Live data from Hacker News

Viewing profile — IncludeSecurity

IncludeSecurity

HN member
Joined
Wed, Feb 19, 2014, 4:42 PM UTC
HN karma
190
Public activity
44 items

About IncludeSecurity

Erik from www.IncludeSecurity.com

Recent public activity

  1. comment
    Comment #29785381

    SEEKING FREELANCER | Remote | 4-12 Hours/Week IncludeSecurity ( http://includesecurity.com ) works on security assessments of cutting edge and mass scale tech. We are looking for a…

  2. comment
    Comment #29506182

    After having worked on software security for 20yrs+ I can tell you first hand that it is a long-term losing game. Libs, frameworks, and SDKs are written to provide functionality an…

  3. comment
    Comment #29408295

    Hey HN, we're IncludeSec. We've done thousands of assessmnts for hundreds of clients and are well on our way to replacing all of the legacy lower-quality junior heavy appsec consul…

  4. comment
    Comment #28384024

    Hi OP, I'm Erik CEO of IncludeSec. We do many FOSS audits for Mozilla, OpenTechFund, etc. I can give you some ranges and points of consideration from what I'm seeing in the industr…

  5. comment
    Comment #28382931

    IncludeSec | app assessment/pentest | full-time | REMOTE World-wide||US Only (depends on role) Hey HN, we're IncludeSec. We're well on our way to replacing all of the legacy lower-…

  6. comment
    Comment #28308833

    Google is one of only a handful of companies in this world that can fundamentally change the state of security in the tech industry. I love google and have many friends who work th…

  7. comment
    Comment #28055656

    https://portswigger.net/research/alert-is-dead-long-live-pri...

  8. comment
    Comment #28041107

    IncludeSec | appsec/pentest managing consultant | full-time | REMOTE US ONLY Hey HN, we're IncludeSec. We're replacing all of the legacy lower-quality junior heavy appsec consultin…

  9. comment
    Comment #27909822

    I'd guess that those same presidents will call them up and buy. They'd rather be a customer than try and change a behemoth with political power like these guys.

  10. comment
    Comment #27752216

    We do security audits for a living. In a nut shell, here's why things are so screwed up IMHO: 1) Most of these companies have had audits, but they're being done by 3rd rate or very…

  11. comment
    Comment #27704962

    Include Security | Senior Security Assessment Research Consultants | Remote | Full-time | https://www.includesecurity.com twitter.com/IncludeSecurity * You're a dev, but have alway…

  12. comment
    Comment #27680390

    It says it's trained on "billions of lines of code" I would augment that to "billions of lines of code that may or may not be safe and secure" If they could tie in CodeQL into Copi…

  13. comment
    Comment #27597830

    Recommend for OS diffing, or OS config vuln scanning? Former, no idea, the latter is fine with any major COTS product that does vuln scanning (Nessus/Rapid7/whatever) they're all p…

  14. comment
    Comment #27481805

    My team found the tinder vuln, there are still plenty of location based apps that have that vuln...plenty. :(

  15. comment
    Comment #27374817

    They know exactly where their sploits are going and how they're being used, they chose to look away with a blind eye.

  16. comment
    Comment #27374745

    CEO of a pentesting company here, I've participated in or supervised close to ~2k tests of applications and networks. Sadly I have to report what you state is possible, but not pla…

  17. comment
    Comment #26986357

    Trying to demystify CORS in a couple of paragraphs....good luck with that! I think 200 page book would still be too short to demystify it. It's a crazy topic

  18. comment
    Comment #26614480

    On the security assessment side of tech we face similar problems that these types of awesome dev tools could help us solve. Our clients either: 1) Have no docs (48%) 2) Have outdat…

  19. comment
  20. comment
    Comment #26028095

    Even worse, what happens when they MITM all of the installs because the docker container has really bad security such as: RUN wget http://nginx.org/download/nginx-1.18.0.tar.gz htt…

  21. comment
    Comment #25955337

    Having been in this silly industry of hacking for 20yrs, I really wish publishing negative results became more normalized. There are orders of magnitude more unpublished info regar…

  22. comment
    Comment #25866112

    Idea and driving force to make this product reality was Kevin Poulsen, Aaron Swartz did most of the code on the MVP, and James Dolan did most of the security/documentation/evangeli…

  23. comment
    Comment #25731869

    Having worked with all of the founders of SecureDrop (Aaron, James, and Kevin) to audit the alpha version it was tough to see Aaron go. Also super sad that we lost James a couple o…

  24. comment
    Comment #25636597

    Include Security | Senior Security Assessment Research Consultants | Remote | Full-time | https://www.includesecurity.com | @IncludeSecurity * You're a dev, but have always been re…

  25. comment
    Comment #25449972

    This is a great FOSS tool if you don't want to deal with all of the low level stuff. https://github.com/StreisandEffect/streisand We did an audit of it and they fixed lots of confi…