3 ms·
Security shouldn't be offered as an ad-on. Most clients expect you as developer to know what's best practice. It is also your responsibility to comply with loc
by kellros 14y ago
Security shouldn't be offered as an ad-on. Most clients expect you as developer to know what's best practice.
It is also your responsibility to comply with local/country and international laws.
I reckon the only time it might be allowed to allow certain exploits/unwanted behavior is in a restricted controlled environment.
- awebdev 14y agoI wish it were that simple. Insecure code is often inherited, not created ourselves. If the client has a limited budget and only wants to add X, how do you propose upselling them on security for their whole infrastructure?
- debacle 14y agoI've worked on a lot of these projects. The best you can do is a gratis quick audit (I found SQL injections in these files, XSS in these files, and you really need to stop storing passwords in plaintext). I'd consider it gratis because being a consultant is one part programmer and ten parts professionalism.