Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The old age question with fail-closed is then not locking yourself out when things go wrong

Everything has/should have a "break window" escape, and yes, that's a security weakness, but I don't see many alternatives to that.



The platform operator should have such a mechanism, yes. Not randos on the Internet the moment a critical dependency fails.


When you own the platform and source code, then you always have a "break window" escape of updating the code. You can also have it fail open only when requests are coming from the internal network, or have a fail-safe authentication mechanism that allows authentication with a super-admin password that can be used "in case of emergencies."




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: