Morning!
👋
@orestis we switched from “native” mongo ObjectIds to randomly generated ObjectIds because you can “guess” the possible values of the next couple of ObjectIds, which makes for an attack surface.
(defn gen-id! []
(format "%024x" (BigInteger. 96 (SecureRandom.))))
Oh, and if you’re a saas thingy, do consider using https://www.hackerone.com. It’s like an ongoing pen-test
Is this a company that does pen tests? Or something more like https://www.zaproxy.org/
You could look at hackerone as a pentest platform.
They help set up bounty programs, and have a bunch of hackers which try to hack orgs (like ardoq)
When the hackers find security holes, we pay them.
The hackers are incentivised to learn the app, and they find so much more than your yearly pentest does.
And your org is incentivised to keep the app secure, as it pays for every security bug found.
Oh that’s nice. We had a pentest which found some things but missed some glaring ones. Cost an arm and a leg and was very stressful since it was time bound.
Is there a pricing guidance on what to expect? I would hope the costs are bounded and there’s NDAs... a bunch of random “hackers” trying to get in sounds scary if they’re not bound by some contract.
Morning
Is it wrong that I make hackerone rhyme with macaroni
And a very good day to @borkdude especially
good day!
Good morning!
macarone?
I see no problem with that.
morning
mogge
Good morning :hugging_face:
morning, feels like lunch already 🍝
spooky
Lunch? I haven't even woken up yet properly!!! You crazy man 😉
Morning