3 ms·
"The U.S. military agency itself did not require a source code review before purchasing ArcSight and generally does not place such requirements on tech companie
by rmchugh 9y ago
"The U.S. military agency itself did not require a source code review before purchasing ArcSight and generally does not place such requirements on tech companies for off-the-shelf software like ArcSight, the Pentagon spokeswoman said. Instead, DISA evaluates the security standards used by the vendors, she said."
So the Russian government has higher security standards than the US?
- throwawaymanbot 9y agoThe Russians do. They even use typewriters in some dept.
- inetknght 9y agoDoes that surprise you?
- Retric 9y agoI don't know if that's really true. DoD gets the Windows source code for example.
- MikusR 9y agoSo does Russia.
- Retric 9y agoI don't see how that's relevant. Tools exist to audit anything on the windows CLR. So, from a security standpoint they have everything they need and can request the source code if any red flags show up. Sure, the source code is great if you want to maintain code. But, for a security audit it's often more deceptive than useful.