Hacker News new | ask | show | jobs
by lucb1e 3264 days ago
> No amount of checklisting and best practices substitutes for hiring someone smart to break your stuff and tell you how they did it.

Which is not to say that it doesn't help.

As a pen tester, I'd much rather they tick all the boxes and save money because now I don't have to report all the low hanging fruit (which is fun the first two times you pwn an application but gets boring quickly -- I'd rather have something interesting to test).