3 ms·
> However, please do not let the absolute state of things cause you to give up on security. I'm the security guy on our team and I'm pretty much over it. Once
by dogleash 1y ago
> However, please do not let the absolute state of things cause you to give up on security.
I'm the security guy on our team and I'm pretty much over it. Once you get a project's security up to baseline status quo, then the security community only produces tiny scraps of actionable input for improving something they're vocally unhappy with.
How did specialized QA from people who like breaking security controls for fun turn into acting like the business owner for security requirements? And also somehow getting away with a level of haranguing that we wouldn't accept from our actual stakeholders?