7 ms·
Have you contracted an independent pen-testing company to assess your design and implementation?
by andremat 8y ago
Have you contracted an independent pen-testing company to assess your design and implementation?
- kingbirdy 8y agoThis is mentioned in the article > In preparation for open sourcing we also engaged with Security Innovation, a widely respected agency who count Microsoft, Symantec, and Amazon as clients, to do a more in-depth, week long assessment, with full access to source code and design documents. This found no major issues, which gives us the confidence to open source sso today.
- baby 8y agoIt was only a week long assessment though, I don’t know Security Innovation but I’m sure they would have appreciated more time.
- itwasntandy 8y agoThat is understood, and is always why we engaged with some of the top researchers who contribute to our bug bounty program, from the start with this project. For example offering increased bounties during certain windows, or providing early access to the source code. We highly value our bug bounty program, and find it to be a very effective mechanism for continuous security validation. I'll write a tech blog post in the near future about how we facilitate our program.
- yubozhao 8y agoLooking forward to read about it. Thank you for the project!
- itwasntandy 8y agoYes, as mentioned in the blog post, we worked with Security Innovation to do a week long security assessment with full access to source code, design documents and endpoints. We also have a long term consulting arrangement with a widely respected security architect, and they helped review our design and implementation. Additionally, BuzzFeed has a bug bounty program on hackerone (https://hackerone.com/buzzfeed https://hackerone.com/buzzfeed), and have invited partipating researchers to report on any issues found. We’ve paid out bounties for a number of minor issues, which were addressed prior to open-sourcing. Additionally, knowing that security is never done, we continue to make it eligible for bounties -- see https://github.com/buzzfeed/sso/blob/master/README.md#security-vulns https://github.com/buzzfeed/sso/blob/master/README.md#securi...
- xeromal 8y agoWhy don't people read shit before posting?
- rkho 8y agoYour comment is incredibly unhelpful and does not contribute to the discussion. HN is not the kind of platform to shitpost on.
- gknoy 8y agoIn the blog article, they state: > we have made sso a priority target for penetration testing by researchers on our bug bounty program — we’ve paid bounties for a number of reported issues! While that makes it clear that they cared about penetration testing, it isn't what the person was asking to that you replied to -- they asked if they had contracted with an independent company to do testing. This did not seem to be answered by the article, and seems like a reasonable question to ask.
- itwasntandy 8y agoWe did talk in the blog article about engaging with Security Innovation too.