3 ms·
If you are a business, then definitely yes. But the average self-taught developer will not have the resources available to hire a security consultant. Instead
by paragon_init 11y ago
If you are a business, then definitely yes. But the average self-taught developer will not have the resources available to hire a security consultant.
Instead of throwing money at the problem, you can instead choose to teach yourself more about the subject. We maintain a curated list on Github for people interested in learning about application security for this very reason.
https://github.com/paragonie/awesome-appsec https://github.com/paragonie/awesome-appsec
But if you're a company and your operating budget is in the millions of dollars hire a security consultant!
- balls187 11y ago> If you are a business, then definitely yes. But the average self-taught developer will not have the resources available to hire a security consultant. True. You don't need to hire consultants to perform a security audit. Ask HN and Security Stack Exchange are good free alternatives to get critiques on your approach.
- paragon_init 11y agoIf you build something open source and it gets incredibly popular, security researchers will also probably come to you. This creates its own problems, of course. (Can't have problems without PR.)