2 ms·
> We don’t discuss all of our security processes and technologies in specific detail for what should be obvious reasons, but here is a high-level overview. Isn
by sumitgt 9y ago
> We don’t discuss all of our security processes and technologies in specific detail for what should be obvious reasons, but here is a high-level overview.
Isn't that the opposite of good practice? You shouldn't rely on obscurity. It's better to have the security processes out in the open so that it can be audited and flaws pointed out.
- xkcd-sucks 9y agoI think it's > We don’t discuss all of our security processes and technologies [with each other internally, so dumb stuff keeps happening]
- siler 9y agoYeah, I found this an important aspect of the article. I don't know anything about the culture at NPM, but this feels related to the mismanagement of communication with consumers/the public about the incident itself. i.e., being secretive for no good reason.
- detaro 9y agoDiscussing anti-spam/abuse systems in specific detail would be fairly unusual, can you name any larger operation that does? There's a lot of questions open that are non-specific to that though, so I'd agree that they could be sharing more.