Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Can you give examples of the sort of problems it found?


  - Private IP address disclosure (1)
  - Allowed HTTP methods (1)  
  - Non HTTP-Only Cookies (2)  
  - Insecure Cookies (4)
Note: This is a 2-page website. Looks like the cookie problems are a result of the default Heroku 404 page.


It's good to have a fast check for these things, but you realize how simple that stuff is to spot, right? Insecure cookies and HTTPOnly (which: HTTPOnly is a bit of a band-aid; it's not a vulnerability not to have it) are trivial regexes on set-cookie headers; methods is something you can do with curl and a shell script.

If you're spotting these kinds of things only after using a 3rd-party tool, consider whether this is the kind of stuff you want to build into your integration testing.


In that vein, we search for a lot more than just these.

We're actually working on some tools to help integrate Tinfoil into your integrating testing scheme - more to come on that in the future. :)


Sorry! I know you do (for the benefit of the thread: I've been talking to 'borski for awhile about Tinfoil). I'm not commenting about Tinfoil so much as developers who are surprised to not be using secure cookies. :)




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: