Skip to main content

Sqreen wants to become the IFTTT of web app security



French startup Sqreen recently launched a Security Hub with dozens of plugins to put you in control of the security of your web app. In many ways, it feels like enabling tasks on popular automation service IFTTT.

Sqreen participated in TechCrunch’s Startup Battlefield and Y Combinator’s current batch. The vision of the product hasn’t changed. Sqreen lets you protect your web service with little effort from your side.

Big companies have dedicated security teams that protect services, try to run attacks to find weaknesses and more. Smaller companies don’t necessarily have enough time and money to build a dedicated team. But your product is still vulnerable to SQL injections, XSS attacks and brute-force attacks.

Sqreen isn’t a firewall. You just have to install a library package on your server and add a couple of lines at the top your source code to require the Sqreen module in your application.

Once this is done, Sqreen monitors attacks in real time without a big performance hit — the startup says there’s a 4 percent CPU overhead. Sqreen now works for web apps in Node.js, Ruby, PHP, Python or Java.

In addition to protecting you against common attacks, Sqreen makes security recommendations so that you can regularly fix vulnerabilities. And with GDPR coming soon, tech companies have a greater responsibility when it comes to protecting customer data and disclosing hacks.

Customers wanted to know more about what Sqreen was doing. That’s why Sqreen launched a security hub with documented plugins.

“All security vendors are very secretive,” Sqreen co-founder and CEO Pierre Betouin. “Usually, you can’t test the product and you have no information on what they do. We were like this at the beginning of Sqreen. Our positioning was really ‘install our library and we’ll cover a range of security features.’”

“We had a big push back. So we wondered how we could be more transparent, provide something more rational. We explain each plugin completely.”







You can find a plugin to protect you against SQLite injections, vulnerable dependencies, XSS Javascript injections in various frameworks, bot activity, etc.

Sqreen will recommend plugins for your app depending on the technologies and frameworks you’re using. You can then enable or disable each plugin and configure notifications on Slack or PagerDuty for instance.

In the future, you can imagine that third-party companies could contribute to this marketplace and add new plugins. Sqreen is also working on other plugins related to email abuse and payment page protection.

In addition to those new features, Betouin is moving to San Francisco and opening an office there. Companies like Front, Mindbody, BlaBlaCar, Triplebyte, Toptal and Algolia are now using Sqreen.

Comments

Popular posts from this blog

What is your preferred smartphone screen size

Screen envy. We all have it. Or do we? See, that’s the thing, I’m just not so sure. One thing I am sure about is that our phone screens have gotten progressively bigger and bigger over the last few years. The funny thing is, we as a society have taken that ball and run with it, like we just don’t care. But I always thought we did care? Some time ago, when phones were in the sub-5” range, we used to have a term called “phablet” which described an almost absurdly big phone. The definition varied from person to person. I always considered a phone with a screen 5.5” or bigger to be a phablet. The Galaxy Note fell into that category. The Lumia 1520 certainly did. There are others as well. I was safely ensconced in the 4.5” area at the time with my Lumia 920. What did I know? Leon’s getting laaaaaaaarrrger But slowly, phones started topping the 5” mark. I’m not talking about phablets here, I’m talking about normal flagship phones – the Galaxy S4 (barely) and the HTC One (M7) are ...

Facebook Now Supports PGP To Send You Encrypted Emails

You can now instruct Facebook to encrypt every email it sends to you so nobody — not even the NSA — is likely to be able to read your messages anytime soon. All you have to do is import your public PGP key into your Facebook settings and you’re good to go. The problem here, of course, is that most people have no idea how public/private key email encryption works and how to even get started with it. In the wake of Edward Snowden’s leaks, a number of organizations, including Google, promised to completely hide the complexities of end-to-end email encryption from regular users. Very few of these products have materialized so far, however — not for lack of trying, but because this is actually a very complex problem, both from a technical and user experience perspective. Facebook uses the well-established PGP scheme (the GNU Privacy Guard implementation of  OpenPGP, to be precise) to encrypt messages and tools lik...

Intel announces the first 14 nanometre processor

At the Computex conference in Taipei, chipmaker Intel has revealed a fanless mobile PC reference design using the first of its next-generation 14nm "Broadwell" processors. The 2 in 1 pictured here is a 12.5" screen that is just 7.2 mm thick with keyboard detached and weighs 670 grams.  The Surface Pro 3  – for comparison – is 9.1 mm thick and weighs 800 grams. It includes a media dock that provides additional cooling for a burst of performance. The next-generation chip is purpose-built for 2 in 1s and will hit the market later in  2014 . Called the Intel Core M, it will be the most energy-efficient Intel Core processor in the company's history with power usage cut by up to 45 percent, resulting in 60 percent less heat. The majority of designs based on this new chip are expected to be fanless, with up to  32 hours of battery life,  offering both a lightning-fast tablet and razor-thin laptop. Intel is also delivering innovation and performance for the ...

Laser gun is deployed and operational on U.S. Navy warship

After several years of research and testing, the U.S. Navy has introduced a new laser gun designed to protect ships without using ammunition.   Another entry on our  timeline  is now a reality as the U.S. Navy has authorised the first operational use of a laser weapon. This new hi-tech system – known as the Laser Weapon System (LaWS) – is designed to serve as a form of defence against drones and other small flying vehicles or small-boat enemies including suicide attackers. It is highly accurate, able to hit objects moving at up to 300 mph (480 km/h). The LaWS fires a solid-state infrared beam with two modes: high output to destroy a target, and low output for optical "dazzling", warning shots or to cripple a potential attacker. Among the advantages of this device versus projectile weapons is the low cost per shot, as each firing of the weapon requires only minimal cost for generating the energetic pulse; by contrast ordnance for projectile weapons must be des...

How to Choose BitLocker Drive Encryption Method and Cipher Strength in Windows 10?

BitLocker is an encryption method that enables users to lock the different drives in  Windows . The drives which are protected by BitLocker are accessed by passwords. Windows has provided opportunity for users to choose and configure the  cipher  strength and algorithm used by BitLocker Drive Encryption. This can be achieved via the Local Group Policy editor. The Local Policy Editor will let you configure and select the cipher method for BitLocker encryption. By default it is not configured but you can choose your choiceable encryption method by enabling the Policy Setting. If the drive is already encrypted or if encryption is in progress, the encyption method will have no effect. If you leave the policy unconfigured, then BitLocker will use the default encryption method of AES 128-bit with Diffuser or the encryption method specified by the setup script. Steps to Choose BitLocker Drive Encryption Method and Cipher Strength in Windows 10 1.  ...