HN user

bqe

2,311 karma
Posts55
Comments152
View on HN
twitter.com 5y ago

LOL just got kicked out of @ycombinator

bqe
1041pts588
www.seancassidy.me 6y ago

Wiggle the mouse to fix the test (2013)

bqe
2pts0
www.seancassidy.me 6y ago

Phishing Simulations Considered Harmful

bqe
4pts2
medium.com 7y ago

Self-Driving Cars Will Always Be Limited

bqe
6pts0
www.nybooks.com 8y ago

Ur-Fascism (1995)

bqe
2pts0
yatebts.com 8y ago

The 'rogue GSM tower' episode (2018)

bqe
2pts0
www.seancassidy.me 8y ago

Host an infodump session (2014)

bqe
1pts0
thewalrus.ca 8y ago

The Science of Loneliness (2017)

bqe
1pts0
www.newyorker.com 8y ago

The Case for Not Being Born (2017)

bqe
2pts1
github.com 8y ago

Better Java

bqe
3pts0
news.ycombinator.com 9y ago

Ask HN: Is AWS support worth it?

bqe
1pts1
www.washingtonpost.com 9y ago

Russia has developed a cyberweapon that can disrupt power grids

bqe
4pts0
github.com 9y ago

Mastodon

bqe
55pts13
en.wikipedia.org 9y ago

National Popular Vote Interstate Compact

bqe
19pts7
en.wikipedia.org 9y ago

Stanislav Petrov

bqe
1pts0
eprint.iacr.org 9y ago

Balloon Hashing: A Function Providing Protection Against Sequential Attacks [pdf]

bqe
62pts21
eprint.iacr.org 10y ago

OpenSSL DSA key recovery attack

bqe
184pts17
www.seancassidy.me 10y ago

Meditations Redux

bqe
3pts0
www.openwall.com 10y ago

S/party/hack like it's 1999

bqe
77pts31
www.seancassidy.me 10y ago

Privilege

bqe
3pts0
www.seancassidy.me 11y ago

We, the Weapons

bqe
1pts0
www.seancassidy.me 11y ago

The Practice Startup

bqe
2pts0
www.seancassidy.me 11y ago

Code as Risk

bqe
3pts0
blog.seancassidy.me 11y ago

Sherlock Holmes Debugging

bqe
114pts28
hearstartup.com 11y ago

Startups Are a Risky Business

bqe
1pts0
www.slate.com 11y ago

Innovation Starvation, the Next Generation

bqe
1pts0
blog.seancassidy.me 12y ago

Your Interface is what Matters

bqe
1pts0
blog.seancassidy.me 12y ago

Write in the Margins

bqe
7pts0
blog.seancassidy.me 12y ago

Meditations

bqe
130pts34
blog.seancassidy.me 12y ago

Better Java

bqe
17pts4

I remember being asked this during my interview at Google. It was the first time I heard it and I gave an answer that iterated over the list twice. The interviewer said that it wasn't good enough and I am only allowed to iterate over it once. He didn't let me write my O(2n) solution down so he returned a strong no as feedback.

Why this is interesting: a major defense against mass account takeovers (ATOs) at large scale companies has been fingerprinting browsers. You as a normal user see this most when you use something like reCaptcha, but it's actually happening on nearly every login flow for major websites. By blocking automation like evilginx, you stop a lot of phishing and credential stuffing attacks against your users.

Using VNC here is super clever. This means that the "automation" part of the phishing attack is actually a browser just like the user is using, so you can't fingerprint it. In fact, the victim is really typing in their password into a real Google login page, but the attacker is logging everything through VNC. It's going to be very hard for Google (or anyone else) to detect this.

The solution to this (like all phishing attacks), is still WebAuthn. However, many of us in security were hoping we could get by with bandaids like fingerprinting until WebAuthn was more widespread.

Awhile ago I wrote a Python library called LiveStats[1] that computed any percentile for any amount of data using a fixed amount of memory per percentile. It uses an algorithm I found in an old paper[2] called P^2. It uses a polynomial to find good approximations.

