Is ‘fulfilling legal requirements’ all you look for in a business relationship?
A restaurant has no legal requirement to make this food tasty but it’s what I’m looking for when choosing where to go.
Is ‘fulfilling legal requirements’ all you look for in a business relationship?
A restaurant has no legal requirement to make this food tasty but it’s what I’m looking for when choosing where to go.
I think many engineers often overlook the business implication of disclosing security issues, as it would impact multiple business units as well as the board's stance on security, resource allocation, and potentially the stock price too.
>A restaurant has no legal requirement to make this food tasty Food is a core deliverable for a restaurant, whereas information on a potential breach is not for a SaaS service unless it is legally required.
GH has no evidence this was not exploited. They just didn't log enough things to know if it was exploited or not.
I couldn't care less. I want value as a customer. Any company that prioritizes stockholders to customers doesn't deserve my customer money.
Unfortunately, people got used to this practice and gladly accept when such companies fulfill all their legal obligations, even when this hurt them or their business.
Somewhat tangential but I'm not even sure that's entirely true. It gets all sorts of tricky due to the subjectivity, but surely fit-for-purpose laws apply here? I'd be really surprised if a five star restaurant selling $500 tasteless gruel with chunks wouldn't manage to get into trouble if they refused refunds.
[1] - https://www.nbcnews.com/news/world/ants-cod-liver-moss-denma...