SShortSingh.
Back to feed

Developer Builds Passive Security Scanner Using Public Data to Avoid Legal Risk

0
·5 views

A developer was commissioned to build a domain security scoring tool for a client's lead generation funnel, but quickly identified a legal problem with the standard approach. Active scanning methods such as port scanning can constitute unauthorized computer access under certain laws, even when no data is altered. To sidestep this liability entirely, the tool was redesigned to rely solely on data already collected by third-party services like Shodan, Censys, SSL Labs, and certificate transparency logs. These sources provide information on open ports, SSL configurations, and forgotten subdomains without sending a single packet to the target system. The result is a narrower but legally defensible tool suited for public-facing use cases where no prior authorization from the scanned domain's owner exists.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

HelloNash.ai and Backboard Studio Released as Open Source Projects

The team behind Backboard Studio and HelloNash.ai has announced that both platforms will be made open source. The decision was framed as an act of solidarity with the broader AI community. Backboard Studio is positioned around the concept of Sovereign AI, emphasizing user ownership of their own intelligence and data. The announcement underscores a privacy-first stance, with the developers stating that users' business affairs are not their concern.

0
ProgrammingDEV Community ·

Why the AI Harness, Not the Model, Is the Real Engineering Challenge

As AI adoption grows, engineers argue that the true complexity of production AI systems lies not in the language model itself but in the surrounding infrastructure, known as the AI harness. This harness governs critical decisions such as model selection, input routing, output validation, and orchestration logic. Two teams using identical foundation models can achieve vastly different results depending on how well their harness is designed. Experts suggest AI engineering is shifting from prompt crafting toward software architecture disciplines like observability and system design. Teams that invest in building reliable, well-orchestrated harnesses are seen as better positioned to ship production-ready AI products.

0
ProgrammingDEV Community ·

How Solo Devs Can Secure Internal Services with TLS and mTLS on a Zero Budget

A developer running a small two-server production setup — one hosting Redis, another running Postgres alongside NestJS containers — found that firewall rules and private networking alone did not encrypt inter-service traffic. To address this without costly managed PKI tools or Kubernetes-based solutions, they built a self-hosted Certificate Authority using only OpenSSL. The approach enables both standard TLS and mutual TLS (mTLS), where both client and server authenticate each other, making it suitable for service-to-service communication. The guide covers certificate generation, key custody rules, and lifecycle management including rotation and expiry monitoring. It is aimed at solo developers and small startups who need production-grade encryption without a dedicated security infrastructure budget.