Hacker News new | ask | show | jobs
by boyter 5427 days ago
If you just have a sales website its probably not high on your list of priorities no. Same with anything that doesn't collect data (IE presentation only) or an expensive paid for service with a long sales cycle.

In all of the above cases I would consider security while creating, but I wouldn't do a lengthy pen test while trying to get the product out there. Of course that's also dependent on your target audience.

1 comments

You are your brand. If your homepage gets turned into a billboard for goat.cx you are owned in more ways than one...

There is really no point in us discussing this further. We have dramatically different assumptions on the importance of security and the value of a company's image/reputation.

I didn't say it wasn't a priority, or that you should leave yourself open to being totally owned, just that executing a pen test against your new website is probably overkill in some situations.