3
0 Comments

Offer IH: Security baseline check for your product.

I have been following and reading IH now for a while and learned many helpful things. I think its about time for me to give back. I see too many web services that are missing the easily achievable basics.

I want to do this a few times if people are interested in it. I think I can do about 2 apps per round.

I do security consulting for the last couple of years, and have built and established some security programs in a few companies. Did a fair share of pen testing and found some issues in known SaaS apps while using them. (Sometimes curiosity guides me)

I am offering a simple and free checkup on some of the following pieces:

  • Doing a quick app check for the essentials and explaining what and why I checked it (mostly OWASP TOP10)
  • Checking for some best practices around authentication.
  • Source code review of crucial parts (ruby, node only as this is my expertise)

Optional:

  • Cloud environment checkup (AWS and GCloud)
  • Organizational checkup: do you protect your accounts etc appropriate.

Requirements:

Your app needs to have users/customers and ideally some revenue. Usually, it does not make too much sense for a small company to invest in security until they actually are off the ground.

My contact info is in my profile, send me an email or comment on this threat and we take it from there.

I am also happy for feedback, what would you like to test, where do you see your weaknesses.