4 ms·
Side point: +1 on not silly at all. Re: anything w/ security (esp how it works), if you don't know ASK. ASK. ASK. PLEASE ASK. Security is incredibly complex
by securityty2020 7y ago
Side point: +1 on not silly at all.
Re: anything w/ security (esp how it works), if you don't know ASK. ASK. ASK.
PLEASE ASK.
Security is incredibly complex and minor/subtle mistakes can destroy companies and other potentially catastrophic consequences (especially to your employment.) If you're not sure about something, ASK. End-users are bad enough when it comes to security, but engineers should always feel empowered to "make sure" about all matters of security, large or small.
Obviously it's best to to be familiar with best practices, but if you're not a security "expert" and you're unclear about something, ASK.
There no dumb questions in security, just dumb practices. The dumbest thing of all is not asking your question because you think it's "obvious."
tl;dr: ASK!
- scurvy 7y ago> Security is incredibly complex and minor/subtle mistakes can destroy companies For better or for worse, that's not the case. These days, security mistakes just end up in 2 years of free credit monitoring. Ironic case in point, Equifax. I'm not saying you shouldn't take security seriously. But it's not fair to say that insecurity could destroy your company. Mainly, most end users just really don't care (or have a choice).
- spenczar5 7y agoIt depends on the company. What you say is true for a consumer website, but much less true for a SaaS product which depends on customer trust. For example, imagine an AWS or Salesforce or Github security breach that released very private business data.
- scurvy 7y agoOf the 3 mentioned, I doubt they'd lose more than 5% of revenues.