5 ms·
For some time now I've been working on a new project with the idea that you want to use a single testing tool that can give you comprehensive, coherent, and dee
by ivanr 9y ago
For some time now I've been working on a new project with the idea that you want to use a single testing tool that can give you comprehensive, coherent, and deep advice. It's early days and there's a lot to add still, but even now it's pretty good: https://www.hardenize.com https://www.hardenize.com
Hardenize starts with the domain name (WHOIS), then DNS/DNSSEC/CAA, then email configuration (SMTP/STARTTLS/DANE/SPF/DMARC), then your web application (TLS/COOKIES/HSTS/HPKP/CSP/various headers, etc).
Before Hardenize, I built SSL Labs.
- SamUK96 9y agoThis sounds very interesting for budding platform developers. One problem is testing the more bespoke vuln routes - that's to say, the buffer overflows, the old package exploits, the strange oddities. By the sounds of it, you are building an "obvious security pitfalls" testing bot, which is in itself very valuable don't get me wrong, but i'm pushed to say that it's an NP problem to test bespoke vuln routes, which means the kind of testing process you are developing (linear-time problem solver) will struggle with testing the non-linear-time problems of bespoke vulns. However, I wish you luck, hats off to this, it's a great idea!
- ivanr 9y agoMy goal is to promote good engineering and security practices, and to make it easy to adopt them and deploy them correctly. I feel that's one area that doesn't get enough attention. At the same time, it's the only direction that will actually improve things in the long run. Chasing vulnerabilities is a fact of life, but even if you could eradicate them from your software today, you're not going to be safer tomorrow. To that end, Hardenize doesn't check for vulnerabilities. There's plenty of existing tools that do; I don't want to reinvent that wheel.
- hdhzy 9y agoIvanr this is an excellent resource (just like SSL Labs) but I'm missing the "gamification" element: percentage points that make one strive for 100% (whether it is a good idea is a separate matter). Regarding DANE is there a benefit in deploying it now that browser vendors are against it? Also worth noting is that Key Pinning may be a very sharp knife.