Hacker News new | past | comments | ask | show | jobs | submit login

Publish procedures?

Yes. Generally speaking, an open and auditable system is more robust and secure than a closed and non-auditable system.

There are obviously limits (e.g. publishing what specific VLAN numbering scheme you use is obviously not helpful to anyone and just provides information that wasn't known).

But yes, it is best practice to publish and accept feedback on generalized procedures.

You should sign up for the MDSP dev-security-policy mailing list and see how the (open) conversations have continued to improve security for all.




fully audited absolutely yes, feedback come internally with many (100's) of technical/ network architects poking and proding

I fail to see any positives in openly publishing anything, unless you provide an extememly very detailed view - I see only negatives




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: