Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Heh. You’re proposing around... well, ${a lot of money} worth of work.

When I was a pentester, I once ran the numbers and concluded that each pen test must have cost some absurd amount of money for us to be profitable. And they do, because it’s effective. But I wanted to point out a likely possibility: they wanted to do what you were saying, and concluded a million dollars spent on a pentest was beyond reach.

a review of the web, desktop and mobile apps and the browser plugins

If a million dollars sounds like an overestimate, you’re right to be skeptical. But $270k seems entirely reasonable; that’s $30k per app, for 9 apps.

So it might be tempting to feel like “it’s just a browser plugin though. How can the cost be anywhere comparable?”

Because pentests are billed in days, and a day on a plugin is a day on an app.



Yeah I'm fairly well aware how pentests are billed (I've been in testing for ~15 years as a buyer, seller and tester :) )

My point was, that there was a gap between how the blog appeared to be billing the test "thorough security assessment and penetration test" and the report's statements around scope.

Obviously companies can't always afford all the testing that they need to get as much coverage as they could, but when your major selling product is a downloadable application, a comprehensive review would usually at least touch on it as part of the work performed, for it to be called thorough.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: