Hacker News new | ask | show | jobs
by dguido 3324 days ago
Literally no information to judge whether this service is competent or not...

As a security expert myself, I mostly have recommended tinfoilsecurity.com and tenable.io to the small businesses I consult with. In cases where you want more than simple web application scanning, CyberGRX.com tries to accumulate a more holistic picture of the security practices of your company.

1 comments

Hell, skip competent for a moment. There's no information to judge whether this service isn't just a way to gain access to website backends in the guise of scanning.
I'd say there's not anything to even judge if it's not just a way to charge a credit card. Picking a plan asks for a web address (which isn't validated in any way, you can type a single letter), and then it shows what looks like a Stripe CC popup (which probably signs a user up for recurring billing on stripe). Nothing about a login, email or password (I can ASSUME that's after a card is entered, but who knows..). I would never use something like this in its current state.