HN user

jjguy

1,757 karma

ex-fed hacker turned startup guy. Co-founder & CEO at Sevco Security, previously CTO/COO at JASK, founding team of Carbon Black. San Antonio, TX.

@jjguy jeffrey.guy@gmail.com linkedin.com/in/jjguy

Posts55
Comments148
View on HN
newsletter.pragmaticengineer.com 9mo ago

What caused the large AWS outage?

jjguy
8pts1
securitylabs.datadoghq.com 1y ago

Supply-Chain Firewall: Protecting Developers from Malicious Open Source Packages

jjguy
5pts0
www.sevcosecurity.com 1y ago

iPhone Mirroring at work may expose employees’ personal information

jjguy
58pts73
www.sevcosecurity.com 1y ago

Don't use iPhone Screen Mirroring on a work computer

jjguy
5pts1
www.sodiumhalogen.com 3y ago

Show HN: Cybersecurity Company Jingle Service

jjguy
1pts0
www.bloomberg.com 6y ago

Did a Chinese Hack Kill Canada’s Greatest Tech Company?

jjguy
6pts1
mobile.twitter.com 7y ago

Steven Sinofsky on Apple’s pricing strategy

jjguy
1pts0
trustedidentities.blogs.govdelivery.com 9y ago

Updated NIST 800-63 finalized with new identity and authorization guidelines

jjguy
3pts0
www.carbonblack.com 12y ago

Security startup Carbon Black merging with Bit9

jjguy
1pts0
blog.udacity.com 12y ago

The Design of Everyday Things Online Course Launches

jjguy
2pts0
www.faa.gov 12y ago

FAA to Allow Airlines to Expand Use of Personal Electronics

jjguy
9pts0
www.cnn.com 13y ago

Ex-CIA chief Michael Hayden: What Edward Snowden did

jjguy
7pts2
www.carbonblack.com 13y ago

Show HN: my startup - a "distributed process monitor" for the enterprise

jjguy
2pts0
blogs.technet.com 13y ago

Microsoft Announcing New Bounty Programs

jjguy
6pts2
www.carbonblack.com 13y ago

Blackstone invests in enterprise information security startup Carbon Black

jjguy
1pts0
www.linkedin.com 13y ago

LinkedIn is down; java stack traces

jjguy
1pts0
www.nytimes.com 13y ago

Nate Silver's NCAA Final Four Bracket

jjguy
2pts0
awelonblue.wordpress.com 13y ago

Exponential decay as an alternative to circular buffers

jjguy
2pts0
www.hackersforcharity.org 13y ago

Google Hacking Database from Johnny Long

jjguy
2pts0
blogs.adobe.com 13y ago

Inappropriate Use of Adobe Code Signing Certificate

jjguy
84pts13
krebsonsecurity.com 14y ago

HN's tptacek on how to break into a security job

jjguy
3pts0
www.lightbluetouchpaper.org 14y ago

Ross Anderson: Debunking Cybercrime Myths

jjguy
3pts0
ddtek.biz 14y ago

Remind HN: DEFCON CTF registration closes tomorrow

jjguy
2pts0
www.lightbluetouchpaper.org 14y ago

The quest to replace passwords

jjguy
2pts0
getcarbonblack.com 14y ago

Real world antivirus performance: 30 days with 43 different antivirus products

jjguy
1pts0
aluigi.org 14y ago

Exploit code released for MS12-020, remote pre-auth vuln in RDP

jjguy
1pts0
bathsheba.com 14y ago

Bathsheba Sculpture - art embodied as 3D printed mathematical sculptures

jjguy
4pts0
www.cardozolawreview.com 14y ago

The legal history of "fuck" (2007) [pdf]

jjguy
49pts27
www.seagate.com 14y ago

Forget TrueCrypt, use self-encrypting drives. Gear-level crypto.

jjguy
1pts1
www.guardian.co.uk 15y ago

List of the 100 all-time best non-fiction books

jjguy
3pts0

I didn’t personally know your dad, but like many others here depended on his work with QModem during the late 80s and early 90s. The fact we are all on Hacker News is evidence of how it impacted our lives - and the relevance of the community here.

Thank you for posting - I’ve enjoyed reading the outpouring of history and stories and hope it brings you the same sense of wonder it has me. Godspeed to you and your family.

Similar to all the rest of you HN lurkers, especially the grey beards - thanks for being here and thank for keeping the “hacker” in “hacker news” alive.

Hey look on the bright side. If this is legit, then it will inevitably become a reference in the bill to overhaul the DMCA when it (finally) gets introduced!

The beginning of the end, the moment when thr DMCA jumped the shark (for the broader world, not us tech geeks)

All this, but there is also some negative PR getting funded, presumably by the incumbent car manufacturers threatened by Tesla.

