HN user

InitialBP

280 karma
Posts4
Comments124
View on HN
Making 5 hours ago

The restaurant comparison doesn't really hold up. The parent didn't go choose from a menu of new apps that they wanted AI to create. They discovered a problem or a feature that doesn't exist on other platforms and they employed tools to create that. Does a product manager not get to claim they "made" something because they plan it out and employ others to actually build the finished product?

Both of the examples the parent gave include some kind of planning and ideating to get to a final product, regardless of the fact that they employed tools to do a bulk of the coding work.

The AirPods Effect 1 month ago

This is actually the exact opposite for me. Rubber tipped buds will not stay put in my ears when I move around, while the original airpods models sit within my ears and don't fall out unless I'm doing cartwheels.

Another example is Old School Runescape, who reverted back to an earlier save and has now diverged as an entirely separate game running with older systems as they lost a ton of players with their "Evolution of Combat" update. While nostalgia is definitely a powerful tool, I agree with the previous commenter that the original WoW was a very different game than the modern version and it seems like that is one of the core aspects of what people desired.

This comes entirely down to the scope of the agreement for the assessment. Some teams are looking for you to identify and exploit vulns in order to demonstrate the potential impact that those vulnerabilities could have.

This is oftentimes political. The CISO wants additional budget for secure coding training and to hire more security engineers, let the pentesting firm demonstrate a massive compromise and watch the dollars roll in.

A lot of time, especially in smaller companies, it's the opposite. No one is responsible for security and customers demand some kind of audit. "Don't touch anything we don't authorize and don't do anything that might impact our systems without explicit permissions."

Wiz is a very prominent cloud security company who probably has incredibly lucrative contracts with AWS already, and their specialty, as I understand it, is identifying full "kill chains" in cloud environments. From access issues all the way to compromise of sensitive assets.

I'm sure you are correct about being able to do some clever prompting or tricks to get it to print inappropriate stickers, but I believe in this case it may be OK.

If you consider a threat model where the threat is printing inappropriate stickers, who are the threat actors? Children who are attempting to circumvent the controls and print inappropriate stickers? If they already know about topics that they shouldn't be printing and are trying to get it to print, I think they probably don't truly _Need_ the guardrails at that point.

In the same way many small businesses don't (most likely can't even afford to) opt to put security controls in place that are only relevant to blocking nation state attackers, this device really only needs enough controls in place to prevent a child from accidentally getting an inappropriate output.

It's just a toy for kids to print stickers with, and as soon as the user is old enough to know or want to see more adult content they can just go get it on a computer.

"If you select those people, what’s to keep them from creating a system that gives them ever more amounts of money, to the detriment of their constituents?"

That is literally the system that exists today, except instead of in the open (e.g. salary) it's through stocks with insider information and who knows how else.

The point isn't to optimize for people who are most incentivized through money, the point is to make the position more accessible for anyone who actually wants to do the "service" part, and to minimize the reasons that it's hard. As the previous commenter pointed out, right now independently wealthy people are some of the only ones who are actually capable of running, and someone who isn't independently wealthy who wins is even more susceptible to bribes because they may be in a tenuous financial position.

I would agree with you that we want individuals who's goal is to do "service" for their society, but our current system obviously isn't working and there are a lot of solid reasons why something like this _could_ improve the situation, what alternatives would you recommend?

That is awful, but it doesn't lessen the impact of someone who right now has access to your email and or other accounts. China having your DNA profile is not near as impactful as someone actively stealing your identity and potentially ruining your finances. Use 2fa everywhere, and if your email is in this list, you should change your password.

Defaulting a furnace to on certainly shouldn't be considered safe. What if it's leaking CO into your house, what if it gets dangerously hot and causes a fire?

A thermostat and controls are a necessary requirement for HVAC systems and defaulting anything to "run" if your control plane doesn't exist anymore is definitely not the safe option.

The other issue is that in almost all situations (like this one) what you think is a safe and sane default won't align with what other people think.

There should be defaults and they should be clearly defined, but I don't think it's always obvious to determine what they are.

I believe the CLI _does_ ask permission for each program trying to access it. The author's example includes a malicious vscode extension abusing the fact that he intentionally granted vscode permission to access the vault for one purpose and then a malicious extension leveraged that access to retrieve information through the op cli.

The “whole point” of 2fa is that even if someone knows your password they cannot login with just credentials.

Compromising or stealing a device is a significant escalation from guessing passwords.

https://news.ycombinator.com/item?id=44259556

I posted another comment explaining why 1Password Vault with both a password and a OTP code is still secure, but in short it does not defeat the purpose. Your vault's are protected and in the situation where someone gets access to your vault it's most likely to be full access to your computer at which point they have other viable methods to get access to a specific service you use.

Two Factor doesn't mean 2 devices. Two factor generally has been thought of as "something you know, and something you have."

Let's do a quick threat model on putting both passwords and MFA tokens in a 1password vault.

1Password employees a recovery key + password login by default, and logging into a vault requires you to either have a device with the encrypted vault on it and your password, or have knowledge of your password and knowledge of your recovery key (normally in a file which makes it something you have) essentially traditional 2fa needed to log into a new device.

If someone steals your phone with 1password installed - they need your 1password to be able to access your credentials on the physical device. At that point they already have both your factors - your phone (have) and your password (know) - still protected by 2fa.

