|
|
|
|
|
by dsr_
1577 days ago
|
|
This is missing an extremely important upfront concept: you need to know what you're protecting and how valuable it is. It does no good whatsoever to require every user of a grocery-list app to have a Yubikey to verify their identity. It might not even make sense to have users login at all. The balance between usability and security must be consonant with the costs of implementation. |
|
There could be (and probably are) entire books written about how to define what "an acceptable level" means... but that is the same point you are getting at - security is not a guaranteed lockdown of your assets, it is self-defined sufficient deterrence to attack. Sometimes that means light security, sometime that means heavy... but it is up to you to make those decisions.