Hacker News new | ask | show | jobs
by thwarted 4429 days ago
So then you're going to take at face value evidence provided by the party who hired the auditor? That sounds just as dubious as the claims of independence asserted by the hiring party itself!

It's entirely possible for one to look up an independent auditors credentials and history out-of-band. If you can't find anything to substantiate Github's claims of the auditor's record/independence, then call that out.