Re: [Full-disclosure] [Professional IT Security Providers - Exposed] Cybertrust ( C + )

2007-12-20 Thread guiness . stout
I'm not really clear on how you are grading these companies. I've had no personal experience with them but I don't decide a companies quality of work simply by their website and what information I get from some customer support person. These grades seem pointless and frankly unfounded. You

Re: [Full-disclosure] [Professional IT Security Providers -Exposed] Cybertrust ( C + )

2007-12-20 Thread Epic
-disclosure] [Professional IT Security Providers -Exposed] Cybertrust ( C + ) I'm not really clear on how you are grading these companies. I've had no personal experience with them but I don't decide a companies quality of work simply by their website and what information I get from some

Re: [Full-disclosure] [Professional IT Security Providers -Exposed] Cybertrust ( C + )

2007-12-20 Thread Peter Dawson
Agreed. !! I think theres a lot of 'fair play' with the secreview folks. -- We're going to give Cybertrust a C but if you can convince us that they deserve a different grade then we'll revise our opinion. So they are open for rebuttals and to changing their opinions ! On Dec 20, 2007 9:55 AM,

Re: [Full-disclosure] [Professional IT Security Providers -Exposed] Cybertrust ( C + )

2007-12-20 Thread Kurt Dillard
PM Subject: Re: [Full-disclosure] [Professional IT Security Providers -Exposed] Cybertrust ( C + ) I'm not really clear on how you are grading these companies. I've had no personal experience with them but I don't decide a companies quality of work simply by their website and what information

Re: [Full-disclosure] [Professional IT Security Providers -Exposed] Cybertrust ( C + )

2007-12-20 Thread Mike Vasquez
a favour and get a proper job. - Original Message - From: guiness.stout [EMAIL PROTECTED] To: full-disclosure@lists.grok.org.uk Sent: Thursday, December 20, 2007 2:05 PM Subject: Re: [Full-disclosure] [Professional IT Security Providers -Exposed] Cybertrust ( C

Re: [Full-disclosure] [Professional IT Security Providers-Exposed] Cybertrust ( C + )

2007-12-20 Thread c0redump
IT Security Providers -Exposed] Cybertrust ( C + ) I'm not really clear on how you are grading these companies. I've had no personal experience with them but I don't decide a companies quality of work simply by their website and what information I get from some customer support person

Re: [Full-disclosure] [Professional IT Security Providers -Exposed] Cybertrust ( C + )

2007-12-20 Thread guiness . stout
:[EMAIL PROTECTED] On Behalf Of Epic Sent: Thursday, December 20, 2007 11:56 AM To: c0redump Cc: full-disclosure@lists.grok.org.uk Subject: Re: [Full-disclosure] [Professional IT Security Providers -Exposed] Cybertrust ( C + ) Isn't ANY review subjective to opinion?I do

Re: [Full-disclosure] [Professional IT Security Providers - Exposed] Cybertrust ( C + )

2007-12-20 Thread trains
I am a pentester and IDS/IPS administrator for a large-ish security firm. None of our tech staff worked on the corporate web site. We are too busy, and frankly, it's just not my bag. Public facing websites are usually outsourced to professional graphics arts firms and developed under the

Re: [Full-disclosure] [Professional IT Security Providers - Exposed] Cybertrust ( C + )

2007-12-20 Thread elazar
Public facing websites are usually outsourced to professional graphics arts firms and developed under the supervision of the Director of Business Development. It's usually a solid pile of fluffy buzzwords and crap. Its sad how true this is. What makes it worse is half the time the Director

Re: [Full-disclosure] [Professional IT Security Providers - Exposed] Cybertrust ( C + )

2007-12-20 Thread SecReview
Greetings list. We've had an abundant amount of questions and challenges with respect to the grades that we give to businesses. As a result we will be posting a grade key on our site in the near future. At the risk of being redundant, our opinions of companies are formed by approaching the

Re: [Full-disclosure] [Professional IT Security Providers -Exposed] Cybertrust ( C + )

2007-12-20 Thread SecReview
? From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Epic Sent: Thursday, December 20, 2007 11:56 AM To: c0redump Cc: full-disclosure@lists.grok.org.uk Subject: Re: [Full-disclosure] [Professional IT Security Providers -Exposed] Cybertrust ( C + ) Isn't ANY review subjective to opinion

Re: [Full-disclosure] [Professional IT Security Providers - Exposed] Cybertrust ( C + )

2007-12-20 Thread SecReview
Trains, Thank you for the good email. We'll take your suggestions into consideration. We do already ask for sample reports, but the questions that you provide later are great. Thanks again! On Thu, 20 Dec 2007 10:20:57 -0500 trains [EMAIL PROTECTED] wrote: I am a pentester and IDS/IPS

Re: [Full-disclosure] [Professional IT Security Providers -Exposed] Cybertrust ( C + )

2007-12-20 Thread SecReview
Sent: Thursday, December 20, 2007 2:05 PM Subject: Re: [Full-disclosure] [Professional IT Security Providers -Exposed] Cybertrust ( C + ) I'm not really clear on how you are grading these companies. I've had no personal experience with them but I don't decide a companies quality

