logoalt Hacker News

solenoid0937 • today at 6:05 PM • 1 reply • view on HN

> You can put incentives in to make sure organizations monitor and report vs trying to hide things.

Yes, this is exactly my point. Fining companies large % of their revenue and throwing their engineers in prison is not the way to get them to report these issues.

> If you make not reporting potentially worse than reporting, why not? Also, why would it come down to single persons always? Mandating processes, controls, clearances, etc is also something done in various areas.

Hiding things is way easier than finding things. Take the model hacking incidents. They could have just done their searches in a way that didn't turn up anything. Then they could say, "well, we did look for it..."

As far as auditing goes: I've never met an auditor that doesn't find something the company isn't okay with them finding.


Replies

RandomLensman • today at 6:15 PM

Hiding things is not necessarily trivial when a lot of processes and controls ars mandated. For starters, could just try to make incidents themselves less likely. Not looking in certain specified ways might also not be an acceptable option, for example.

Why do you think we even have regulations for how to deal with dangerous things then?

➕ show 1 reply