Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The whole "it wasn't us, it was our third-party vendor" line is getting way too common. If you're collecting government IDs for age verification, the security bar should be extremely high... no matter who's handling the data


But our subcontractor made a contractual promise to use only sub-subcontractors who use only sub-sub-subcontractors who promise to be secure!


Ahh I see you've done work for the government.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: