Thanks a lot @hnshah for hunting us 🙌
Hi Everyone! ✋
Sherif Koussa here, Founder @ Reshift Security. I have been a developer, a software security auditor at a large bank, a hacker and an OWASP Chapter leader.
Being a developer for 8 years and working directly with developers to help them secure their code for another 13 years, a few things became super clear to me:
- Developers are cognitively overloaded with too many frameworks, technologies, and languages 🧠
- Software development and deployment speeds are 100x faster than they were 10 years ago 🚀
- Application security responsibility is falling on the laps of developers hence the “Shift Security Left” movement ⏪
- Existing tools are slow, inaccurate, expensive and/or ineffective 🐢
In 2019, we set out to change that. We created Reshift , a developer-first security tool that helps developers find and fix vulnerabilities in their custom code.
Reshift is different from existing tools in the following categories:
1. Developer UX: Reshift is built from the ground up to help developers focus on writing and shipping secure code faster 🚀
2. Scanning Speed: Reshift uses DataLog technology which is 30x-40x faster than existing technologies 🚀
3. Findings Accuracy: Reshift’s comprehensive set of rules helps developers focus on the most important security bugs 🚀
I would love your feedback. Myself and our whole team will be responding all day and look forward to hearing your thoughts!
We’re excited to help teams shift security left! I know I’ve had my fair share of success and horror stories helping clients integrate security earlier into the software development lifecycle. What has been your experience shifting security left?
Meet the Team
2:00 - 3:00 EST Zoom Link: https://us02web.zoom.us/webinar/...Reshift Community:
Join Reshift Community Slack channel to speak directly to our engineers and meet other security-minded developers, share what works and what doesn't in shipping secure code faster. We also schedule free educational webinars exclusive to our community. See you there!
@sherif_koussa Congratulations to you and the team. You have a unique, developer-centric approach to getting teams to understand and write secure code. It's awesome to see all of this experience manifested in a product that's very usable.
@david_mennie Thanks David, we've certainly worked hard to build a developer-centric security tool so it means a lot coming from you!
Report
Quick poll for your engineering team:
How many developers feel code security is important? (everyone raises their hands 🙋♂️🙋♀️)
How many developers feel like they aren’t security experts? (likely also 100%🙋♂️🙋♀️)
How many of them like fixing security bugs? (probably none of them 🐞❌)
We hear this all the time from development teams. A developers job is to write and ship new features. Security is often a priority, but it is challenging to implement and often overloads the developer with more work that inherently slows down releases.
Excited Reshift is looking to change that and make shifting security left easier for developers!
@olivianharris I agree, being in the industry for over 20 year, both on the development and security sides on things, I have seen both sides of the table. Developers talk new features, and Security talk Risk and Compliance.
While the concept of shifting security left is great in theory. It is much easier said than done. Application security has to be baked in the software development and has to be super easy to do, and that's exactly what Reshift is set out to do.
Report
I had been eagerly awaiting Javascript support since it was announced as NodeJS has become such a key part of our product platform. While we are just beginning our journey with ReShift and NodeJS, so far the scanner has been fast, and has not generated useless noise which is always the bane of automated code analysis.
@kmcampott Awesome, thanks a lot for the great feedback :) Looking forward to supporting you guys get the most out of Reshift.
Report
@kmcampott Thank you so much for that feedback, we're happy you were with us on this journey to releasing JavaScript! Always a pleasure working with Klipfolio :)
Report
An incredibly important tool to help developers create and learn about producing secure code from a dedicated team who can make it happen.
@garth_boyd Thank you Garth, it means a lot hearing that from you!
Report
I've seen the @reshift team build this tool over the past year and heard from developers loving the quick results! Fixing vulnerabilities in custom code, so needed!
@hrishio@_jamesmundy@abrahamparangi@shedd@mscccc@ruxandrafed@karimsfubc@olivianharris for most startups, security is a risk and part of doing business, as the startup grows with more customers, clients data, etc. That risk grows to unacceptable levels and the company deals with it. Nowadays, most companies are forced to deal with the security risk earlier as part of doing business. For example, most startups in the B2B space can't do sell without showing evidence that proper security hygiene has been followed.
@fisch0920@philfreo@nateritter@timolins@ankurnagpal@balajis@olivianharris From my experience, software development teams have to take small steps. While shipping code is always the priority, small steps to deal with security technical debt always pays dividends down the road. This what Reshift is trying to do. Help software development teams secure their code without slowing them down.
Reshift Security
Klipfolio
Reshift Security
Reshift Security
Reshift Security
Reshift Security
Reshift Security
Reshift Security
Reshift Security