Secure by default
Protective behaviour is the shipped configuration. A user should not have to find an obscure setting before an application handles their data safely.
- Request only permissions required for the current capability.
- Keep secrets out of client code and source control.
- Treat storage, transport, logging and release configuration as security decisions.