Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You should see the financial industry…


Or manufacturing. Or mining/oil. (I know we are getting away from the sensitive data part of the comment though. But this is how you get children digging thru cobalt pits with their bare hands)


Literally any industry.

I only have recruiters from companies that do this sort of work reaching out to me on LinkedIn. Whole companies where you are hired based on resume keywords.


Yuuup, there’s at least 4 layers there…


In my experience, even though there are layers of subcontractors, the individual ultimately doing the work is vetted thoroughly.

Source: 1st hand experience being a provider of such services.


Once your CS is offshore and you don’t control it, the vetting process is a formality and doesn’t actually have to be anything more that a compliance process.

Having worked in call centres where strict compliance and security was critical, the reality is that doing things properly is expensive.


Good background checks are expensive. I am paying for it to make sure things turn out well.

I'm sure there are organizations and outsourcing companies that skip it or treat it purely as a formality. I don't do that with my clients.


They want to make sure someone is going to do it, do it right, and make everyone looks good so they can continue fleecing.


but they have bank-level encryption!


I once submitted a bug report to my bank, through 3rd party that they had hired to administer their bug bounty program. The 3rd perty determined that it was a pretty high severity issue, because the setting to require a password could be disabled without entering a password. The bank closed it as works as intended, because they had only meant for the password to be optional, out of convenience.

I gues this is in line with their normal practices, as they were unable to issue me a debit card that only works with a PIN, and can only issue cards where the PIN is optional.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: