Jump to content
Enpass Discussion Forum

Leaderboard

Popular Content

Showing content with the highest reputation on 12/15/16 in all areas

  1. I understand that you do not wish to open-source your product, but I am reluctant to use it because of the fact it is closed-source, the company is based in India (yes, this matters) and there is no information about the development team. Have you considered having an independent 3rd-party audit your source-code on a regular basis as a way to gain credibility without open-sourcing your product? Thanks, Gili
    1 point
  2. Hermant, I didn't say it's not true, just wanted to point that if it is then some response to these topics might help. Actually I am not that concerned about anyone stealing the credentials to my favourite restaurant's website (I don't keep sensitive data in these programs), but nevertheless I am doing my homework in form of a "security audit". I am no security expert nor have access to the source code, but can still find the obvious things (database, encryption, cloud sync, communication, etc) which might make people a little bit less afraid of your software. Even then, these days it's quite common that people are afraid of anything when it comes to their privacy. This is something that you should keep in mind when choosing not to do a third-party audit because <insert any reason here>.
    1 point
  3. +1 If you choose not to share the source, its sorta up to you to pay some third party to review the code with NDA. And as Gili said, no one expects reoccuring audits. Its mostly, or at least about customers needing to know that you've implemented cryptography in a acceptable way and of course that there are no additional ways in to a running process of Enpass.
    1 point
  4. Hemant, Thank you for your response. I don't think anyone is expecting frequent audits. Once a year or every 3 years should be enough. As to the cost... that's the cost of doing business. The primary reason I skipped over this product was because it was both close-sourced and unaudited. Otherwise, I would have purchased a copy. Gili
    1 point
  5. At least an answer please? AFAIK "Security of our data is your utmost priority." We have questions and thoughts, yet there is not even an answer from the maintainers. This itself means a serious security concern.
    1 point
×
×
  • Create New...