HN user

BCharlie

1,186 karma

charles [dot] belmer at ge.com

Posts33
Comments36
View on HN
papers.ssrn.com 5y ago

Democracy and Mass Skepticism of Science

BCharlie
1pts1
nullsweep.com 5y ago

Security Bug Hunting with Proxies

BCharlie
1pts0
nullsweep.com 5y ago

NoSQLi – A Fast NoSQL Injection Framework Written in Go

BCharlie
3pts0
nullsweep.com 5y ago

Kindle collects a surprisingly large amount of data

BCharlie
545pts379
nullsweep.com 5y ago

Defcon 2020 Live Notes

BCharlie
1pts0
nullsweep.com 6y ago

Secrets Management for Developers

BCharlie
1pts0
nullsweep.com 6y ago

Government Surveillance of Protestors

BCharlie
1pts0
nullsweep.com 6y ago

Why Is This Website Port Scanning Me?

BCharlie
1294pts430
nullsweep.com 6y ago

My Favorite InfoSec Learning Resources

BCharlie
2pts0
nullsweep.com 6y ago

A Better Way to SSH in AWS

BCharlie
3pts0
nullsweep.com 6y ago

Subdomain Reconnaissance

BCharlie
2pts0
nullsweep.com 6y ago

Deploying Docker Securely

BCharlie
2pts0
nullsweep.com 6y ago

A NoSQL Injection Primer (With Mongo)

BCharlie
2pts0
nullsweep.com 7y ago

HTTP Security Headers – A Complete Guide

BCharlie
709pts78
nullsweep.com 7y ago

Show HN: Firefox Plugin Privacy Test Database

BCharlie
10pts0
nullsweep.com 7y ago

Digging Through Someones Past Using Osint

BCharlie
3pts1
nullsweep.com 7y ago

Personal Security and Privacy Tools I Recommend

BCharlie
2pts0
nullsweep.com 7y ago

How to Detect If a Browser Plugin Is Spying on You – A Complete Guide

BCharlie
11pts0
nullsweep.com 7y ago

A Comprehensive Web Server Security Guide

BCharlie
2pts0
nullsweep.com 7y ago

Security Patching Docker Containers

BCharlie
2pts0
nullsweep.com 7y ago

Intrusion Prevention and Detection for Docker

BCharlie
1pts0
nullsweep.com 7y ago

Docker Static Analysis with Clair

BCharlie
2pts0
github.com 10y ago

Show HN: Easily manage Firefox hidden privacy settings (plugin)

BCharlie
1pts1
news.ycombinator.com 11y ago

Ask HN: How to defend against SSL visibility appliances?

BCharlie
1pts2
ooni.torproject.org 13y ago

Zambia censors grass roots Zambian Watchdog

BCharlie
1pts0
www.att.com 13y ago

AT&T changes privacy policy to sell user data

BCharlie
6pts0
www.bootstrappingindependence.com 13y ago

Creating a Startup Marketing Plan With No Marketing Background

BCharlie
3pts0
www.bootstrappingindependence.com 13y ago

How to Create Marketing Your Customers Love

BCharlie
3pts1
www.bootstrappingindependence.com 13y ago

The non-sleazy way to sell on forums

BCharlie
12pts2
mmenu.frebsite.nl 13y ago

Create Slick Sliding Menus for Mobiles with jQuery

BCharlie
1pts0

I mention that the data that appears to be used for those purposes is sent again in a separate request to a separate end point, so we have two types of requests: last read location, and reading analytics. Sorry it wasn't clear, I'll try to improve the wording.

Though I haven't analyzed other devices (because I don't own them), they could easily have similar issues. I personally really want an open e-ink device, but I haven't seen one for sale unfortunately. For now, I do Calibre ODPS server with Marvin app on a phone, but it doesn't really compare.

Perhaps calling it an heroic effort would suit your taste more?

"Those teams rebuilt around 4,000 servers and 45,000 PCs and other devices" over 10 days (according to another article), while the company "ground to a halt".

I don't know about you, but if I had a team that pulled that out, I would have a deep respect for their service and contribution to the business.

Maybe I am missing something, but I didn't see anywhere where this was a company brought in, I am under the impression it is the company's internal staff recovering from ransomware, and now being laid off.

I wish I knew of some way to change this paradigm. I have repeatedly seen IT/Engineering teams pull out miracles that save a business, or deliver the critical edge for growth, only to have the business value that same team close to zero shortly after.

It seems to me the gap in time between reducing staffing and disaster is perhaps too long for intuitive connections to be made, but that seems overly simplistic to me too.

