HN user

jenandre

433 karma

Software developer, with occasional opinions.

http://jenpire.com

Posts36
Comments51
View on HN
seekmaro.com 1y ago

Building an AI Code Review Agent with Claude Code

jenandre
4pts0
www.reverbadvisors.com 8y ago

How venture capitalists make money and why it matters to you

jenandre
8pts0
medium.com 9y ago

When it comes to debugging, believe no one

jenandre
2pts0
komunity.komand.com 10y ago

Introduction to Sysdig Falco

jenandre
3pts0
komunity.komand.com 10y ago

GDB for fun and profit

jenandre
1pts0
komunity.komand.com 10y ago

Introduction to Osquery for Threat Detection and DFIR

jenandre
2pts0
medium.com 10y ago

My Experience with Linux of the 90s, or Why I Have Linux Desktop PTSD

jenandre
2pts0
cortlandtjohnson.com 10y ago

The West Coast Offense for Startups

jenandre
2pts0
github.com 10y ago

RPC over Docker containers as plugins

jenandre
2pts0
cortlandtjohnson.com 10y ago

Keys to Building a Successful Cybersecurity Startup: Credibility,Maturity&Trust

jenandre
1pts0
github.com 10y ago

Show HN: Codetainer – A Docker container in your browser

jenandre
42pts9
github.com 10y ago

Show HN: Codetainer – A Docker container in your browser

jenandre
4pts0
github.com 10y ago

Safe-commit-hook: prevent developers from checking in sensitive files

jenandre
42pts8
www.linkedin.com 10y ago

Pitching Your Cybersecurity Startup: Do’s and Don'ts

jenandre
2pts0
securityhq.io 10y ago

Hacker news for security

jenandre
3pts0
dockersecurity.org 11y ago

What's all the hubbub about vulnerable Docker images?

jenandre
1pts0
medium.com 11y ago

After all this time, we still can’t crypto

jenandre
2pts0
blog.threatstack.com 11y ago

Who Watches the Watchmen? Securing Configuration Management Systems

jenandre
1pts0
blog.threatstack.com 11y ago

The Linux “Grinch” Vulnerability: Separating Fact from FUD

jenandre
2pts0
medium.com 11y ago

Hackers or Engineers? Who to hire for your startup, and why

jenandre
1pts0
blog.threatstack.com 11y ago

A Tale of Nagios and the Bash Vulnerability

jenandre
5pts0
medium.com 12y ago

Docker breakout exploit analysis

jenandre
16pts2
medium.com 12y ago

Startups, Security, and Noble Vision

jenandre
1pts0
boingboing.net 12y ago

Dune is in your head

jenandre
2pts0
medium.com 12y ago

Free startup idea: fix micropayments for content

jenandre
1pts0
medium.com 12y ago

Opening files in node.js considered harmful

jenandre
3pts0
gist.github.com 12y ago

One Day of Go

jenandre
4pts0
medium.com 12y ago

"Yt? Seeing something odd in the logs..."

jenandre
2pts0
medium.com 12y ago

Cloud Security is not a binary question

jenandre
2pts0
gist.github.com 12y ago

Setting up a Kernel Debug Environment (for pussies)

jenandre
1pts0

Komand (ONSITE Boston, US)

What: We are building a cybersecurity automation platform (IFTTT for security). We have an awesome, technically savvy team that has built multiple products and companies in the infosec space. Work with Go, Docker, and React to build a modern platform for security teams. PS: we're also fun. We routinely make breakfast together in the office, we're a diverse team across a wide age range + genders.

Culture: Team players, world class talent, no brilliant assholes. We have a culture of ownership + responsibility. We are all experienced devs and have great tooling/process even for a company so young.

Jobs: https://angel.co/komand/jobs. We're hiring primarily software engineers. Security background not required, but an interest helps.

Interview Process: We have a very collaborative interview process. We are looking to measure skills, not whiteboard ability. First, after an initial phone call, do a coding exercise offline and then come meet the team and pair with us.

Want to learn more? http://www.komand.com, jobs@komand.com

"Imagine doing lots of small allocations - you can cause a lot of fragmentation resulting in needlessly having to resize your heap which in dire scenarios can result in thrashing."

The article repeatedly talks about how managing memory manually increases the risk of fragmentation. And that this risk somehow goes away with gc managed heaps.

...so garbage collectors don't also have to manage their own internal heaps and have fragmentation issues? Hm, not sure I buy this.

Are there seriously investors that only back purely female teams? That seems ridiculously sexist and financially stupid to eliminate so many good startups that aren't all female.

I meant this to mean they have invested in all-female founding teams, not JUST all female teams. I have edited it to hopefully reflect that better.

Regarding your second point: I don't think the author's goal was purely to stop sexism in VC. She was describing her own experience. It's not a waste of time to educate people about the poor behaviors you see, regardless of whether or not she has a solution for it.

I sympathize with you, having also experienced subtle sexism in both the tech and investment world (I'm a technical co-founder, and I've fundraised successfully). Here's a couple of points I hope are helpful.

- You should look to connect with partners at firms that have female founders (ideally purely female-founding teams) among their portfolio. There are also a few female partners out there as well -- get access to them, with your YC network it should not be hard. Listen hard and press them to get honest, specific feedback when given "no"s.

