Hacker News new | ask | show | jobs
by screeno 862 days ago
Truthfully it’s not unlike working with a security consultant.
2 comments

Or internal security - who look at your system and say doing that process that way is insecure please change it. When you ask how (as you aren't a security expert) they say not our problem and don't say how to fix it.
Sounds like you have a bad infection of security compliance zombies.

You should employ some actual security experts!

In the security team there were experts but I suspect the issue was that if they suggested a solution and it did not work or I implemented it incorrectly then they would get the blame.
A security consultant tells you best practice, they do the very opposite of not letting you know how things work.