Google announced today that they are releasing their internal web assessment tool called ratproxy into public open source. It looks like an interesting tool, not with the full developer’s approach of something like HP WebInspect, but it likely has some interesting analytics to complement commercial tools. It is a passive tool, which has the disadvantage of less thoroughness than a tool that tries to actively break web sites, but has the advantage of not being disruptive to web sites since it doesn’t really touch them, of course essential to Google because they didn’t actually have permission to test web sites. The big deal is that it is free, which may cause some chaos in a market that charges quite a bit for these tools.
Google in and of itself is a sizeable security company, it has other proprietary internal security tools, and one wonders when and what else it could give away.








