@jerry I just ran our (mostly passive) security analyzer against infosec.exchange. You did an excellent job hardening the domain, DNS, and the web services. Just wanted to recognize that you put in the time and paid attention to the details. It did not go unnoticed and is appreciated!
Would we want to ever “trade and grade”? If that makes sense? I did a really shitty scan of our stuff the other day and I would be happy to begin collaborating on a small effort to just standardize the checks and keep an eye out for the broader community.
Here’s my work BTW — these have sense been fixed as far as I know.
@nova@jerry I'm happy to run assessments for community projects. My company builds this platform and normally charges for these, but if it's for the greater good, I would consider free assessments - especially if the trade points out something we overlooked checking.