Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you are a business, then definitely yes. But the average self-taught developer will not have the resources available to hire a security consultant.

Instead of throwing money at the problem, you can instead choose to teach yourself more about the subject. We maintain a curated list on Github for people interested in learning about application security for this very reason.

https://github.com/paragonie/awesome-appsec

But if you're a company and your operating budget is in the millions of dollars hire a security consultant!



> If you are a business, then definitely yes. But the average self-taught developer will not have the resources available to hire a security consultant.

True. You don't need to hire consultants to perform a security audit. Ask HN and Security Stack Exchange are good free alternatives to get critiques on your approach.


If you build something open source and it gets incredibly popular, security researchers will also probably come to you. This creates its own problems, of course. (Can't have problems without PR.)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: