▲ | dzhiurgis 2 days ago | ||||||||||||||||
How you are confident you don’t have these issues? | |||||||||||||||||
▲ | zrobotics a day ago | parent [-] | ||||||||||||||||
I'm not at all confident we don't have any security issues, that would be an impossible statement to make no matter what company I work for. I am confident we don't have issues like baking API secrets into our shipped javascript, or just not doing auth at all and not validating account registration endpoints. Again, these are literally 101 level errors that any level of testing should have caught. PCI compliance isn't what I would call the highest bar for software security, and this stuff would fail an audit (at least the ones I've been involved in, I'm sure there are people who rubber stamp them). So while I can't say we don't have security vulnerabilities, I am very confident we don't have the types of vulnerabilities that anyone with even a passing knowledge of pentesting would be looking for. | |||||||||||||||||
|