Hello everyone,
I’m Zachi, a software engineer and security researcher with about 6 years of experience. During this time, I’ve conducted security tests on over 200 apps, and in more than 70 cases, I found critical vulnerabilities (SEV-1) in apps with 10+ million users.
I’m currently planning a curated portfolio of smaller Android apps to identify patterns and use them to guide further research. This means you’ll receive a security review, which typically costs in the four-digit range, for free. I don’t have, nor do I want, any special access; I work with the same permissions as any external tester. I'll use the network traffic and extract the apk, everyone could do that.
The only requirements are active permission to perform non-permanently harmful tests against your backend and your consent to allow me to publish the findings, anonymized if necessary, on my blog.
All findings will be presented to you, including fixes. Nothing will be published until it has been fixed.
If you’re interested, you can either contact me directly here on reddit, in the comments or via email at [me@zachi.dev](mailto:me@zachi.dev)
submitted by /u/Born_Excuse_5610[link] [comments]