4 ms·
Hi tptacek, Indeed security tools should be part of the developer's workflow but not necessarily the way they are presented in Burp. We are yet to see a horde
by passfree 12y ago
Hi tptacek,
Indeed security tools should be part of the developer's workflow but not necessarily the way they are presented in Burp. We are yet to see a horde of developers who can spend spare time fiddling with requests in order to find bugs in their own code. There are not only time constraints but also this type of thinking is not natural to everyone.
Websecurify is working hard to find out better ways to enable developers do the minimum security testing without getting in their way.
- tptacek 12y agoI'm not saying developers should use security tools to do security testing (although that is also a good idea). I'm saying that in terms of the day-to-day workload of developers building web apps or APIs, a tool like Burp is as valuable or more valuable than a debugger is to a C programmer.