|
|
|
|
|
by pmjordan
6112 days ago
|
|
Okay, I can understand why most of these are on the list, but this one stands out like a sore thumb: 6. Don’t trust the client, it is in the hands of the enemy. When did that ever stop being true or important? In fact, amazingly many people get this wrong, including many programmers I've come into contact with as a consultant. The top suggestion for securing their server/service is typically to use encryption even though they don't control the client. I don't think this fallacy can be pointed out often enough! |
|