7 comments

[ 3.7 ms ] story [ 27.8 ms ] thread
> General Bytes said the company has received “multiple security audits since 2021”

Let's publish names of the audit providers. Let's fix the industry of sloppy audits just "for compliance". Let's blame them as well, as they certified it's secure.

I agree, as someone who performs audits.

However, just because they've had multiple security audits, doesn't mean those audits didn't find issues that weren't dealt with.

"multiple security audits" as you know, means hardly anything.

Also, if it is a zero day bug, then potentially the audit may not have ever picked it up.

While I agree that previous engagements might have found vulnerabilities that may or may not be addressed (after all, that's up to the client) I think a core part of a decent source code audit or pentest is to find those so if that was the case then it could speak of the proficiency of those involved.

In my own experience I've noticed that a lot of times it's really hard to get the clients to address these sorts of issues, even when it's clear that they are critical and could directly translate to monetary loses which makes no sense to me but sadly doesn't surprise me at all.

Just to be clear, of course there is a scope and a web service audit doesn't usually end up with a thorough audit of all the packages used by the application because nobody will pay for that and even if they would, it's usually mind numbing enough to end up in people glancing over things and checking boxes but in most cases this is not the root of the issue.

Probably that's the difference between audit/report and certification. With they would not receive the certificate. And then it becomes important what agency issued the certificate.
I'm curious why someone thought it was a good idea to let an ATM user upload files of any kind.
Its weird to classify a simple remote to local upload overwrite as a "0-day". Maybe I'm just being pedantic.
Technically it is a zero-day since the vendor didn't know about the vuln. "zero-day" has nothing to do with complexity