Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My incentives as an employee are similar. Far better to hide a problem than admit and fix it.


Covering up legit vulnerabilities is dangerous - it is a criminal offense. And no “my manager doesn’t like it” is not an effective defense (see uber ciso case)


> Covering up legit vulnerabilities is dangerous

It is incredibly hard to prove someone else knew about something you didn’t/don’t know about though.


That is a sign that you work at a deeply unhealthy company. Even at a moderately healthy company it's usual to have "Don't shoot the messenger" policies in place to avoid blaming developers for doing their job.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: