Earlier quoted context omitted.
>it shifts accountability away I agree. I think what we are split on is purpose/intent. >could not reasonably be expected to protect against. Why not? If I'm hiring a cybersec thats probably in my top 3 reasons to hire them, if not them then who? Number one is probably compliance/regulation. > “get out of jail free” This is one of my red flags I also keep seeing. Whoops we can't do the thing we say we do. The entire…
> I agree. I think what we are split on is purpose/intent. I… don’t think so? Your original comment was that companies claim nation state attack as a way to get government funding. That has nothing to do with assessing blame for an attack. > Why not? If I'm hiring a cybersec thats probably in my top 3 reasons to hire them, if not them then who? If you think you as a private entity can defend against a tier 1 nation s…
do you mean they pay companies to put backdoors into products? or you mean they just go hunting for vulnerabilities. maybe both?