HN
Hacker News
Top
New
Best
Ask
Show
Jobs
Comment by NovemberWhiskey | Hacker News Reader
Parent
Full thread
NovemberWhiskey
·
t.b.h. all this tells me is that your pentesters are bad.
View on HN
cyberpunk
·
Bingo. We don't get to choose them, though, and they hold the strings on the certifications that our business needs. Sometimes it's easier to bend.
bonzini
·
You used to pay Red Hat, did you try passing them the hot potato?
attentive
·
If they make a claim that some package has CVE and you can demonstrate that to be false as per official distro changelogs etc they can go hike.
_ea1k
·
The problem is that if they don't fix the tool, you'll get to tell them that every week (or however often they scan).
Dealing with bad security audits isn't fun.
mshook
·
Pretty much but that's my experience as well, I made the same comment above...
Reply on news.ycombinator.com