Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This fails to satisfy one of the core lessons here: trust nothing, not even your own training and culture.


Reminds me of a situation early in my career where I was talking with the CTO about some security concern and I said "well it's all on the internal company network" and he immediately said "why on earth do you think you can trust our internal network?"


So I take it you are employed by someone that allows you to connect to nothing and change nothing? Because if you can do any of those things, your employer is clearly Doing It Wrong, based on your interpretation.

(If you happen to be local-king, flip the trust direction, it ends up in the same place.)


Especially not the information security team. They're the most likely to be compromised.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: