4 ms·
google.com scores 50/100. This is one of those scanners crappy pentesters use for multi page reports of false positives?
by progbits 2y ago
google.com scores 50/100. This is one of those scanners crappy pentesters use for multi page reports of false positives?
- mavamaarten 2y agoHah this triggers me. Last week we got a pentest done on our apps. This week we got some high-prio tickets on our board because they found major security violations!!! Our app, which uses an API, used a dangerous permission! "android.permission.INTERNET" How they can report this with a straight face, I don't know. Makes me want to go in the security business though, if that is the level of competence I'm absolutely positive that I could do that job and earn a lot more than a generic app developer.
- CrimsonRain 2y ago> Why isn't the app obfuscated, why can it be run on rooted device and why doesn't the app use https with pinning? The app in question: a wrapper of a PWA ticket purchase webapp which saves no payment info. Being able to run on rooted device was determined as severe category.
- SebFender 2y agoFrom experience, most are very junior and use automated solutions which just don't make sense. When we do ours we really focus on core elements and very material findings... as everyone should. But competency is so rare in this field it's hard to follow.