3 ms·
Since this 'Drata' thing is intended to keep employees/contractor computers in check with policy requirements, runs as (equivalent of) root, and auto-updates, I
by cure 5y ago
Since this 'Drata' thing is intended to keep employees/contractor computers in check with policy requirements, runs as (equivalent of) root, and auto-updates, I assume it must be:
* completely open source
* have gone through security audits with public reports, and a favorable outcome
* have reproducable and verifiable builds, and those are the only ones distributed, and the end user can easily verify that their binary copy is an official build?
Right?
Because if not, aren't you just adding another attack vector onto all your employee/contractor laptops when you use 'Drata' to check a policy box on your SOC2 application?
[edit: formatting bullet list]
- handrous 5y ago> Because if not, aren't you just adding another attack vector onto all your employee/contractor laptops when you use 'Drata' to check a policy box on your SOC2 application? I have bad news: gaining security certifications mostly through pointless or even harmful measures is the norm.
- danielzev 5y agoThe agent is intended to ensure devices meet the security/compliance requirements of the company. It is a lightweight read-only osquery based agent that we are happy to share the configuration of with prospects/customers. To address some of your other points: * We have been talking about making it open source, though it is not today. * We do have a third party security validated report that we are happy to share with prospects/customers. * Builds are pulled directly within the Drata portal and the agent does auto-update to ensure we can push any security updates to it that we need to. We do sign the code and you should be able to validate it. Source: I am the Drata CTO