Loading comment...
Loading parent story...
Loading comment...
These unknown companies called Microsoft, Oracle, Salesforce, Apple, Adobe, … et al have all had these controversies at various points.
Also, something being a liability and something having upkeep costs are not the same thing.
What would your definition of /liability/ be then? 'An ongoing commitment to pay future costs' is a pretty good one.
> I thought I was just going to be given my passport and sent on my way, or maybe asked a couple of questions, but they made some pretty outlandish accusations. They said, ‘We know you have two mobile phones. We’ve been tracking your calls. We know you’ve been selling drugs’.
https://www.theguardian.com/us-news/2025/apr/11/australian-w...
That's why you install endpoint security tools. That's why you're forced to fulfill all kinds of requirements, some of them nonsensical or counterproductive, but necessary to check boxes on a compliance checklist. That's why you have external auditors come to check whether you really check those boxes. It's all that so, when something happens - because something will eventually happen - you can point back to all these measures, and say: "we've implemented all best practices, contracted out the hard parts to world-renowned experts, and had third party audits to verify that - there was nothing more we could do, therefore it's not our fault".
With that in mind, look at the world from the perspective of some corporations, B2B companies selling to those corporations, other suppliers, etc.; notice how e.g. smaller companies are forced to adhere to certain standards of practice to even be considered by the larger ones, etc. It all creates a mesh, through which liability for anything is dispersed, so that ultimately no one is to blame, everyone provably did their best, and the only thing that happens is that some corporate insurance policies get liquidated, and affected customers get a complimentary free credit check or some other nonsense.
I'm not even saying this is bad, per se - there are plenty of situations where discharging all liability through insurance is the best thing to do; see e.g. how maritime shipping handles accidents at sea. It's just that understanding this explains a lot of paradoxes of cybersecurity as a field. It all makes much more sense when you realize it's primarily about liability management, not about hat-wearing hackers fighting other hackers with differently colored hats.
Yes, 'cyber' security has devolved to box checking and cargo culting in many orgs. But what's your counter on trying to fix the problems that every tech stack or new SaaS product comes without of the box?
For most people when their Netflix (or HN) password gets leaked that means every email they've sent since 2004 is also exposed. It might also mean their 401k is siphoned off. So welcome the annoying and checkbox-y MFA requirements.
If you're an engineer cutting code for a YC startup -- Who owns the dependancy you just pulled in? Are you or your team going to track changes (and security bugs) for it in 6 months? What about in 2 or 3 years?
Yes, 'cyber' security brings a lot of annoying checkboxes. But almost all of them are due to externalities that you'd happily blow past otherwise. So -- how do we get rid annoying checkboxes and ensure people do the right thing as a matter of course?
Waymo is like the most courteous, respectful driver you can possibly imagine. They have infinite patience and will always take the option which is the safest for everyone. One thing which really impressed me is how patient they are at crosswalks. When I'm jogging, a Waymo will happily wait for me to cross - even when I'm 10 feet away from even entering the crosswalk! I don't know if I even have that much patience while driving! I've had a number of near misses with human drivers who don't bother checking or accelerate for no reason after I'm already in the crosswalk. Can you imagine a Waymo ever doing that?
If I see a Waymo on the street near me I immediately feel safer because I know it is not about to commit some unhinged behavior. I cannot say enough good things about them.
I still remember the first time I went through a four-way stop intersection and saw a driverless car idling, waiting for its turn. It was weird and nerve-wracking. Now… I’d much prefer that to almost any other interaction at the same spot.
But their enterprise strategy destroys their good will. I can only assume it's focused on killing old school VPN products. The free tier that we love is a marketing expense. And it’s not even a conversion play.
People are complaining about ~10/user/month -- add basic things that you'd need to manage more than 10 peeps (SAML/SCIM support) and you're talking ~20/user/month. For us, a small sub 200 person company, they immediately lost their chance. We have lots of problems in the security space, some we're willing to spend more than 20/user/month to solve. Legacy network access is not one of them.
Loading parent story...
Loading comment...
I tried web apps before but iOS would cut them off when the phone went to sleep.
https://apps.apple.com/us/app/meditation-timer-zenitizer/id6...