4 ms·
Eh, can't only blame product managers for this. Developers don't like security features that make development slower either. I made the mistake of adding Cont
by throwaway_bad 7y ago
Eh, can't only blame product managers for this.
Developers don't like security features that make development slower either.
I made the mistake of adding Content Security Policy to an app that was still in the prototype stage and it caused endless headaches whenever I needed to add new dependencies.
Your app shouldn't be outright insecure, but defense in depth (e.g., security features that are only useful contingent on the presence of another security vulnerability) can be safely deprioritized until your app gets complex enough to need it.
- dspillett 7y ago> can be safely deprioritized until your app gets complex enough to need it I'd accept "until your app looks like it might leave proof-of-concept classification". And always be mindful of how quickly PoC code can magically end up needing to be production ready overnight or worse being in production before it is... Retrofitting security can be a nightmare, one that can be so easily avoided.