How can we get such audits done for our own open source projects?
PhpMyAdmin Project Successfully Completes Security Audit
111–112 of 112 posts
Re: PhpMyAdmin Project Successfully Completes Security Audit
#112Earlier quoted context omitted.
$10,000/week range seems low for a week long audit, but depends on time charged. Most audits I've worked on, while a week long, have a 2 week pre-audit familiarization period for the audit team, and a 1 week long post-audit report-writing period. This means a 1 week audit is an actual week of investigation, and for $10,000 this sounds low. Via the article, it seems like a leading client / lead of future potential cli…
Interesting. Do you mind if I ask what sort of audits you were working on? I can understand the 2 week pre-audit familiarization period. How would you price this out instead? I was operating under the assumption that the pre-audit familiarization was priced into the first week as threat modeling and discovery. This would also lend credence to the report admitting that they did not have time to investigate as thorough…
I may have read the article wrongly, however. On second reading, it seems audit in the sense of check. Not audit as I assumed on an institutional level. In this case, certainly not everything is checked. Tires are kicked in the first couple of days, and if something seems like it has a leak, an extremely deep dive will be taken, for example checking thousands of records by hand (well, probably in Excel) looking for something missed - a signature, a verifier, etc. Non-cooperation results in the audit being extended in time until the auditor is satisfied with their findings.