Nit picking: I know the copy isn't written for security geeks, but boasting of "MIT engineers" (mechanical engineers?) and "heavy security experience" doesn't ring of a strong correlation to me. Could you expand on the bios in your "About Tinfoil" page? I don't know if an executive looking at that page would be convinced you're all security experts (and I know this isn't "cool" but slightly more professional profile…
Democratizing Security
11–20 of 33 posts
Re: Democratizing Security
#12Nit picking: I know the copy isn't written for security geeks, but boasting of "MIT engineers" (mechanical engineers?) and "heavy security experience" doesn't ring of a strong correlation to me. Could you expand on the bios in your "About Tinfoil" page? I don't know if an executive looking at that page would be convinced you're all security experts (and I know this isn't "cool" but slightly more professional profile…
Re: Democratizing Security
#13Nit picking: I know the copy isn't written for security geeks, but boasting of "MIT engineers" (mechanical engineers?) and "heavy security experience" doesn't ring of a strong correlation to me. Could you expand on the bios in your "About Tinfoil" page? I don't know if an executive looking at that page would be convinced you're all security experts (and I know this isn't "cool" but slightly more professional profile…
It actually reads worse for security geeks, but optimizing your copy for security geeks is usually a very bad plan.
Re: Democratizing Security
#14Earlier quoted context omitted.
- Private IP address disclosure (1) - Allowed HTTP methods (1) - Non HTTP-Only Cookies (2) - Insecure Cookies (4) Note: This is a 2-page website. Looks like the cookie problems are a result of the default Heroku 404 page.
It's good to have a fast check for these things, but you realize how simple that stuff is to spot, right? Insecure cookies and HTTPOnly (which: HTTPOnly is a bit of a band-aid; it's not a vulnerability not to have it) are trivial regexes on set-cookie headers; methods is something you can do with curl and a shell script. If you're spotting these kinds of things only after using a 3rd-party tool, consider whether this…
We're actually working on some tools to help integrate Tinfoil into your integrating testing scheme - more to come on that in the future. :)
Re: Democratizing Security
#15Earlier quoted context omitted.
It's good to have a fast check for these things, but you realize how simple that stuff is to spot, right? Insecure cookies and HTTPOnly (which: HTTPOnly is a bit of a band-aid; it's not a vulnerability not to have it) are trivial regexes on set-cookie headers; methods is something you can do with curl and a shell script. If you're spotting these kinds of things only after using a 3rd-party tool, consider whether this…
In that vein, we search for a lot more than just these. We're actually working on some tools to help integrate Tinfoil into your integrating testing scheme - more to come on that in the future. :)
Re: Democratizing Security
#16Nit picking: I know the copy isn't written for security geeks, but boasting of "MIT engineers" (mechanical engineers?) and "heavy security experience" doesn't ring of a strong correlation to me. Could you expand on the bios in your "About Tinfoil" page? I don't know if an executive looking at that page would be convinced you're all security experts (and I know this isn't "cool" but slightly more professional profile…
Re: Democratizing Security
#17Nit picking: I know the copy isn't written for security geeks, but boasting of "MIT engineers" (mechanical engineers?) and "heavy security experience" doesn't ring of a strong correlation to me. Could you expand on the bios in your "About Tinfoil" page? I don't know if an executive looking at that page would be convinced you're all security experts (and I know this isn't "cool" but slightly more professional profile…
(more notes... i signed up for the free account, added my website, it brought me to a page that did nothing. i tried to sign in and it said i needed to confirm my account. okay, a notice would have been nice... i confirm the account and log in, and my website i added initially is not there? ok, i add it... now it's asking for my software stack? that seems slightly unnecessary, but okay, i try to remember what i'm usi…
We'd definitely like to take a look into your issues and see what went wrong.
Re: Democratizing Security
#18Re: Democratizing Security
#19Nit picking: I know the copy isn't written for security geeks, but boasting of "MIT engineers" (mechanical engineers?) and "heavy security experience" doesn't ring of a strong correlation to me. Could you expand on the bios in your "About Tinfoil" page? I don't know if an executive looking at that page would be convinced you're all security experts (and I know this isn't "cool" but slightly more professional profile…
(more notes... i signed up for the free account, added my website, it brought me to a page that did nothing. i tried to sign in and it said i needed to confirm my account. okay, a notice would have been nice... i confirm the account and log in, and my website i added initially is not there? ok, i add it... now it's asking for my software stack? that seems slightly unnecessary, but okay, i try to remember what i'm usi…
Re: Democratizing Security
#20Earlier quoted context omitted.
(more notes... i signed up for the free account, added my website, it brought me to a page that did nothing. i tried to sign in and it said i needed to confirm my account. okay, a notice would have been nice... i confirm the account and log in, and my website i added initially is not there? ok, i add it... now it's asking for my software stack? that seems slightly unnecessary, but okay, i try to remember what i'm usi…
Hey Peter - please feel free to email support@tinfoilsecurity.com or join us in our support chat at http://tinfoilsecurity.com/chat We'd definitely like to take a look into your issues and see what went wrong.