements to work with any other entity somewhere publicly available, so that it will not be something ad-hoc invented for some entity.
I have seen companies trying to treat smaller ones like some kind of supplicant entity, that one can push around and ask about interna, that could easily lead to the bigger company building a copy of the smaller company in a few months, since they got much more workforce to put to it, if they really wanted. Asking for things like "architecture diagrams". I am quite sure, that big companies will laugh you out of the room, if you asked them to provide same for their architecture.