Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
IncludeSecurity
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
IncludeSecurity
5y ago
SEEKING FREELANCER | Remote | 4-12 Hours/Week IncludeSecurity ( http://includesecurity.com ) works on security assessments of cutting edge and mass scale tech. We are looking for a freelance technical writer to join our exis
2.
▲
by
IncludeSecurity
5y ago
After having worked on software security for 20yrs+ I can tell you first hand that it is a long-term losing game. Libs, frameworks, and SDKs are written to provide functionality and interop. The more functionality/interop they have the
3.
▲
by
IncludeSecurity
5y ago
Hey HN, we're IncludeSec. We've done thousands of assessmnts for hundreds of clients and are well on our way to replacing all of the legacy lower-quality junior heavy appsec consulting teams doing work in Silicon valley and the re
4.
▲
by
IncludeSecurity
5y ago
Hi OP, I'm Erik CEO of IncludeSec. We do many FOSS audits for Mozilla, OpenTechFund, etc. I can give you some ranges and points of consideration from what I'm seeing in the industry today. First consideration point is quality of t
5.
▲
by
IncludeSecurity
5y ago
IncludeSec | app assessment/pentest | full-time | REMOTE World-wide||US Only (depends on role) Hey HN, we're IncludeSec. We're well on our way to replacing all of the legacy lower-quality junior heavy appsec consulting teams
6.
▲
by
IncludeSecurity
5y ago
Google is one of only a handful of companies in this world that can fundamentally change the state of security in the tech industry. I love google and have many friends who work there, I truly believe in their mission. They have the talent
7.
▲
by
IncludeSecurity
5y ago
https://portswigger.net/research/alert-is-dead-long-live-pri...
8.
▲
by
IncludeSecurity
5y ago
IncludeSec | appsec/pentest managing consultant | full-time | REMOTE US ONLY Hey HN, we're IncludeSec. We're replacing all of the legacy lower-quality junior heavy appsec consulting out there in the world and are growing quic
9.
▲
by
IncludeSecurity
5y ago
I'd guess that those same presidents will call them up and buy. They'd rather be a customer than try and change a behemoth with political power like these guys.
10.
▲
by
IncludeSecurity
5y ago
We do security audits for a living. In a nut shell, here's why things are so screwed up IMHO: 1) Most of these companies have had audits, but they're being done by 3rd rate or very inexperienced external consultants. 2) The compan
11.
▲
by
IncludeSecurity
5y ago
Include Security | Senior Security Assessment Research Consultants | Remote | Full-time | https://www.includesecurity.com twitter.com/IncludeSecurity * You're a dev, but have always been really good at hacking apps
12.
▲
by
IncludeSecurity
5y ago
It says it's trained on "billions of lines of code" I would augment that to "billions of lines of code that may or may not be safe and secure" If they could tie in CodeQL into Copilot to ensure the training set only
13.
▲
by
IncludeSecurity
5y ago
Recommend for OS diffing, or OS config vuln scanning? Former, no idea, the latter is fine with any major COTS product that does vuln scanning (Nessus/Rapid7/whatever) they're all pretty decent for doing an authenticated scan
14.
▲
by
IncludeSecurity
5y ago
My team found the tinder vuln, there are still plenty of location based apps that have that vuln...plenty. :(
15.
▲
by
IncludeSecurity
5y ago
They know exactly where their sploits are going and how they're being used, they chose to look away with a blind eye.
16.
▲
by
IncludeSecurity
5y ago
CEO of a pentesting company here, I've participated in or supervised close to ~2k tests of applications and networks. Sadly I have to report what you state is possible, but not plausible in today's modern heterogenous enterprise.
17.
▲
by
IncludeSecurity
5y ago
Trying to demystify CORS in a couple of paragraphs....good luck with that! I think 200 page book would still be too short to demystify it. It's a crazy topic
18.
▲
by
IncludeSecurity
5y ago
On the security assessment side of tech we face similar problems that these types of awesome dev tools could help us solve. Our clients either: 1) Have no docs (48%) 2) Have outdated/incorrect docs (48%) 3) Have correct and updated doc
19.
▲
by
IncludeSecurity
6y ago
Even worse, what happens when they MITM all of the installs because the docker container has really bad security such as: RUN wget http://nginx.org/download/nginx-1.18.0.tar.gz https://github.com/signal
20.
▲
by
IncludeSecurity
6y ago
Having been in this silly industry of hacking for 20yrs, I really wish publishing negative results became more normalized. There are orders of magnitude more unpublished info regarding stories of not finding vulns there are about finding vu
21.
▲
by
IncludeSecurity
6y ago
Idea and driving force to make this product reality was Kevin Poulsen, Aaron Swartz did most of the code on the MVP, and James Dolan did most of the security/documentation/evangelism work. Aaron and James are no longer with us. So
22.
▲
by
IncludeSecurity
6y ago
Having worked with all of the founders of SecureDrop (Aaron, James, and Kevin) to audit the alpha version it was tough to see Aaron go. Also super sad that we lost James a couple of years later too https://en.wikipedia.org/w
23.
▲
by
IncludeSecurity
6y ago
Include Security | Senior Security Assessment Research Consultants | Remote | Full-time | https://www.includesecurity.com | @IncludeSecurity * You're a dev, but have always been really good at hacking apps and would lik
24.
▲
by
IncludeSecurity
6y ago
This is a great FOSS tool if you don't want to deal with all of the low level stuff. https://github.com/StreisandEffect/streisand We did an audit of it and they fixed lots of configuration problems, it's now
25.
▲
by
IncludeSecurity
6y ago
Include Security | Senior Security Assessment Research Consultants | Remote | Full-time | https://www.includesecurity.com | @IncludeSecurity * You're a dev, but have always been really good at hacking apps and would like a
26.
▲
by
IncludeSecurity
6y ago
This sort of thing happens even for high-end pentesting. Here is the same assessment done by four decent consulting companies. They all found risks that the other companies missed. https://ostif.org/four-audits-of-randomx-fo
27.
▲
by
IncludeSecurity
6y ago
Hi hi! Speaking as both a bug bounty vet, and a consulting vet (I run includesecurity.com), here's my .02 on some things you may not have considered given your comment. 1) Sam and the other hackers did not do this as a full time gig, t
28.
▲
by
IncludeSecurity
6y ago
The main developer of Calibre has had a long history of arrogant statements like that. Most famously illustrated in this bug report thread https://bugs.launchpad.net/calibre/+bug/885027 It's like...how many t
29.
▲
by
IncludeSecurity
6y ago
Many mobile apps rely on shared components/libs/frameworks that are either developed by the company or are FOSS (libpl_droidsonroids_gif for example). In either case...they are platform agnostic and usually written in C. And as we
30.
▲
by
IncludeSecurity
6y ago
Tried to find an article from earlier this week, no dice. https://hndex.org/?q=open%20source%20security https://hndex.org/?q=openssf Great idea, I appreciate how fast it returns results! Just needs more mor
More ›