Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> They said a pentest would find them if they were important.

Is it just me, or are pentests about as useless as a UK home survey? Like, they're not going to move the furniture to look for issues.

I've experienced many companies who think due diligence is done by paying a 3rd party company to do the annual pentest. Meanwhile, the eng that actually work on the product, and know about potential issues, can't get leadership buy-in to invest in security.



Counterpoint: pentests are good to catch regressions over time.

Should it be your only security strategy? No. But it can help in combination with other solutions.


They're not all bad. We're selling our house and the buyer's surveyor was incredibly thorough - he picked up on some small issues I'd never even noticed even though they were right in front of my eyes the last few years (nothing serious though). He was so good that I'd definitely use him for any future moves.


> as useless as a UK home survey

Hey it confirms the loft exists at least, by virtue of the surveyor sticking their head through the hatch

Is there a more cushty job in existence??


Pentests can be brilliant if you know the scope you want to have tested. The additional benefit being the business is more likely to pay (engineering time!) for fixes of the issues reported.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: