So the takeaway here, there isn't real significant consequence for this kind of stuff. Can I just create startup and store passwords in plaintext and lie about it so that I can focus on the core user facing features of the product? Once we get big enough I'll just hire some security engineers to do things right.
I'm exaggerating a bit with the above example, but how much corners can someone cut and how much lies can they get away with when it comes to security? Because finding the right balance seems like a serious competitive advantage in the startup space.