logoalt Hacker News

jacquesmtoday at 7:08 AM2 repliesview on HN

Yes. But I'm not working at either company and I'm 99.9% sure that it would lead to absolutely nothing other than a lot of misery for myself. The NDA's I sign have some pretty stiff penalties attached. I was actually hoping to see my trust in the auditing company confirmed and I'm still more than a little bit annoyed that they did not respond in a more constructive way.

My response however is a simple one: I used to steer (a lot of) business their way and I have stopped doing that.


Replies

maxbondtoday at 7:29 AM

Wouldn't it require a huge leap of faith for them to admit the audit was improper in order to have that discussion? Who's to say you aren't recording?

show 1 reply
madaxe_againtoday at 7:46 AM

Similar boat. Seen the same shenanigans being played with actors who really should know better - everything from military secrets to medical data, and absolutely YOLOing it with an audit mill. I have it on good authority that there are superuser credentials floating around for their production systems that they’ve lost track of.

And no, I won’t whistleblow either, as it would mostly be me that would face repercussions, and I am unafraid to say that I am a coward.

We choose the battles we fight, and I’d like to believe that ultimately, entropy will defeat them without me lifting a finger.