You are right on this - I thought you could set multiple sites by setting multiple headers, but it doesn't work that way, which I should have known because headers don't work that way in general...

The recommended way to do multiple sites seems to be to have the server read the request header, check it against a whitelist, then dynamically respond with it, which seems terrible.

Thanks for catching this - I updated the post to reflect this and make it more clear.

Thanks for the feedback! I did link the official site, but it's kinda buried in the paragraph and maybe not obvious.

I added some text to the x-frame-options to note the CSP rules - it's a great addition.

That is true! I do set frame-ancestors in the sample CSP for this reason. I could probably do a dedicated post on CSP to do it justice, but don't want to overwhelm anyone who just wants to start setting headers.

One good reason to set both options, as I mention in the post, is that scanners who rate site security posture may penalize site owners who don't set both - no harm in doing it that I know of.

I think it's a good point which is why I set the time low, even though many other resources set it to a week or longer. I just don't like very long cache times for anything that can break, so that site owners have a little more flexibility in case something goes wrong down the line.

I'm not an analyst, but I'm in the field. It's broad, and not many good targeted communities exist that I know of. Here is my current list of places to check regularly. Let me know if you know of others!

## Social https://www.reddit.com/user/goretsky/m/security/ - compliation of 90-100 security subreddits.

## Security / Tech News https://www.darkreading.com/ https://www.bleepingcomputer.com/ https://news.ycombinator.com/ https://nakedsecurity.sophos.com/ https://threatpost.com/ https://blog.erratasec.com/ https://krebsonsecurity.com/ https://medium.com/mitre-attack https://threatpost.com/

## Threat updates / SOC https://www.securitywizardry.com/radar.htm - dashboard - virus news, latest alert feeds https://www.talosintelligence.com/ - reputation lookup for networks & vuln reports

## Podcasts http://defensivesecurity.org/ https://securityledger.com/ https://securityweekly.com/ https://risky.biz

## Slack Communities OWASP - owasp.slack.com DFIR IR - dfircommunity.slack.com - mostly around the Demisto products, but some other discussion as well Hangops Infosec - hangops.slack.com - infosec channel

GE Power | Sr Cyber Security Engineer / Programmer | Atlanta GA, Schenectady NY, Cincinnati OH, Greenville SC, Glen Allen VA, Van Buren MI (Others may be considered) | onsite | https://jobs.gecareers.com/ShowJob/Id/59338/Sr-Cyber-Securit...

Job number: 3148791

About us: GE Power is building industrial IoT and analytics to help Power the world more efficiently. I lead the Secure DevOps team at GE Power, focused on helping the business build secure software through automation and deep security expertise.

About the role: This is a role for a great programmer who loves security, or a great security professional who loves programming. We are happy to train security skills if coming from a programming background with a security interest. The focus of the role is on building security tooling for other development teams. Some examples we are working on today: a two factor auth library in Java, A webhook for code analysis in Java/Spring, and a framework for automating security scans across networks and systems in Go.

We also consult with other teams to build product security features, threat model, implement CI/CD, or train development teams on secure coding practices.

Our goal is to enable our product teams to ship daily code while maintaining a very high level of security. Our product threat model adversaries include everything from common malware all the way up to targeted nation states attempting electrical grid and generation disruption.

Main technologies: Java with Spring is the most frequently used today, but we also use or support Node, Go, Python and C/C++ for various projects.

If this sounds interesting, apply at the link above or reach out to me and I will be glad to answer any questions.

GE Power | Sr. Software Security Programmer | Atlanta GA, Schenectady NY, Detroit MI | ONSITE http://jobs.gecareers.com/ShowJob/Id/388/Staff-Software-Secu...

About us:

We're a team of software engineers focused on helping the business build secure software on GE's Predix platform (predix.io) and industrial internet of things.

About the role:

We build security tools for development teams, security focused libraries and embed with product teams as security focused developers - focusing on user stories around security.

Technology focus areas:

GE is a big company, and we support teams that use all sorts of languages, frameworks, and technologies. The most frequent technologies we work with are:

* Java with SpringBoot

* Angular

* Polymer

* Node

Other languages I am seeing more of: Python, Ruby, Elixer, Go

When we build internal tooling, we pick the best tools for the job: Elixer, Scala, Python, Node or whatever makes sense.

What we look for:

Great programmers who love security and understand secure coding. Experience with the technologies listed above, CI/CD, TDD, and general development best practices is key.

We hire at all skill levels and are more than happy to train in any technology or skill set if you bring enthusiasm and a programming background to the table.

If you love to code, understand how to find, exploit, and fix vulnerabilities in web apps, and want to help us build security tooling, I'd love to chat!

Apply

You can find the full job posting at http://jobs.gecareers.com/ShowJob/Id/388/Staff-Software-Secu..., or go to ge.com/careers and search for job number 2749772

You can also just reach out to me with questions!

GE Power | Sr. Software Security Programmer | Atlanta, GA USA | http://www.ge.com/careers/opportunities?keyword=2749772

About us: We're a new team of software engineers focused on helping the business build secure software on GE's Predix platform (predix.io).

About the role:

We build security tools for development teams (CI/CD security plugins, platform scanners, log aggregators), security focused libraries (2 factor authentication, OAuth wrappers, encryption wrappers), and anything else that might help our teams be more secure.

We also embed directly with product teams as security focused developers - ensuring user stories around security are being implemented, teaching developers about secure coding, and building the most sensitive parts of our critical applications.

Technology focus areas: GE is a big company, and we support teams that use all sorts of languages, frameworks, and technologies. The most frequent technologies we work with are:

* Java with SpringBoot * Angular * Polymer * Node

Other languages I am seeing more of: Python, Ruby, Elixer, Go When we build internal tooling, we pick the best tools for the job.

What we look for: Great programmers who love security and understand secure coding. Experience with the technologies listed above, CI/CD, TDD, and general development best practices is key.

If you love to code, understand how to find, exploit, and fix vulnerabilities in web apps, and want to help us build security tooling and improve app, I'd love to chat!

Apply You can find the full job posting at http://www.ge.com/careers/opportunities?keyword=2749772, or go to ge.com/careers and search for job number 2749772

You can also just reach out to me with questions!

GE Power | Sr. Secrurity Engineer (Programmer) | Atlanta, GA USA | http://www.ge.com/careers/opportunities?keyword=2749772

About us: We're a new team of software engineers focused on helping the business build secure software on GE's Predix platform (predix.io).

About the role:

We build security tools for development teams (CI/CD security plugins, platform scanners, log aggregators), security focused libraries (2 factor authentication, OAuth wrappers, encryption wrappers), and anything else that might help our teams be more secure.

We also embed directly with product teams as security focused developers - ensuring user stories around security are being implemented, teaching developers about secure coding, and building the most sensitive parts of our critical applications.

Technology focus areas: GE is a big company, and we support teams that use all sorts of languages, frameworks, and technologies. The most frequent technologies we work with are:

* Java with SpringBoot * Angular * Polymer * Node

Other languages I am seeing more of: Python, Ruby, Elixer, Go When we build internal tooling, we pick the best tools for the job.

What we look for: Great programmers who love security and understand secure coding. Experience with the technologies listed above, CI/CD, TDD, and general development best practices is key.

If you love to code, understand how to find, exploit, and fix vulnerabilities in web apps, and want to help us build security tooling and improve app, I'd love to chat!

Apply You can find the full job posting at http://www.ge.com/careers/opportunities?keyword=2749772, or go to ge.com/careers and search for job number 2749772

You can also just reach out to me with questions!

GE Power | Sr. Security Engineer (Programmer) | Atlanta, GA USA | http://www.ge.com/careers/opportunities?keyword=2749772

About us:

We're a new team of software engineers focused on helping the business build secure software on GE's Predix platform (predix.io)

About the role:

We build security tools for development teams (CI/CD security plugins, platform scanners, log aggregators), security focused libraries (2 factor authentication, OAuth wrappers, encryption wrappers), and anything else that might help our teams be more secure.

We also embed directly with product teams as security focused developers - ensuring user stories around security are being implemented, teaching developers about secure coding, and building the most sensitive parts of our critical applications.

Technology focus areas:

GE is a big company, and we support teams that use all sorts of languages, frameworks, and technologies. The most frequent technologies we work with are:

* Java with SpringBoot

* Angular

* Polymer

* Node

Other languages I am seeing more of: Python, Ruby, Elixer, Go

When we build internal tooling, we pick the best tools for the job.

Apply

You can find the full job posting at http://www.ge.com/careers/opportunities?keyword=2749772, or go to ge.com/careers and search for job number 2749772

You can also just email me (in profile) with questions!

GE Power | Security Engineer | Atlanta GA, Schenectady NY, Detroit MI, New Orleans LA | https://xjobs.brassring.com/tgwebhost/jobdetails.aspx?partne...

We're building a team of software engineers who are passionate about security. Help us build and secure the industrial internet (IoT for large Power installations). We focus mainly on securing web services, but embedded devices are growing in scope.

Tech Stack: We support multiple teams doing a variety of things, so diverse experience is welcome! Most apps are built in Java with Spring, Node, Python, or Go.

