Live data from Hacker News

Democratizing Security

blog.tinfoilsecurity.com

31–33 of 33 posts

Re: Democratizing Security

#31
post #30
post #28

Earlier quoted context omitted.

Yea, agree with the above comments. This can all be done with Nessus (for free). What do you mean by `deep dive`? Are you reselling Burp? What do you plan to offer on the network security side? Keep in mind you should be targeting people who know nothing about security (you may want to play with the wording on your site). because experts already have a tool bag of tricks that can exceed these offerings for free.

We've written a lot of custom tools to do some heavier auditing of a website than off-the-shelf Nessus. With that said, we are definitely targeting those companies and teams that don't have the time or experience to be focused on setting up and running Nessus consistently. Our SQLi and XSS modules in particular are quite a bit heavier than Nessus', but there are other features like page de-duplication that optimize s…

Nobody should ever be using Nessus as their first-line tool to test web applications. Nessus isn't a web application tool.

A much more realistic option is Burp Suite, which is $299.

Re: Democratizing Security

#32
post #24

Earlier quoted context omitted.

To clarify: it's not 250 unique sites, it's 250 pages per unique site. That is, news.ycombinator.com could have thousands of URLs. With the basic plan, we'd scan the first 250. We offer a lot more than Nessus, in terms of doing a deep-dive on web application security. With that said, Nessus does a better job at network security, for example; this is something we're working on.

oh, ok, that makes it a lot more clear. thanks! If I were you I would consider a model where I would be to do a full scan, display only the top X vulnerabilities found, and simply charge more to show the rest of the results. Another thing I'm curious about: does this work on a pure client-side web application (e.g. my app is just one html page + javascript that loads all the html from templates)? Are you including st…

We've done some tests, and many of our customers would much rather have a basic scan and see the full results of the scan, than only be shown a piece of the scan. It gives off the impression that we're holding their vulnerabilities hostage, and that's definitely not what we hope to do!

The best test to see how we differ from Nessus/Burp is to try it yourself! A lot of the vulnerability classes we scan for are very similar, but the ways in which we scan for them are different. We do offer our Standard Plan for a free 30 day trial. Would love to hear what you think :)

If you have any issues, ping us at http://tinfoilsecurity.com/supportchat

Re: Democratizing Security

#33
post #31
post #30

Earlier quoted context omitted.

We've written a lot of custom tools to do some heavier auditing of a website than off-the-shelf Nessus. With that said, we are definitely targeting those companies and teams that don't have the time or experience to be focused on setting up and running Nessus consistently. Our SQLi and XSS modules in particular are quite a bit heavier than Nessus', but there are other features like page de-duplication that optimize s…

Nobody should ever be using Nessus as their first-line tool to test web applications. Nessus isn't a web application tool. A much more realistic option is Burp Suite, which is $299.

True; wasn't saying Nessus is a good tool for web applications. Quite the opposite.

Burp Suite is great for anyone who knows what they're doing; for anyone that isn't already a security guy/gal the UI is near impossible to figure out, and the results aren't particularly actionable. That's much of what we try to fix.

Not trying to be argumentative, just clarifying! :)

Post reply on HN