TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Exploit Prevention as a Service for Rails

23 pointsby tkelloggover 11 years ago

4 comments

jphover 11 years ago
Take my money! :) Your service is super-useful for app security. I&#x27;m signing up right now. Great idea.<p>My two cents for you: you&#x27;re far enough along that you can start seeding your market as fast as possible.<p>* How about going to meetups at app dev companies such as Pivotal, Carbon 5, ThoughtWorks, etc.?<p>* How about a free version for open source projects, or students, or nonprofits?<p>Try to make the signup faster and easier.<p>* How about an item on the homepage saying &quot;Upload a Gemfile.lock to see if it&#x27;s secure&quot;? I would personally do this first because it&#x27;s fast, easy, and needs no setup.<p>* How about an item on the homepage asking &quot;What&#x27;s your GitHub username?&quot; then skim for vulnerabilities? I would personally do this because I write many open source gems.
评论 #6838172 未加载
borskiover 11 years ago
This is a really useful service for what we call &quot;version tracking,&quot; and it looks like it&#x27;s running Brakeman for you too. With that said, it won&#x27;t find vulnerabilities you code in yourself - only publicly released vulns that Ruby, etc. have issued patches for. A tool like <a href="https://www.tinfoilsecurity.com" rel="nofollow">https:&#x2F;&#x2F;www.tinfoilsecurity.com</a> can help you find more vulnerabilities that either a) haven&#x27;t been found yet publicly or b) you&#x27;ve written in yourself. (Disclosure: I&#x27;m the cofounder)
评论 #6835711 未加载
评论 #6835839 未加载
revisionzeroover 11 years ago
Love the idea. An upcoming project, that I am a part of, will likely be built on Rails, so this has been bookmarked!
评论 #6835856 未加载
homakovover 11 years ago
Automated security audits are useless until we have some fancy AI
评论 #6835858 未加载