3 ms·
Just hire pentesters along with the development team. Make sure they are not affiliates. You can put in contract that as long as security issues are present the
by comboy 3y ago
Just hire pentesters along with the development team. Make sure they are not affiliates. You can put in contract that as long as security issues are present they need to fix them before getting paid, which seems like a reasonable expectation. Even the best make mistakes, so let's at least leave those which are not trivial.
We don't trust building ethics, independent inspector comes and checks if everything is as it should be before it can be used by the public.
- otherme123 3y agoThis can't happen more often than not, because the client has no idea what a pentest is. They don't even know what a is XSS means, or even API. These things are negotiated by people that only can see the frontend, and if it looks great, _snappy_, _flashy_, with random animations and following current trends it's OK. The contractors know and can easily detect this, so they focus on frontend and don't waste their time in behind-the-scenes polish. You don't polish the security or find a costly query that could bring the site to their knees, but you add a scroll-spy that brings some images from nowhere.
- comboy 3y agoInvestors have no idea what thickness the wall should be in their building either. Clients not being experts at the job they are getting somebody else to do is not a new pattern. So while some trust is required, it's best if you can get somebody else to verify. I've seen a few smart clients over the years which when faced with some excuses from a software house hired another one to give them opinion about the codebase and capabilities. It seems pretty intuitive. It seems like a money well spent.
- JohnFen 3y ago> Clients not being experts at the job they are getting somebody else to do is not a new pattern In fact, a whole lot of the time, the entire reason someone hires a professional is precisely because they themselves aren't experts.