Thing I would like to see in OWASP (and other) standards and guidance: some kind of assessment on how much debate should one have over a problem instead of just fixing it.
How much should people discuss on what things could happen if CSRF-tokens are not used or what are the implications of […]