Hacker News new | ask | show | jobs
by m3047 1116 days ago
Security is largely a quality problem, and quality is something you do not something you buy; this is why. For some reason I've latched onto baseball as my analogy for this.

A high-performing team has quality metrics, not only for the players but for the team. A high-performing individual outperforms a low-performing individual (a tautalogy for sure, definitional even). What qualities would you say the high-performing individual exhibits?

If you give both players high-quality or low-quality gear, what happens?

Can a baseball player who does a quality job of hitting home runs make better baseballs? Oh yeah: can they make better baseballs within the constraints under which baseballs are made? Why do those constraints exist?

The high-performing team is going to practice. They will wear out or destroy equipment in the process. Teammembers could potentially suffer career-ending injuries, during practice. During practice.

But when the real thing comes along, the practice is the deciding factor for performance individually and as a team.