Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> But I am surprised anyone bought it in the first place.

Possibilities:

* the company had nobody competent enough internally to evaluate it because nobody competent will work for them (either due to money or working conditions) so the company operates in a self-reinforcing feedback loop of mediocrity

* the objective of introducing the system is not true security (because that would be hard/costly/raising uncomfortable questions) but to mislead the users into a false sense of security, scoring PR points among the clueless while avoiding the costly "true security" work

* some people internally will benefit from this system being introduced regardless of the actual value it provides, so any concerns will be ignored - by the time those problems come to light, whoever benefited would've moved on or even been promoted and is out of reach of the consequences

These are not mutually-exclusive.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: