|
|
|
|
|
by whyme
4461 days ago
|
|
> The argument here is "build a clojure framework lots of people use. The argument I am addressing is that people are deploying products with poor security because a great, all encompassing, framework does not exist. There's no excuse for doing that. This is not about having to understand cryptography, it's about knowing when and where you need to use it and making sure it's included when you do. The issues outlined in the video are trivial. |
|
Setting up a scenario where everyone has to get everything right all of the time is setting everyone up for a lot of heartbreak.
Having bad password management and opening everyone up to CSRF and XSS is not "trivial". They're gotchas, and looking out for gotchas is a waste of everyone's time.