That's awesome. We used OpenVPN because that's what we were familiar with, but your L2TP script looks great. Would you mind if we tried to integrated that at some point?
HN user
ainsleyb
My favorite day is pi day, though I don't eat pie. Co-founder of Tinfoil Security https://www.tinfoilsecurity.com
Follow me at ainsleybraun.com
There are a number of ways: malware, browser extensions, man in the middling, etc. SQLi would have been a better example than XSS, but there are definitely ways in which XSS can still be harmful if thrown in a cookie. If you wanted a persistent XSS for example, you could use a reflected XSS to create a longer lasting XSS attack in someone's login cookie, causing that to be executed every time they hit the page rather than just the one time they click on a malicious link you sent them. Does this make more sense?
Flying cars DO exist! :) http://www.terrafugia.com/
No problem at all! We may very well start crawling your advisory DB for our own mailing list, which isn't limited to just Ruby, to be fair. ;)
It's always good to have more eyes on security issues - Ruby or not - and keeping the community informed. Feel free to get in touch with us at support@tinfoilsecurity.com - we'd love to chat about any ways we can work together.
This is an interesting take. For us, it's not about age, but about personality. We have a financial controller who is 20 years older than everyone else on the team and we'd bring her on full-time in a heartbeat if we needed a full-time controller. She has a great personality, is fun to have in-house, and knows what she's doing.
How I look at the Sunday test is less of a "are they like me" and more of a "will I get along with them many hours a day"? We work anywhere from 7 hours a day, up to 18 (especially during major code pushes) - we try to avoid this as much as we can, but sometimes (for us at our stage), it's inevitable.
I do have to enjoy working with my colleagues, and someone for whom I won't be willing to come in on a Sunday has a higher chance of bringing me down on a regular basis. That doesn't mean we work Sundays (we're typically in the office M-F), but it's important to be able to get along with people and it's a good litmus test, imho.
As a founder your job is to take the high road as much as possible while still pushing through the strengths of your company. It seems pretty obvious that NYT won't be changing their opinion, and maybe even reached out to Musk to confirm this suspicion. If Musk were to reply to this negatively he'd essentially be feeding an ever-lasting flame. He's taking the best parts, spinning them to those who care about his product, and is continuing on with building out a great product.
Not to mention, he's gotten a lot of good press from other media sources since (as he points out in his blog post).
Sorry about the confusion.
If you run a scan from our homepage, you're actually looking for a lot more than just the YAML vulnerability (XSS, Mixed Resource, etc.) as our product isn't limited to just the YAML vulnerability.
If you run the scan from https://www.tinfoilsecurity.com/railscheck, then you'll get a quick check for just the YAML vulnerability.
Does that clarify it a bit?
There are other workarounds, too. You could disable XML parameter parsing, for example (as seen here: https://groups.google.com/forum/?fromgroups=#!topic/rubyonra...).
Thus, you might be running an old version, but still actually be safe by disabling the vulnerable bits.
I've posted a little bit more on our blog at: http://blog.tinfoilsecurity.com/use-rails-check-yourself-for...
Mind if we copy that verbatim? :)
We're actually offering free web security, too: http://news.ycombinator.com/item?id=4792073 :)
Love what Mixpanel is doing, so we'd like to jump on the bandwagon. Offering our $59 Basic plan for free for life, and 50% off all other plans. Happy to keep startups secure :) Email your YC rejection letter to founders@tinfoilsecurity.com
The first episode is available for free on iTunes: https://itunes.apple.com/us/tv-season/start-ups-silicon-vall...
It's a travesty, and puts female entrepreneurs in a poor light, pitting them against each other and making them look petty.
This looks a lot like BugHerd (http://www.bugherd.com). Might be worth looking at what they do?
Seems awesome - like a GUI for git-flow.
What is the pricing for this? Seems there's a free download at the top, but the bottom says "Buy for $29.99". Might want to make the pricing structure clearer. :)
And this is the precise reason we exist. :)
I'm super surprised that the plans for 2013 don't include a charging station in the Bay Area, seeing as they're headquartered here.
This looks great! It seems to make Stripe simpler (since Stripe is essentially simple payments for developers, but non-developers have a hard time grasping all of their docs). If you don't plan on expanding it too much, you might try to talk to the Stripe team and have them integrate :)
What we've found is that there are 2 mindsets: building and breaking. When you're building a product it's super hard to switch to the breaking mindset of security, simply because mental context switching is expensive and mentally exhausting. The most important thing is to force yourself into that mode before posting anything publicly. If you don't have the security experience, have a friend or service (like ours) look it over. Data is one of the most important assets to your company (or project), and any sort of disclosure can shut you down permanently.
Legally you must disclose any sort of security breach to your users: http://en.wikipedia.org/wiki/Security_breach_notification_la...
