Remix.run Logo
Twirrim a day ago

> Lots of teams that are supposed to be in charge of security don't ask "does this CVE affect us", but simply shift the burden of patching downward and outward

Unfortunately, I've had many a frustrating session with compliance auditors who do not care that it couldn't affect you, you're required to meet the PCI-DSS deadlines of 90 days for low, etc, and I've seen security groups force to accept that this is what they have to do, and then get the unfortunate task of dealing with engineers pissed off that them for forcing them to what security is being forced to do. Everyone's a whole big bundle of happy joy joy, all because of some stupid auditor following a stupid (but well intentioned) checklist.

josefx 3 hours ago | parent | next [-]

> auditor following a stupid (but well intentioned) checklist.

I once heard that the worst thing you can run into is someone who is both well intentioned and bad at their job.

pseudohadamard 6 hours ago | parent | prev [-]

At least it's got slightly less bad recently, it used to be 30 days critical, 90 days everything else, now you're required to perform a targeted risk analysis but it's still a lot of work to do.