HN user

hrbrmstr

91 karma

[ my public key: https://keybase.io/hrbrmstr; my proof: https://keybase.io/hrbrmstr/sigs/B4ep-4X35yfgJTMR8QrOZi275cFEnB4u30BaHBFsSjU ]

Posts57
Comments25
View on HN
rud.is 8y ago

A bookdown “Hello World”: 21 (minus 2) Recipes for Mining Twitter with rtweet

hrbrmstr
1pts0
community.rapid7.com 9y ago

The Ransomware Chronicles: A DevOps Survival Guide

hrbrmstr
1pts0
community.rapid7.com 9y ago

On the Recent DSL Modem Vulnerabilities (TR-069 Data, Vis and Metasploit Module)

hrbrmstr
1pts0
community.rapid7.com 9y ago

Election Day: Tracking the Mirai Botnet

hrbrmstr
2pts0
community.rapid7.com 9y ago

[Cloud Security Research] Cross-Cloud Adversary Analytics

hrbrmstr
1pts0
community.rapid7.com 10y ago

The 2016 Verizon DBIR Summary – The Defender's Perspective

hrbrmstr
1pts0
rud.is 10y ago

Using R to make Vega-Lite Visualizations

hrbrmstr
3pts0
medium.com 10y ago

Don’t Wait for the Cuyahoga to Burn Again

hrbrmstr
1pts0
datadrivensecurity.info 11y ago

Five Critical Points to Consider When Hiring a Data Scientist

hrbrmstr
2pts0
rud.is 11y ago

Making streamgraphs in R

hrbrmstr
2pts0
datadrivensecurity.info 11y ago

Mapping IPv4 Address (with Hilbert curves) in R

hrbrmstr
1pts0
securityblog.verizonenterprise.com 11y ago

The 2014 [In]Security Hall of Fame

hrbrmstr
1pts0
datadrivensecurity.info 11y ago

Building a DGA Classifer: Feature Engineering (i.e. “finding bad domains”)

hrbrmstr
1pts0
datadrivensecurity.info 12y ago

Reproducible Security Domain Research With Sucuri Darkleech Data

hrbrmstr
1pts0
datadrivensecurity.info 12y ago

Ripal – Password Dump Analysis in R

hrbrmstr
1pts0
datadrivensecurity.info 12y ago

An Example Of Using Shiny For Interactive Security Data Analysis

hrbrmstr
1pts0
datadrivensecurity.info 12y ago

Inspecting Internet Traffic: Part 1

hrbrmstr
1pts0
datadrivensecurity.info 12y ago

The Data Science Love Child of Doom (rPython / rpy2)

hrbrmstr
2pts0
datadrivensecurity.info 12y ago

The Timing of Cyber Conflict

hrbrmstr
1pts0
datadrivensecurity.info 12y ago

Data exploration of a publicly available malware dataset in R

hrbrmstr
2pts0
rud.is 12y ago

Live Maine Power Outage Maps in D3 (County & Town)

hrbrmstr
2pts0
rud.is 12y ago

Visualizing “ObamaCare-related” Job Cuts

hrbrmstr
8pts1
rud.is 12y ago

Rforecastio – Simple R Package To Access forecast.io Weather Data

hrbrmstr
3pts0
rud.is 12y ago

ZeroAccess Bots Desperately Seeking Freedom (Visualization)

hrbrmstr
2pts0
rud.is 13y ago

Security Hobos

hrbrmstr
3pts0
rud.is 13y ago

SHODAN API in R (With Examples)

hrbrmstr
2pts0
rud.is 13y ago

Easier HTML Table-scraping For Scripts With Google Drive

hrbrmstr
1pts0
beechplane.wordpress.com 13y ago

The [95%] Confidence of Nate Silver

hrbrmstr
2pts0
rud.is 13y ago

Watching Sandy in 'R'

hrbrmstr
3pts0
rud.is 13y ago

Get an R Data Frame from a MongoDB Query

hrbrmstr
3pts0

Well, when you force users to login at least 1/month to keep their handle/account, you're 100% going to get an inorganic and non-truthful MAU metric, especially if you define that "A" to be <=20 seconds.

I realize the study was unable to or just did not perform “follow-ups” with the individuals they are positing “no longer work”. But, what exactly are these malcontents doing instead, then?

Living with parents? (Why would a parent enable this juvenile behavior)?

Relying on their spouse's income to survive (and, if so, is there any real harm/issue with this)?

Going “off the books” and just being part of the underground economy (in which case, this 'not working' posit is partly a falsehood).

Even woefully entitled dudes have to eat, no?

That particular page appears to have been created with "Unbounce" (https://preview.unbounce.com/) (the "lp-*" strings give that away). If you look for said "lp-" strings on the web there are more than a few pages using them. Unbounce is primarily designed for creating HTML email that won't break and won't get auto-rejected and it's likely easier for the builder program to stick in hardcoded values in-tag than to rely on complex CSS, especially with the varied capabilities of mail clients.

Yep. If you move around in google faster than "normal" humans it's flagging that behaviour more lately. I suspect some malicious (i.e. made by content thieves) web scraping instrumentation frameworks have added more natural human behaviours to their capabilities but still operate at a higher-than-"normal human" rate and those of us who are highly adept at legitimately utilizing google now fit into that new classifier slot. It's been super annoying.

Properly constructed information security questionnaires enable a business partner to conduct a high-level, non-intrusive assessment of your organization. You have a right to be concerned about the sensitivity of the data, but if you distrust your business partner that much, then don't do business with them. Your org is not a special snowflake and this is a very common practice by organizations of all shapes and sizes with organizations of all shapes and sizes. They are not the be-all/end-all of information sources (orgs regularly fib on these forms) and you do have a similar right to ask the inquisitors how they will protect your form data (that will also partoy show them you at least give lip-service to data security). It's also far more likely that your organization is going to get pwnd via phishing that is completely unrelated to the potential loss of confidentiality of this document. I say that as someone who has formally studied cybersecurity breaches for years.

Also, as cyberinsurance increasingly becomes "a thing", you're going to see this questionnaire situation increase in frequency. Your org should consider creating a pre-composed (and regularly updated) SSAE 16 (https://en.wikipedia.org/wiki/SSAE_16) to avoid having to fill out unique assessment questionnaires for every request that comes in. It'll save you time and — unless you "go N/A crazy" on the SSAE 16 — should be accepted by any firm worth doing business with.

Congrats to the team for launching something in 2018 on macOS without it being signed! Great way to encourage good security & safety practices for data folks on macOS! Signing is super hard, too. Totally not baked in to any workflows.

Rather than emoticon-ing away your responsibility in a potential site DoS, perhaps read up on responsible crawling - https://webarchive.jira.com/wiki/display/Heritrix/Responsibl... + http://blog.mischel.com/2011/12/20/writing-a-web-crawler-pol... . You had no need for either unlimited or even 50 parallel crawl tasks. And, if your intent is anything but personal use, you shld prbly (re)read https://www.brewtoad.com/legal since you just got their attention in a pretty big way.

From the methods outlined in the thread so far, I think I'd pick Akamai after a quick test of each of them. (results in the following are based on the 'real' value returned in a 'time' command

  Google 'ping' "baseline" from my ISP
     20 packets transmitted, 20 packets received, 0.0% packet loss
     round-trip min/avg/max/stddev = 19.858/23.823/31.484/2.593 ms

  #/SITE/METHOD
  #1: myip.opendns.com (dig)
  #2: whatismyip.akamai.com (curl)
  #3: ifconfig.me (curl)
  #4: ip.nux.ro (curl)
  #5: icanhazip.com (curl)

  RESULTS

  #1      #2      #3      #4      #5
  0.051   0.144   3.45    0.24    0.333   
  0.05    0.143   7.229   0.237   0.106   
  0.053   0.147   1.986   0.246   0.103   
  0.047   0.143   7.065   0.246   0.109   
  0.045   0.145   2.15    0.257   0.102   
  0.046   0.141   4.301   0.273   0.113   
  0.05    0.141   2.763   0.242   0.103   
  0.048   0.144   3.685   0.251   0.114   
  0.045   0.149   15.312  0.256   0.195   
  0.047   0.148   5.091   0.244   0.118   
  0.044   0.144   2.637   0.248   0.133   
  5.038   0.142   1.535   0.247   0.109   
  0.049   0.143   7.065   0.238   0.115   
  0.044   0.146   4.098   0.241   0.106   
  0.05    0.145   1.665   0.248   0.216   
  0.05    0.142   1.365   0.261   0.108   
  0.051   0.143   2.509   0.256   0.159   
  0.046   0.17    5.323   0.245   0.109   
  0.044   0.141   83.252  0.246   0.117   
  0.05    0.145   1.435   0.242   0.119

  0.048   0.144   3.685   0.246   0.113 MEDIAN
  0.310   0.145   8.551   0.248   0.135 AVERAGE
  1.144   0.006   18.377  0.008   0.057 STDEV
Data protection 14 years ago

For #1, I would suggest that your application/API will be the weaker link in the security/privacy chain. While it's possible that you could have Heroku or EC2 admins do "bad things" or have "unruly neighbors", it's far more likely you'll introduce flaws via insecure coding practices or by using insecure libraries. If you rely on solid data encryption (at rest and in transit) practices and make the effort to secure credentials properly, you should be fine in either setup. I'd make the dedicated VPS vs "cloud" setup based upon need for scalability/etc vs security. You should be able to secure a "cloud" config to your needs.

For #2 – since it seems you're in more a 'privacy' realm than a 'compliance' realm, it may be worth the time to peruse the White House's framework – http://www.whitehouse.gov/sites/default/files/privacy-final.... – from this past Feb (which has links/refs/comparisons-across privacy standards) and then the CSA's Cloud Controls Matrix : https://cloudsecurityalliance.org/research/ccm/ : or the whole CSA GRC stack : https://cloudsecurityalliance.org/research/grc-stack/ : which should help you assess which provider/service is right.

The prescriptive controls in PCI can help you design your data access & handling strategy, but you have to remember that PCI is highly focused on protecting a sixteen digit number and you'll need to determine what your critical data components are from a privacy perspective to effectively map against PCI or other control frameworks.

What UPS knows 14 years ago

As others have pointed out, they use an identify verification service. In most cases, any org that uses such a service doesn't even see the data the form is asking for (i.e. it's just a pass thru, much like CC# forms in IFRAMEs).

Granted, it is scary what is aggregated about you and stored in some giant data warehouse somewhere (prbly not protected very well). But I'd rather an org use a third-party such as this vs begin to aggregate similar data on their own.

However, think about what else UPS knows about you (without this data). They have your name, address, phone and know precisely (for all things they handle) how often you receive shipments from where, how much they weigh and potentially other data (depending on whether they've done any scanning or if there is any hazardous or perishable labeling on it). If they've ever tried to deliver and needed a sig and you weren't there, they have a record of when you're not home as well.

I wonder if they (or FedEx, et al) have a policy whereby you can request all the data they have stored on you like this…

Growl, meet Bark. 14 years ago

I think it is indeed "just" a stop-gap but is also more of an alternative for folks who want to keep with the non-gate-kept ecosystem. The concept of Bark is cool, but I'm not keen on running code that injects at the level it does without it being open source and something I can inspect/build on my own.

Growl, meet Bark. 14 years ago

It does code injection and is different primarily in that all Growl notifications show up as "Hiss" notifications in ML NC vs being unique sections that you an select and go to the app context with.

I've worked and consulted in over 15 very large enterprises. While it may not constitute a survey of the entire Fortune 500+, I've come into contact with enough business & IT professionals to know that is is - in fact - not a well-received feature. It's used by either underperforming folks as a CYA measure or other folks who have side-swiped by self-serving individuals.

There is no legitimate use or business-case for a read-receipt service, especially ones that use the same techniques as malware writers.

I fully support your third-party "who responded to me?" reporting & reminder tool, as I can see that being incredibly useful - especially to those who are not adept at scripting and/or using mailer APIs.

I'm with dpcan on this one. I started my current 10yo on Scratch at 8 and have been giving him incremental "challenges". The immediate feedback for even his first "program" was enough to keep him hooked. He regularly keeps making new games and often pushing the system to its limits (Scratch has many annoying limitations if you're a seasoned programmer or even a kid who has figured out that something like an array - he wouldn't use that word, tho - would be useful).

He started 5th grade last week and one of his classes is a programming class which uses MicroWorlds - http://www.microworlds.com/ - as the learning platform. I grabbed the demo and may shell out the $100 for the home version, just so he can do stuff here in it as well. It's not a horrible system, but it's definitely rough around the edges.

I fully expect to have him starting in Python by 6th grade, tho.