Earlier quoted context omitted.
> the systems should be tight enough to make sure absolutely no-one has access to customer data without consent - and that any actions taken are logged for auditing. You haven't really done OpSec have you? There is very little absolutism in defining who gets access to what data. In fact barring nations that have historically shared data with their governments is exactly one step closer to how you would achieve this.…
> "You haven't really done OpSec have you? There is very little absolutism in defining who gets access to what data. In fact barring nations that have historically shared data with their governments is exactly one step closer to how you would achieve this." When was the last time you've contracted for a serious client? When it comes to tech - you don't implement "OpSec" by blanket banning hiring Chinese/Russian indiv…
Uhh, today? I have about 20 on-going contracts with "serious clients", which include manufacturers, distributors, software companies, etc. What's your point?
> When it comes to tech - you don't implement "OpSec" by blanket banning hiring Chinese/Russian individuals. Disregarding your bizarre definition of "OpSec"
Banning hiring from countries isn't an exclusively isolated tactic for executing OpSec...I'm not sure why you implied that.
> Those companies actually invest into background checks, have dedicated security teams, are investing into locking networks down and improving monitoring.
Those companies all have physical presences in those countries. Gitlab does not. BIG DIFFERENCE.