I’m doing testing on a new release of Abacus at the moment, so I’m in a software QA (Quality Assurance) frame of mind. One of the tenets of software QA is “Assume users are malicious”. That’s also one of the tenets of security engineering, but in a completely different way. A security engineer treats users as malicious, as the users he or she is most concerned about...