If someone manages to fully root your computer, they could wait until you unlock your vault and then extract your credentials. However, if you use traditional 2fa on a separate device - then they can just wait until you log into the target app, and then ride your session and get the same level of access to the target. While there may be a small difference in level of effort or how long it takes, the same access level is possible, and the requirements are that they have very privileged access to your operating system. Someone rooting the device that you login to services is grants them "single factor" access to your services when you access them.

There is some subtle differences between these, but except for situations where you have very high privileged requirements, at which point you should be using yubikeys or standalone MFA devices, using 1Password with OTP and password is very comparable to using a separate device for MFA.

I'm a previous red teamer and currently a blue teamer.

Not sure which ranger you're talking about - but if you mean the 6ft one, 18 inches of bed length is definitely noticeable.

It's also definitely possible to haul all those things with almost any truck. Hell, you could even buy a rack for a maverick that makes full 8ft by 4ft sheets of drywall/plywood super easy to carry around, but being able to really easily load up stuff and not have to do some complicated strapping/securing of the payload is a big win with a bigger bed. I personally haul motorcycles a lot, and being able to have two motorcycles in the bed with tailgate up is a huge plus for me.

edit: misunderstood your first comment. What year Ranger are you talking about? The difference between an 80's/90's small truck and an early 2000s can be very considerable.

There's a whole different conversation and argument about the general size of vehicles in the US that is essentially circular and leads to bigger and bigger vehicles in the name of "safety".

I think that you're looking at extremes exclusively when it comes to your assessment. I live in a "city" in WV and need my truck all the time to get to rural areas, but that doesn't mean that I don't have reasonable access to electricity. Furthermore delivery around my city really isn't affordable or available in a lot of cases.

That being said, I really wish we had a small ICE truck in the USA, or an equivalent to the s-10/ranger. Even the ford maverick is exceptionally tall and it doesn't come with a bed that is big enough to conveniently move building materials. The maverick bed is only 54" or 4.5ft and older model rangers and S10s can be had with up to a 6ft bed.

https://www.motor1.com/news/698055/toyota-13000-dollar-hilux...

A company that has to "follow the rules" is way less desirable to work for then a company that embraces the spirit of the rules. I'm in the US so can't really speak for companies in other countries, but many US companies are doing everything they can to skirt the letter of the law and spending a ton of money to have them rewritten to be less favorable to employees and more favorable to the business. Finding a company that truly cares for employees is a very rare treat!

Glad to hear you guys are making progress. Password rotation is definitely more of a hindrance than a help and is a big reason that you end up with Spring2025! style passwords for sure.

I think the industry is realizing that less is more when it comes to passwords and we're starting to see far more adoption of password managers and a bigger focus on getting SAML/SSO login options for SaaS tools, even if they are often gated behind paywalls or "enterprise" plan options.

Now that I'm in a more "defensive" position my primary focus on the credential front has been pushing password manager adoption across the org and looking for good opportunities to showcase that password managers are both significantly faster and easier to use if people are willing to change their workflow.

I'm a former red teamer - Credential spraying attacks are incredibly successful on a business that has at least a few hundred employees. Many employees not only aren't aware of why cybersecurity is important, but often go out of their way to avoid learning or implementing security best practices because they see it as an annoyance and a hindrance.

One of our most standard and most successful playbooks to find a foothold:

1. Pull employee names from linkedin

2. Find an example email for format (first.last@company.com)

3. Setup password spraying for a password like: Spring2025!

4. Leverage a tool like https://github.com/ustayready/CredKing to avoid IP blocking.

5. Get credentials and go from there...

Because they have evidence "in writing" that everyone at the gym had to pass a test that proves they know how to properly and securely belay a climber. In the event that there is an accident, the liability falls completely on the belayer and/or the climber and not the gym itself for allowing someone to participate in something that is "obviously dangerous" without demonstrating they have the ability to do it properly.

A lot of time (most?) writing software isn't about writing software for the pleasure of doing so, but for building something that helps generate revenue.

For businesses, having a highly optimized web application that takes a long time to develop and doesn't allow for quick additions of new features is not worth the cost. Instead, they can have a poorly optimized web application with way more features and a faster feature production because Python/Ruby/Javascript are more approachable than other native languages.

Kipchoge is less like "quietly focusing on a sustainable career" and more like "consistently maintaining the highest quality and pace of development and rarely if ever having an off week".

Your example isn't a very good one. If you are 99.99% as good as the next candidate you get no job? How about you get a different job because you're still a top performer. Most (all?) jobs don't have only a single role to be filled across the entire world.

Sure you might not get THE singular highest paid/best position to do what you do really well, but you can certainly still get the 2nd or 3rd or be among the top 100/1000 well paid people who do X.

I stand by the previous commenter, in the vast majority of cases you're still going to have some significant benefit from being near the top even if you aren't "the best".

Agree with you if privacy first is the goal then open sourcing it is absolutely the right move. However, it IS still possible to MITM these days - although more difficult.

frida.re has a ton of useful features and community tooling built around it including scripts that will let you "un-pin" certificates by hooking and rewriting the functions that verify whether cert pinning worked or not.

https://frida.re/

https://codeshare.frida.re/@masbog/frida-android-unpinning-s...