HN user

fmavituna

1,407 karma

Ex-founder

Posts128
Comments225
View on HN
pauljerimy.com 5y ago

Security Certification Roadmap

fmavituna
1pts1
neilonsoftware.com 6y ago

Difficult Development Managers

fmavituna
1pts0
robertsspaceindustries.com 6y ago

Star Citizen's crowdfunding passes $250M milestone

fmavituna
4pts0
blog.dofo.com 7y ago

Oldest Domain Names and Their Current Status

fmavituna
1pts0
hbr.org 7y ago

How CEOs Manage Time

fmavituna
2pts0
www.netsparker.com 7y ago

Analyzing Impact of WWW Subdomain on Cookie Security

fmavituna
2pts0
www.netsparker.com 7y ago

Exposing the Public IPs of Tor Services Through SSL Certificates

fmavituna
1pts0
www.netsparker.com 7y ago

Pros and Cons of DNS Over HTTPS

fmavituna
3pts0
www.resetera.com 7y ago

NPD: 67% of Americans play games average 12 hours per week

fmavituna
3pts0
toucharcade.com 7y ago

Apple Kills the App Store Affiliate Program

fmavituna
2pts0
medium.com 8y ago

How to take 7 years to ship a beta

fmavituna
233pts56
www.netsparker.com 8y ago

How Type Juggling (PHP) Can Lead to Authentication Bypass

fmavituna
4pts0
www.tunngle.net 8y ago

Tunngle is shutting down tomorrow due the new GDPR

fmavituna
40pts17
www.viralriff.com 8y ago

$945,200 Penalty for Lootboxes in Korea

fmavituna
1pts0
www.rockpapershotgun.com 8y ago

Flight sim group put malware in a jet and called it DRM

fmavituna
12pts1
www.netsparker.com 8y ago

Exploiting a CSRF in Grammarly to steal private documents

fmavituna
1pts0
gmaster.io 8y ago

Gmaster – git client with semantic diff

fmavituna
11pts7
toshellandback.com 8y ago

Hijacking Control of Wireless Mice and Keyboards

fmavituna
2pts0
www.gandi.net 8y ago

“No Bullshit” promise

fmavituna
2pts0
altvr.com 8y ago

A Very Sad Goodbye – AltspaceVR Is Shutting Down

fmavituna
2pts1
wololo.net 9y ago

Xbox One Exploit Proof of Concept Released, Based on Chakra Exploit

fmavituna
108pts27
www.glixel.com 9y ago

“Witcher” Studio Boss: 'We Had No Clue How to Make Games'

fmavituna
2pts0
www.youtube.com 9y ago

11 Streamers Get Swatted Live

fmavituna
1pts0
www.netsparker.com 9y ago

Preventing CSRF Attacks with the SameSite Cookie Attribute

fmavituna
1pts0
collapsed.co 9y ago

Collapsed – Learn Lessons from Failed Startups

fmavituna
2pts0
www.netsparker.com 9y ago

Identifying WordPress Websites on Local Networks and Bruteforcing Login Pages

fmavituna
4pts0
www.netsparker.com 9y ago

Hacking local MongoDB installation from web with CSRF and timing attacks

fmavituna
1pts0
www.netsparker.com 9y ago

Using the Same-Site Cookie Attribute to Prevent CSRF Attacks

fmavituna
1pts0
www.netsparker.com 9y ago

CSRF Vulnerability in Yandex's Login Page Allows Steal Browsing Data

fmavituna
1pts0
scotthelme.co.uk 9y ago

Alexa Top 1M Crawl – August 2016

fmavituna
2pts0

We need to kill the cliche that language/framework doesn't matter but we also need to understand, it still won't solve all problems.

I wrote about a similar topic from a web application security point of view: Why Framework Choice Matters in Web Application Security* ( https://www.netsparker.com/blog/web-security/why-framework-c... )

Also today there is enough data in the industry to prove this argument beyond any doubt for web applications.

* original article is written about 11 years ago or something this is a republished version

It's a nice mix of issues. Web security (client/server-side) is a big field, and keep changing. We need a lot of awareness.

If you like this kind of web security focused articles, our security researchers publish (almost weekly) very basic to advanced web security topics in our blog : https://www.netsparker.com/blog/web-security/ Some of them are very specific like;

PHP Type Juggling Vulnerabilities: https://www.netsparker.com/blog/web-security/php-type-juggli...

and some of them are 101 kind of coverage such as HTTP Response Splitting: https://www.netsparker.com/blog/web-security/crlf-http-heade...

Whenever I hear about wealth inequality, I think of Zakat ( http://www.bbc.co.uk/religion/religions/islam/practices/zaka... ).

It's one of the 5 pillars of Islam. One has to give 2.5% of their wealth to poor. It's compulsory unlike Sadaqah - Charity ( https://en.wikipedia.org/wiki/Sadaqah ).

I guess if everyone followed just this 2.5% rule, there wouldn't be any poor left in the world (I didn't do the math though).

P.S. When I say poor, I'm not referring to people who cannot afford the new iPhone.

It's a bit (actually a lot) worrying that their donation page that you enter personal and credit card info is not over HTTPS. Possibly it will significantly decrease the donations they'll receive online.

My argument was about software development and I don't know how much it would hold up for other fields.

Employer pays the time for that employee to acquire the knowledge, employer serves the know-how that the employee might never ever able to learn by herself. How is it not reasonable to expect that knowledge to be used against the employer? Why is it one-way? I'm not talking about knowledge in a sense that "good code should include comment" kind of dev best practice. I'm talking about domain specific know-how that the employer came up with in many years by spending lots of money (R&D, trial & error, field studies etc).

I agree, but if we want that we should start from demolishing "patents" and many other similar more basic issues first, but we all know why that's not going to happen.

Secondly when you do that, aren't you actually killing commercial research? Why would I spend $10M to research something if one of my employees can just take that know-how and move to my competitor?

Sorry I wasn't clear on the original comment, how can NDA stop a developer to use what he knows while writing code or creating procedures?

If you are a developer and worked on a code for 2 years. NDA cannot cover what you know what you don't. Your know-how that you captured on that company can simply be replicated in another company. You'll write the code from scratch, and NDA or copyright, or even patent in majority of the cases will not be enough to enforce or stop such a think. In rare cases patent can solve it but do we want all companies to patent everything?

Trade secrets, IP, secret sauce: covered by NDA and IP assignment agreements

As a developer pretty much none of these matter or protects anything.

Imagine this scenario; - John has no idea about video encoding but a good developer.

- John joins to a video encoding startup

- This startup encodes videos 3 times faster than the competitor

- After working on the core product for 2 years, John knows a lot about video encoding, because he's been trained. He also knows why they can do faster than anyone else. It's not one thing, bunch of things.

- Then John receives an offer from the competitor with 50% more salary (obviously this is smart thing to do for competing company). He obviously leaves, because 50% more! All the know-how, experience etc. will be just automatically transferred to this competitor. NDA, copyright etc. nothing can prevent it.

So how is this good for anyone but John? If you think this kind of stuff doesn't happen and all this kind of advancements are public domain anyway, you are wrong. There are many niche fields where competing advantage comes from technical excellence and understanding couple of key things better than your competition.

Not to mention John will have inner knowledge of so many other non-technical but important details that can give obvious unfair competitive advantage.

When non-competes are removed companies do need to treat their employees differently. "If I don't trust this employee enough I shouldn't give them the important bit of the source code, shouldn't train them on X know-how that we internally produced" etc. which is pretty bad for everyone.

I used to commute 3 hours a day, I used to finish 1-2 books per week. 3 hours of solid reading every single day.

Now, depending on the book it can be 1 week to 3 months as I don't commute and when I'm at home it's quite hard to drop everything read for one hour.

So I think it depends on people's lifestyle, if you are commuting 3 hours a day reading a book in a week is very very easy.

