Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Does your work computer only allow access to whitelisted websites? I hope not, because that would make it really hard to get anything done.

Security always involves trade-offs. Unthinkingly choosing the most restrictive policy every time is not a good security practice.



I'm speaking more from the database/XSS side of things, where a blacklist is about as useful as no list at all.

There are absolutely times where security has to be compromised, even abandoned, in the name of usability, and times where security must be ironclad, even user-hostile. Civil rights law is definitely the former.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: