Whichever way you look at it, there are many effective security technologies that we can use today, and yet only a small number of deployments do.

WHOIS, DNS, DNSSEC, DANE, CAA, SMTP, STARTTLS, CAs, X.509, SPF, DKIM, DMARC, IPv4, IPv6, HTTP/2, SSL, TLS, HSTS, CSP, HPKP, RC4, SHA, cookies, mixed content, SRI, privacy, ...

Few people can dedicate themselves to understand all the technologies individually and also how they work together.

As a result, we have to work hard to secure systems only after they have been deployed. This approach is not only inefficient, but also doesn't work very well. We need to try something else.

