5 ms·
Penetration tester here - My anecdotal experience: I've worked on a number of projects where bill rate is something like $250-$400/hr per engineer depending on
by InitialBP 5y ago
Penetration tester here - My anecdotal experience:
I've worked on a number of projects where bill rate is something like $250-$400/hr per engineer depending on complexity, access to source code, size of the project, etc.
Usually equating to something like 10-12k for a single engineer on a project for a week. For bigger projects like this I would think it's totally reasonable to see anything from 4 engineering weeks -> 12 engineering weeks depending on different pieces and especially given this is a very high profile project. Based on that estimate of something between ~40k-120k. I know that's a huge range, but just wanted to share what I do know.
- tpmx 5y agoFor a Berlin-based team like the one Mozilla used, $250-$400/hr/engineer is kinda hard to believe. Probably closer to $150-$200/hr. The average software engineer in Berlin makes $71k/yr. The compensation levels are very different compared to SV.
- codethief 5y agoDon't forget to add the employer's mandatory social security contributions and any additional employee benefits and equipment[0], the USD<>EUR exchange rate, and the fact that even in Berlin a senior security engineer will definitely make more than 71k€. [0]: The founder of a (Germany-based) IT consulting firm recently told me that, as an estimate, pretty much any engineer at a tech firm costs at least 100,000€/yr.
- sbradford26 5y agoSo he is talking about bill rate which is very different than what someone makes. At my company someone might make $50 but their bill rate might be like $175. Your bill rate factors is all sort of costs like having an office building, insurance, taxes, and everything that goes into having an employee above just salary. So even if they are in Berlin their bill rate is most likely comparable.
- tpmx 5y agoYes, I am aware of all of those factors.
- lucb1e 5y agoI am familiar with Berlin rates and this person is right. 400 USD (337 euros) an hour is unrealistic, unless you are hiring Cure53 specifically because employee X did groundbreaking research on topic Y and that's why you need that expertise; only then would I expect Mozilla to agree to that sort of rate. The range is more likely to be 110 - 250 euros per hour, where both ends are fairly unlikely but it's not as if I have comprehensive industry-wide data on everyone's financials. (I'm not that kind of hacker, heh.) The sibling commenters are right, though, that the hourly rates charged by the company are not very related to how much you earn as a person. I wish I got my hourly rate as salary, but I see what kind of organisational crap the founder has to do and it's just not worth the headache to me.
- megous 5y agoWould Mozilla blow one engineer's year's salary on such a thing though?
- skrtskrt 5y agoCompanies do this because customers have already demanded it or because they know companies will demand it. It's expensive, but it helps you land customers, which pay you enough to cover it.
- InitialBP 5y agoOn top of just "compliance" or "customers demand it", these types of penetration tests can and do expose real, serious vulnerabilities in software. Furthermore, I wouldn't underestimate the positive press that having a third party security firm assess your product and share the results publicly. VPN Services have been under special scrutiny lately so I think something like this makes total sense for Mozilla, regardless of the cost.
- jopsen 5y agoWhy not? it's a one time expense that helps you launch. If throwing money at a problems solves, that's rarely a hard argument to make. If you throw engineers at a problem it might get solved, or it might not. Hiring an engineer to work on something is a high risk investment. side note: Mozilla does have great engineers, when I was there a few years ago the security was also very competent. But it's probably not the same as getting specialized consultants.
- megous 5y agoIt's 1800 yearly subscriptions at $110k, and that's assuming $5/month is pure profit, which it is not. So this one off audit would have to hit them, say, 6000 extra 1 year subscriptions to pay itself off, let alone turn profit. Sounds like a stretch. It would certainly be hard to measure. On that note, how many customers do these public customer oriented VPNs have, typically? 1k's? 10k's? More?