> Also, many startups consider security to be a waste of time
Do you have evidence to support this?
I wouldn't say that security is considered a waste of time.
It is, however is a trade-off[1] between money, time, and other resources, things that, generally speaking, start-ups tend to be short on.
I worked for a startup that provided multifactor authentication using biometrics (amongst others), and almost all of our business came after publicized (and not publicized) breaches, from both large and small firms.
We may be talking about the same phenomenon from different points of view. I have evidence but I really don't want to name names - but anecdotally, I have pointed out massive issues (like not even escaping user-provided variables in inline SQL queries) to clients, and seen it dismissed as less important than just getting live.
Maybe my comment was a bit too biased and hyperbolic, but I've certainly encountered that attitude.
Do you have evidence to support this?
I wouldn't say that security is considered a waste of time.
It is, however is a trade-off[1] between money, time, and other resources, things that, generally speaking, start-ups tend to be short on.
I worked for a startup that provided multifactor authentication using biometrics (amongst others), and almost all of our business came after publicized (and not publicized) breaches, from both large and small firms.
[1]https://www.schneier.com/essay-155.html