Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Government may be incompetent, inefficient and slow, but at least they won't cut corners on security. For sharing tweets or something a startup can get the infrastructure done pretty quick, for something more serious (eg tax info) you really want a proper security team and proper insurance and legal advice.

VC's and advisors need to provide a platform to give startups those tools. For security using Google AppEngine or the Amazon cloud, combined with automated penetration testing tools, combined with some kind of cheap application security testing (does it exist yet?) might get enough of the way there, but would you really trust something so flimsy, run by two kids out of college who are working it out as they go, with your serious data?



You don't appear to know how security really operates in federal government software. They hire Booz-Allen-Hamilton for millions of dollars to come in with 200 consultants and produce a massive report declaring their software meets all "certification and accreditation" requirements. This document then goes on a shelf somewhere and government workers continue to email all kinds of PI data around in Word and Excel attachments because the software is so obtuse it's the only way they can actually get anything done.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: