Hacker News new | past | comments | ask | show | jobs | submit login

You didn't really address the point you quoted.

The problem isn't that someone is getting IN; it's that the company throws up their hands and says "tough sht."

Or in a worse case, when Equifax puts up a compromised site to find if you were hacked that requires a significant amount of your SSN and personal details.

(edit: format)




> it's that the company throws up their hands and says "tough sht."

What exactly is your solution to the problem? You are more or less complaining without providing any insights into addressing the issue or without knowledge of the threat landscape.


Spending money on security architecture/engineering/pen testing/etc in concert with government regulation/oversight.

Full disclosure: I work in security architecture/risk management in the financial services industry.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: