logo

An AppSec checklist for when finding vulnerabilities is the cheap part

Posted by paulbleicher |5 hours ago |1 comments

paulbleicher 5 hours ago

I work at Konvu and I wrote this

When I tell security people I used to work at Sqreen, I get one of two reactions. A blank look, or "Oh, Sqreen. I remember using the CTO Security Checklist." It helped thousands of people, and it ran here twice [1][2].

But it was also written for a different world. With "rogue AI agents" breaking out of sandboxes and exploiting 0days [3], we needed an update.

So I wrote a new one, out of a couple hundred conversations with security engineers over the past two years. The criticism of the old one that stuck with me was tptacek's in that 2019 thread: the seed/A/B staging was cutesey, most of what it deferred shouldn't have been, and the whole thing existed to put RASP on the do-now agenda. He was right. This one is marketing too, but I hope it's still valuable like the first one was. It stages by how much of your loop is automated rather than by funding round, which I think is a better axis. It's still a staging device though, and it will let someone skip a control they should already have.

What did I miss?

[1] https://news.ycombinator.com/item?id=20055442

[2] https://news.ycombinator.com/item?id=16615593

[3] https://huggingface.co/blog/agent-intrusion-technical-timeli...