If you are a developer that wants to focus more on security, or a security professional who loves to program, then let's talk!

Daily work includes: - Coding sensitive application user stories like authentication, encryption & key management, secure API design, and much more! - Building shared tools for business teams - static code analysis, contributing to OWASP Open source projects, and leveraging them in our projects - Teaching other dev teams how to code in a secure way - Pen testing and evaluating IoT platforms and deployments

Apply or email me directly with questions.

GE Power | Atlanta, New Orleans, Schenectady, and US Remote considered for the right candidate | Security Software Engineer

About us: GE is building industrial IoT and analytics to help Power the world more efficiently. The Secure DevOps team is a new team focused on helping the business build secure software on GE's Predix platform (predix.io).

About the role: You'd be focused on building security libraries for Predix developers, automating the security development lifecycle (building or deploying CI plugins to integrate development with static analysis and dynamic analysis security tooling, automate reports, log generation & shipping, etc), training development teams in secure coding practices, and participating in code & architecture reviews from a security perspective.

There's a good chance you might be asked to join sprints to quickly shore up insecure code, analyze existing platforms and software for design flaws and vulnerabilities, and craft good common sense policies as well.

Our goal is to enable our product teams to ship daily code while maintaining a very high level of security.

Main technology: Java with Spring is the most frequently used for web components, but more teams are picking up Node and Go. Python and C++ are often used in devices.

The job will be posted in the next few days on ge.com/careers. If this sounds interesting, shoot me an email (in profile) and I will tell you as soon as it is posted or answer any questions you have.

As a technical leader, the biggest hurdle I faced personally was understanding how to measure and improve myself in the right ways.

While success in an engineering role can generally be described as "write good code" (with all the nuances therein), technical managers are measured on totally different things, and it isn't obvious how to improve most of them.

When I transitioned and realigned myself to these things, my outlook changed, and I started really enjoying leadership roles:

* Embrace the idea of being hands off technically. I have never seen a hands on technical manager that worked out well - politics will always come into play. Instead, encourage friendly inter-team debate, which you can coach and steer into a healthy dynamic to make the right decisions. Feel satisfaction that the team you build creates better engineering than you could alone.

* Focus on helping your team lead fulfilling careers and lives. See in them what they could become in 10 years and help them achieve it, even if it sometimes conflics with your short term interests.

* Build amazing products - The leader is way more instrumental in this than often credited.

* Create a great team environment that people want to be a part of.

* Get a seat at the business table - you should absolutely be a big part of the product roadmap. Done right, eventually you should have sales/customer teams coming to you for advice and input like 'Customer X wants Y, what do you think?'

* Create great communication flow - make sure everyone else knows how important your team is, and help your team see how what they do contributes, and how the market/product is changing and why.

On your comment about fighting fires and other managers - you can change this. These things make any job unpleasant. I strongly recommend reading The Phoenix Project to get some ideas from an IT perspective - it can easily be read in a weekend and addresses exactly these common problems.

I saw some of these parameters discussed here recently, so I figured I would share with the community if there's interest.

It seems like a continuous topic that these are hard to set for the average user, but I don't think it should be that way.

If you know of settings I missed (that don't break most sites!) please let me know.

SEEKING WORK - Atlanta GA, USA - Remote only

I run a small Django shop focused on long term relationships with startups and small businesses looking to grow. Web applications, API's, automating painful business processes, and everything else you need to succeed.

I happily manage code repositories, test case development, server deployment, administration, monitoring, and full website development - all without any management or oversight needed. Point me at a business problem and I will help you automate / solve it.

More details at http://www.sandalssoftwareconsulting.com - reach out if it sounds interesting!

I agree that there will still be something worth seeing, but at the cost of a naturally beautiful place being made less. Personally, I am glad that some places exist in this world that I cannot get to without significant effort, and I don't want to change that. Humans don't need easy access to every corner of the earth.

"...who like the idea of enabling a large number of people to enjoy the great canyon’s very heart, a stunningly beautiful and remote site long inaccessible to the masses."

Don't they realize that being remote and inaccessible is a big part of what makes it stunningly beautiful? The moment you arrive there with 10,000 other people, the place will no longer have what you came there to see.

I work in Django, and I love it. I chose it because I also wanted to learn Python, since it is used in Open source projects I support and is commonly used in a variety of spaces beyond web development.

I think it will boil down to your personal preferences for the most part. On the other hand, when I was looking for jobs early this year, there were 5-10 times more openings for RoR developers than Django, so if you are looking for work in the medium term, I would choose RoR.