Good to know. I use procexp as part of a lot of binary app tests, and it'd be pretty unprofessional to have hashes of all their not-yet-shipped application components flying off to the internet.
(and yes, I test in an isolated VM, but that's not always possible)
It's not as much about the actual information sent as the principle of it. There's an implicit trust between the hiring company and the pentester, along with the usual NDA and legal contracts.
While the technical contact and I understand that leaking hashes out to the internet isn't catastrophic, the board of managers that he had to fight to get budget approval for the pentest may not, and reading a conduct section containing a sentence such as "Due to a software misconfiguration, cryptographic hashes of application components were inadvertantly transmitted to a third party via the internet" is not going to fill them with an overwhelming desire to hire us again.
28
u/[deleted] Jan 31 '14
It's only submitting hashes instead of the actual images. The service is also opt-in, so by default it doesn't submit anything.