- While the sexism is unfortunate and it's hard not to get frustrated, you may want to look long and hard at your pitch and company. If you've really talked to 40 investors and sent out ~500 emails, and this is a hot space for disruption, it's very unlikely that all of them are dismissing you due to gender; something isn't connecting. I's very easy to dismiss all feedback ("their feedback means nothing; they are rejecting me because I am a woman") just because you are soured by your bad sexist experiences.

Ask yourself these questions honestly: Are investors giving the same criticisms and feedback for saying no? Are there questions you struggle with in the pitch about your business? Is the value prop clear? Is the product demo well orchestrated? Try to examine all of the feedback you've gotten objectively, and see how can you improve the pitch. Find someone who is ideally involved in the venture community (e.g. as a partner, associate, EIR) that you can trust, that can give you brutally honest feedback on your pitch and business.

- Fundraising is hard for everyone. It's going to be harder for you. It sucks, but that's the truth of life. You are one of those pioneering women who are paving the path for others so hopefully in 20-30 years, it's not even an issue. It would be great if you didn't have to deal with this, but that's not the reality of the world. What doesn't kill your company will make you AND your company stronger.

IMO as long as the research in these tools are being funded by corporate entities (e.g., Microsoft) then there's little hope of any open research.

Fortunately, there's money to be had for open source and research projects that are willing to organize and look elsewhere for some cash. Look at projects like Bro and Suricata -- commercial security tools which are government and educator funded.

not true if they are taking on money. any investor will require a vesting period over 4 yr w/ usually a 1 yr cliff (which resets every time you take money)

It's missing some key features (Generics anyone?) that put it somewhere in terms of usability between C and Java, and it has nowhere near the same tooling or performance characteristics as the JVM. So, it has a while to go yet I think but would love to see a serious JVM competitor here.

What I Didn't Say 13 years ago

I would be interested in the stats of 'successful' startup investments (for YC and otherwise), how many of those technical founders actually started programming at age ~13 (vs 17 or 18).

Would also be interested in seeing what the relative success/failures of investments with startup founders at 23 w/ 10 years experience (started programming in teams), vs 28 (who started programming at 18).

+1. If you want threads, build a node c++ addon that manages your threads/high performance work (and try not to pass too much back and forth with your Javascript, because of the performance overhead of marshaling described above). Which means you are just writing a lot of C++, and your javascript simply becomes a convenient interface to start/stop the processing and script actions on values emitted from your c++ addon.

Or, like everyone else recommends: use processes and ipc (e.g., the cluster module).

What library is missing the symbols? You may be able to tell by the stack trace. You should get symbols for something at least before it's lost. Examine that frame to see what it's doing. Linking some non-debug library w/ a debug executable just means that gdb won't display the symbols when it enters code for that library. But if your addons are built with -g you'll get the symbols for the addon before it starts calling the other library it is using.

Btw, people often write javascript wrappers that manually refer to the build/Release/.node version instead of the debug version (which will get added to build/Debug/.node). Check that first.

Even if you are using dynamically linked libraries (like the zmq addon does), you can always build debug versions of those to get all of the symbols (try CFLAGS=-g when ./configure).

Crashes (that can be reliably reproduced) should be way easier to debug than memory leaks.

a) build a `debug` version of node (building node from source creates a node_g version which is a debug version)

b) build a `debug` version of all of the c++ addons in your node_modules folder (node-gyp build -d for each addon)

c) start gdb with the debug version of node: `gdb ./node_g`

d) in gdb, run your node script using `run <script.js>` -- add any other options

e) wait for it to crash, and then type `bt` - you'll see the location of the crash which should give you a good starting place.

I don't know, plenty of cities are flat.. NYC is mostly flat?

Biking in .nl was actually quite arduous for me the few times I've been. One word: wind. No mountains or anything to break it, it's like being on an endless hill. I did a few short out of town trips (<15km) and I highly underestimated how long it would take because of the wind...

"Exploiting an unknowable amount of users of a service as to hunt them. Using illegally harvested data from botnets, while others get hunted and prosecuted for coding them. This tiered society where the legally immune can profit off acts that get others jailed."

Not that I disagree with this sentiment, but how is this different from the fact the government is "legally immune" from using/possessing weapons and firearms that the average person can't possess or use?

I use supervisor with all of my node.js deployments... It seems straightforward for me just to drop a new .conf script in, it's agnostic to what code it's starting/monitoring (I use it with ruby as well) so I'm confused as to what problems have you had using it with node?

That said, this looks pretty cool, I'm going to try it out.

Yeah, my point is, we don't really know what the scope is -- we have Snowden's word and some slides that mention direct access to servers. But the engineers who worked at the companies and performed the integrations know and probably have evidence if it was just standing up a box they scp'd data to manually upon request, or a more elaborate automated system. If some of those people would step forward with evidence, we could could confirm or refute Snowden's claims.

I would find it really interesting if some employees at companies like Google, Microsoft, etc would come forward and corroborate Snowden's claims as well. At some point, SOME engineering work was involved on their side to make it happen, and there is likely documentation. I would love to see design documentation on how the collection systems work so we can confirm exactly the government has automated access to.