This is a severe lack of customer service. The least that can be done is a quick shutdown of the site until there's a good fix, an email to all customers (since legally they have to disclose the breach: http://en.wikipedia.org/wiki/Security_breach_notification_la...), and a thanks out to whomever reported the issue.
If you make a mistake, own up to it. Honesty is the best key to building a business, and I'm sure they've at least lost the HN trust for any product in the future.
Legally, they're now required by law to disclose to their users of a security breach: http://en.wikipedia.org/wiki/Security_breach_notification_la...
Since whomever discovered the bug was able to access others' sensitive information, they have to disclose.
We've done some tests, and many of our customers would much rather have a basic scan and see the full results of the scan, than only be shown a piece of the scan. It gives off the impression that we're holding their vulnerabilities hostage, and that's definitely not what we hope to do!
The best test to see how we differ from Nessus/Burp is to try it yourself! A lot of the vulnerability classes we scan for are very similar, but the ways in which we scan for them are different. We do offer our Standard Plan for a free 30 day trial. Would love to hear what you think :)
If you have any issues, ping us at http://tinfoilsecurity.com/supportchat
Send us your address; we'll send you a tinfoil hat! :)
I'll be playing this song on repeat all day :)
I have multiple responses to multiple comments on this thread, so I'm going to continue here.
For full disclosure, I'm a young entrepreneur (<25), run a company that was started a few months after curebit (my cofounder applied and interviewed for the same YC class with a different idea), have raised pretty close to what curebit has raised, and am also a 500startups-funded company.
I'd just like to take a minute to hope that a couple of screw ups by others won't put companies like ours at a disadvantage. It makes me sad to think that "how old are you guys" is one of the first questions someone would ask, since I'm not sure physical age has anything to do with how people react to different situations. I'd sure like to think that if I screwed up people would chalk it up to me being me and not my generation.
I also hope people realize the big mouth investor with no taste (especially in what he wears ;) isn't the only person vetting 500startup companies. He has a whole investment team. Yes, Dave does pick a lot of the 500s companies himself (he was our biggest advocate), but the entire 500s team has a say. I also think you're overlooking the fact that curebit was also supported by YCombinator (and Dave has a lot of respect for PG's team and the companies they accept).
I don't condone what curebit did (far from it). I am close to positive someone at YC would have at least helped hash out ideas for design (and 500s' mantra is design, data, distribution), and, Dave has always said: running lean doesn't mean running cheap. But I hope that what one company does doesn't ruin it for the rest of us.
A startup is not a 5000 person corporation and shouldn't be run as such. I remember the author posting a Show HN last February introducing his company. At that point in time he was still in a full time job. Now, I don't know what's happened in the life of his company over the past 11 months, but I would venture to guess he has less than 10 employees. I'd even venture to guess it's somewhere less than 5. At this stage you're more looking for collaborators, not people to manage. And when you're looking for early stage employees you should really be looking for a true personality fit, in addition to the required technical prowess (which, incidentally, doesn't necessarily mean "knows ruby").
Yes, hiring is hard. Yes, as an early-stage startup it will take you a very long time to hire. But you have to remember those you're hiring today will make or break the company tomorrow. Their "5 yr plan" should have no bearing on whether or not they get a job at a very early startup, but by the end of the interview you should know not only that they're technically capable, but can roll with any changes you foresee the company making, and that they have the right personality to mesh with you and the rest of your team (you'll be spending a lot of time together - could you grab beers with them?). You should also know that they're so sold on the idea and vision of your company that their 5 year plan and your 5 year plan become one (or are at least related). Realistically, your startup probably won't even be alive in five years.
Of course I know a lot of people look at things differently, and I have complete respect for different opinions and methods (and love reading about them). We're still trying to figure out hiring ourselves, but I think the best engineers come with all sorts of non-corporate eccentricities. If we had followed the author's suggestions, we wouldn't have hired either of our two founders (including myself) or our first engineer. I'll leave it up to the reader to decide whether that would have been a mistake or not. :)
This just isn't the case.
The show was supposed to portray TS in a good light, and even the Davids are taken back by this reaction.
As one of our investors (in the interest of full disclosure), Tisch is awesome. He's always looking out for the best for his companies, either as personal investments or TS companies. I'm also sure none of the TS companies would say the program was a net negative, rather than a net positive.
As for the mentoring aspect, what Bloomberg didn't show is that the entire 1st month of TS is spent with 40-60 mentor meetings so you find the best mentors for your company. Tisch and Cohen are there to keep you on track from an investor's perspective, but they heavily rely on their mentors to keep you on track.
We've actually found it much easier and cheaper to find houses in this area. Granted, we moved here with the major influx of interns :P