HN user

lousken

1,634 karma

sysadmin

Posts3
Comments849
View on HN

They see their dashboard, when the number is high, they want to get the number low as fast as possible. If the number is close to zero, they want to see zero. It is that simple.

They do not care if the issue is in a piece of code that is never executed and would require full access to the machine. It is there and tool X reports it.

Even security audits are terrible, when they don't find anything major they start reporting stuff that few percent of companies have implemented just to stuff their reports, it is ridiculous.

It depends, I guess if they still dont care about losing money or they already had subscriptions then they keep using them, likely either openai or anthropic. If they noticed the bill going up, like with github copilot, they are looking at the alternatives.

Often they do not even know where the data is. It only becomes a problem if it is not available all of a sudden.

My most recent - "I can't search my mailbox because exchange online is broken?" - new outlook + 180days offline cache max + online only search

It would be nice to have defaults that are following regulations because it sucks to have and maintain explicit list. If it would be a simple toggle - secureciphersonly=yes sure, but listing them is just creating tech debt.