Post AWetUetPVRlAdoHuQS by mensrea@freeradical.zone
 (DIR) More posts by mensrea@freeradical.zone
 (DIR) Post #AWec0tOdJrEhiO73E8 by tek@freeradical.zone
       2023-06-13T16:24:07Z
       
       0 likes, 0 repeats
       
       I love working with the pentester we've hired this year. There's a good chance we’ll meet up at DEF CON, where he's spoken before.And I think he likes working with us. I’ve given him a ton of information about how our stuff works, and vowed to be an open book to him. If the end result is that he can’t find a way to attack us, I want it to be because he had all the information an attacker could possibly want and we're still solid.Seriously, pen tests are fun.
       
 (DIR) Post #AWeelLIK7tVfT8REbA by mensrea@freeradical.zone
       2023-06-13T16:55:01Z
       
       0 likes, 0 repeats
       
       @tek not when the report you get is basically just "nope, didn't find anything. you're good."
       
 (DIR) Post #AWesc9mUxhUKVs4B1s by tek@freeradical.zone
       2023-06-13T19:30:17Z
       
       0 likes, 0 repeats
       
       @mensrea Yeah, you hope they find *something*, or at the very least can show you what they tried.
       
 (DIR) Post #AWetUetPVRlAdoHuQS by mensrea@freeradical.zone
       2023-06-13T19:40:12Z
       
       0 likes, 0 repeats
       
       @tek yeah. saw one for our PCI environment and there was no detail about what was tried or how it was tried. apparently for compliance it's good enough but as a useful tool to the business it was a wast of money
       
 (DIR) Post #AWevEs7YkwRqwVVRQG by tek@freeradical.zone
       2023-06-13T19:59:47Z
       
       0 likes, 0 repeats
       
       @mensrea That'd be frustrating. We're not just doing this to check a box. We genuinely want to know if there's something we could be doing better.
       
 (DIR) Post #AWevRo3jAXuw6rshnM by mensrea@freeradical.zone
       2023-06-13T20:02:01Z
       
       0 likes, 0 repeats
       
       @tek i'm trying to get folk to a 'do it right and compliance will happen' mindset but it's taking a minute
       
 (DIR) Post #AWf42jf3Hb9ookSYiG by eviljarred@waytoomuch.info
       2023-06-13T21:38:20Z
       
       0 likes, 0 repeats
       
       @tek teams that aren’t open and transparent with the testers they’ve hired are wasting their money. Great attitude.
       
 (DIR) Post #AWfBCupXJJjg26AHvU by tek@freeradical.zone
       2023-06-13T22:58:44Z
       
       0 likes, 0 repeats
       
       @eviljarred Right? It’s like lying to your doctor. Congratulations: you got a fake good bill of health.