Democratizing Security
blog.tinfoilsecurity.com
Democratizing Security
1–10 of 33 posts
Re: Democratizing Security
#2Re: Democratizing Security
#3Re: Democratizing Security
#4My favorite part? They point out security problems AND give actionable advice on how to fix them. That's useful.
Re: Democratizing Security
#5Just scanned one of my websites. Pretty quick results, once I got through the signup, email confirmation (why!), and site ownership confirmation. My favorite part? They point out security problems AND give actionable advice on how to fix them. That's useful.
Re: Democratizing Security
#6Great service! I got stuck at the point where you need to upload an HTML file or do one of the other two options but I understand why it's necessary. I'll get it done when I have some time so I can see the full report.
Re: Democratizing Security
#7Could you expand on the bios in your "About Tinfoil" page? I don't know if an executive looking at that page would be convinced you're all security experts (and I know this isn't "cool" but slightly more professional profile pictures might help)
Other than those points and the name ('tinfoil' doesn't inspire tons of confidence in me, but whatever, it's a name) I like the idea and presentation. Good luck!
Re: Democratizing Security
#8Just scanned one of my websites. Pretty quick results, once I got through the signup, email confirmation (why!), and site ownership confirmation. My favorite part? They point out security problems AND give actionable advice on how to fix them. That's useful.
Can you give examples of the sort of problems it found?
- Private IP address disclosure (1)
- Allowed HTTP methods (1)
- Non HTTP-Only Cookies (2)
- Insecure Cookies (4)
Note: This is a 2-page website. Looks like the cookie problems are a result of the default Heroku 404 page.Re: Democratizing Security
#9That said: I'm not in love with the messaging here. The push/pull isn't between ineffective, inexpensive tools and ineffective, expensive consultants. Appsec teams are very effective. They just cost too much for startups.
My recommendation: stop positioning against security products and services. Nobody in the startup market really uses them and they don't care about their track records. Meanwhile, people in enterprise and large software markets are automatically wary of automated tools (like Appscan and WebInspect on the low end, or Veracode and Fortify on the high end).
You have a compelling story just by pitching the value of automated on-demand security testing at that price point. The direct comparison to competing tools just begs questions you don't want to answer.
(I've recommended Tinfoil to lots of people and continue to do so. Definitely glad they're finally launching!)
Re: Democratizing Security
#10Earlier quoted context omitted.
Can you give examples of the sort of problems it found?
- Private IP address disclosure (1) - Allowed HTTP methods (1) - Non HTTP-Only Cookies (2) - Insecure Cookies (4) Note: This is a 2-page website. Looks like the cookie problems are a result of the default Heroku 404 page.
If you're spotting these kinds of things only after using a 3rd-party tool, consider whether this is the kind of stuff you want to build into your integration testing.