Penetration testing report from a "highly respected" security company:
* 20 pages of risk assessments, methodology discussion, tables, charts and other nonsense
* conclusion: "this report does not include any findings"
π€¦ββοΈ
@kravietz i once got a feedback for a malware scan I did, where they told me that it was suspicious because ** BEfOrE yOu dId tHE scAnN we NeVer haD pRobLems**
Fantastic approach... π€¦ββοΈ Actually, I've seen that a lot with penetration testing or SAST tools. With the latter it's partially justified by the fact that a scanner that is not tuned will instead flood the dev team with tons of irrelevant findings...
@kravietz I've seen it too, so I manually validate each finding to be sure they are not false positives, like when some macOS certificates get caught as malware, even when they came brand new. But what they want is a reason to not spend money on a threat they can't see ππππ
@kravietz