Hacker News new | ask | show | jobs
by ArcHound 171 days ago
Consider this situation: security review before a project go-live.

I have never seen this team before and I'll "never" see this team after the fact. They might be contracted externally, they might leave before the second review.

Let's say I can sus out people doing this. I don't have the option of giving them the benefit of the doubt and they have the motivation to trick me.

I guess I've answered my own question a bit, such an environment isn't built to foster trust at all.