HN user

carmaa

48 karma

http://twitter.com/#!/MaartmannMoe

Posts4
Comments17
View on HN

I feel that we may be ignoring the psychological aspects of having a strong BATNA here. It's easy to say that you should just "ask for a better offer", but it is waay easier to actually do that when you know how much you are worth to another employer.

Some people may be able to pull off something like what you describe, but all research I've read on negotiating indicate that knowing your BATNA and having a strong one is key to achieving good negotiation results.

Never name a range. Ask for 15, 20 or 25% more, based on what you want.

If someone comes to me asking for 15-20% more, I'm going to offer them something below the low end of the range. You're essentially giving away 5% for free.

A "report" not covering the greatest current use case for the currency - namely anonymously buying weed through the Internet tubes? Not saying it is a good thing, just that there's actual value creating going on. Right now.

Hey.

Do you leave your PC or in standby when traveling? When you leave your desk at work?

More importantly, do you think that end users would expect password protection to work? Even when their PC is on?

There's plenty of scenarios where a PC may end up being in another persons control while powered on. This is a relevant threat scenario. Deal with it.

Over time, yes. Your statement about physical access == compromise is missing that crucial detail. There's no reason why someone should be able to access all your data just because they have physical access to your device for a short period.

If you really want to do the analogy thing, the DMA vulnerability would be the equivalent of a safe with a door where no key is needed in the back. It would not be a very good safe.

Just sayin'.

It should not be that way, though. Physical access should not equal compromise.

There's no good reason why this vulnerability still exists after 10 years except a failed design, laziness on the part of OS developers and that security professionals in general meet the problem with the above statement that "physical access equals compromise".

I think end users deserve (and expect) secure devices, even when physical access is lost. I realize that it's harder to protect a physical device, but it's not impossible.

From BofA's guidelines on online privacy and security [1]:

"Protect your Online ID and Passcode. You should always guard your Online ID and Passcode from unauthorized use. If you share this information with someone, all transactions they initiate with the information are considered as authorized by you, even for transactions you did not intend for them to make."

Sure, why not.

1. http://www.bankofamerica.com/onlinebanking/index.cfm?templat...

From the article that has ceased to be:

---

We have been doing a lot of interviewing at Referly lately, and my team asked me to share an interview question we get the most mileage out of. I’ve been doing this question for years and now have seen over two hundred different answers now. It’s without a doubt my favorite interview question, because it only take 5 minutes and it tells me a remarkable amount about candidates. Even though it’s not a technical question per se, I still give it to every programmer I interview.

Setting up the interview question

Here’s how I set up the question:

I want you to explain something to me. Pick any topic you want: a hobby you have, a book you’ve read, a project you worked on–anything. You’ll have just 5 minutes to explain it. At the beginning of the 5 minutes you shouldn’t assume anything about what I know, and at the end I should understand whatever is most important this topic. During the 5 minutes, I might ask you some questions, and you can ask me questions. Take as much time as you want to think it through, and let me know when you want to start.

When I give this, I usually emphasize each of these points multiple times, with a real stress on their goal: have me understand what’s most important about the topic.

Empathy

As they start explaining, I make sure to have the most vacant look on my face possible. I do not give any “uh huh” or “I see” kind of interjections that underlie most conversations. A star candidate will pick up on this and ask if I understand so far. On the job, these star candidates also are the same kind of people that empathize with customers and think about it in all the work they do once we hire them. Conversely, weaker candidates think that presentation and communication are one in the same, and loose sight of their audience. They end up being the hardest developers to work with just to understand how they’re solving a problem, much less have a constructive argument with them.

Explaining by analogy is a shortcut some of the best candidates use. One example I heard while someone was teaching me the basics of poker was to take advantage of the fact I had played backgammon even though I hadn’t played poker. He talked about how in backgammon all the pieces on the board are exposed information that both players can see, but in poker you have hidden information. These type of explanations go a long way towards quickly communicating an idea with all kinds of implications very succinctly.

Goal directed and organized

It is amazing how many candidates will not premeditate before diving into this interview question. Once the trigger happy type candidates get going, they don’t have any kind of bulleted list or outline in their head of what they hope to get across. What’s most incredible about this is how accurately it predicts disorganized and non-goal directed behavior on the job. I’ve been over ruled a few times by my manager on a hiring decision, and question was a harbinger of things to come. Conversely, the people that think it through and have a few crystal clear points are amongst the best people I’ve worked with. They are not just easy to communicate with, but get results in their work.

Leaders have the guts to say no

For senior positions, I will ask a question early in the 5 minutes that is a complete tangent and has little to do with their goal. A star candidate will politely refuse to go down this rat hole and insist that we stay on topic. This seems unfair since an they’re in an interview and just doing what they’re being asked. In reality though, the very same thing happens often in real work. Even mangers do not innately know what is most important about a topic, and it’s key to have confident people on the team that add focus to conversations.

Stacking up

Usually only 1 or 2 out of every 10 candidates will do well on all these points. That has held true after giving this interview question over two hundred times.

I take a risk sharing this, because this question has been an amazing tool in picking apart the best talent from rest. I ended up deciding this was worth sharing because after years of telling people exactly what I am looking for in the set up, weaker candidates still can’t help but get tripped up.

Want to experience it first hand? We have open positions right now :)

She forgot to factor in the dealbreaker; the fact that engaging in a startup (or any other intensive work if you ask me) with your significant other is a major risk in itself, and a bet where not only your career is at stake, but also your relationship.

Your logic is flawed; just because password complexity doesn't mitigate some of your carefully constructed scenarios, doesn't mean that it's useless. You even mention up some of its merit yourself.

Password complexity (when done right) DOES makes it more difficult to:

-brute force passwords -crack hashes -perform rainbow table attacks -do password sweeps, e.g. do one password guess on every known user name (effectively avoiding account lockout) -do 'one off' guesses

It is not perfect alone, but it is one very important component of every secure and reliable application.