Search

Showing top 98 results for "security and audit"

People also ask

Why a security audit?

Any tool that runs with elevated privileges on shared infrastructure needs to earn trust. Inspektor Gadget runs with root-level access on nodes to do its job, so an independent review of its security posture is a natural step as the project matures and adoption grows. OSTIF is a nonprofit dedicated to improving the security of open source software. Over the past ten years, OSTIF has managed security engagements that have uncovered more than 800 vulnerabilities across 120 open source projects.

Inspektor Gadget: Results from the first security audit

Top stories

Discussions and forums

Hacker News · u/introvertmac · Dec 3, 2025

Tell HN: Compliance is not equal to Security

For over a decade, I’ve been doing bug bounty, security audits, and security consulting. And if there’s one thing I’ve seen repeatedly, it’s this:Most startups call a security engineer or hire a security agency only when…

1 1
r/devops · u/50lies · 3w ago

I don't think anyone at my company actually knows where all our pii lives

Security asked us a simple question during an audit. Where is all customer pii stored. And the room literally went silent lol. Warehouse. Backups. Old postgres instances. Abandoned s3 buckets. Random notebooks. Exported …

r/sysadmin · u/Lol_Panda2004 · May 11, 2026

fastest way to kill an enterprise SaaS deal: make IT feel nervous during auth review

i sit in on procurement/security reviews for a mid-sized company and honestly a shocking number of SaaS products lose trust in the first 10 minutes. usually it’s stuff like: “SSO is only on enterprise” MFA = SMS only no …

Hacker News · u/lmushro · May 12, 2026

Show HN: Vibe – Responsible AI Review for Cq (Stack Overflow for Agents)

Six weeks ago, Daniel Nissani at Mozilla.ai shared cq (https://news.ycombinator.com/item?id=47491466), Stack Overflow for agents. One of the top concerns in that thread was security and trust around shared knowledge.So w…

3
Hacker News · u/0kenx · 1w ago

Show HN: Nucleus – A security-hardened, Nix-native container runtime

Hi HN, I've been building Nucleus, a lightweight Linux container runtime focused on two workloads: ephemeral AI-agent sandboxes and declarative NixOS services. It's a single Rust binary, no daemon.It is not a Docker repl…

37 13