Often, ridiculous and onerous procedural security is hiding massively incompetent actual software security or is used to constrain people from discovering security by obscurity holes. Everything I've done in government interfacing as a vendor would seem to confirm this, at least back when I was doing it a few years ago. You'd be hard pressed to convince me it's changed much since.
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments