4 ms·
The intentions are good, but right now it looks like an incoming traffic source (and since it's on HN's front page, it might have succeeded). It enumerates the
by oferzelig 9y ago
The intentions are good, but right now it looks like an incoming traffic source (and since it's on HN's front page, it might have succeeded).
It enumerates the Top 10 Most Critical Security Risks, but doesn't explain what each one really means, gives examples of where and how they're exposed, or how to mitigate them. Things that OWASP does.
Now, you might say that it's just the beginning and they iterate. Fine, but without any detail on these Top 10, this document is not super useful.
It would have been better to wait until it had more "meat".
- tptacek 9y agoI agree. This would be market-y even if the actual resource wasn't hidden behind a signup page; most security firms have guidance for lambda security, which makes it odd to see a random firm declare the "top 10".
- toomuchtodo 9y agoAny non-commercial canonical resources you'd recommend for serverless security architecture?
- m3mnoch 9y agoyou have to dig for the pdf meat. https://www.puresec.io/resource-download https://www.puresec.io/resource-download
- johnbillow 9y agoSeems like these guys did a thorough job, and also involved a long list of respectable folks.