Hacker News new | ask | show | jobs
by mozzieman 483 days ago
It is all about backing up this question with confidence before asking it. Not about trust you earn over time but trust each time you ask it.

I require teams to do their own security reviews, that includes requirement gathering before shipping anything. If i get a "Anyone have any objections / concerns question"

I usually know directly if they just bullshitting and only done the minimal viable to get something out and want to be able to say "but i asked" or if they done their due dilligence.If the person only says short what they will do and just broadcast it. "Throws it over the fence". Imho is just bullshit. The people that are good have backed it up with explanations, proper knowledge about different areas what they are doing, presenting their thoughts and make sure stakeholders are informed in person or by good documentation and overall just come across like they know stuff. Then it is okey / good to ask like this to find out if you missed anything.