I think it depends on team dynamics. On a team I was on (Fortune 100 company), a techlead would just buddy up with a very junior one, and have them rubber stamp their code review. The techlead almost committed a bug similar to one in this post- I had to step in and leave a review comment to prevent this vulnerability. I almost wanted to have it shipped to get back at at these code review buddies, but decided against it as I valued not having a vulnerability more.
Not FANG, but at Fortune 50 company. I can second to this.
There are teams that move quickly, use new technology, create new products.
But most of the SWEs work on mature products with moats- the development is slow because of the complexity of the product, and redtape.
Interesting :) Follow up, trying to cement my understanding here.
If two devices may talk to each other (as defined in the ACL), only then they get to know each other's public keys, right?
If so, how would this ACL be negated later- do the devices forget eachother after this disallow?