Remix.run Logo
sandeepkd 21 minutes ago

Any company where understanding of security practices has a direct impact on its revenue from early phases can be considered as a security company in my view.

From what I have seen a large chunk of internet exists and stands on the shoulder of folks who did the volunteer work cause they were passionate about it and enjoyed that part. Once built, the nominal fee for API to check IP address should cover the costs way easily for the servers.

Letsencrypt is a great example, it did took away the big money from all these commercial CA's, who used to issue blue, green and what not kind of checkmarks. Thats one big reason reason why the migration to HTTPS happened faster.

strictnein 3 minutes ago | parent | next [-]

So I guess your answer is yes, you would like someone to do this work for you for free, because others have done other work for free. And then once the free work is done, you will happily pay a nominal fee to gain the benefit of all the free work?

> Any company where understanding of security practices has a direct impact on its revenue from early phases can be considered as a security company in my view.

This could, quite literally, be any company on earth then? But not CrowdSec, because they had a single security issue? Every company on earth has had those, including every security company.

itintheory 16 minutes ago | parent | prev [-]

The basic software is open source, and the list is free if you're running the tool and contributing detections back. They do have some curated lists that you have to pay for.

It's quite a bit less expensive than most other commercial products of this kind that I've looked at.