why i take security seriously as a designer

cybersecurity · Nov 6, 2025 · 1 min read

most people in my field treat security as the part someone else handles. the brief says make it beautiful, another document says make it safe, and both of those conversations happen without me in the room.

that is wrong, and here is the part where design is actually the skill.

  • most security problems are interface problems. people reuse passwords because the login form is hostile. people ignore warnings because the warning looks like an ad. people click the thing because the button was honest about what it would do and the other one lied
  • defaults are design. the path of least resistance is the most powerful thing on the screen
  • an error message is a security control. a vague error prevents a fix; a precise one teaches the user what went wrong

the specific things i changed on my own sites because of this:

  • the settings that weaken security are grouped, labelled with the cost, and never one click from the safe option
  • anything destructive asks for a name, not just a confirmation
  • the import and export paths are symmetric, because data you cannot get back is data you have lost

i am not a security engineer. i am the person who decides what the user is offered, and that is enough to lose data.