3 ms·
Being easy to reason about is so important. In my experience this is somewhere Security teams often make what I consider mistakes. Although something may appear
by fullsend 4y ago
Being easy to reason about is so important. In my experience this is somewhere Security teams often make what I consider mistakes. Although something may appear to make the system more secure, it can make it much more complex, and then troubleshooting it or changing it becomes so burdensome that people skip upgrades, use weak passwords, and a litany of other workarounds to be able to actually use the thing to do their work. You also have no visibility into where holes might be. For example by creating unique interfaces for every operation, you do separate concerns. You also ensure no one will have time to review them all. Interesting tradeoffs.