Hacker News new | ask | show | jobs
by dmix 837 days ago
> These companies have gotten burned

Have they really though? Usually companies overreact to a lot of social media outrage that would blow over in a couple days. But their very online PR/social media employees turn everything into an emergency. Imagine infosec people making every CVE a big deal, you’d end up with a needlessly limited system - that ironically doesn’t satisfy anyone, because the infosec people will always have a new urgent CVE tomorrow.

This automatic fear based approach to doing anything, without actually balancing risks and tradeoffs, is its own ritualistic system of self-harm. Companies burning themselves on the stove.

1 comments

> Imagine infosec people making every CVE a big deal, you’d end up with a needlessly limited system - that ironically doesn’t satisfy anyone, because the infosec people will always have a new urgent CVE tomorrow.

That already exists, it's called SIPRNet, and it satisfies several millions people in their day to day job.