Remember that NYT article came out in 2018 that painted such a terrible picture of Elon (1)? A year later it showed up on my Facebook feed as a paid advertisement. Who pays to promote a year-old news article?

For those of you unfamiliar with the specific challenges IoT patching brings, here is a blog post from just last week on one aspect of the topic: http://tomalrichblog.blogspot.com/2023/08/british-cuisine-de...

FTA:

I assumed that device manufacturers update the software in their device about every month...he said they do it annually.

Those devices are at least _getting_ updates - there is a long tail of devices whose operational lifecycle [far] exceeds the vendor's support timeframe - in other words, they don't get patches at all N months after release.

The solution to these problems is straightforward - we've been managing it in software for a long time. EOL OSes, Long Term Support (LTS) OS releases, etc - but the device manufacturers are not as mature, and have not been making natural progress to do so.

And since this is HN - there is a startup hidden in the midst of all of this: an enterprise-grade IoT OS that "does security right." Sell to the device manufacturers, allow them to market it as "enterprise-ready" or some such. If the FCC guidelines here are approved, there will be a suddenly increased demand!

Ancestry.com is a very well designed product with lots of data and a powerful network effect. I designed a search products for incident response data - also high volume, noisy but highly relational data set - ancestry’s design is very thoughtful.

The monthly subscription carries no commitment and you don’t lose data when not subscribed. So don’t think of it as “$xx per month commitment is so expensive!” But instead as “I’d happily pay $20 this month to support the research I want to do. Next month, we’ll see.” I’ve subscribed / stopped / resubscribed several times over the years as the time I have ebbs and flows.

My view, you are describing the Kindle.

Amazon sees the same potential - and risk - and has been quietly iterating for over a decade in the segment.

If you want to go seriously explore it as a product, I’d start with a deep dive study there and develop a few theories how you think you could be different enough to blow it wide open.

I like your anecdote, I might steal that one.

IANAL, but I negotiate a lot of enterprise SaaS agreements. When considering the SLA, it is important to remember it is a legal document, not an engineering one. It has engineering impact and is up to engineering to satisfy, but the actual contents of it are better considered when wearing your lawyer hat, not your engineering one.

e.g., What you're referring to is related to the limitation of liability clauses and especially "special" or "consequential" damages -- a category of damages that are not 'direct' damages but secondary. [1]

Accepting _any_ liability for special or consequential damages is always a point of negotiation. As a service provider, you always try to avoid it because it is so hard to estimate the magnitude, and thus judge how much insurance coverage you need.

Related, those paragraphs also contain a limitation of liability clause, often at capped at X times annual cost. Doesn't make much sense to sign up a client for $10k per year but accept $10M+ liability exposure for them.

This is just scratching the surface -- tons of color and depth here that is nuanced for every company and situation. It's why you employe attorneys!

1 - https://www.lexisnexis.com/lexis-practical-guidance/the-jour...

I’d recommend joining an existing, early stage startup in the same/similar niche you eventually want to build your own product in. While there, make an effort to network with the non-technical staff.

Not only will you learn a ton about shipping product in a startup (risking someone else’s money), but you will also grow your own network - including non-technical founder types.

This model worked for me. I spent twelve years with the US federal government. I had great tech and business skills, but it was all federally focused.

I joined the founding team of a startup, using my tech background. We got acquired 15 months in by a later stage startup. The resulting company IPO’d four years later. I joined another startup in the same industry as CTO just after their Series A, we got acquired two years later. Then I launched my own - 8 years after leaving the federal government.

It is a ton easier now, with all the relationships from the last two. (Not to mention the depth of knowledge on everything)

It is easy to think startups are all about the product & technology. But it is so much more!

This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models.

This applies to every "connected device:" printers, cell phones, home routers, refrigerators, thermostats -- you name it. Michael DeGusta did a great infographic demonstrating this for Android phones in 2011 [1, 2]. Sadly, this hasn't materially changed in the eight years since. Just this year, Google added new terms to the Android license requiring security patches, but even then only for "popular devices." [3] Imagine those dynamics in the secondary and tertiary markets of printers and refrigerators.

As an industry, we've been to this rodeo before. The advancements we've made in operating system and core applications security over the last 20 years have more about patching speed and agility than shipping fewer bugs. However, those areas have backing and control from Apple and Microsoft, managing the end to end ecosystem. There is not a similarly equipped manufacturer of embedded operating systems with the scale to provide post-sale/post-deployment patching infrastructure.

Since this is Hacker News, I'll point out the enormous opportunity to anyone who can address that problem. Can you provide an "enterprise class embedded OS" to device manufacturers and address post-deployment updates? Can you provide infrastructure device manufacturers can use to manage post-deployment updates themselves? Do you have a better approach to it? There's a burgeoning multi-billion dollar market waiting for a few leaders to take it over.

