3 ms·
I wish it were that simple. Insecure code is often inherited, not created ourselves. If the client has a limited budget and only wants to add X, how do you prop
by awebdev 14y ago
I wish it were that simple. Insecure code is often inherited, not created ourselves. If the client has a limited budget and only wants to add X, how do you propose upselling them on security for their whole infrastructure?
- debacle 14y agoI've worked on a lot of these projects. The best you can do is a gratis quick audit (I found SQL injections in these files, XSS in these files, and you really need to stop storing passwords in plaintext). I'd consider it gratis because being a consultant is one part programmer and ten parts professionalism.