Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

First punish them. Then change the laws.


In many countries, that'd trigger an automatic release/repayment of unjustly sentenced fines.


I bet you and my "first build the product, then worry about security" manager would get along.


That one is tough, because they are blind to the risk. I try to only work with people who have been burned before or have been around long enough to have seen the aftermath. Let me guess, they are probably telling you "show me the vulnerability", but refuse to delay shipping or fund the PoC.

Best advice is to communicate in writing the most likely risk and threat scenarios, with as much data or extrapolated data as possible. When the security flaws are later discovered, that is data you can refer to.

From what I read, this is what Zoom was like early on. They had amateur hour security and then when s*t hit the fan they beefed it up and retained a security team. I guess you could say it worked for them?


My approach is same. First fire that manager. Then define security.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: