I am very new to Indiehacker stuff and it seems like the kind of thing that excites me the most.
I wear multiple hats- full-stack dev, Machine Learning researcher, Cyber Security expertise, etc. I live far away from any 'startup-ish' place and I don't want to build something that people don't use/ wouldn't pay for. So I instead chose to turn to the community to ask about your security painpoints you'd want to be solved. Or any guidance in general would be appreciated :)
I have few in mind:
API testing- You just point your API IP address, and all the VULNERABILITY testing is done whenever you hit 'run'. I can add functionality testing too and STRESS testing too.
Virtual IT infra monitoring system- No matter how big or small you're, you can get a dashboard where you can access live logs of visitors, attacks, suspicious activities. If anything is down, you'll get a live feedback.
Authentication- you want to integrate FIDO authentication (i.e. passwordless) in your application, I can build that as a service.
Site Reliability Engineering (SRE) as a service.
Hey Dave, what about aggregating data from multiple cloud-based cybersecurity products into a single view? Being able to run ML on those data feeds and present alerts/anomalies in a better way. If you wanted to get involved in this, you could wear every hat you have listed and would have complete freedom to innovate. If you're interested, drop me a line at leemora@gmail.com
Something like #2 is compelling to me.
Sometimes I get unhandled exception notices that clearly look like someone or something script poking around for exploits. I never know what to do with these. Were they successful in their attempt? Can I block their IP somehow? Is there some specific exploit they are attempting and a dependency upgrade I missed?
As a first step, do you think that a dashboard where you can fetch and tag (as in Event Management) would be helpful? And may be additionally the ability to block certain IPs. Also what kind of infra do you use to run you applications- barebones servers, or dockers, etc.?
Thanks, @daveIdito! My preferred stack is Ruby on Rails, hosted on Heroku.
Honestly, I don't understand this, so I usually ask for help from someone good at this. Indeed, I'm such a person who has ideas and the ability to organize and manage everything. But I can't do it on my own, so I just hire people who are well-versed in particular issues to implement my ideas on a professional level. More than that, the kubernetes penetration testing price https://www.cyberlands.io/kubernetespenetrationtesting nowadays is affordable enough for everyone. So I don't need to worry about safety and quality because finding a professional you can trust is the main thing. It is always better not to go there in what you do not understand so as not to make it worse
Cybersecurity has always seemed very difficult to me. I've tried to come up with something more than once, but each time I've started thinking too much, trying to predict how a cybercriminal might behave. So I was trying to come up with a perfect defense that would be very difficult to break. Well, I didn't succeed... The issue of cybersecurity remained open to me for a long time, so I could not get my project out of the closed beta testing. By chance I found a service like https://www.swiftcomm.co.uk/products/managed-it-services/cyber-essentials/ , which became my salvation. Thanks to these guys, I was finally able to provide excellent security for my project, which allowed me to withdraw it from the beta testing.
for 4. I noticed Indiehackers itself was down about 30 mins ago!