Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The key idea is the very general principle that you increase security by reducing the scope of resources that you must trust.

cperciva is giving 2 examples: (1) use a service provider that doesn't require your trust. (2) limit the exposure of customer sensitive information to your employees that you must trust to keep it private.

I agree this is a better strategy than simply updating a privacy policy, as far as actual security is concerned.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: