Democratizing Security
blog.tinfoilsecurity.com
blog.tinfoilsecurity.com
That said: I'm not in love with the messaging here. The push/pull isn't between ineffective, inexpensive tools and ineffective, expensive consultants. Appsec teams are very effective. They just cost too much for startups.
My recommendation: stop positioning against security products and services. Nobody in the startup market really uses them and they don't care about their track records. Meanwhile, people in enterprise and large software markets are automatically wary of automated tools (like Appscan and WebInspect on the low end, or Veracode and Fortify on the high end).
You have a compelling story just by pitching the value of automated on-demand security testing at that price point. The direct comparison to competing tools just begs questions you don't want to answer.
(I've recommended Tinfoil to lots of people and continue to do so. Definitely glad they're finally launching!)
I agree. Additionally, I'm not sure who would actually subscribe to the paid version of this. Startups generally don't have a plethora of websites for testing. Someone with 250 urls to scan per month is likely going to be asking: what about my other (non-website) assets? Furthermore, if I were the IT person on site for a 250+ website installation I would be asking: what do I get out of this I don't get out of running another free tool such as Nessus (the answer, I'm afraid is going to be "less")? Sure, having to to go through the Nessus install process is kind of a pain (although this realistically represents < 5 minutes of my time); but as soon I saw that I had to add some kind of website verification I stopped there as well.
We offer a lot more than Nessus, in terms of doing a deep-dive on web application security. With that said, Nessus does a better job at network security, for example; this is something we're working on.
If I were you I would consider a model where I would be to do a full scan, display only the top X vulnerabilities found, and simply charge more to show the rest of the results.
Another thing I'm curious about: does this work on a pure client-side web application (e.g. my app is just one html page + javascript that loads all the html from templates)? Are you including static urls or somehow tracking "clicks" into a web app? Actually, most of the things I would concerned about in my web applications are things like not validating that I'm correctly doing correct validation in POST-requests. I'd be interested in seeing if you guys are doing that kind of "fuzzing" in that respect (though not sure if there is an automated way to do that safely). Additionally, I'd be curious to see what you detect Nessus/BurpSuite etc doesn't in terms of web application security.
Anyway, neat idea, perhaps I'll check it out a bit more thoroughly and do a comparison.
The best test to see how we differ from Nessus/Burp is to try it yourself! A lot of the vulnerability classes we scan for are very similar, but the ways in which we scan for them are different. We do offer our Standard Plan for a free 30 day trial. Would love to hear what you think :)
If you have any issues, ping us at http://tinfoilsecurity.com/supportchat
Our SQLi and XSS modules in particular are quite a bit heavier than Nessus', but there are other features like page de-duplication that optimize speed as well.
A much more realistic option is Burp Suite, which is $299.
Burp Suite is great for anyone who knows what they're doing; for anyone that isn't already a security guy/gal the UI is near impossible to figure out, and the results aren't particularly actionable. That's much of what we try to fix.
Not trying to be argumentative, just clarifying! :)
My favorite part? They point out security problems AND give actionable advice on how to fix them. That's useful.
- Private IP address disclosure (1)
- Allowed HTTP methods (1)
- Non HTTP-Only Cookies (2)
- Insecure Cookies (4)
Note: This is a 2-page website. Looks like the cookie problems are a result of the default Heroku 404 page.If you're spotting these kinds of things only after using a 3rd-party tool, consider whether this is the kind of stuff you want to build into your integration testing.
We're actually working on some tools to help integrate Tinfoil into your integrating testing scheme - more to come on that in the future. :)
Could you expand on the bios in your "About Tinfoil" page? I don't know if an executive looking at that page would be convinced you're all security experts (and I know this isn't "cool" but slightly more professional profile pictures might help)
Other than those points and the name ('tinfoil' doesn't inspire tons of confidence in me, but whatever, it's a name) I like the idea and presentation. Good luck!
We'd definitely like to take a look into your issues and see what went wrong.
Hmm.