4 ms·
> It's laudable that they invested in penetration testing I don't think they should be lauded for doing their jobs and discovering they failed at them. If your
by hackuser 10y ago
> It's laudable that they invested in penetration testing
I don't think they should be lauded for doing their jobs and discovering they failed at them. If your QA team discovers huge numbers of bugs, you don't laud yourself for doing QA.
If a leading accounting firm hires an outside auditor and discovered their own books were rotten, should they be lauded? I guess there's a silver lining in everything.
I guess I'd be willing to trust Palantir's advice on hiring penetration testers, but not on securing my systems.
- dsacco 10y agoTo play devil's advocate: there is a reasonable expectation that an organization's accounting is legally and correctly balanced. It is not a reasonable expectation that software, even security software or software developed with security expertise, is secure.
- homunculus 10y agoI would say you can reasonably expect that unaudited software is not secure and that unaudited books are not legally and correctly balanced.
- jsprogrammer 10y agoWhy would you trust them in hiring pen testers? Their systems might have been so bad that any one attempting could have gotten in and thus firm was just lucky enough to get the contract.