3 ms·
> I wish audit tools and corporate policies are smart The ball is in the court of the enterprise purchaser mandating the auditing company and they don’t give a
by ben_jones 3y ago
> I wish audit tools and corporate policies are smart
The ball is in the court of the enterprise purchaser mandating the auditing company and they don’t give a ** if your dev team has to hot swap a yaml parsing library
- jimbokun 3y agoThey should. They are paying devs a ton of money to futz around with code that works perfectly well and is just as secure today as it was yesterday. So you have security theater and TPS reports consuming the time of some of your most highly compensated human resources.
- anotherhue 3y ago> just as secure today as it was yesterday. Agreed but the gotcha is when a new issue comes out and there is no security fix available. It would be enough to say 'we are comfortable patching this if a CVE is found', but at that point they might as well start to maintain it.