40 karma · joined December 21, 2013
It also won the Modern Language Association's top award — the James Russell Lowell Prize for the most outstanding book published in 2023.
Having an established business with customers in revenue, obviously significantly helps in the fundraising process and evaluation. The other huge advantage is you can benefit significantly from the Qualified Small Business Stock statute which provide an exemption/shield on federal taxes when you sell that is the _greater of_ either $10m or 10x times your valuation at the time of funding.
[1] https://www.nowsecure.com/blog/2017/12/29/enable-ios-app-tra...
[2] https://developer.apple.com/news/?id=12212016b
[3] https://www.klundberg.com/blog/app-transport-security-delay/
[1] https://www.nowsecure.com/blog/2025/02/06/nowsecure-uncovers...
If folks are interested in this space, I just got the mailing list [2] running last night and you can see a list of all the current incidents on my Incident Tracker [3].
I have many more data points I plan on tracking as well as adding 10-K GRC items to the list (potentially helpful for CISOs, other risk managers and investors to eval a companies risk management maturity).
Welcome any feedback!
[1] https://www.board-cybersecurity.com/incidents/tracker/202401...
Static binary analysis looks for the version string but doesn’t currently do deeper analysis of reversed code to see if it’s patched. Could go either way.
And determining if the code is triggered and exploitable is quite challenging. Dynamic analysis can help here, provided you have the coverage.
More generally tho, istm that there will be instances when the version is unpatched and there is some exploitable vector (even if it’s just crashing the app). My hope is to raise awareness for developers (and security) about 1) transitive dependencies and 2) some really old OpenSSL versions in very popular mobile apps. I don’t believe most folks think about this and awareness can lead to shipping safer apps.
I posted additional details in this blog+video: https://www.andrewhoog.com/post/how-to-detect-openssl-v3-and...
If you're interested in mobile security, you can get an idea about our work in a recently vulnerability we helped Samsung patch impacting 200m+ devices. [2]
Over 50% of our company is remote and we're hiring 30+ people this year. If you're interested in mobile and/or security, would love to hear from you. [3]
[1] https://www.nowsecure.com/ [2] https://www.nowsecure.com/blog/2015/01/27/samsung-corrupdate... [3] https://www.nowsecure.com/careers/
Disclaimer, co-founder here.