Benign
Independent security researcher
Areas of work
- Mobile application security
- Android internals and ARM64 reverse engineering
- Web and API security
Disclosure practice
- Findings go to the affected organisation first. Nothing is published without their written agreement.
- Testing uses only accounts and devices under my control.
- An issue is demonstrated with the smallest action that proves it, and no further.
- Destructive functionality is analysed, never invoked. No testing at a volume that could affect a live service.
- Retesting after a fix is deployed is free.
Contact
- General
- benign@benignsec.com
- Report an issue
- security@benignsec.com
PGP fingerprint
C487 FF8A A9DE 4D0C FC03 53EE 9D77 0A97 53EA 7558
- Public key
- benignsec.com/pgp.txt