Tangential: Can anyone with experience in this field provide an estimate for how much this kind of audit costs? Just considering the viability of open source projects fundraising to cover the cost of an audit.
Penetration tester here - My anecdotal experience:
I've worked on a number of projects where bill rate is something like $250-$400/hr per engineer depending on complexity, access to source code, size of the project, etc.
Usually equating to something like 10-12k for a single engineer on a project for a week. For bigger projects like this I would think it's totally reasonable to see anything from 4 engineering weeks -> 12 engineering weeks depending on different pieces and especially given this is a very high profile project. Based on that estimate of something between ~40k-120k. I know that's a huge range, but just wanted to share what I do know.
On top of just "compliance" or "customers demand it", these types of penetration tests can and do expose real, serious vulnerabilities in software.
Furthermore, I wouldn't underestimate the positive press that having a third party security firm assess your product and share the results publicly. VPN Services have been under special scrutiny lately so I think something like this makes total sense for Mozilla, regardless of the cost.
Why not? it's a one time expense that helps you launch.
If throwing money at a problems solves, that's rarely a hard argument to make.
If you throw engineers at a problem it might get solved, or it might not. Hiring an engineer to work on something is a high risk investment.
side note: Mozilla does have great engineers, when I was there a few years ago the security was also very competent. But it's probably not the same as getting specialized consultants.
Not sure about that. The major VPNs have similar (not identical) functionality and price. They're competing on the perception that they are more secure than others. In that light, having a passing security audit by a reputable company would be table stakes for a lot of customers. As noted by another commenter already, not having one could also be a deal-breaker on a vendor security assessment by a big company, too.
For a Berlin-based team like the one Mozilla used, $250-$400/hr/engineer is kinda hard to believe. Probably closer to $150-$200/hr. The average software engineer in Berlin makes $71k/yr. The compensation levels are very different compared to SV.
So he is talking about bill rate which is very different than what someone makes. At my company someone might make $50 but their bill rate might be like $175. Your bill rate factors is all sort of costs like having an office building, insurance, taxes, and everything that goes into having an employee above just salary. So even if they are in Berlin their bill rate is most likely comparable.
I am familiar with Berlin rates and this person is right. 400 USD (337 euros) an hour is unrealistic, unless you are hiring Cure53 specifically because employee X did groundbreaking research on topic Y and that's why you need that expertise; only then would I expect Mozilla to agree to that sort of rate. The range is more likely to be 110 - 250 euros per hour, where both ends are fairly unlikely but it's not as if I have comprehensive industry-wide data on everyone's financials. (I'm not that kind of hacker, heh.)
The sibling commenters are right, though, that the hourly rates charged by the company are not very related to how much you earn as a person. I wish I got my hourly rate as salary, but I see what kind of organisational crap the founder has to do and it's just not worth the headache to me.
Don't forget to add the employer's mandatory social security contributions and any additional employee benefits and equipment[0], the USD<>EUR exchange rate, and the fact that even in Berlin a senior security engineer will definitely make more than 71k€.
[0]: The founder of a (Germany-based) IT consulting firm recently told me that, as an estimate, pretty much any engineer at a tech firm costs at least 100,000€/yr.
It of course depends a lot on the scope of testing you want done (code audit, probing your running SaaS, some light breaking & entering [1]…) and how much time you want to give them to probe.
And how well organized you are in providing them info/how much trouble it seems like you're going to be for them.
And how well known the vendor doing the work is.
And lots of other factors. Possibly somewhat discounted for OSS or high-profile projects, this is also an advertisement for Cure53 to some degree.
But as a random guess for a random project, at least low 5-figures.
Hi OP, I'm Erik CEO of IncludeSec. We do many FOSS audits for Mozilla, OpenTechFund, etc. I can give you some ranges and points of consideration from what I'm seeing in the industry today.
First consideration point is quality of the team and the seniority of the people ACTUALLY DOING THE TESTING (a lot of pentest shops do bait and switch senior presenting but juniors do the actual work.)
Next consideration is location of company; EMEA and Asia are lower hourly rates than US teams.
Next consideration is scope. Do you want the front door checked, or the entire house inside and out? In this case Cure53 spent 25 work days on this asmt, which gives quite a lot of time to analyze the software and check lots of different avenues of attack.
Next consideration is type of attacks to try and security assessment methodology. Do you want just fuzzing? Perhaps you can get that for free from Google's OSS-Fuzz, they will sponsor people to set up your FOSS app with their fuzzer via CI/CD. Do you want static analysis from some big COTS vendor like coverity/fortify/checkmarx/etc. that could be useful and they often have discounted/free scans they will do for FOSS. Or perhaps you want super smart hacker pentesters to code review and dynamically attack your app (that's what my team does)
Next consideration is publicity, do you want this reporting public? Some charge extra for that.
There's a million other thing to consider when hiring a pentester, but this message is already too long. To give you a ballpark, estimate $10k to $40k for small projects, $40k to $80k for medium sized projects, and $80k to $150k for large projects. YMMV of course, but those ranges and the consideration points should get you well on your way.
Hit us up if you need more tips, happy to help via email <myfirstname>@includesecurity.com
Speaking from a buyer's perspective (I've managed about three penetration tests) they costed around 10-15k per person week-ish.
The cost can be adjusted depending on how experienced the testers are, timing (I need it now vs I need it next month), and how much time they are expected to spend writing up executive reviews. We always opted to just get a list of vulns and passed on the executive reviews as they tended to take up at least a whole day or so of the budget.
You can also save a lot of time by having a really well prepared dev system set up and ready to go for them. Getting someone familiar with your setup while also trying to sort out VPN access, GitHub permissions, etc... costs time and money, so doing that ahead of the engagement saved me about a day of budget.
You can get things that are a lot cheaper, but that's usually just going to be a newly hired tester running burp suite or some other automated testing tool. It's still worthwhile to do though if you haven't, an OWASP top 10-20 automated scan may cost less than $5k but still can be helpful/insightful if you want to reduce your risk surface area.
Is this figurative or do you really get a discount for planning it one month ahead where you're from? From my (n=2 employers) experience, projects are usually planned at least two months ahead (if it's not busy; end of year you can expect 4-5 months).
The executive summary thing is also interesting. We take maybe 30 minutes at the end to sum up what we tested, which issues we found (particularly the impact in semi-layman's terms, depending on the impression we got from the contact person), and sometimes if there are big omissions from the scope that smell foul and someone (us or another company) really should still have a look at then we might remark that there as well. But we don't charge a day's rate for a short summary. I guess what you mean is more substantial than this?
It wasn't a negotiated line item, but more that we had a specific ask, and the agency we were engaged with had a particular expert available if we could wait > a month. This didn't directly affect the cost - which maybe I should have made more clear, but still affected what I think would be the value of the engagement. I guess I'm saying: be aware that you may pay the same for less if you are in a hurry, but it'll still be better than what you have without paying :) It's still my suggestion that if you know there's a specialist available, wait if you can and bring them in.
For the summary: we always got the short summaries, list of vulns, recommended remediation. Tbh - I never paid for the exec summary, but my guess is that it was just taking all that stuff, spiffing it up into a PDF with clickable sections, and making it a lot more flowery? It sounded like something more desired by larger enterprise companies (maybe like this blog post!) than small ones like the one that I managed these engagements for.