• jet@hackertalks.com
    link
    fedilink
    English
    arrow-up
    13
    arrow-down
    1
    ·
    2 years ago

    I think the security researcher has a valid point.

    In a secure environment you don’t want random things running in memory, sending samples to third parties.

    Would a static virus scanner run periodically on the volume itself been sufficient? If yes, then the researcher was being unreasonable.

    • flying_sheep@lemmy.ml
      link
      fedilink
      English
      arrow-up
      4
      ·
      2 years ago

      Totally reasonable to not do a dumb thing if you have no contractual obligation to do the dumb thing.

      Sadly they had that obligation, so they have to weigh the cost of doing the dumb thing with the cost of breaching contract.