I never used them or seen them in a benchmark so cannot comment much of the capability or quality. I think it's best if you compare it for yourself. Running a scan very easy and won't take much of your time, drop me an email and will get you a license or account to our cloud solution, so you can test it and see how it compares. Email: contact@netsparker.com

2 things:

* It's about how make the suggestion. "How about making this blue darker?" vs. "Do you think making this blue darker would give us more engagement? Are there any studies, or have we done A/B testing on this? I think it fits on our branding better because..." etc. Derek's example is really bad one though. Why would a manager (unless an experienced designer) would make such a pointless suggestion?

* If everything you say is just done without any sort of questioning then it's obvious there is a problem.

So I think any decent manager would notice it.

If your team cannot take your feedback just like taking feedback from their colleagues, cannot argue with you or veto your idea easily with a legitimate response, take everything you said as a "command" then you have failed as a manager anyway.

I assume Derek's advice makes sense for Korean culture where manager and team dynamics are different.

Use static source code analysis and dynamic web app scanners.

They are easy to integrate into your SDLC, they are not going to replace manual testing or secure development practices but they'll help a lot. They'll pick up tons of stuff for free, they'll remind you best practices.

I have a startup (at least it still feels like a startup!) and we are developing a web application security scanner called Netsparker [0]. It found over 100 zero days in open source applications while testing it [1], including very popular vulnerabilities in applications such as Wordpress and Joomla. I guess that by itself proves how good scanning can be.

If you want to try it on your websites and see it for yourself drop an email / message to contact@netsparker.com with a mention of HN and I'll get you a fully functional trial that you can use on your own websites.

[0] Netsparker Cloud https://www.netsparker.com/online-web-application-security-s... - Netsparker Desktop https://www.netsparker.com/web-vulnerability-scanner/

[1] https://www.netsparker.com/web-applications-advisories/

For whose wondering, brief read of the paper's initial chapters show that it's a methodology (and toolset) to find access control issues in RoR. Seems like a smart approach, need to see it in production though. I'm not really surprised if they found various ACL related vulnerabilities with this model in web apps, it's a common issue and not easy to test & check.

Injection vulnerabilities (XSS, SQLI etc.) are out of the scope of this document/toolset, it's heavily designed for detect ACL issues in web applications.

That's pretty much bullshit for the pure reason that a job very rarely can only include the things you love. I love programming but I hate polishing up the same features for days, but that's what's necessary to make a good app. I hate testing, but it's part of the game.

How photographers really spend their time : http://www.cambyte.com/wp-content/uploads/2015/05/piechart.j...

Having said that I'm sure, some people in some industries reach that dream but I can't think of any...

With 7 years experience of running a remote & distributed team (5+ countries) at Netsparker [1].

We have 4 platforms:

* Bug Tracking / Project Management

* Group Chat

* Skype / Voice

* Email

Since we grew organically, here is how I shaped the culture from 2 team members to 20 and quite happy with it at the moment:

Groupchat is for "2. Red Alerts" (via @everyone mentions), "3.Having Fun" and "4. Sense of belonging". Finally to share random stuff from funny moments to interesting articles. Stuff that's completely optional to consume. Very very rarely for "Hashing things out quickly" for that we use Skype. If you want to toss an idea back and forth, just talk. If you are not in the same timezone just wait for all to be in the same timezone (we don't have extreme timezone differences, max is about 10 hours)

Voice is for pretty much everything else. We don't type or discuss anything on chat if it's more than 3 message exchanges, when that happens someone just calls. It's just waste of time, we just get on a call and talk. We also have a routine of initiating skype calls to ensure it's normal to call people but it's also normal to ignore calls as well. So you have the option to quickly talk but also option to not be distracted.

We made it OK to be offline. Especially for devs it's OK to just be offline.

If something is really urgent, we'll call you or send you a text message. Which rarely happens.

If it's a task/bug put it into the bug tracking system. Then it'll be visible on the developer chat channel automatically.

So we found that voice chat is superior to pretty much anything else for many purposes. Another habit we are getting better at is taking notes in voice conversations and putting them on to the tasks.

These make text group chat a very minimal part of the flow. Another good example: I was away for 2 weeks and it took me about 10 minutes to catch up with all the group chat because we use it sparsely and discussions always use threads (this is something we teach during the orientation) so you can read the first line and just skip the whole thing.

Maybe it works because we have only 20 people, we're planning to continue to do this until it doesn't work anymore.

[1] https://www.netsparker.com

There are many apps like this;

Skype, Whatsapp, Twitter, LinkedIn are come to my mind (a few of my personal list), heck even Flash & Java Runtime (same problem different field). For the lack of better and popular alternative we have to stick with these. LinkedIn being on of the prime examples.

Twitter on the other hand has a different problem, solutions such as FriendFeed was a much better, almost by all means compared to Twitter (you could actually have a sensible conversation and while keeping almost all the benefits of Twitter) yet it didn't make people to switch from Twitter. Later acquired by Facebook, so I guess they succeeded.

Hey Ken, hope you guys the best, good project.

As a seasoned (although retired) pen-tester I wanted to say you'll have some serious problems with rating when it comes to results.

When a company hires pen-testers and pen-testers do or do not find stuff, the company has no idea about the coverage. So the pen-test team might have missed many stuff or identified all. I'm sure you've seen in real world even the same members of the same pen-test team might find different issues for the same test.

Therefore one of the biggest problems is to actually knowing whether they are good or not at what they do. It's easy to rate communication skills, responsiveness, attitude, report quality etc. But very hard to rate the quality of the results (which is the real reason for carrying out a pen-test).

When they don't find something, maybe there really is nothing there. When they found something, maybe there is more there. The customer has no idea at that point. It'll be only a fair amount of time later they'll figure out the coverage / vulnerability finding quality.

I'm sure in the long run market will stabilize (assuming you can change your rating for a pen-tester even after a year) but this is something to consider.

Update: BTW personally I don't like the idea of logging in via LinkedIn (for finding a security talent), it's feels too intrusive, beside of the personal preference my experience showed me especially security industry don't like SSO style things.

I've been working from home for the last 7 years.

Interruptions suck and you don't need to embrace them. You can perfectly have a dedicated time for your family as well as dedicated time for your job. It's all about planning and ensuring that people around you understand your schedule.

You can still have 1 hour allocated time with your son during the day and you can be present, that doesn't mean your son needs to interrupt you 5 random times within 3 hours. If you know when he comes home from school, by all means allocate that fixed 30 minutes or whatever to him, perfect.

There is pretty much no difference between allocating random time frames to people you love vs. allocating fixed times to people you love.

We all know from experiments, various sources and for many from personal experiences interruptions do hurt productivity, induce stress and generally bad.

Also, you can turn this around. Instead of being interrupted between your tasks (out of zone moments) just make rounds at the house, talk to your wife, enjoy a snack, take 15 minutes break. Then go back to hacking with a clear, recharged head.

So why sacrifice your focus/productivity when you don't have to?

I see that CEOs are being picked on about really high salaries regularly, the real question is what would happen if they got paid much less? Company would make more profit and that profit would go to the shareholders.

Honest questions: So why does it matter? Whether the part of money goes to a CEO or another rich shareholder? How does it change anything? To be honest pretty much in every company major shareholders make way more money than CEOs.

Is it the idea that "middle class" can be a CEO so in theory it's attainable yet being a major shareholder is not even within the reach of "middle class" therefore it's almost being jealous of fellow man (CEO), because it's human yet major shareholders are more like "Pharaohs and Emperors" ?

... I had to change and decided to jump into the startup world.

You don't have to choose one of them. I was in a similar position about 6 years ago, software + security background and passion for startups which led me to start my own company (https://www.netsparker.com/), we're building a tool to automate web app security and advancing the automated scanning in web apps, it's really fun stuff if you are into security.

Security industry is great for startups and new comers, another option is obviously working for a security startup, there are tons of them.

1. If a manager leaves work unassigned and you pick it up, prepare to have a LOT more work dumped on you in the future for no reward.

Why do you assume "no reward"? What kind of company/manager wouldn't reward an employee who goes that extra mile?

Aren't all pay-to-win games are like this yet we see they keep succeeding commercially? (i.e. Clash of titans and tons of F2P+P2W PC games)

Based on your assumption they all should've failed but clearly (and unfortunately) this business model works.