4 ms·
Yeah like when we bundled in a .js library for client side date processing that has a CVE affecting node.js servers with high score. Our auditors don’t care th
by icameron 1y ago
Yeah like when we bundled in a .js library for client side date processing that has a CVE affecting node.js servers with high score. Our auditors don’t care they tag the whole app as high risk. It doesn’t even run on the server!
- czk 1y agothe auditors that sign off on your security to meet your clients requirements usually know way less about your security posture than your clients do its all just surface-level box-checking. most companies required to get 'penetration tests' just get an overpriced Nessus scan sold as a pentest and that meets their reqs.
- JohnMakin 1y agowhile this is true it in no way diminishes the value that orgs like cve provide
- jeroenhd 1y agoIncompetent auditors don't detract from the classification system, though. If we removed every data point auditors misinterpret or don't care to understand, we may as well remove all metrics.