The reason I made this was an old Amazon interview question. The question was basically, "Find the median of a huge data set without sorting it," and the "correct" answer was to have a fixed size sorted buffer and randomly evict items from it and then use the median of the buffer. However, a candidate I was interviewing had a really brilliant insight: if we estimate the median and move it a small amount for each new data point, it would be pretty close. I ended up doing some research on this and found P^2, which is a more sophisticated version of that insight.

[1] https://github.com/cxxr/LiveStats

[2] https://www.cs.wustl.edu/~jain/papers/ftp/psqr.pdf

Goodbye, Fleets 5 years ago

I think the simplest solution to this would be to simply hide comment/retweet/like counts. It will be possible to sort of figure this out from the engagement, but it won't be easy to figure out if a tweet is popular or wildly popular.

They pay for expensive ($$$$$$) cloud anti-bot/anti-scraping, captcha you after a few requests if you run adblock, they pay for extensive browser/device (attempting to reidentify a user across multiple devices/multiple browsers) fingerprinting services and Fastly.

This sounds like a great anti-account takeover program. I imagine with all of the various compliance programs they have to deal with and the legal risk, these are prudent measures.

Q2 2020 Update 6 years ago

The parent commenter was discussing revenue and not profit. If they were aggressively expanding, I would expect that profits to remain small or negative, but I'd expect revenue to grow as a result.

The thing is running a marathon isn't that hard and there's little to no luck involved. By following a rigid plan most people can do it in about a year. Millions of people do it every year.

However if you followed all of Sam's advice to the letter you could remain relatively unsuccessful despite all that advice. That's what survivorship bias is about: there's a significant luck component to success.

I think you underestimate how many people blindly copy examples without understanding them. Safe example code results in more correct programs.

Whenever free will comes up I like to bring up Conway's Free Will Theorem[1].

If you define free will as future choices cannot be predicted based on history, then it turns out that if humans have free will, so do elementary particles. To me, this doesn't mean we don't have free will, but instead the linear, deterministic model that's often used to discount free will is just not how the universe works.

Note that this result does not depend on statistical randomness like some of quantum mechanics, but just three simple axioms. I highly recommend reading the full paper, especially the end, "Free Will Versus Determinism".

[1] http://www.ams.org/notices/200902/rtx090200226p.pdf

Rents in Seattle have stayed relatively constant over the past several years despite adding tens of thousands of residents because many new apartment buildings have been built.

However, home prices (including condos) have risen drastically because of the limited supply. There's no new space for single family homes, and because of a Washington law which increases liability for developers, few new condominium buildings are built.

I think Peterson is a little too intelligent to speak frankly on race, so he speaks in code to his followers that are in the know and allows them to make the logical deductions he leads them to. There's a discussion on his subreddit[1] that examines exactly this.

My main point is that it is not a surprise that he attracts alt-right types when he is tweeting dog whistles[2] while claiming not to be a member of that group.

[1] https://www.reddit.com/r/JordanPeterson/comments/7hkbzo/is_j... [2]: https://twitter.com/jordanbpeterson/status/85146415170895052...

To those wondering why alt-right/neo-nazi/1488-type people are flocking to Jordan Peterson: this comment accurately describes both Peterson's views and the alt-right view on race. Many alt-right people claim they acknowledge "factual differences" of race, which is the basis for their ethno-nationalist views.

Here's a discussion on the alt-right following of Peterson on his subreddit: https://www.reddit.com/r/JordanPeterson/comments/7gb5af/is_j...

Here's some dispassionate inquiry: he leans on IQ far too heavily to explain how the brain works. While there is correlation between jobs and IQ and some research that shows a mild inverse relationship between IQ and crime, it's not the end-all-be-all of psychology, as he claims, "If you don’t buy IQ research, then you might as well throw away all of psychology."

What of all of the other areas of psychology? If IQ was found to be completely spurious, we'd still have other psychological research. IQ is not foundational like he claims.

It's like Peterson has never read the criticisms[1] of the Bell Curve and believes it in its entirely. His lectures and interviews on the subject are really just a rehashing of the same, mostly discredited arguments. Even Charles Murray has stepped back from a single number determinant of a single kind of intelligence[2].

[1] http://www.dartmouth.edu/~chance/course/topics/curveball.htm...

[2] https://web.archive.org/web/20050205010706/http://www.skepti...