HNHacker News
TopNewBestAskShowJobs

kenbaylor

443 karma · joined October 14, 2015

submissionscomments
kenbaylor··on What I’ve learned from seeing 20k company pitches
Uber brought in close to a billion in profit in it's developed markets (mostly USA) last year
kenbaylor··on Uber to Sell China Business to Rival Didi After Losing Billions
Or Uber invested $2bn and walked out with $7bn. Not a bad deal. Plus the value of the combined entity will skyrocket.
kenbaylor··on All Signs Point to Russia Being Behind the DNC Hack
30 seconds on google: http://www.express.co.uk/news/world/692601/NATO-military-chi...

http://www.zerohedge.com/news/2016-06-15/nato-says-it-might-...

And look who gets blamed for the DNC leak:

http://www.zerohedge.com/news/2016-07-25/fbi-launches-probe-...

kenbaylor··on All Signs Point to Russia Being Behind the DNC Hack
No. I don't think either extreme makes the world a better place.

Good fences make good neighbors.

That goes for all parties involved.

kenbaylor··on All Signs Point to Russia Being Behind the DNC Hack
You mean like how we respect the borders of Afghanistan, Pakistan, Iraq and Syria?
kenbaylor··on All Signs Point to Russia Being Behind the DNC Hack
There's also a lot of evidence that NATO is being prepped to get more aggressive with Russia, and that Hillary wants a major escalation with Russia.

Given that the DNC emails provide enough rope to hang themselves, Russia would be stupid to NOT do this.

If it comes down to: Trump - friendship with Russia, Clinton - war with Russia, I know which way I'd vote.

kenbaylor··on Russian Government Seize Private Internet Access' Servers
Quick comment on two Russian laws that often get mixed up:

242-FZ: It requires data on Russian citizens be kept in databases within the borders of Russia, and that first-write and first-update happen in Russia.

The other laws involved required retention of internet access logs for 6 months.

kenbaylor··on How Uber secretly investigated its legal foes and got caught
Oh you mean like Austin, Vancouver and SF. Who needs the ability to make decisions when politicians will make them for you?
kenbaylor··on Parker Conrad Steps Down as Zenefits CEO
Either one of two things: a) like normal employees now, VCs insist founders vest over 4 years, so what he has vested he keeps, or b) the board says he was fired 'for cause' and can claw back ALL his equity (many but not all contracts have such provisions)
kenbaylor··on Show HN: Building a Market for Penetration Testing
Since this posting, I've had 3 boutique firms sign up. It is a supply constrained market, but a highly inefficient one.
kenbaylor··on Show HN: Building a Market for Penetration Testing
The transparency of who actually is good. The talent in companies ebbs and flows and the scores will reflect the work they are doing now, not what they did in their best or worst days.

There are many boutique companies that are excellent, but don't have a fair share at the market.

Companies that are 'all things to all men' tend to have quality issues over time... like the big security giants of the last decade. Eventually people get tired of it and look for specialists. That's where this will help.

kenbaylor··on Show HN: Building a Market for Penetration Testing
The complaints I have heard is similar to the big 4.

Many go to them, they see awesome resumes. They also see very large costs. The the customer finds he doesn't get the A-team, but the F-Team, due to 'unprecedented demand'.

This is about making the process transparent.

kenbaylor··on Show HN: Building a Market for Penetration Testing
The answer from raesene4 is the right way to go.

For baby steps I would advise starting with nessus, and metasploit then targeting virtual machines that you build on your own home network.

kenbaylor··on Show HN: Building a Market for Penetration Testing
Some of this can be covered by the methodology section, where the pen testers shows the approach taken and has an overview of what they did. There's a happy medium between one-line reports 'nothing found' (which encourages questions like 'did you even try?'), to the voluminous crap produced like old vulnerability scanners. Providing the report template in advance may help set expectations. The industry is moving towards standards based pen testing. That has some pros but many cons as well. For the moment, setting expectations and having a thorough debriefing with the customer may have to do. Your question is the scientific one: How do I know what you did was good enough. Just like a patient evaluating a medical professional care, the customer isn't an expert and goes with their gut in some cases. That's why the industry also wants you to use different pen testers. I've seen many a time, when one team finds nothing, and another rips the infrastructure apart. Competency is a variable over time and so is trust. TLDR: The scientific question does not have a simple fix by any means.
kenbaylor··on Show HN: Building a Market for Penetration Testing
I believe a LOT of security testing will evolve to QA and software testing. There a LOT of issues will be found. Instead on micro-focuses (in the past), the CD approach can test the whole system, which is a huge leap forward.

Pen-tests should be good reality checks to ensure the system is working, and that it is sufficient to withstand current attacks.

Sometimes companies are very smug and need the reality check. Boards are starting to request them to ensure the confidence is warranted.

I've also seen pen tests used as a tool to GET funding. Fail one big time due to known vulnerabilities just to show how messed up things really are...then get a budget to fix them.

kenbaylor··on Show HN: Building a Market for Penetration Testing
I hear you and I get it. What you are describing are security-focused pen testers, mission-focused red-teams. They are absolutely welcome, and they are a subset of the pen-tester universe. They are not a good fit for someone needing to get a PCI pen test, but they do incredible work in other areas. It highlights the point in the blog that the landscape of finding the 'right' pen-test team is not easy. Some are brilliant at one thing, others at many, but even an elite group may not be the right fit for the task at hand.

We are taking the feedback system seriously and are slowly testing it out. An easily gamed system is useless for everyone.

kenbaylor··on Show HN: Building a Market for Penetration Testing
1 Way NDA: Let's have an open honest conversation, but as you signed MY NDA, written in MY favor then: I CAN tell everyone about YOUR secrets, but you CANNOT tell anyone about my secrets

2 Way NDA (also called Mutual NDA):Let's have an open honest conversation, and as you signed MY NDA, written in neither party's favor then: I CANNOT tell anyone about YOUR secrets, and you CANNOT tell anyone about my secrets. It enables honest dialogs.

TLDR>> 1 Way NDA's suck

kenbaylor··on Show HN: Building a Market for Penetration Testing
You rock. Thank you. Will fix it.
kenbaylor··on Show HN: Building a Market for Penetration Testing
The NDA is mutual. It might say 'company x failed our pic-audit, we need help fast'. It guarantees we keep that secret but use that info to find the right match.

Also on the pen test side, we wont't say vendor C put in a $10k bid, you should put one in at $9k. It just means we value trust and privacy, as everyone in the security field should. Testers would also sign an NDA when they take a job, so that they won't leak things they learned in confidence.

kenbaylor··on Show HN: Building a Market for Penetration Testing
The LinkedIn approach is to validate people are who they say they are. We have a number of people who have very limited LinkedIn profiles, and some that have 'skeleton profiles'. Once you authenticate the profile you fill out is only seen by us for the purpose of finding you work. We take the 'stealth' very seriously. We also didn't want to store people's creds.
kenbaylor··on Show HN: Building a Market for Penetration Testing
Great feedback. Will flesh out the team section. You're right on the customer feedback section that there may be a huge disconnect between customer and vendor perception. We will likely have to get in the middle of that in certain situations to ensure feedback is fair and accurate. There is some movement on standardization of reporting e.g. Now a 43 page document from the PCI council on how to do the pen test. On your personal peeve: I hear you. That why I tried to define pen-testing for what it means to me. There's tons of other definitions out there and many are prejudicial to scope and quality.
kenbaylor··on Show HN: Building a Market for Penetration Testing
Thank you. Will investigate. Just moved the site to AWS and may have some 'cert challenges'
kenbaylor··on Show HN: Building a Market for Penetration Testing
Well described. Also pen testing is a litmus test that can be done anytime. The vuln models are for the few companies who have made great progress in squishing bugs and are taking a very proactive approach. Unfortunately that is still a small percentage of companies
kenbaylor··on Show HN: Building a Market for Penetration Testing
Great feedback. I want to build a service that the HN community finds useful. The approach I've taken has been based on my experience and approx 15 others. But that said, it's highly susceptible to groupthink. I want to solicit HN to see if it resonates, needs a tweak, or completely needs a redo.
kenbaylor··on Show HN: Building a Market for Penetration Testing
This is Ken, who wrote the blog. I am in the thread.
← PreviousPage 3 of 3