Hacker News new | ask | show | jobs
by rmc 5007 days ago
"security" is not just programming, but the whole methods & procedures. They might have good 'programming', but they had bad policies and bad security. If there's an email account of a founder, that when compromised, leads to the entire contents of your bank vaults being robbed clean, then you have bad security.

It should not be possible for there to be a virtual machine console, or for one compromised email account to give you that much power. That's how you do security.