For startups this young, it certainly IS NEVER security. -unless security is part of their core or value-add. (ie dropbox would be nowhere if security wasnt #1)
How can security be anywhere on their early timeline? (i agree it should) but the market (10-20yr olds) and investors are not asking for more security. Also, how secure is secure? Very difficult to know when you are secure enough - and what will your product be tomorrow?
Securing your API to an acceptable level and not exposing your users' details really isn't THAT hard. It's just something a lot of app developers have never even picked up a book on.
Comments
For startups this young, it certainly IS NEVER security. -unless security is part of their core or value-add. (ie dropbox would be nowhere if security wasnt #1)
How can security be anywhere on their early timeline? (i agree it should) but the market (10-20yr olds) and investors are not asking for more security. Also, how secure is secure? Very difficult to know when you are secure enough - and what will your product be tomorrow?
My thoughts on a solution: Short term: "AMA request - Head of security for startup XYZ". Which leads to a community security score/rank. EDIT: http://www.reddit.com/r/IAmA/comments/28n64e/ama_request_per...
Long term: ONE COMMON Open Source framework that is way too easy to implement regardless of the languages used. Seriously way too easy NOT to use
Securing your API to an acceptable level and not exposing your users' details really isn't THAT hard. It's just something a lot of app developers have never even picked up a book on.