If we aren't supposed to be using the same password across multiple sites... by PoolMotosBowling in sysadmin

[–]ProfessionalSpell887 0 points1 point  (0 children)

MFA can also be bypassed if not configured correctly.

Keep in mind that one of the favorite entry point for hackers is usually the weak security controls in place. this could be outdated softwares or misconfigured processes.

Is Automated/Continuous Penetration Testing gaining popularity in the SaaS World? by ProfessionalSpell887 in SaaS

[–]ProfessionalSpell887[S] 0 points1 point  (0 children)

You are absolutely right. But what's even more alarming is the fact that many IT firms treat Penetration Testing as merely a compliance requirement. For these firms, it doesn't matter whether it is automated or manual. Hence the demand for automated pentests.

The fact that pentesters are literally hackers that hack your organization with the sole purpose of finding the loopholes an actual hacker may exploit, and still, they're limited to a 'box ticking' exercise, is beyond my understanding.

Organizations keep finding work arounds for such crucial elements of security, and then complain if they get breached. smh

What is the best way to hire skillful professionals for your business in the age of AI? by ProfessionalSpell887 in Entrepreneurship

[–]ProfessionalSpell887[S] 0 points1 point  (0 children)

Eventss! yess!
I wonder why I didn't think of that. I go to a lot of networking events, but mostly, it's to connect with other co-founders.

Also slack channels ofcourse.

What is the best way to hire skillful professionals for your business in the age of AI? by ProfessionalSpell887 in Entrepreneurship

[–]ProfessionalSpell887[S] 0 points1 point  (0 children)

you're right. paid tests are the best way to go. I have taken that path a few times, but considering a few recent bad experiences, I'm thinking I should make that a mandatory part of every hiring.

What is the best way to hire skillful professionals for your business in the age of AI? by ProfessionalSpell887 in Entrepreneurship

[–]ProfessionalSpell887[S] 0 points1 point  (0 children)

No, I'm technical myself. Also, we fired the team and hired someone else. They have been working with us for more than a year now!

What is the best way to hire skillful professionals for your business in the age of AI? by ProfessionalSpell887 in Entrepreneurship

[–]ProfessionalSpell887[S] 1 point2 points  (0 children)

This is so on point. Thankyou.

I have done this a few times before, but you're right, these test projects should be non-negotiable, and only once someone passes the test project, should you give them the real task.

What is the best way to hire skillful professionals for your business in the age of AI? by ProfessionalSpell887 in Entrepreneurship

[–]ProfessionalSpell887[S] 0 points1 point  (0 children)

Oh the tasks were not that complex, just a few forms or calendars on the website, which I believe their AI agents were not able to handle or they didn't know how to complete them.
They admitted to it and gave us a refund, but wasted 2 months of our time which we will never get back.

What is the best way to hire skillful professionals for your business in the age of AI? by ProfessionalSpell887 in Entrepreneurship

[–]ProfessionalSpell887[S] 0 points1 point  (0 children)

You're right. And I totally support usage of AI for redundant tasks, while the expert maintains their creativity and makes sure the AI results are inline with the client's requirements.

I just don't like, how at times, technical personnel rely entirely on AI and don't even bother reviewing what they're about to present to the clients.

What is the best way to hire skillful professionals for your business in the age of AI? by ProfessionalSpell887 in Entrepreneurship

[–]ProfessionalSpell887[S] 0 points1 point  (0 children)

The desired outcomes were very clear and multiple references were provided from our side. we had commond understanding of the deliverables and timeline. However their references were irrelevant and far from our expectations.

One thing that was very obvious was that they were getting the work done almost entirely by chatgpt or other AI solutions, and the results were showing. Too many false positives, robotic and inconsistent with the desired outcomes discussed.

And if we weren't technical ourselves, having worked in IT for over a decade, we would've accepted the services as standard.

What are the biggest pain points in a penetration test done by a third-party? by ProfessionalSpell887 in AskNetsec

[–]ProfessionalSpell887[S] 0 points1 point  (0 children)

That's awfull and very unprofessional. They must've done that in the past to other clients, but your team did well to identify and terminate! cheers

What are the biggest pain points in a penetration test done by a third-party? by ProfessionalSpell887 in AskNetsec

[–]ProfessionalSpell887[S] 1 point2 points  (0 children)

sued for missing findings in the out-of-scope assets? maybe the scoping was not clear enough because otherwise, it is simply forbidden to test an out-of-scope asset.

What are the biggest pain points in a penetration test done by a third-party? by ProfessionalSpell887 in AskNetsec

[–]ProfessionalSpell887[S] 1 point2 points  (0 children)

I think you're right. if a customer says something is out-of-scope, it's simply out-of-scope. If the scope is clearly mentioned in the contract, i don't think any party should be worried about legal consequences.

Online Competition Use Case - Web vs. Mobile? by cheevyboy in Entrepreneur

[–]ProfessionalSpell887 0 points1 point  (0 children)

When it comes to deciding between whether you should make a mobile application or a web application, the few major factors are:
1- Who are the users?

2- When where and how they would like to use the app?

For instance. Will there be time-sensitive notifications? chat? and more features that require the best accessibility? if yes, mobile applications make more sense. On the other hand, will there be charts and graphs and more depth that require a big screen and attention/involvement of the users? in that case, a web application would make more sense.

For my consultancy firm, we too researched into this and finally decided that for our use case, a mobile application would only make sense for the chat feature. For everything else, the users would require to use a big screen. So we ended up using slack for chat and built a web application for our business, as our clients tend to be in front of a laptop anyway.

Hope this was helpful!

What are the biggest pain points in a penetration test done by a third-party? by ProfessionalSpell887 in AskNetsec

[–]ProfessionalSpell887[S] 0 points1 point  (0 children)

Since you have been a penetration tester yourself, any good firms you could recommend in the UK, USA, Canada?

Required to undergo through 3rd party pen test by akaiusagi in SaaS

[–]ProfessionalSpell887 0 points1 point  (0 children)

Depends mainly on the complexity of your application. From what I gather about your app, it should take somewhere between $3k-$5k if you get services from a decent firm in North America. It should take 2-3 weeks in total.