Earlier quoted context omitted.
Yeah but when you partner with companies, they sometimes force your company to adhere to those ancient guidelines. I’ve worked for companies where they ask for the out of date NIST stuff you mention and it’s either you follow what they ask or you lose out on a deal to fund your company.
If you require PCI DSS compliance it won't fly either. https://pcipolicyportal.com/blog/pci-compliance-password-req...
SaaS CTO Security Checklist
111–114 of 114 posts
Re: SaaS CTO Security Checklist
#112Discussed previously: https://news.ycombinator.com/item?id=16615593 In the year this has percolated with me, I've grown to actively dislike it. I have three major problems with it: 1. This cutesey "seed, A, B" triage scheme is misleading. In reality, you can break everything down into just two categories: "do it before product/market fit" and "do it after product/market fit" (or "now" and "later", or whatever you'd l…
Taken by itself the suggestion is odd, but in concert with the next entry "use password management software" it makes for a low-cost, zero management, higher security stance than not suggesting 2FA by itself. Noone should ever ignore the option to turn on 2FA.
Re: SaaS CTO Security Checklist
#113Earlier quoted context omitted.
If you require PCI DSS compliance it won't fly either. https://pcipolicyportal.com/blog/pci-compliance-password-req...
If you require PCI DSS I hope you're not just blindly following some random post on hackernews for your policy ;)
Re: SaaS CTO Security Checklist
#114Earlier quoted context omitted.
Yeah but when you partner with companies, they sometimes force your company to adhere to those ancient guidelines. I’ve worked for companies where they ask for the out of date NIST stuff you mention and it’s either you follow what they ask or you lose out on a deal to fund your company.
If you require PCI DSS compliance it won't fly either. https://pcipolicyportal.com/blog/pci-compliance-password-req...