Earlier quoted context omitted.
The point is that it's a really bad tradeoff, because the impact to the users is high, and the impact to security is low. And yet we do it, because "You don't stop securing it just because you've found one good option", and that's a really bad reason to improve security by such a small increment with such large negative consequences. The problem with 'defense in depth' is that it comes as close as possible to locking…
Ding ding ding! If you want to defend in depth - more power to you. If the way you're "defending in depth" is mostly not adding security, and is actively making the product less useful... I'm going to call it shite. If you blindly say "defend in depth" without actually... you know... evaluating what that defense does to the product as a whole, you're doing your job poorly.
> If you want to defend in depth - more power to you.
> If the way you're "defending in depth" is mostly not adding security, and is actively making the product less useful... I'm going to call it shite.
Agreed. Sure, there is defense at different depths, but there's no reason to add depth without adding defense as well.