Live data from Hacker News

PhpMyAdmin Project Successfully Completes Security Audit

phpmyadmin.net

111–112 of 112 posts

Re: PhpMyAdmin Project Successfully Completes Security Audit

#111
post #78

How can we get such audits done for our own open source projects?

There are selection criteria listed at https://wiki.mozilla.org/MOSS/Secure_Open_Source , and, if you think you meet most of the criteria, you can fill out a form to apply.

Re: PhpMyAdmin Project Successfully Completes Security Audit

#112
post #44
post #42

Earlier quoted context omitted.

$10,000/week range seems low for a week long audit, but depends on time charged. Most audits I've worked on, while a week long, have a 2 week pre-audit familiarization period for the audit team, and a 1 week long post-audit report-writing period. This means a 1 week audit is an actual week of investigation, and for $10,000 this sounds low. Via the article, it seems like a leading client / lead of future potential cli…

Interesting. Do you mind if I ask what sort of audits you were working on? I can understand the 2 week pre-audit familiarization period. How would you price this out instead? I was operating under the assumption that the pre-audit familiarization was priced into the first week as threat modeling and discovery. This would also lend credence to the report admitting that they did not have time to investigate as thorough…

Banking. But there was a standard policy, regardless of department - HR, Operations, Technology, Sales, everything. What was important was the scope.

I may have read the article wrongly, however. On second reading, it seems audit in the sense of check. Not audit as I assumed on an institutional level. In this case, certainly not everything is checked. Tires are kicked in the first couple of days, and if something seems like it has a leak, an extremely deep dive will be taken, for example checking thousands of records by hand (well, probably in Excel) looking for something missed - a signature, a verifier, etc. Non-cooperation results in the audit being extended in time until the auditor is satisfied with their findings.

Post reply on HN