4 ms·
Responsible disclosure and proper handling of passwords as well as not storing credit cards. Barring no breach at all, this is about as well as something like t
by papayawhip 10y ago
Responsible disclosure and proper handling of passwords as well as not storing credit cards. Barring no breach at all, this is about as well as something like this can go.
- matt_wulfeck 10y agoBonus points for mentioning the hashing algo and for not confusing "hashed" with "encrypted".
- teej 10y agoThat incident response firm seems to be worth it.
- tptacek 10y agoWeebly is one of the more clueful startups. They didn't get this from the IR team. They've been doing stuff right for a long time.
- teej 10y agoI don't doubt that they're clueful. That's why I'm confident that they hired an excellent incident response team and wisely chose to have them review and edit any external communication. Anything less would be irresponsible.
- dsacco 10y agoWeebly's team made the conscious decision to use security protections like bcrypt hashing on passwords, and they've been doing that for a long time (years). They're well aware of security best practices, and that did not come out of work with an incident response team for discovery.
- nso 10y agoAgreed, minus the lack of salting and hashing of upadtresses in the db. Sace meta like country and city about the ip and then store the adress unrecoverable. Generally no big eeasons to have the actual ip stiored.
- nso 10y agond of course the email adress should be encrypted (2 way)
- tptacek 10y agoAnyone who tells you they're "encrypting" email addresses in their SaaS app is almost certainly describing a cosmetic security feature. Every day of the week and four times and Tuesday I'd prefer the team that spends their marginal dollar on finding the next marginal reflected XSS bug than the one that wastes it on "two-way encryption of email addresses". I don't know what Weebly does for appsec (I've never worked with them and probably never will), but if they've spent even $50 on external appsec testing, they're 1000% better than 90% of rest of the applications we all use every day.
- drusenko 10y agoIn terms of appsec, we run quarterly black box pen tests and annual comprehensive white box pen tests with well regarded firms, and have been rotating vendors on a regular basis for diversity. We also do a lot of stuff internally, like regular scanning, and internal sprints focused on vuln detection. We've been doing this for years. That's not to say we're perfect (we clearly are not) but we do take it seriously.
- wglb 10y agoWhat sort of security training do you do for your developers and other staff.