1 - https://theunderstatement.com/post/11982112928/android-orpha...

2 - img link is broken in his post, the graphic itself: http://media.theunderstatement.com/016a_android_orphans.png

3 - https://www.theverge.com/2018/10/24/18019356/android-securit...

Graph databases are the NoSQL of this half decade. Move cautiously. Just because you conceptualize it in your mental model does not mean you need a graph database. Further, recognize most (all?) implementations are not yet as performant or scalable as traditional data storage solutions.

Design your data schema first, then design your queries and finally your data lifecycle pipeline. Run some estimates on the order of magnitude for inserts, query rates, query types and storage sizes - then compare those numbers to the real-world perf of the various graphdb solutions. In general, compared to more typical solutions, you have more expensive inserts, query costs and storage sizes in exchange for more expressive queries. There aren't many application where those cost tradeoffs make sense.

Source: Twice now (2012 and 2018) I've reviewed available graphdbs for storage of enterprise security data when doing the initial platform technology selection. Both times the team fell back onto more traditional approaches.

I have an unusual food allergy to poultry. I had the same question - seeking deeper understanding so I could better manage my life.

I searched online, had family in the medical research hunt for papers and finally made an appointment with a renowned allergist in DC - I flew there just for the appointment.

I left disappointed. My allergy is too unusual, there is no research available. What I need does not exist. For the common allergies - like kids and nuts - there are plenty.

The net/net from my experience is seek out an allergist, and be very specific in your requests.

No. It is an unreasonable paranoia, to steal kenneth’s words.

In addition to kenneth’s very practical perspective on the technical challenges, the other consideration is that you are simply not worth the trouble.

Grabbing audio, video or picture content worth blackmailing someone with is time-consuming, above and beyond the technical challenge. There is not an at-scale monetization path for an attacker to make it worth his time for the general user.

High-profile folks like Comey and Zuckerburg change that decision calculus - they are likely to be individually targeted for many reasons. You are not.

This is why I continue to hang out on HN. Is there anywhere else on the internet this kind of connection would happen?

For those of you who read this article and believe there may be a thread of a good idea within, go read Neuromancer.

Gibson had a vision of an Internet with decentralized social media, including decentralized code execution, 35 years ago, and we have not yet realized it - or anything remotely close.

This will change with time. I have thought, studied, talked, and written extensively on this general theme. What comes to mind to frame it for you is my "four principles:" [a]

1. Compromise is inevitable 2. Default-allow products always fail 3. 1 and 2 are not opinion or marketing spin, just simple truths 4. As an industry, we are still learning 1 and 2

Security is slowly shifting from an administrative IT function to an operational function. In IT, the business value comes from the products and people are a tax required to administer the products. In security operations, the business value comes from the people, products are just tools in their toolbag. [c]

Keep walking this dog and you realize basic IT activities for core infrastructure are critical for security, to the point the CIO will report to the CISO -- unless the CIO steps up. [b]

So - in short - your frustrations are accurate, but the winds are shifting. Companies will incresingly value top people for their internal staff/blue teams. It's going to take a few more years, but I believe it is inevitable.

[a] - https://www.linkedin.com/pulse/my-four-cybersecurity-princip... [b] - https://www.linkedin.com/pulse/cio-report-ciso-j-j-guy [c] - https://www.linkedin.com/pulse/cio-report-ciso-why-j-j-guy

For many years, I have used "Words of Estimative Probability" - a similar CIA "on writing" piece: https://www.cia.gov/library/center-for-the-study-of-intellig...

Also written in the 60s, it reflects upon their experience with how to convey uncertainty in prose, in a meaningful and consistent manner. Imagine an analyst writing a two pager for the President, who is going to use it to decide go/no go on a covert action. It's a big, ugly and complex situation - with a mixture of highly confident assessments, educated guesses and total speculation. Synthesizing it into something simpler is The Art of Writing; doing so while not losing the anecdotal quantification of uncertainty of the discrete issues is a more unique skill.

If you are in a position where you write about uncertain situations, it's worth the read. I'm a security guy and frequently find myself in that role (think annual risk assessments and estimating the likelihood of a successful attack). It's been a go-to reference for many years to refresh my thinking.

You're giving "the data" too much credit. There are only a few variables:

- new cost

- depreciation per year

- increasing maintenance costs per year

The "F-150" assumption was used to estimate new cost and depreciation over time.

You should not discount the data based on a single model, but it is wise to recognize those three variables can diverge significantly between models - enough to change the outcome.

Assuming by "pretty good hackers" OP means the developers actually doing the work, they are typically GS-12 or GS-13 - so $80k to $120k. GS-14 slots and above are reserved for management and spend much less time doing the real work.

A lot of the teams employ contractors alongside the USG employees, with higher pay ranges.