3 ms·
> BTW I'm quite wary of "security products" for enterprise; it reeks of antivirus software writ large. That said I can see some benefit to services like audits,
by thrownawayalrea 7y ago
> BTW I'm quite wary of "security products" for enterprise; it reeks of antivirus software writ large. That said I can see some benefit to services like audits, or even things like honey pots or "dark net scans" for detecting leaks. But something tells me that's not what you're talking about...
The product itself is quite reasonable on paper [1]. (And, yes, it would provide value even if all of the software industry would ramp up their security practices, so it's not a band aid like antivirus software.) The execution is the problem. Despise selling "nation state attacker secure" appliances, we are not internally focusing on producing a high security product but give priority to certifications and features. The disconnect between marketed identity and day-to-day developer experience is breathtakingly depressing... at least to those of us who have an interest in security. Management doesn't care of course. It sells (because of certification and little alternatives on the market), so all is well.
[1] Sorry for being so vague. Given the set of statements I've given already, anything more would make me personally identifiable to my coworkers.