Collect Only Data You Can Protect, Security Principle Urges Developers
Software developer Serguey Shinder argues that every piece of stored data is not just an asset but a liability that must be actively protected. He proposes a simple rule: do not collect data you are not prepared to defend, shifting the question from 'might this be useful someday?' to 'is the potential value worth the responsibility?'. Shinder also highlights that data retention periods matter — information kept indefinitely becomes a forgotten, unguarded risk over time. He emphasizes that deleting data no longer needed is as important a security practice as protecting data that is still in use. The core principle is that the safest data is data never collected in the first place.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in