Viewing profile — IncludeSecurity
IncludeSecurity
HN member- Joined
- Wed, Feb 19, 2014, 4:42 PM UTC
- HN karma
- 190
- Public activity
- 44 items
- HN profile
- View on Hacker News ↗
About IncludeSecurity
Recent public activity
-
comment
Comment #29785381
SEEKING FREELANCER | Remote | 4-12 Hours/Week IncludeSecurity ( http://includesecurity.com ) works on security assessments of cutting edge and mass scale tech. We are looking for a…
-
comment
Comment #29506182
After having worked on software security for 20yrs+ I can tell you first hand that it is a long-term losing game. Libs, frameworks, and SDKs are written to provide functionality an…
-
comment
Comment #29408295
Hey HN, we're IncludeSec. We've done thousands of assessmnts for hundreds of clients and are well on our way to replacing all of the legacy lower-quality junior heavy appsec consul…
-
comment
Comment #28384024
Hi OP, I'm Erik CEO of IncludeSec. We do many FOSS audits for Mozilla, OpenTechFund, etc. I can give you some ranges and points of consideration from what I'm seeing in the industr…
-
comment
Comment #28382931
IncludeSec | app assessment/pentest | full-time | REMOTE World-wide||US Only (depends on role) Hey HN, we're IncludeSec. We're well on our way to replacing all of the legacy lower-…
-
comment
Comment #28308833
Google is one of only a handful of companies in this world that can fundamentally change the state of security in the tech industry. I love google and have many friends who work th…
-
comment
Comment #28055656
https://portswigger.net/research/alert-is-dead-long-live-pri...
-
comment
Comment #28041107
IncludeSec | appsec/pentest managing consultant | full-time | REMOTE US ONLY Hey HN, we're IncludeSec. We're replacing all of the legacy lower-quality junior heavy appsec consultin…
-
comment
Comment #27909822
I'd guess that those same presidents will call them up and buy. They'd rather be a customer than try and change a behemoth with political power like these guys.
-
comment
Comment #27752216
We do security audits for a living. In a nut shell, here's why things are so screwed up IMHO: 1) Most of these companies have had audits, but they're being done by 3rd rate or very…
-
comment
Comment #27704962
Include Security | Senior Security Assessment Research Consultants | Remote | Full-time | https://www.includesecurity.com twitter.com/IncludeSecurity * You're a dev, but have alway…
-
comment
Comment #27680390
It says it's trained on "billions of lines of code" I would augment that to "billions of lines of code that may or may not be safe and secure" If they could tie in CodeQL into Copi…
-
comment
Comment #27597830
Recommend for OS diffing, or OS config vuln scanning? Former, no idea, the latter is fine with any major COTS product that does vuln scanning (Nessus/Rapid7/whatever) they're all p…
-
comment
Comment #27481805
My team found the tinder vuln, there are still plenty of location based apps that have that vuln...plenty. :(
-
comment
Comment #27374817
They know exactly where their sploits are going and how they're being used, they chose to look away with a blind eye.
-
comment
Comment #27374745
CEO of a pentesting company here, I've participated in or supervised close to ~2k tests of applications and networks. Sadly I have to report what you state is possible, but not pla…
-
comment
Comment #26986357
Trying to demystify CORS in a couple of paragraphs....good luck with that! I think 200 page book would still be too short to demystify it. It's a crazy topic
-
comment
Comment #26614480
On the security assessment side of tech we face similar problems that these types of awesome dev tools could help us solve. Our clients either: 1) Have no docs (48%) 2) Have outdat…
- comment
-
comment
Comment #26028095
Even worse, what happens when they MITM all of the installs because the docker container has really bad security such as: RUN wget http://nginx.org/download/nginx-1.18.0.tar.gz htt…
-
comment
Comment #25955337
Having been in this silly industry of hacking for 20yrs, I really wish publishing negative results became more normalized. There are orders of magnitude more unpublished info regar…
-
comment
Comment #25866112
Idea and driving force to make this product reality was Kevin Poulsen, Aaron Swartz did most of the code on the MVP, and James Dolan did most of the security/documentation/evangeli…
-
comment
Comment #25731869
Having worked with all of the founders of SecureDrop (Aaron, James, and Kevin) to audit the alpha version it was tough to see Aaron go. Also super sad that we lost James a couple o…
-
comment
Comment #25636597
Include Security | Senior Security Assessment Research Consultants | Remote | Full-time | https://www.includesecurity.com | @IncludeSecurity * You're a dev, but have always been re…
-
comment
Comment #25449972
This is a great FOSS tool if you don't want to deal with all of the low level stuff. https://github.com/StreisandEffect/streisand We did an audit of it and they fixed lots of confi…