HN user

huntsman

208 karma

Shane Huntley @shanehuntley Director, Google Threat Analysis Group

Posts0
Comments28
View on HN
No posts found.

The vacancy rate of offices looks low because the big tech companies are still "occupying" them, but if go into many of them and they still look like ghost towns. Much more that offices in other locations.

This feels unsustainable.

In this case we only obtained a Chrome exploit.

Whether that means they didn’t have exploits for other platforms as part of this attack or that we just didn’t succeed in determining them is unknown.

TAG has certainly found and reported exploits in other platforms many times so it is not a matter of not caring.

Source: I am lead of TAG at Google

I think you’ll find TAG regularly gives assessment on attribution at least at the country level. Iran, China, Russia, Belarus and North Korea at least have been named in the last few years.

(Disclaimer: I am head of TAG)

I've found that the most useful discussions I've had are around how the people up the ladder think about the junior persons area/projects and how it fits into the bigger picture.

The junior person knows more about the details and the senior person should understand more about the strategy so both have a chance to learn from each other and to each walk away with a better overall perspective.

As a skip level manager myself it's also seems like a better use of everyones time than me answering generic questions.

Ghidra 9.2 6 years ago

I'd also highly recommend the training course slides that are included in the Ghidra distribution. The "Advanced" course especially covers some cool tricks and ways Ghidra is different from IDA/Binary Ninja.

You'd be surprised. I've seen a number of times where new managers used to just being one of the team don't realize that joking about performance, compensation or someone's job takes on a very different tone when they have some actual or perceived power over these things.

Are reviews of managers by employees that uncommon? At Google every manager is reviewed by a survey of their direct reports every performance cycle and that certainly feeds into assessment of manager performance.

My point is that being first to name a number isn't necessarily "giving away" your leverage. If you give too low a number you certainly may be, but naming a number could also Anchor (https://en.wikipedia.org/wiki/Anchoring) the negotiation at a higher point.

Lets say you've done your research and you know the company pays $160k-$200k for this position and you've done interviews and they want to hire you.

They want a number from you of expectations.

Sure, saying $160k is dumb and you've lost out. Refusing to say anything might get you $180k.

But if you are confident in your knowledge of the ranges putting out $240k as your starting number may be a good strategy. Sure if you got it wrong they might have offered you more but unlikely. But more likely the recruiter is now in the position to try and negotiate you down to their salary range vs you having to negotiate them up.

All of this is somewhat situation dependent but my point is that absolutist advice on never be the first to name a number is not always correct.

I feel this hard rule of never mentioning a salary as candidate is too simplistic.

There's certainly the risk of lowballing yourself if you don't understand your market worth but there's also the opportunity to anchor the starting point of the negotiation.

Learning the strategies for successful negotiations is a skill a recommend everyone to look into. Skills in this area can have a very high payoff in your professional and personal life.

It's a range of factors. Basically this warning means that what we detected ties in some way to wider activity that looks government backed. There's some border cases, but in practice the targeted campaigns of governments look very different in both technique, volume and targeting to say a widespread cybercrime phishing campaign. It's not a perfect science, but we believe its worth calling out separately the activity that does fall into this bucket.

My team at Google is responsible for identifying the users we give these warnings to. Here's what I wrote last year to provide a bit more context: https://security.googleblog.com/2017/03/reassuring-our-users...

The most important point is that this indicates signs of targeting not compromise. Also,like all systems there are false positives especially for security researchers and the similar types but we hope it is a useful indicator to reassess your security posture.

There's many other warnings and notifications that Google gives users about phishing and hijacking attempts. This specific warning is exposing the fact that we think someone is being targeted by a government backed attacker. We believe this is information that could be useful for some people and that we shouldn't keep this to ourselves.

At one stage I suspected I was in charge of the oldest in use computer still running in the world.

In 2001, the Australian Navy still used the Mk152 computer. https://en.wikipedia.org/wiki/UNIVAC_418 on the last remaining Charles F Adams class destroyer, HMAS BRISBANE.

It was a general purpose computer entirely constructed from individual transistors with magnetic core memory. We had two of these onboard and if both were down we couldn't fire the missile system. I had 3 sailors dedicates solely to keeping these ancient machines running.

We got to diagnose some pretty cool bugs, like what happens when the card corresponding the the lowest significant bit of the least use register has an intermittent fault due to a bad mechanical connection.

We (Google) have tried to find the balance with this since day one back in 2012 "If you see this warning it does not necessarily mean that your account has been hijacked. It just means that we believe you may be a target, of phishing or malware for example".

The aim is to give the users useful information that they may be targeted without totally compromising the detections and protections we have in place. It seems whatever a company says they are either going to be accused of being too vague or making statements that can't be proven.

At Google when we have done these alerts we have not discriminated by country. The alerts only cover what we see with phishing and malware targeting by what we believe is nation state activity and has nothing to do with law enforcement requests or other legal processes.

Yes, applying for permanent residence with an E-3 visa is possible and not prohibited by dual intent. I successfully did this and there were no problems.