HN user

EnFinlay

1,013 karma
Posts2
Comments220
View on HN

I can't find the article right now, but I remember reading an article many years ago on Wired about the Obama campaign and their use of targeting and "big data". Really interesting stuff about how they were buying TV spots and the Romney campaign couldn't figure out why, and how their use of technology was a massive advantage.

I'm having trouble articulating this, so bear with me.

In general, having a Bug Bounty program is good. We can agree on that, right?

Most Bug Bounty programs have a scope, and staying inside the scope is important to the business for reasons. My guess is that most scopes are defined by a combination of confidence in the security of the code, resources to triage vulnerabilities in that part of the code, and the risk to the business from vulnerabilities found in different parts of the code.

That is to say, I suspect that either Valve doesn't have many developers well versed in that part of the code base, or they are not confident in the security of that code base, or they considered it a low priority (even if we disagree about the priority of this vulnerability).

Now, let's pretend that I'm right about those reasons. Even further, let's pretend that they did not include it in the scope because they don't want to pay a bunch of bounties on code they knew was insecure.

(Aside, I'd much rather have companies only include things in bug bounty programs once they're confident they are secure, relying on BB to do your security for you is begging for trouble because then the company isn't taking responsibility for, or even trying, to do things securely)

Given this train of thought, which is making more than a couple assumptions, I don't think their actions are extremely bad or pointless. They are trying to keep their bug bounty program in scope. Bug bounty programs involve a fair amount of trust. If that trust is broken and they don't want that researcher anymore, then that's fair.

There probably should have been better communication. It probably (definitely) shouldn't have been a WONTFIX. Overall, terrible outcome for everybody.

It's just one of those things where every decision looks reasonable in isolation and leads to a really bad outcome and the company looking terrible.

a) Program has scope that doesn't include X

b) Researcher reports vulnerability that falls under X

c) Since it's out of scope, it's closed as N/A

d) Report is locked because company doesn't want to publicly disclose a vulnerability in their system via the Hackerone platform

What's the problem here? Just go with normal vulnerability disclosure. Bug bounty programs are a two way street, and respecting the scope is part of that.

Edit: I guess the important part is that the researcher was then banned for disclosing the report. Seems reasonable, honestly. I don't agree with it, but I understand it.

The WeWork IPO 7 years ago

Might be easier to lay off everyone on that half-full 3rd floor and save money on your lease next cycle.

Uber Lays Off 400 7 years ago

I have no insight into the matter.

My guess is that their traction and market dominance are far more fragile than you think. Because their drivers are contractors and not employees, they can't be forced to only work for Uber, so even though they created the pool of drivers, they have not "captured" them. So a huge cost is the ride subsidies which maintain their market position. Once the ride subsidies end, there is no reason that a locally focused company can't compete for the same drivers and riders.

From what I've read, when Uber started their app technology was borderline magical (pushed the boundaries of what smartphones could do), but since that's no longer the case, there is much less of a barrier to entry.

I want to make sure that I understand your analogy.

- The right to secure encryption is like the right to bear arms

- Government mandated weakened encryption are like gun control

- The victims of weak encryption (stolen data for example) are similar to innocents harmed by gun control? (I'm not sure on this one, please correct me if I'm wrong).

- Saying weak encryption is bad is like saying gun control is bad

I'm not trying to straw man you, if that's not what you mean, please correct me.

Also, I completely disagree.

I don't think you need a conspiracy to get to a place where in aggregate the decisions of people in control create or perpetuate a poor underclass.

Just like some companies make decisions for the benefit of the next quarter, rather than the next 5 years. If you are able to make a decision that increases near term metrics, at the expense of some other metric you aren't even paying attention to (like making poor people poorer) I can see that happening independently thousands of times a day.

Take payday loans, more commonly used by people with a lower socio-economic standing. They aren't there to create an underclass, they are there to provide a service (loans) at a cost that matches the risk (ignoring the conversation about the cost not matching the risk due to predatory loans). But if decisions are made to increase profit from payday loans, a natural consequence is that the underclass is going to be made more of an underclass.

This is just one example, and it's clearly got some issues. I have no problem imagining many other decisions that will help create an underclass. Maybe the impact is 2 or 5 steps removed, but each one makes a difference, and leads to in aggregate "the rich work to keep the poor, poor".

But what do I know. I'm a developer who took one econ course.

This is a some next level bullshit

3. 10x engineers laptop screen background color is typically black (they always change defaults). Their keyboard keys such as i, f, x are usually worn out than of a, s, and e (email senders).

I doubt you would get a positive reaction because listening to music isn't considered a problem. There might be a lot of reasons for that, one of them might be that most people don't sit and exclusively listen to music.

- Many convention talks are really good and are too many to list - OWASP - zseano - hackerone - Bugcrowd (Jason Haddix's stuff is a pretty important pillar) - OWASP - DarkOperator - Absolute AppSec - KacperSzureEN - PwnFunction - LiveOverflow

There are a ton more, these are just ones I've been watching in the past 6 months or so.

There are thousands of hours of excellent cybersecurity content hosted on YouTube. The possibility of losing this wealth of information and history is shocking to me.

Time to start the archive effort. And to finally appreciate what so many other communities have gone through when they've found themselves on the wrong side of one of the internet behemoths. I feel naive.

As far as I can tell, jokes are an important method of communication. There are times where they are light-hearted, or just part of the culture, but there are other times (where there is, say, one person in a position of authority, making the same joke repeatedly) where it is meant to call out a behaviour and implicitly shame it.

It's like if you're on the bus and someone's sitting really close. Some people would say "Excuse me, you're too close", but others would jokingly say "Little close, aren't you?", but the meaning is the same - Move.

Pixel 3a 7 years ago

That's my perception of all phones, iPhones included.

A dev posting their own content for once should be some of the most welcomed content. It's usually accompanied by Q&A and insights into the design process, the rare opportunity to actually talk to the creator of a game on that subreddit. Sad to see so many people attack it because it's just obvious advertisement.

I disagree with this. There are thousands of Indie developers out there trying to win the game programming lottery, and the main tool at their disposal is posting on sites like reddit or spamming on twitter. The result is that most of this content is low quality and of little interest to the broader gaming community.

To put it differently, for every Vlambeer there are legions producing low quality spam that no one wants to see.