Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

There is a strong case to be made that 37signals should have access to this data for debugging purposes or similar. And as others have suggested, customers trusting 37signals with data should expect this at some level, unless the customers are encrypting everything at their end first.

But should everyone in the company have that level of access, or should access be restricted to the minimum necessary? What I don't see in others comments here (except tghw's [1]) is any recognition of that. It's all very well saying you want to give your devs access, and that you can be trusted, but over time and as your company grows you're exposing yourself to the risk of a rogue operator. And it only takes one person to do something bad to severely damage the trust your customers hold in you.

It's a balance, to be sure, but I'm inclined to think a blanket "we trust our devs, so they have the access they need" could be exposing yourself to a large risk you don't need.

[1] http://news.ycombinator.org/item?id=3471338



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: