Hacker News new | ask | show | jobs
by MatthewElvey 4983 days ago
"Mint attested to doing quarterly external audits?" Really? It seems they didn't, or at least I can't find evidence or mention of it, and Mint support doesn't know about it.

A Hackersafe pen test is not a security audit. A public company SEC-required annual audit is not a security audit either.

There is no audit if there is no public audit statement from the auditor. Without one, whatever security measures were taken cannot be called an audit.

Perhaps some reporters (like the ones that reported on the WMD-based justification for going to war against Iraq) didn't do their jobs properly.