> This is pretty unusual for Cure53, who have a reputation for being a bit effusive about the products they're paid to review. I'm not sure I've ever seen them throw shade before.Yes, and it's getting really old. I'm tired of seeing security consulting firms wax poetic about how good the client's security is in their reports, then bend over backwards to frame obviously serious findings in the best possible light. That's not their job, their job is to report security vulnerabilities objectively, with sufficient coherence, context and reproduction steps so as to make the problem evident and motivate a solution.
Naturally, as soon as Cure53 decided to politely categorize what are clearly critical vulnerabilities as high severity, Remembear took to Twitter to crow about how much of a success the security audit was - "No critical findings!" I have serious reservations about the incentives at play between companies and the consultants paid to (security) review their products, especially when the report is publicized.
In my opinion, companies should not be using security consulting firms as a component in a press release. It encourages a mischaracterization of the state of the company's security and the severity of findings, and it puts a pressure on other security consulting firms to "play ball" and gush about their clients' products in publicized reports.