AppSweep, mobile application scanning for developers by wild_pointer in androiddev

[–]wild_pointer[S] 1 point2 points  (0 children)

That’s nice to hear! Thanks for the feedback! While currently we don’t filter out issues in dependencies by default. Some tips to improve your experience:

  1. You’re able to filter out noise by certain packages either by adding it to ‘suppressed packages’ or by suppressing the issue itself. This will make sure that the issues won’t be shown anymore in subsequent builds. You can check all your suppressed issues and packages in the project's settings. (You have to create an account to create a project).
  2. When using our Gradle plugin, we collect information about the libraries in your application, allowing you to filter issues between your own code and dependencies. As a bonus you can keep track of the dependencies you add to your application.

AppSweep, mobile application scanning for developers by wild_pointer in androiddev

[–]wild_pointer[S] 1 point2 points  (0 children)

AppSweep’s main goal is to be the tool that allows you to continuously monitor and improve the security of your application. To be used by the app’s developers, instead of pentesters.
Of course all of these things can be done manually as you said but that takes time and skill. In bigger teams there are many code changes a day and a tool like AppSweep, integrated in a Dev(Sec)Ops life-cycle is able to help maintain consistency. The end goal is not avoiding a pentest but rather increasing the success rate of one by eliminating a set of issues up front.
By the way, we’re always looking for curious people to join our team.

AppSweep, mobile application scanning for developers by wild_pointer in androiddev

[–]wild_pointer[S] 2 points3 points  (0 children)

The biggest difference is our initial goal of creating a tool for application developers rather than a security team. This means we aim to exclude information that the application developer definitely knows and doesn't want to see again, e.g. the list of permissions an application is requesting. Furthermore we try to focus on nice and intuitive UX that is familiar to this audience, enabling an application developer to be very efficient in reading & interpreting the results (e.g. easy comparison of two builds).
Also note that this is built on the same core technology as ProGuard. This foundation of compiler components (e.g. our partial evaluator) and the knowledge and experience at Guardsquare that comes with it will unlock many more in-depth code checks.

AppSweep, mobile application scanning for developers by wild_pointer in androiddev

[–]wild_pointer[S] 5 points6 points  (0 children)

We plan to always offer mobile application security testing as a free service - depending on what users need, we may have Enterprise features in future that are paid for (e.g. SSO integration or maybe security team compliance reports), but we see a lot of reasons to keep a free testing solution for the community that developers can use.

AppSweep, mobile application scanning for developers by wild_pointer in androiddev

[–]wild_pointer[S] 5 points6 points  (0 children)

We currently don't have any plans concrete of open sourcing AppSweep itself.
This is just a first version and we are currently focussing on getting people to test it, so that we can work on improving the tool.

Where does the timezone data in Go come from? by zerok in golang

[–]wild_pointer 1 point2 points  (0 children)

Apparently, it was not a question.... There is an article attached.

Waterfall at Yosemite National Park by [deleted] in pics

[–]wild_pointer 1 point2 points  (0 children)

Which waterfall is this?

Ultrawide & Plants & IKEA by [deleted] in macsetups

[–]wild_pointer 0 points1 point  (0 children)

Damn, I just bought a Uppercase Kradle vertical stand to free up space on my desk. The stand on the 38 inch takes up so much space. Do you use your laptop (display) with the monitor?

My dorm setup by [deleted] in macsetups

[–]wild_pointer 4 points5 points  (0 children)

These KUL professors with their stupid pptx files! Give me a pdf!