4 ms·
While the core point is correct, and I am not arguing against it in the slightest... the concept of "secure-by-default" seems implausible because different syst
by codingdave 1y ago
While the core point is correct, and I am not arguing against it in the slightest... the concept of "secure-by-default" seems implausible because different systems have different requirements for what needs to be secure in the first place. I'm sure you could put in a scan that gives a warning that tells people if there is exposed PII, but beyond that basic level, how would a tool know the intent of any data access?
The goalpost should probably be set closer to automated communication of what data is accessible to what users and roles, which lets the users decide whether or not the observable results of a security scan do or do not match their intent.