Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Much of things boils down to doing a risk assessment and deciding on mitigations.

So... paperwork, with no real effect, use, or results. And you're trying to defend it?

I do agree with need something, but this is most definitely not the solution.




Putting in mitigations relevant to your size, audience and risk factors is not "no real effect".

If you've never considered what the risks are to your users, you're doing them a disservice.

I've also not defended it, I've tried to correct misunderstandings about what it is and point to a reliable primary source with helpful information.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: