Live data from Hacker News

Web Developer Security Checklist

simplesecurity.sensedeep.com

1–10 of 249 posts

Re: Web Developer Security Checklist

#7
post #6

"Hack yourself" May I suggest the opposite, and say if you're going to pen test your infrastructure, don't have the same people maintaining the infrastructure trying to hack the infrastructure.

Do both. I'm a big believer in having dev learn and own a part of the security process. You learn an enormous amount by hacking yourself. But you are right, you definitely need other eyes to pen test as well.

Re: Web Developer Security Checklist

#9
Not simple by any means, this one is very thorough and one of the better security checklist I've come across in a while! Sensedeep looks very intriguing and I often wondered if anyone has created an alternative to Atomic Secured Linux. Could this be it? Or is it like an ids / ips with a gui?

Re: Web Developer Security Checklist

#10
post #9

Not simple by any means, this one is very thorough and one of the better security checklist I've come across in a while! Sensedeep looks very intriguing and I often wondered if anyone has created an alternative to Atomic Secured Linux. Could this be it? Or is it like an ids / ips with a gui?

We're just in beta. SenseDeep is part host-IDS and part cloud-side. The key is real-time. We want to detect attacks in real-time on the server or on the cloud-side. It has a GUI on top to unify and give a cloud complete view. The focus is DevOps and not companies with a security team. Not sure if this helps or confuses things.
Post reply on HN