Don't ask 37s to meet a standard that nobody else meets. It's just muddying the real issue, which they're clearly trying to address.
This comment, btw, isn't about 37s. It's about the singularly bad advice that web startups should have a fully-transparent conservative "security" page that talks about cross-site scripting and CSRF attacks, when their competitors have pages about "state of the art firewall security". To normal people (ie, customers), the "state of the art firewall security" people sound like they know what they're doing.
Comments
He addressed your second point, and your first point isn't reasonable. Product "security" pages don't need to read like SEC disclosures.
Compare their security page to:
* http://www.salesforce.com/company/security.jsp
* https://www.paypal.com/us/cgi-bin/webscr?cmd=xpt/Marketing/g...
* http://www.apple.com/macosx/security/ (heh)
* http://www.webex.com/pdf/wp_security_overview.pdf
* http://www.netsuite.com/portal/infrastructure/main.shtml
Don't ask 37s to meet a standard that nobody else meets. It's just muddying the real issue, which they're clearly trying to address.
This comment, btw, isn't about 37s. It's about the singularly bad advice that web startups should have a fully-transparent conservative "security" page that talks about cross-site scripting and CSRF attacks, when their competitors have pages about "state of the art firewall security". To normal people (ie, customers), the "state of the art firewall security" people sound like they know what they're doing.