Penetration Testing Effectiveness

Discussions center on the value, limitations, quality, and alternatives like bug bounties to penetration testing (pentesting) for cybersecurity assessments, often questioning why companies skip it or its effectiveness in finding critical vulnerabilities.

📉 Falling 0.5x Security
1,966
Comments
19
Years Active
5
Top Authors
#9414
Topic ID

Activity Over Time

2008
3
2009
10
2010
22
2011
45
2012
63
2013
86
2014
57
2015
107
2016
103
2017
164
2018
115
2019
141
2020
192
2021
209
2022
155
2023
190
2024
142
2025
134
2026
28

Keywords

VA opentech.fund UAT ycombinator.com NDA QA CVE NCC wikipedia.org testing pen penetration security bug report reports library bounty recognise

Sample Comments

totalrobe Mar 31, 2015 View on HN

Pen testing not a viable alternative?

kasperni May 6, 2020 View on HN

I wonder if they do any form of penetration testing?

boppo1 Oct 16, 2021 View on HN

Why not bother with pentesting?

buildbuildbuild Feb 28, 2017 View on HN

"Was just pentesting it" ... hopefully with their permission. Be careful.

tptacek Dec 19, 2025 View on HN

Just going to say here that people routinely engage pentest firms, several times annually, for roughly that sum of money, hoping but not expecting game-over vulnerabilities (and, from bitter experience as a buyer rather than a seller of those services over the last 5 years --- "no game-over vulnerabilities" is a very common outcome!)

ericalexander0 Aug 15, 2023 View on HN

You're better off doing a private bug bounty through bug crowd or hackerone.Pentests are point in time assessments. Usually with one to two testers, with limited scopes of expertise.Bug bounties can bring in hundreds of testers with a wide breadth of expertise that continuously test.

Eridrus Oct 15, 2017 View on HN

They're just a tool. You can use them wisely or you can use them poorly. They can be an incredibly useful additional set of eyes if you've already done the basics, or you could get flooded with piles of issues that anyone could have found.I used to work in sec consulting a decade ago and it was a shitshow, clients wouldn't have credentials ready when you were meant to start testing (but they'd still get billed), we were told to scope pentests to IPs with no listening servi

muricula Jul 15, 2021 View on HN

This exists: https://en.wikipedia.org/wiki/Penetration_test

jacobr1 Apr 4, 2020 View on HN

Periodic pentesting by a reputable firm

toomuchtodo Feb 27, 2024 View on HN

Do they pen test it?https://news.ycombinator.com/item?id=39378235