Show HN: Building a Market for Penetration Testing
stealthworker.com
stealthworker.com
As a seasoned (although retired) pen-tester I wanted to say you'll have some serious problems with rating when it comes to results.
When a company hires pen-testers and pen-testers do or do not find stuff, the company has no idea about the coverage. So the pen-test team might have missed many stuff or identified all. I'm sure you've seen in real world even the same members of the same pen-test team might find different issues for the same test.
Therefore one of the biggest problems is to actually knowing whether they are good or not at what they do. It's easy to rate communication skills, responsiveness, attitude, report quality etc. But very hard to rate the quality of the results (which is the real reason for carrying out a pen-test).
When they don't find something, maybe there really is nothing there. When they found something, maybe there is more there. The customer has no idea at that point. It'll be only a fair amount of time later they'll figure out the coverage / vulnerability finding quality.
I'm sure in the long run market will stabilize (assuming you can change your rating for a pen-tester even after a year) but this is something to consider.
Update: BTW personally I don't like the idea of logging in via LinkedIn (for finding a security talent), it's feels too intrusive, beside of the personal preference my experience showed me especially security industry don't like SSO style things.
When they don't find something, maybe there really is
nothing there. When they found something, maybe there is
more there.
Also, if you try to evaluate on "number of issues found" you encourage the testers to report junk issues to get their count up.Is your firm instead relying on self-assessment by clients? Then, like Ferruh Mavitunah said, I'm not clear how this system can work: most clients aren't qualified to evaluate the effectiveness of a pentest, and will instead evaluate based on soft-skills.
I have another business question. The most lucrative clients across the board are "house accounts" that source repeated tests from a single firm. When one of these companies sources a consultancy through your market, what prevents them from bypassing you for all future engagements?
This is a race-to-the-bottom problem that plagues freelancer programming markets.
So without doing anything either illegal or unethical, things that could lose me my current job, how does one build up the skills and experience?
You should probably start by picking an area that you're interested in (e.g. web, infrastructure, mobile) as whilst there's some commonalities each area has it's own toolset and specific areas of focus.
For learning there's things like https://pentesterlab.com/ , https://www.offensive-security.com/metasploit-unleashed/
For practicing legally , a lot of CTF competitions make use of skills which are useful for penetration testers, also places like vulnhub https://www.vulnhub.com/ have downloadable challenge machines that you can run in a VM.
In terms of meeting up with people in the industry, look out for local Defcon chapters or B-Sides conferences, both of which tend to be free or low cost and have some good content.
For baby steps I would advise starting with nessus, and metasploit then targeting virtual machines that you build on your own home network.
edit: the metasploit site asks for payment in the form of a donation to charity, so I'll take closer look at that one first. Now that's a link worth sharing.
Which is to say, at least in the app pentesting market, I'm a little skeptical of the premise.
This is, for what it's worth, my field; I co-founded Matasano and helped run it until we sold to NCC.
Many go to them, they see awesome resumes. They also see very large costs. The the customer finds he doesn't get the A-team, but the F-Team, due to 'unprecedented demand'.
This is about making the process transparent.
The software pentesters with gold-plated resumes do high-value targets (because there are more high-value targets than there are pentesters to service them). Google is not going to source Google Mail pentesters on DICE. Adobe doesn't source pentesters for Reader on DICE. Microsoft doesn't source pentesters for SCHANNEL.DLL on DICE. Apple doesn't source pentesters for the iPhone bootloader on DICE. That's where the A-Team ends up.
What transparency are you adding here?
If the argument behind this was, "we're going to drive down the price of pentesting", that would be a coherent pitch, although I'd still want to hear how you expect this service will do that; again, the market is supply-constrained.
There are many boutique companies that are excellent, but don't have a fair share at the market.
Companies that are 'all things to all men' tend to have quality issues over time... like the big security giants of the last decade. Eventually people get tired of it and look for specialists. That's where this will help.
I'm not talking about "big security giants" like IBM and Deloitte. I'm talking about boutique application security firms that do little other than test software. They're already specialized.
I think what patio11 is doing with Starfighters.io is orders of magnitude better. Run developers through a gambit of supremely difficult tests via a fun CTF-type game and pair the best hackers with the highest enterprise bidder. Works not just for pentesters, but all devs really.
Also, I know where to get the best pentesters because they're listed on all the top companies' bug bounty pages. It's proof of skill I'm after, not some Gartner-esque gatekeeper telling me who's best because they've "background checked" them.
Give me a system more like StackOverflow or Starfighters where I can see the work. Not something subjective like eBay or Yelp, which can be easily gamed.
We are taking the feedback system seriously and are slowly testing it out. An easily gamed system is useless for everyone.
But why must demonstration of skill be limited to elite red-team style pentesting? You could devise challenges geared at demonstrating all sorts of knowledge (HIPAA, PCI, websec) basic or advanced.
If you've seen the sad state of PCI audits in particular these days, you'll get my drift. I think there's a huge opportunity here to raise the quality bar with your marketplace.
I'd just want more proof than "Bob says he does a bang-up job" -- there's so much incest in enterprise, recommendations and upvotes mean nothing.
