|
|
|
|
|
by charliesome
5094 days ago
|
|
I'm sorry but you can't fix 'failing Web startup security' with automated scans. Automated scans are useless for finding all but the most trivial of vulnerabilities. There's almost no doubt in my mind that the only way to fix the situation is with education. I think that if your goal is to fix poor security practises, you should change your strategy to teaching developers how to be security aware, rather than offering a service that merely pokes around for a few well known vulnerabilities. |
|
BUT, there are charlatans armed with little more than nmap and a cursory understanding of the output that sell themselves as penetration testers, for a whole lot more than I assume this service will cost.
This, at least, is normalized, repeated, reported consistently, and history is kept. That's worth something.
It's incomplete, but I assume at the price point, it will be more cost efficient and trustworthy than the other options -- the most popular of which is doing nothing.
Usual rant about false senses of security elided for brevity.