> The stance you take is harmful when said organizations are responsible for the stewardship of the data of others
Do you make a habit of visiting banks uninvited to test their vaults?
Do you make a habit of visiting banks uninvited to test their vaults?
The analogy doesn't hold when applied to the digital services we all depend upon as such assurances are impossible.
Rather than allowing anyone to try to crack a server as long as they claim to be a white hat, I'd much rather require corporations to go through a standard, "extensive third-party verification of security practices that may be publicly audited upon request" and default cracking attempts to "illegal."
I may be misunderstanding something in what you're saying, though -- if I am, could you clarify that for me?