Take a look at the leaderboard for Microcorruption some time. It's public. (SF's are not, as a considered design decision for the moment.) If you do and cannot understand the claim I am making, that's cool, but I feel no particular need to elaborate.
More important in the long term than the names you will recognize are the names you will not.
I saw the StealthWorker table at Shmoocon and wanted to swing by and ask some questions, but I got distracted by some of the other goings-on. Anyways, I finally got around to signing up a few days ago.
One issue that I have from the pentester's point of view is the lack of transparency after sign up. I haven't seen any confirmation that my application was received and is under review. However, I understand that StealthWorker is still in its infancy so this is understandable.
Excited to see what the future of StealthWorker holds!
I feel a little uncomfortable signing an NDA unless the work has been outlined and the work is to begin.
Also I think you're really cutting out a significant portion of the market with LinkedIn requirements. I understand it's probably needed to filter the plebs, but you should probably allow for an alternative sign-up approach (ie combination of phone verification, require business email, etc).
Altogether very cool! I'm trying to get into InfoSec myself. Good to see innovation in the industry!
Also on the pen test side, we wont't say vendor C put in a $10k bid, you should put one in at $9k. It just means we value trust and privacy, as everyone in the security field should. Testers would also sign an NDA when they take a job, so that they won't leak things they learned in confidence.
Sorry, I'm not sure I exactly understand that. ELI5?
2 Way NDA (also called Mutual NDA):Let's have an open honest conversation, and as you signed MY NDA, written in neither party's favor then: I CANNOT tell anyone about YOUR secrets, and you CANNOT tell anyone about my secrets. It enables honest dialogs.
TLDR>> 1 Way NDA's suck
Here's the error I get in my Chrome console:
Mixed Content: The page at 'https://www.stealthworker.com/blog/rewarding-pen-testers-on-... was loaded over HTTPS, but requested an insecure XMLHttpRequest endpoint 'http://www.stealthworker.com/'. This request has been blocked; the content must be served over HTTPS.
After I clicked "load unsafe scripts", it reloads the page and I can click the link. I'm assuming my system will explode, shortly.
The link still doesn't work, btw.
- I'd suggest that customer feedback may not necessarily the best way to guage security tester* competence. Many testers report by exception so if the customer gets a relatitvely clean report they may be happy with that, but if the report doesn't detail the testing completed, how do they know the tester just didn't miss things from the review? You could enforce a consistent reporting style with tests completed to address that, but I'd guess that some testing companies wouldn't appreciate being asked to re-tool their reporting process.
- The model seems to imply the customer scopes the review. In my experience for organisation with less experience of security testing, that's one of the hardest parts to get right. More experienced/larger companies would, I'd expect, be less likely to use this kind of service as they already have a panel process/procurement in place. If Stealth Worker are going to participate in the scoping proces it would need the right set of people to complete that task (not a massively common skillset in my experience as it needs a good combination of technical experience and business understanding)
- Will the marketplace validate vendor claims of competence/skillset, and if so how will they do that? This could be a good value add, but is expensive to do well (e.g. designing and running assessments for candidate companies to provide a level of assurance of skill in particular areas).
- It'll be challenging to create an international model for this, as the regulatory requirements are different per country, and whilst testing companies might currently have indemnity insurance in their local market, that may well not cover international situations.
- The site could use some fleshing out on the team side. Currently says "Stealth Worker is a team of CISOs, developers and lawyer" .... To me there's a large ommission there which is from that it implies you don't have any testers on staff?!? I'm sure that's not the case, so it'd be worth making sure that was in clear on the site.
*Pet peeve, I prefer the term security testing to pen testing. The term pen testing rarely describes what most organisations actually need and also what is delivered. Pen testing implies a black box adversarial review "emulates a malicious attacker". This is only really desirable for mature organisations who have a strong handle on all the basic (which is not, in my experience, the majority). Also truly emulating attackers is very difficult as they tend not to worry about breaking the law, unlike testing companies (you'd hope!)
As a software test engineer, we do external audits like this, but I wonder: Documented or "known" vulnerabilities are not worth testing until there are systems in place that expect to cover them.
It seems that all vulnerabilities that are not intentionally addressed should be considered dangerous. If they are penetration tested but vulnerability is unknown, the best you could hope for is "Not vulnerable for unknown reasons" which is just as bad as vulnerable in my perspective.
With some admitted trepidation, I assert that all software should be tested this way, with expected behavior being a primary dependency.
Edit: hiring outside penetration testers is still totally valid and desirable, since development and testing are two totally different domains. I'm only pondering methodology.
Pen-tests should be good reality checks to ensure the system is working, and that it is sufficient to withstand current attacks.
Sometimes companies are very smug and need the reality check. Boards are starting to request them to ensure the confidence is warranted.
I've also seen pen tests used as a tool to GET funding. Fail one big time due to known vulnerabilities just to show how messed up things really are...then get a budget to fix them.
Thanks for the reply.
Your connection is not secure
The owner of www.stealthworker.com has configured their website improperly. To protect your information from being stolen, Firefox has not connected to this website.
Just tested on Firefox and it shows our cert from Comodo, upon clicking more information, what did you see?
Thanks