HN user

arcwhite

80 karma

Director of Software Engineering at Bugcrowd (also employee #1!). Infosec, Ruby, Kotlin, Flutter, Obj-C/Swift.

Sydney, Australia.

Posts0
Comments45
View on HN
No posts found.
Against Usefulness 10 days ago

The thing is you don't know that it's got actual future usefulness. You might think or hypothesize that it does, but for various reasons it may turn out to be a dead-end.

Almost every endeavour has non-zero potential future utility - even as a counterexample or lesson to learn from. I think that definition of "useful" is probably too broad to make an argument against, and so not a useful definition.

Against Usefulness 10 days ago

Deep, paradigm-shifting research often needs decades of deep thought and experimentation, which will not yield weekly, monthly or even annual demonstrations of usefulness to customers or shareholders.

She writes as a VC (I think?) where her job is to allocate capital for shorter-term "useful" (read: profitable) outcomes.

Huh? The bot can communicate with me freely as it sees fit. A "conversation" in telegram parlance is not time-limited, it's ongoing once established, so no it's not only inbound. It can awaken and ping me whenever it wants. This can also work if it's added to a group chat.

If you mean it's not outbound as in it can't message arbitrary random users out of nowhere, well yeah, and that's a very desirable trait.

There's generally no grey market for XSS vulns. The people buying operationalized exploits generally want things that they can aim very specifically to achieve an outcome against a particular target, without that target knowing about it, and operationalized XSS vulns seldom have that nature.

Your other potential buyers are malware distributors and scammers, who usually want a vuln that has some staying power (e.g. years of exploitability). This one is pretty clearly time-limited once it becomes apparent.

I've seen code persist a long time because it is unmaintainable gloop that takes forever to understand and nobody is brave enough to rebuild it.

So no, I don't think persistence-through-time is a good metric. Probably better to look at cyclomatic complexity, and maybe for a given code path or module or class hierarchy, how many calls it makes within itself vs to things outside the hierarchy - some measure of how many files you need to jump between to understand it

A bunch of us in the rest of the world are making great strides in reducing our greenhouse gas emissions without it tanking our economies. Australia is, per-capita, one of the worst offenders and we're on track to reach net zero by 2050.

I think your position is based on very cynical premises. There is no reason to assume with high confidence that humans will obliterate each other in that next 50 years (especially if we do something about one of the major stressors causing conflict)

There is also no reason to believe that reducing greenhouse gas emissions over 15-20 years will cause "more" damage than the worst impacts of climate change? Can you cite sources on this claim?

It is still possible to mitigate the worst effects of anthropogenic climate change.

YT's skateboard introduces the telescopic contact smartwheels pretty early on as a Courier essential.

I don't recall Hiro's motorcycle being much a part of the story, it might also have had the smartwheels but isn't discussed until later...

I would love mailing lists to be a thing again, but the experience of using email is just so bad for me. The sheer amount of unsubscribing I have to do to make it usable - not even taking spam into account - makes email a place I don't want to spend any time.

To some extent? But then we have lobby groups, PACs, regulatory capture and astroturf campaigns that have proven to be quite successful techniques to subvert the political process.

I'd argue that those techniques put us back at the mechanistic system being elevated above other values.

I think "assume good faith" has to be taken as something of a Prisoner's Dilemma proposition.

You don't want to be a dove, and keep assuming good faith when it hurts.

Assume good faith initially because it least has a chance of being productive, but the moment bad faith is detected, either withdraw or "punish" (and propagate social signals that bad faith arguing has been detected so others know not to engage)

Where are you getting this theory that there was an impact event that.killed off both the megafauna and the Clovis people's off?

Everything (credible) I'm able to find suggests/theorises that the Clovis differentiated into different groups of Native American populations, and that gradual climate change did most of the megafauna in.

CFAA isn't going away

There's some pretty concerted efforts in play to at least have it updated and tempered, which could have legs. I don't hold much hope it'll go away but I do think some of these efforts to have it replaced could have legs.

No. Just don’t.

Yeah, fair, I mean I'm all too aware of the consequences myself, but within this setting telling a bunch of people "thou shalt not" seems almost more harmful (IMO it's akin to saying "never roll your own crypto" which someone inevitably ends up taking as a challenge)

Lots of people suggesting that either company was out of line here, but like, CFAA is still a thing (assuming OP is in the USA) and it's still got gnarly teeth. Let alone the possibility of industrial espionage allegations...

If you're going to go hack on a company, make sure you have some legal protection first. Check disclose.io or the company's website (look for a security.txt!) to make sure there's some sort of safe harbor provision, or a pre-existing vulnerability disclosure program or bug bounty program that allows you to do this kind of testing.

If you're not going to do that, then disclose the vulnerability anonymously and cover your ass while you're testing, or just don't.

Meanwhile if you're an American please write your local representative and express your displeasure with the antiquated, overly-simplistic CFAA and ask them to support initiatives to have it replaced or removed.

Yeah, lick that boot!

Tens if not hundreds of thousands of people go to prison each year in the US and don't feel the need to kill themselves

Plenty do, and plenty die while they're in prison. This is not a rational justification for what happened to Schwartz (and looks to me like victim-blaming)

Would we blame that person's ex?

I mean if the ex had maintained years of abuse and was threatening the person's life - yes? Yes we would?

Blaming mental illness is an utterly weak response here. Many, many people struggle with mental health and don't commit suicide; the assumption that mental health issues == suicide is reductive and harmful.

Bugcrowd | Multiple Roles | Hybrid Remote (Australia, US) | Full-Time | https://www.bugcrowd.com

Bugcrowd crowdsources hackers and applies them to cybersecurity work to find and fix critical vulnerabilities faster. We facilitate bug bounty programs, vulnerability disclosure processes, penetration testing and we're looking to enable more hackers to do more types of work (and, importantly, get them paid for their efforts) to keep our customers safe on the internet.

Tech stack: React, Typescript, Ruby on Rails, Kotlin, Kafka, Redis, PostgreSQL, Terraform, Docker

We're looking for:

- Mid and Senior Software Engineers (all timezones)

- Product Designer (Australia)

- Front-end Design System Engineer (Australia)

Infosec is a challenging design space, and so are double-sided marketplaces! Come help us design and implement the service-oriented platform that facilitates interactions between hackers and corporate security.

The team is looking to expand significantly in the coming year, so you'll get to have meaningful impact on product and engineering decisions and there is huge room for career advancement (including active mentoring from talented staff engineers, senior designers and senior product managers).

We're committed to hybrid remote - we won't force you back into the office, but we'll make it an option if you want to. Pay, perks and options are competitive, and we're strong proponents of conditions better than merely 'work/life balance'.

Check out our careers page: http://bugcrowd.com/careers or email me: andy@bugcrowd.com

Storms and Teacups 13 years ago

Allegedly. I see plenty of people speaking their minds, on either side of the issue, and many of them are reasonable. I'm left to wonder how one can be so certain that 'the most reasonable people' (by what metric? In whose judgement?) are 'afraid to speak their mind'.