Hacker News new | ask | show | jobs
by varunjain99 1166 days ago
The only way you can do secure by design/default is if the customer of your service experiences a productivity gain.

For example, if they can deploy infrastructure more efficiently (and securely as a byproduct). Or if they're able to get reliability out of a software library (and security as a byproduct).

You have to find these win-win situations where the developers/clients are not even aware of security improvements.