Hacker News new | ask | show | jobs
by dragonwriter 718 days ago
Its not a high-trust thing, these vendors exist largely because it gives the organizations with direct relations with consumers a step of removal when a breach occurs; they are blame-outsourcing firms.
1 comments

Sure, but companies also don’t want to deal with building the system themselves (especially if you want to support multiple countries) and dealing with potentially doing something wrong like violating anti-discrimination laws.
Surely you have some reasonability to vet your supply chain.

Not to say that your vendors have to be perfect, but if they have a known credential leak for 18 months that's pretty negligent.