Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Im just saying that all it takes is one employee to click onto the wrong URL to breach your apps security. I am not talking about the app itself. You can have all the security implemented the world has to offer and yet you cant get rid of human errors.


I'm totally not understanding what you're saying then.

> Im just saying that all it takes is one employee to click onto the wrong URL to breach your apps security

Pretend I'm a signal employee. What link can I click that breaches the app's security?

They don't store unencrypted data, pushing source code changes requires review, releases are signed and a single employee can't compromise the release process, so I'm missing how one employee being compromised could lead to the signal app breaching signal's security.

Also, in practice, how often are apps compromised from a phishing attack? I don't even really see news reports on that, so I'm curious if you're operating off like a specific case or something.


Some malicious mail that grants remote access to the employees device? Its not that hard to understand.


Actually it is hard to understand because that employee's device isn't an attack vector.


It absolutely is. Every connection to your app also is a attack vector.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: