Too often web developers think of security as an after thought of web development.

It's probably an effect of the frameworks/technologies taking so much of their time to learn.

But it should be their first and foremost thought, to implement a sound AAA/ strategy before any business operation.

