Remix.run Logo
pragma_x 5 days ago

I think it presents a conflict of interest. Considering we're talking about system security, it's best to not leave this up to the ethics of just one team.

Also: a lot of development teams in security-oriented fields are doing a lot of self-investigation and improvement anyway. Red Teams still have value, and prove that time and again, in spite of that.

IMO, having another team attack your stuff also creates "real" stakes for failure that feel closer to reality than some existential hacker threat. I think just the presence of a looming "Red Team Exercise" creates a stronger motivation to do a better job when building IT systems.