Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yeah I'm fairly well aware how pentests are billed (I've been in testing for ~15 years as a buyer, seller and tester :) )

My point was, that there was a gap between how the blog appeared to be billing the test "thorough security assessment and penetration test" and the report's statements around scope.

Obviously companies can't always afford all the testing that they need to get as much coverage as they could, but when your major selling product is a downloadable application, a comprehensive review would usually at least touch on it as part of the work performed, for it to be called thorough.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: