HN user

gregcmartin

337 karma

Security evangelist and entrepreneur.

I'm hiring in SF: jobs@jask.io

Posts8
Comments31
View on HN

Thanks for sharing your story Kenneth. Unfortunately it will be a common one... Maintainers of open source projects will be increasingly target by sophisticated hacking teams, sometimes government funded. They will often win but the best thing you can do for yourself and your users is to practice good security hygiene and this story is a perfect example why. Strong random passwords everywhere (no repeated passwords) and 2-factor auth should be the minimum. Thankfully there are plenty of free apps out there that help you manage this process. Nobody can have perfect security but you can easily raise the bar high enough to force an attacker to move elsewhere. Also the Op's password was most likely taken from the recently leaked LinkedIn breach (educated guess).

JASK is an Artificial Intelligence + Cyber Security startup located in Downtown San Francisco.

We are hiring big data and ML engineers! If you love spinning up massive hadoop clusters in AWS and developing streaming complex machine learning algorithms with the goal of protecting the world from cyber criminals and espionage? Well you came to the right place... Amazing team and culture. Top quality benefits. JASK jobs@jask.op

The cool thing is you can pair this with Ansible and get 1,000's of honeypots deployed at once. In a proof of concept we deployed nearly dozens using digital ocean API and got blocked by their API creation limits.

If you use more interesting honeypot software like Conpot you can monitor which countries are attacking SCADA systems, etc.

this video is full of FUD..

that being said, it is trivial for a nation state to do automatic JS injection to the DOM using carrier grade MITM packet manipulation on any user-agent or cookies with en_us locale strings leaving a particular telecom provider. We now know this is standard practice even by western countries to foreigners.

Standard level of paranoia should apply if your concerned about privacy regardless if your in Sochi or Starbucks cafe in Cleveland.

Redwood City, CA

Very Senior Frontend and Full Stack developers - Javascript, Python, REST, Bonus: D3.js, Django. Experience in a developing a production SaaS product.

We are a revolutionary enterprise cyber security company with series A funding and an awesome culture of hacking, collaboration, being goof balls and making changes in a very challenging industry.

If this sounds like something you would be interested in, please give us a shout, we would love to meet you.

-Greg CEO/Founder

Please contact: jobs@threatstream.com

Senior Developer - Django, Frontend/Backend, Javascript, Python Rockstar

Job Description

Funded startup in US Cyber Security transforming the landscape of cyber warfare. Are you an unbelievable python developer who can rapid prototype great products over night or enjoy refactoring code to high performance asynchronous design? Want to develop the weapons and defenses of the future all in code?

* Must be based in the US and able to quickly relocate without VISA requirement to Washington DC, Austin TX, NYC or San Francisco (preferred) * Able to work 30+ hours per week - if you need to start out at 15-20 and ramp up to full time, that is fine * Detail oriented. Together we will plan a project and create a road map and you should then follow the plan completely and precisely. * Able to provide valuable feedback to the team about architecture decisions. * Work fast and efficiently * Keen eye for design and usability * Want to defend your nation from evil hackers and nation states

The skills you will need are:

* Django / Python * Javascript / jQuery * HTML and CSS (design is not needed) * A little bit of Java and/or C/Objective C * Database * Testing (Unit tests or similar) * Basic Linux (esp Ubuntu Server) * Git * RESTful APIs

These are nice bonuses: * Backbone.js (or similar client side mvc) * Mobile or responsive dev * Tasty-Pie * D3.js / visualization / charting skills * UI/UX design

Skills Required django python javascript jquery html css design linux ubuntu git mvc mobile

http://www.ziprecruiter.com/job/Senior-Developer/95a5683a/

THREAT STREAM is hiring in NYC http://www.threatstream.com/contact/

We are looking for developers front and back end with chops in:

Python,Django,Flask,ExtJS,MySQL,MongoDB, Bootstrap UI

We are information security company providing actionable threat intelligence to large enterprise and government to put an end to malware and targeted threats.

We are also hiring security analysts if you like researching malware, have a reversing background or attribution the actors behind the threats (osint/linkanalysis/etc)

Contact us if you want to work with some of the smartest talent in the world, and friendly, laid back personalities. We are also located in Meat Packing, NYC next to the Google campus and Chelsea Market (Foodie heaven). Oh and we encourage you to bring your dog to work =)

I was one of the core engineers @ layeredtech who managed the servers and HA for wordpress.com when they launched in 2006.

If I remember correctly we were using DNS round robin and haproxy -> apache -> mysql all on freebsd systems wow have things come a long ways since then also it's incredible the sustained growth of Wordpress after all this time. good memories... congrats Matt on all your success.

I have information this morning from source thats "in the know" that this is definitely a false-flag attack against the FBI.

Non-gov researchers I know also attribute this to a possible hacking of an iphone/ipad application backend DB before Apple put in the UUID storing restrictions to the IOS api.

I'm only bringing this to light because it is easy to fall for things you read on the Internet and get excited/theorize.

If there is brute force protection on the login function blocking a username or IP from attempting x times in y hours AND there is a minimum of 8 characters then I can say thats strong protection on the backend. You are much more vulnerable to having your password phished rather than bruteforced.

Sorry I wasn't implying that the software I used made me a hacker, that is simply just my profession... I use the term very widely to be someone who codes, pentests, reverses malware or jailbreaks iphones...

Most people forget or don't know that Skype was created by the founders of Kazaa and they are hackers (like us) at heart and they built strong encryption into it protecting (actually) the privacy of their users' audio conversations. Skype's encryption has been a heated issue to governments who cannot wiretap Skype for various reasons law enforcement or otherwise.

https://secure.wikimedia.org/wikipedia/en/wiki/Skype_securit...

Ok, maybe not so flippant comment this time...

I thumbs downed the article because as a security professional we try to stress the importance of actual security rather than obscuring the problem for long term success.

Take port knocking for example, interesting idea but what a pain in the ass... just disable root and set a strong password.

Changing the port from 22 will prevent all of the automated botnet driven SSH brute force attacks, which do little more than messy up your log directories.

Best thing you can do is use SSH brute force blocking script which reports attackers back to a webapp which the security community can use to track infected hosts. example: http://danger.rulez.sk/projects/bruteforceblocker/blist.php

Fail2ban is a nice one too as it supports many services including http-auth.

gmartin$ whois -h whois.arin.net 174.132.225.106

OrgName: ThePlanet.com Internet Services, Inc. OrgID: TPCM Address: 315 Capitol Address: Suite 205 City: Houston StateProv: TX PostalCode: 77002 Country: US

Seriously what ericb said, milk the app store and advertise your apps online if you can, keep it going but the investment climate is lame everywhere. I am now in the same situation where I had 30k cash for the first time with no debt and I essentially put it in a safety deposit box at the bank so I won't spend it. If you look at money market, CD's etc, they all stink right now so just lock it up.

If you have not bought a house yet then I would look into doing that and taking advantage of the 8k tax break for first time home buyers. Sounds like you have enough down payment to cover 20% and get out of the PMI insurance.

You might use that money to hire another developer you can train and crank out more apps, and hit the android market as well.

Ok so they use what's called packers to not only obfuscate the malware code to bypass signature based A/V but also hide inside other binaries or Dll's to further evade heuristic defenses. Then a reverse encrypted tunnel for control of infected machine was routed over normal HTTPS also undetectable by IDS. It was to dynamic dns domains such as yahoo1.dyndns.org. Reverse meaning it connects back to the attacker to allow ssh like access to the compromised host via the trojan.

There are all extremely advanced (but known) evasion steps for a very targeted attack. It's rare to see all of them successfully used in one attack because of the complexity and skill required.