TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Apply HN: Hacksplaining – what every web developer needs to know about security

27 点作者 malcolmhere大约 9 年前
Beta online now: https:&#x2F;&#x2F;www.hacksplaining.com<p>There&#x27;s a gap in the market for online security training aimed at developers. Most training companies focus on security awareness for regular employees (making sure your receptionist doesn&#x27;t click on phishing emails) or infosec training for security professionals (learning how to perform penetration tests). Developers have to make do with books, blog posts, and online videos.<p>We&#x27;ve taken the most common security vulnerabilities and put together a series of interactive exercises that ask a developer to put themselves in the shoes of a hacker. Next, we show how to protect against these vulnerabilities with real code samples. Finally, we test developers on what they&#x27;ve learnt.<p>The beta launched a few weeks ago and the feedback has been amazing. We hit the front page of reddit (300,000+ page views in one day) and have more than 13,000 sign-ups so far. Our users are consistently telling us the same thing: they have always worried there is a gap in their security knowledge but have generally been too embarrassed to bring it up to their boss.<p>Getting into YC will help us grow the site into a real product. We have a couple of big security firms interested in working with us and a lot of enquiries about the premium version (which will allow employers to invite and track their employees&#x27; progress through the course). There&#x27;s clearly an appetite for the product, and we want to build a business out of it!<p>If you have any questions or feedback, we&#x27;d love to hear from you. :-)

4 条评论

tptacek大约 9 年前
This sounds similar to Safelight (now, I guess, &quot;Security Innovations&quot;):<p><a href="https:&#x2F;&#x2F;www.securityinnovation.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.securityinnovation.com&#x2F;</a><p>They were quite successful with online security training, and companies will pay for it.<p>So my questions, I guess, are:<p>* How do you stack up content-wise against something like Safelight?<p>* Who are you, and what&#x27;s your pedigree? To a big extent, companies buying security CBT are buying a sort of stamp of approval for their process; how does your brand do that for them?<p>* Why do security firms want online training? That seems like a really tough vertical to sell this kind of training for (big security firms tend to sell training courses like these themselves, except on-site, at nosebleed prices).
评论 #11472900 未加载
bestattack大约 9 年前
Wow, I like this quite a bit. Your tutorials are very informative without making me feel talked-down to.<p>How will you get users? I can imagine doing distribution via company training programs or via people telling their coworkers&#x2F;friends about it (or maybe something else?). One of these vectors is going to be better than the others. Given your success on Reddit it&#x27;s possibly a viral product, but if so, you need to worry about retention - it&#x27;ll be interesting to see if users keep coming back to learn more.
ryporter大约 9 年前
This seems like a useful service that could get traction, but I think you&#x27;ll need to find other ways to monetize it than charging companies to track their employees&#x27; progress. There are a lot of companies that sadly don&#x27;t care enough about security to consider paying for a service like this. I would explore other avenues, such as certification (targeted at developers entering the field), referrals to security firms (e.g., consultants or pen testers), and job boards&#x2F;placement.
JohnSmith78098大约 9 年前
Please give the link to the Reddit comments.
评论 #11472625 未加载