Hacker News new | past | comments | ask | show | jobs | submit login

Why do that when you can wreck a security engineer’s vacation?



Can a company the size of Apple not afford 24x7 security resources? For their installed user-base, I don't think this is unreasonable. Security doesn't have a holiday.


Why would your security engineer take CVE-2008-0001 as a holiday?


On the other hand, it could teach a good lesson on technical debt?


I would claim that there is a very high likelihood that the person having to work all night to fix this on new years Eve is not the same person who prioritizes tech debt pay off vs. new features.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: