benignsec.com

Benign

Independent security researcher

Areas of work

  • Mobile application security
  • Android internals and ARM64 reverse engineering
  • Web and API security

Disclosure practice

  1. Findings go to the affected organisation first. Nothing is published without their written agreement.
  2. Testing uses only accounts and devices under my control.
  3. An issue is demonstrated with the smallest action that proves it, and no further.
  4. Destructive functionality is analysed, never invoked. No testing at a volume that could affect a live service.
  5. Retesting after a fix is deployed is free.

Contact

Report an issue
security@benignsec.com

PGP fingerprint

C487 FF8A A9DE 4D0C FC03 53EE 9D77 0A97 53EA 7558

Public key
benignsec.com/pgp.txt