Re: [Full-disclosure] [Professional IT Security Providers - Exposed] Cybertrust ( C + )

2007-12-20 Thread SecReview
Awesome, So you were an RA Security customer, would you be willing to answer a few questions that we have so that we can revise our post? We don't want to post anything that is not accurate. Your help would be very much appreciated and we'd keep you anonymous. On Thu, 20 Dec 2007 11:49:23

Re: [Full-disclosure] [Professional IT Security Providers - Exposed] Cybertrust ( C + )

2007-12-20 Thread don bailey
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 SecReview wrote: Awesome, ... would you be willing to answer a few questions that we have so that we can revise our post? ... and we'd keep you anonymous. This is the most comedic statement on full disclosure this month. I, too, will ask

Re: [Full-disclosure] [Professional IT Security Providers - Exposed] Cybertrust ( C + )

2007-12-20 Thread SecReview
Don, the origional poster is anonymous so its not actually that funny. On Thu, 20 Dec 2007 14:59:01 -0500 don bailey [EMAIL PROTECTED] wrote: SecReview wrote: Awesome, ... would you be willing to answer a few questions that we have so that we can revise our post? ... and we'd keep you

Re: [Full-disclosure] [Professional IT Security Providers - Exposed] Cybertrust ( C + )

2007-12-20 Thread elazar
I don't mind answering some questions, however we had used them for a very basic scan so I couldn't tell you anything as far as their more in-depth services. Elazar On Thu, 20 Dec 2007 14:45:04 -0500 SecReview [EMAIL PROTECTED] wrote: Awesome, So you were an RA Security customer, would

Re: [Full-disclosure] [Professional IT Security Providers - Exposed] Cybertrust ( C + )

2007-12-20 Thread reepex
nothing don ever does is useful or funny On Dec 20, 2007 2:14 PM, SecReview [EMAIL PROTECTED] wrote: Don, the origional poster is anonymous so its not actually that funny. On Thu, 20 Dec 2007 14:59:01 -0500 don bailey [EMAIL PROTECTED] wrote: SecReview wrote: Awesome, ... would you be

Re: [Full-disclosure] [Professional IT Security Providers - Exposed] Cybertrust ( C + )

2007-12-20 Thread don bailey
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 reepex wrote: nothing don ever does is useful or funny On Dec 20, 2007 2:14 PM, SecReview [EMAIL PROTECTED] mailto:[EMAIL PROTECTED] wrote: Don, the origional poster is anonymous so its not actually that funny. It's true that

Re: [Full-disclosure] [Professional IT Security Providers - Exposed] Cybertrust ( C + )

2007-12-20 Thread Fredrick Diggle
You hax0red the hushmail and stole his ip address information thing? Can I has your sploitz plz? On Dec 20, 2007 5:35 PM, don bailey [EMAIL PROTECTED] wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 reepex wrote: nothing don ever does is useful or funny On Dec 20, 2007 2:14 PM,

Re: [Full-disclosure] [Professional IT Security Providers - Exposed] Cybertrust ( C + )

2007-12-20 Thread Dude VanWinkle
On Dec 20, 2007 6:35 PM, don bailey [EMAIL PROTECTED] wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 reepex wrote: nothing don ever does is useful or funny On Dec 20, 2007 2:14 PM, SecReview [EMAIL PROTECTED] mailto:[EMAIL PROTECTED] wrote: Don, the origional poster is

Re: [Full-disclosure] [Professional IT Security Providers - Exposed] Cybertrust ( C + )

2007-12-20 Thread coderman
On Dec 20, 2007 4:06 PM, Dude VanWinkle [EMAIL PROTECTED] wrote: ... WTF are you taking about Don? Of course hushmail is completely anonymous ! http://blog.wired.com/27bstroke6/2007/11/pgp-creator-def.html that shit makes me laugh so hard... transitive trust in some singular unknown

Re: [Full-disclosure] [Professional IT Security Providers - Exposed] Cybertrust ( C + )

2007-12-20 Thread Fredrick Diggle
The evil .gov are gonna subpoena hushmail for his identity because he told the sec review guy things about a company no one cares about... Oh noes! On Dec 20, 2007 6:32 PM, coderman [EMAIL PROTECTED] wrote: On Dec 20, 2007 4:06 PM, Dude VanWinkle [EMAIL PROTECTED] wrote: ... WTF are you

Re: [Full-disclosure] [Professional IT Security Providers - Exposed] Cybertrust ( C + )

2007-12-20 Thread elazar
However, if you think hushmail = anonymity you're worse at security than even I am. It's a funny coincidence that there are two Elazars posting to full disclosure at one time! I wonder if they're related?!?! HmmM!!m!M!Mm!M Jackpot! Ill give you some of my UK lottery winnings once I get them from

[Full-disclosure] [Professional IT Security Providers - Exposed] Cybertrust ( C + )

2007-12-19 Thread secreview
One of our readers made a request that we review Cybertrust (http://www.cybertrust.com;). Cybertrust was recently acquired by Verizon and as a result this review was a bit more complicated and required a lot more digging to complete (In fact its now Cybertrust and Netsec). Never the less, we