logoalt Hacker News

RandomLensman • today at 6:01 PM • 1 reply • view on HN

If you make not reporting potentially worse than reporting, why not?

Also, why would it come down to single persons always? Mandating processes, controls, clearances, etc is also something done in various areas.

You can put incentives in to make sure organizations monitor and report vs trying to hide things.


Replies

solenoid0937 • today at 6:05 PM

> You can put incentives in to make sure organizations monitor and report vs trying to hide things.

Yes, this is exactly my point. Fining companies large % of their revenue and throwing their engineers in prison is not the way to get them to report these issues.

> If you make not reporting potentially worse than reporting, why not? Also, why would it come down to single persons always? Mandating processes, controls, clearances, etc is also something done in various areas.

Hiding things is way easier than finding things. Take the model hacking incidents. They could have just done their searches in a way that didn't turn up anything. Then they could say, "well, we did look for it..."

As far as auditing goes: I've never met an auditor that doesn't find something the company isn't okay with them finding.

➕ show 1 reply