4 ms·
The idea is for you to stop. Regulatory capture and learned helplessness. The costs of compliance require deep pockets. When you look at what they actually do,
by deckard1 4y ago
The idea is for you to stop.
Regulatory capture and learned helplessness. The costs of compliance require deep pockets. When you look at what they actually do, then it's obvious it's just theater. You'll see so many comments on HN that persuade you that security and privacy are too complex for you to handle (learned helplessness). It doesn't matter if your org is 2000 people with entire departments focused on compliance. Security and privacy will always be somewhere out there on the horizon. A mythical thing that no one can obtain. Definitely not a sole developer working alone in their bedroom. So better not try.
Which is a bit crazy that this blog post is targeting "developers". As if developers care about any of this stuff. Executives at large corporations do. But those same developers working at that same company are off in agile land working on micromanaged tickets. They don't have a say in SOC. Not in whether it's worth it, not in how information is collected. Not even in how information is stored, in most cases. Because, again, SOC is top-down. Not bottom-up. The same executives pushing SOC are the same ones pushing Google Analytics. Theater.