3 ms·
> let's also realize that most of these organizations use proprietary software (untrustworthy by default) This is completely incorrect. The only example of a d
by midev 9y ago
> let's also realize that most of these organizations use proprietary software (untrustworthy by default)
This is completely incorrect. The only example of a data breach you gave was a result of open source software (Apache Struts for Equifax). Open source software has contributed to plenty of data breaches, and I seriously doubt you've ever audited the millions of open source packages and dependencies you're using.
This is bad corporate security, by believing this type of nonsense. Then you'd inadequately assign risk, and fail to protect against real threats, instead focusing on 1990's "M$" risk.
> How proprietary software works is a secret
I don't need to know how exactly software works to make calculated decisions about risk. We sign vendor service agreements with other companies, that give us assurances about their data handling practices, their audit/compliance history, etc. I can look at how vendors manage their PSA process, how transparent they are with security disclosures, things like that.