3 ms·
"Security" is not an atomic property of software. And while there are a lot of difficult tradeoffs between security and usability there are also a lot of low ha
by thinkharderdev 4y ago
"Security" is not an atomic property of software. And while there are a lot of difficult tradeoffs between security and usability there are also a lot of low hanging fruit where entire classes of threat can be mitigated with zero tradeoff for user experience (and sometimes zero tradeoff for developer productivity if the system is built from the start with security in mind). To take a trivial example, hashing (with an appropriately secure algorithm) and salting passwords stored in your database. Or using prepared statements instead of manually building SQL queries. These are things that can effectively eliminate entire classes of vulnerability and are basically free to do.