Hacker News new | past | comments | ask | show | jobs | submit login

I hear you and I get it. What you are describing are security-focused pen testers, mission-focused red-teams. They are absolutely welcome, and they are a subset of the pen-tester universe. They are not a good fit for someone needing to get a PCI pen test, but they do incredible work in other areas. It highlights the point in the blog that the landscape of finding the 'right' pen-test team is not easy. Some are brilliant at one thing, others at many, but even an elite group may not be the right fit for the task at hand.

We are taking the feedback system seriously and are slowly testing it out. An easily gamed system is useless for everyone.




I'll be interested to see what you come up with!

But why must demonstration of skill be limited to elite red-team style pentesting? You could devise challenges geared at demonstrating all sorts of knowledge (HIPAA, PCI, websec) basic or advanced.

If you've seen the sad state of PCI audits in particular these days, you'll get my drift. I think there's a huge opportunity here to raise the quality bar with your marketplace.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: