HN user

0xeeeeeeee

23 karma
Posts0
Comments26
View on HN
No posts found.

A lot of people are talking about revamping these old programs. I don't see what the problem is with less, cat, vim, etc...

I've never been using a program and wished for better functionality. Even when this was all new to me, it was never a problem figuring these out, using them, and I was always satisfied with them..

So...here's the question. I don't think these are broken, so what are you fixing?

Alright. If you are a web developer or you are a whatever who knows nothing about security, please read resources that apply to whatever you do.

Learning security on a topic will make you so much better at what you do and it will make you learn internal details AND best practices.

The things you build will be BETTER not just more secure

I'm really tired of reporting account hijacks and Remote code executions to startups who look at me blankly when I explain what I did

Seeking work. Remote

I do security consulting and work at a well known security startup. If you have a web or mobile app that you need help either implementing, scaling, or someone to pentest and double check your security settings, crypto, token implementation, whatever you need then I'm your guy. I'm available for short or long engagements

You can email me at evanjjohns at gmail

It is incredible, the equivalent of the "Oceans" movies but electronic instead. For everyone one of these sophisticated attacks there is a huge number of smash and grabs.

Really interesting stuff. It is only getting better as well (imho). I am honestly not noticing any increase in security aptitude in the average engineer. People are still making the same mistakes.

SEEKING WORK Location: USA, DC REMOTE: Yes

Security, cryptography, web-development, security consulting.

I work at a successful security/crypto/web startup co. Looking to make some money on the side, remote and short term. I would be great for pentesting your web or mobile apps.

Contact me. evan@honelerts.com

It looks great. UI is really nice to look at.

Looking around, this has a long way to go before it is able to compete feature wise with current commercial managers.

Also, it's going to take a long time, security-wise, to get up to par with the current commercials as well. It sounds like I'm being harsh but there are a lot of possible issues to consider. An HSTS header would be a nice start......

Palantir is pretty mysterious to me. Frankly, I don't see the demand for their software being high enough to warrant their size and number of employees.

I guess I'll just have to wait and see what happens.

I reported this issue a long time ago. Got the same messages back from facebook as everyone else in the thread. I've reported other issues and always get the same thing back.

It sounds like Facebook Security gets a lot of pushback from the developers. Certain things like coffee shop attacks and a lot of other REAL ISSUES get no notice for a long time. It took up until last year to get a damn HSTS header.

I actually reported an issue today about a security practice they implemented completely incorrectly. I got a response back that it was not meant for any actual security.

In theory it's unacceptable, but in practice this is a big company with thousands of employees and a lot of moving parts. Small changes can be hard to make....which to get back to my original point is why facebook seems to just ignore a lot issues but keep the pipes open for the occasional big one.

[dead] 12 years ago

What I mean is the aviation incidents have been quite shocking and peculiar. Mh370 goes missing without a trace. Mh17 is shot down.

Then, it just so happens that several incidents all were clumped together. Foreign airliners crash at a much higher rate than US, but the manner which the two MH flights have gone down is very shocking for such a short period of time.

[dead] 12 years ago

Hope for the best but assume the worst. It's been a scary year in aviation.

I'm hoping future generations look at me crazy when I tell them aircraft and cars used to crash. Increased transportation safety and reliability is something I really want.

I'm still very curious how they plan to make money. I guess we will have to see...

In my opinion urban dictionary actually solves the same problem that Rap Lyrics is solving except instead of explaining a whole sentence urban dictionary explains one-a few words.

Hey I appreciate the response. I'm honestly not sure if they will buy it. If it's cheap enough and portable enough I feel it could be extremely effective in drawing attention from attackers.

If not I guess I'll just open source it and turn it into a con talk =).

Email security is really bad. We have a lot of companies trying to roll out "secure email" every week.

There are a ton of problems to solve before one of these actually works, javascript crypto being the least (since HN likes to discuss it...). Backwards compatibility with old email protocols and insecure service is clearly a weak-link in any hypothetically secure service.

It would be nice to see a more distributed protocol...where the bulk of the world's email is holed up in a few company's data centers.

I'm working on an enterprise honeypot framework with an emphasis on internal honeypots that alerts a network administrator as soon as an attacker messes with it. An example would be a fake PHP myadmin page that alerts a security engineer as soon as it receives a POST request

It's closed source but I've finished the architecture for the software and a couple of the services (MySQL, Web, FTP). They are really cool in my opinion. I'm writing this in Java (yuck but great at the same time), so packaging each service as a Jar file makes deployment super super easy.

It's actually been really successful thus far (and really easy to write, only a few hundred lines). I think enterprises need to use more "trickery" in their security systems and I don't think a framework exists for this previously. It is really powerful to know that

if (honeypotTouched){ //critical alert }

A lot of honeypot software is old and does not send you alerts when something bad happens to it. Most are external facing. I guess a better name for this is "canary". I got the idea my second time sitting through mubix's "Attacker Ghost Stories" talk.

Why I left Pivotal 12 years ago

This type story would make me hesitant to hire him after throwing his last employer under the bus (the usual response to this type of article). But with only one side of the story...you can't draw too many conclusions.

I checked his linkedin and it looks like he was at Pivotal from March to sometime recently. Lots of details are brushed over in this post so...maybe a more extensive post-mortem would be helpful.

Gosh. I can't stand 1&1. When I was in undergrad I bought my first domain from 1&1 because I really had no idea where to buy them.

I've received phone calls from them for 4 years. The always end with "Yes sir, we will remove your number from our list"....so either I'm on a lot of lists or they are lying to me.

Absolutely security is hard...and it's also not what `Yo' is really worried about. If they have to worry about security, then they already hit it big and they can just fix the issue ex post leako.

It's a data leak...very similar to snapchat's issue and the Apple iPad fiasco found by weev. It's pretty sad that an App with almost no functionality had any problem.

It's also interesting how these developers seem to repeat this exact mistake over and over. I don't understand how people don't see a public facing API call for mapping usernames to phonenumbers or phonenumbers to usernames as a bad idea...

TextSecure is very open about the crypto protocol and provides details that independent researchers can evaluate. It's also made by a well-known expert that we trust to do it right.

Wickr is pretty shady about their protocol.

They also make me uneasy because they use the term "military-grade encryption" a couple times on their site. This is a pretty common snake-oil security term...so it makes me uneasy since the protocol details are nowhere to be found.

[dead] 12 years ago

You could, but that requires doing my own research. This site has my browser sending the request to yo-hack instead of yo.

Not even a YC Startup. Any startup. I interned at a very small startup in college that is pretty well known. I learned a ton. Compared to my other internships I had I accomplished a TON more (and more was expected of me, which is good!).

At my startup internship, I pushed real code to real users on the first day. At my internships with BigCos, I wrote code for 3 months and then I left. I have no idea if the code was ever used. I was never checked on and had to be overly outgoing for guidance. I probably could have sat on HN for 3 months and nobody would have known.

If you are in college or high school, you should be searching HARD for internships. Start early and don't be afraid to email people you don't know asking for help. One of pg's essays say something along the lines of ``take jobs when you are young that are challenging where you will learn the most''. Finding these types of internships can be hard, so the search is difficult.

I always get half-sad half-glad when I read these types of things.

Glad that I won't have to see this depressing end to the universe but still sad for humanity, that we won't last forever.