Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It struck me that both in this case and Theranos, they exploited the weakness in "sampling audits" where external parties are shown only a sample of the product on the faith that the rest of the inventory is the same. Like showing a few machines and switching around the serial numbers here, or in Theranos case showing one blood test machine but not the off-the-shelf tester actually performing the assays. It's actually pretty difficult for an auditor to do an exhaustive search - what would they do, ask to visit 3000 machines?


Ask for a spreadsheet of the 3000 machines, pick one at random, and go visit it wherever it is (without warning them ahead of time). But auditors get lazy like everyone else.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: