logoalt Hacker News

cluckindanyesterday at 12:59 PM3 repliesview on HN

If this was in the US, all financial institutions need to audit their code to comply with NIST SP 800-53.

If they haven’t, it would be ethically dubious for you to not report it.


Replies

jacquesmyesterday at 5:36 PM

In theory there is no difference between theory and practice, but in practice there is.

> If they haven’t, it would be ethically dubious for you to not report it.

I can report all I want, someone needs to act on that report for it to have an effect.

There are people out there who think that some static analysis tool plugged into their CI/CD pipeline is the equivalent of a code audit.

show 1 reply
drw85yesterday at 4:14 PM

In my experience, most devs and companies don't consider the dependencies they load 'their' code. They only look at the code they write, not everything they deploy.

DamonHDyesterday at 4:18 PM

These were all multinationals, with very significant US presence.