3 ms·
For example: OpenVAS for vulnerability scanning on the VMs. Clair for container image vulnerabilities, OSSEC for IDS etc.
by auspex 7y ago
For example: OpenVAS for vulnerability scanning on the VMs. Clair for container image vulnerabilities, OSSEC for IDS etc.
- tnolet 7y agoAha, you mean dedicated security scanning / intrusion detection systems. I use none. I use static websites, Heroku and AWS Lambda for all work. So all of the network, vulnerability etc. worries are of loaded to the provider. No user data is stored on our backend: that’s all in Stripe and Auth0. We encrypt some sensitive data (not PII) in the database and in flight. I guess for now the use of various 3rd party services negates the need for dedicated “security stack” products. This might change in the future.