Live data from Hacker News

Tell HN: Stytch Login SaaS Unicorn has common auth vulnerabilities

news.ycombinator.com

51–52 of 52 posts

Re: Tell HN: Stytch Login SaaS Unicorn has common auth vulnerabilities

#51
post #22
post #14

Earlier quoted context omitted.

SOC2 is a joke and pen testers usually do a terrible job. Almost all of SOC2 has nothing to do with whether you built secure software. It seems like pen testers usually just run standard scanners, report all the false positives, and then call the job done. If your software team has been writing millions of lines of code for years, how can you expect someone to find actual security issues in something they have never…

It really wasn't a joke when we went through the process at Arist (YC S20) I can tell you. Pen tester found some really meaningful privilege escalation stuff we were able to fix before launching our new platform that was 100% specific to our system and never would have come up in an automated scanner and went through our entire threat model with great detail. Additionally, the automated scanners at least catch CSRF s…

Who did your pentest? Was that your first one? I'm guessing our codebase is older and bigger if you were S20, and we've had several pentests at this point, so maybe they are scraping the bottom of the barrel.

Re: Tell HN: Stytch Login SaaS Unicorn has common auth vulnerabilities

#52
post #51
post #22

Earlier quoted context omitted.

It really wasn't a joke when we went through the process at Arist (YC S20) I can tell you. Pen tester found some really meaningful privilege escalation stuff we were able to fix before launching our new platform that was 100% specific to our system and never would have come up in an automated scanner and went through our entire threat model with great detail. Additionally, the automated scanners at least catch CSRF s…

Who did your pentest? Was that your first one? I'm guessing our codebase is older and bigger if you were S20, and we've had several pentests at this point, so maybe they are scraping the bottom of the barrel.

we used Federacy. One big advantage we had though is our app is 100% serverless via Ruby on Jets. So it's a bunch of rails code that runs in lambda, makes the security footprint at lot easier to deal with. No EC2 instances for example.
Post reply on HN