top | item 24352576

(no title)

wardnath | 5 years ago

Agreed. This pretty much applies with any data & tool. If the data is extra sensitive, make extra sure the tool you are using is secure. If your data is for dev purposes only, the tool doesn't have to be validated as thoroughly.

discuss

order

beardedwizard|5 years ago

Wow really? Lateral movement is very real, your mindset is dangerous.

wardnath|5 years ago

That is a good point to make. If the development data can lead to exfiltration of higher privacy data then I would define it as "more sensitive" and take that into consideration, this particularly applies to config information required for authentication. I understand your perspective however, it is important to take lateral movement into account.

thinkloop|5 years ago

He addresses this. He mentions leaking implementation details, and possibility for mistakes.