Earlier quoted context omitted.
SOC2 is a joke and pen testers usually do a terrible job. Almost all of SOC2 has nothing to do with whether you built secure software. It seems like pen testers usually just run standard scanners, report all the false positives, and then call the job done. If your software team has been writing millions of lines of code for years, how can you expect someone to find actual security issues in something they have never…
It really wasn't a joke when we went through the process at Arist (YC S20) I can tell you. Pen tester found some really meaningful privilege escalation stuff we were able to fix before launching our new platform that was 100% specific to our system and never would have come up in an automated scanner and went through our entire threat model with great detail. Additionally, the automated scanners at least catch CSRF s…
Re: Tell HN: Stytch Login SaaS Unicorn has common auth vulnerabilities
#51Who did your pentest? Was that your first one? I'm guessing our codebase is older and bigger if you were S20, and we've had several pentests at this point, so maybe they are scraping the bottom of the barrel.