HN user

jrozner

52 karma

CEO and Founder of Based Security (https://www.basedsec.io)

GitHub https://www.github.com/jrozner Twitter @jrozner

Posts10
Comments32
View on HN

Most people only do the simplest of math on a day to day basis. I’d bet that if you asked most adults to do something even remotely non-trivial (addition, subtraction, multiplication) a lot would have trouble without a calculator and/or make a large number of mistakes. That’s probably fine because it’s unlikely most adults are all of a sudden going to have to do non-trivial math without a calculator. That probably isn’t the case for people who are having agents do effectively everything for them in their lives

This seems really cool with very underwhelming specs. They maybe enough for people just getting started, especially at that price point. I think if there are lots of ready to go projects and easily purchasable kits for parts this could be a really great intro for cheap

People hated steam when it launched but you needed it to play CS 1.6. It made installing mods easier. Then HL2 released, orange box, and they were able to get a critical mass as they provided platforms support for other games. Steam got better. It’s still not great but they have so much market share that basically any PC gamer already has it. Epic wants some of that money. The problem is nobody wants to install another store and they aren’t doing anything to improve gamer’s experience other than giving away games and having some exclusives. They’ll never hit the critical mass needed that way.

Fleet was a terrible product. I’m a long time jetbrains user and still use goland, rust rover, and clion. I was really excited when it got announced because I had had a lot of issues with vs code, extensions, and lsp at the time. I was hoping jetbrains was going to build something competitive but it never materialized. Rather than building something lightweight and fast on a native ui toolkit with faster analysis engines they basically built on top of a lot of the tech that was the bad parts of their existing IDEs. important features and the ability for community extensions to fill them never came to fleet which meant it never could replace other tools for real work and jetbrains seemed to focus on building LLM features to capture the hype rather than fixing the issues people have with their existing products. Instead they have mediocre ai features that are essentially commoditized and IDEs that are under invested in that are sluggish. In terms of full batteries included IDEs they’re still probably the best, but they’re losing a lot of the market.

Up or out generally stops once someone reaches engineer or sr engineer. Most of the time a jr engineer is going to need substantial mentoring and support. Them never moving beyond that point likely results in a net negative gain if you need another person always available to provide that for their entire time there if it goes beyond 1-2 years.

Unless he’s getting into a truly top tier school, have him go to a state university for much less. Community college and transferring is also an option but the social experience of going to a 4 year university is unique and fun. If you have something local where he can live at home or work enough while in school to cover part of the expenses, great. Spend $30-40k instead. I went to a fine state school in California and have talked to a lot of CS grads. I’ve rarely seen significant value add for paying more for a mid tier school than whatever the cheaper average option is.

For the most part, everything in your last point is something you can’t solve with an app. Virtually all of that would be problematic meeting someone in any other way and for the most part is all within your control to change. Sure, there are limits to what you can do about conventional attractiveness but there is a lot within your control for most people. Most of those issues you brought up are things that the vast majority of people don’t want in a partner no matter how you meet them. If you like those attributes about yourself you might eventually find someone compatible but if you don’t, most/all of those are things you can address by going to therapy and working on it.

We’re leveraging ssh certificates which are backed by keys stored in a variety of hardware. For yubikeys we’re leveraging piv and the standard ssh tooling. We’re determining whether we’ll be able to use a pkcs11 implementation for TPMs and Secure Enclave or whether we’ll need to build a custom agent.

Building Based Security (https://www.basedsec.io), a startup in the zero trust/identity space creating immovable, attestable, hardware backed identities that can be used for strong and continuous authentication but not moved from the device. We can guarantee the user and the device are known, the user is assigned the device they are using, and characteristics of the identity matches the defined policy. The initial product offering is tied to GitHub/GitLab, offering secure authentication for git over ssh operations with plans to expand to general ssh access and additional systems with pluggable access control.

I can understand the concern about having a second trusted party but think that the value of utilizing the standard ssh ca auth flow is worth the potential risk. If you require keys in attested hardware and verify that before issuing certs, the actual attack becomes very difficult. You need to compromise the actual hardware or compromise the CA in a pretty substantial way to issue certs to untrusted private keys. The certificate alone doesn't actually do anything without the key. In addition to just being supported out of the box, we can also issue hardware bound host keys, which allow us to offer bi-directional verification. We gain the benefit of all the standard PKI tooling (eg. revocation lists, ACME, etc.) and can use the same PKI for other scenarios (eg. mTLS, piv, etc.) by issuing x509 certificates instead. That's our long term plan is moving past ssh auth and having it be an attestable, immovable, hardware backed identity that can be usable for continuous authentication in other areas.

I have looked into OpenPubKey briefly in the past but haven't spent a ton of time with it. We were going in a very different direction and it didn't seem particularly useful based on our goals or what we wanted to achieve.

edit: Looking at the documentation https://docs.bastionzero.com/openpubkey-ssh/openpubkey-ssh/i... It seems like to use OpenPubKey you also need a fairly modern version of OpenSSH. It also requires that the user authenticating have sudo access on the machine, which doesn't sound great. It's not clear to me whether it's possible for the existing authorized_keys file to co-exist or whether that's just to stop access using existing keys but using the standard ssh certs will co-exist allowing for a non-binary rollout if there are use cases that need to be worked around.

I think it's interesting they're choosing to use certificates this way. If they're already using certs, why not just leverage sshca auth? Also, at the end of the day, it's still effectively a bearer token. I founded a company called Based Security last year in this space. We're looking for design partners currently. We host a CA for you (or you can host yourself if you want) and use ssh certificates and bind the user identity (oidc to the IdP) to a physical device (yubikey, secure enclave, tpm, etc.) This ensures that the user is both in possession of the physical device and that the credential can't be stolen without stealing the device, unlike the bearer token examples here. Currently we're offering support for GitHub and GitLab authentication but it works out of the box with standard ssh tooling as well. It just currently requires manually handling user provisioning for standard ssh access.

I agree that personal responsibility is important and both things can be true. I also think anyone who believes our taxes are going to go down if we don’t bail students out is delusional. With that belief, I’d rather my taxes directly improve the lives of tens of thousands of people than funnel more money into defense contractors, poorly run construction companies that can’t build infrastructure, and other already wealthy people’s pockets who aren’t actually returning what I think is enough value to the country for what we’re paying.

After reading the policy when the blog post came out, I think one negative thing about it is that it can self select for people generally later in their career or with a much bigger safety net. When you have a 10-20+ tech career and the money saved up, like the founders and many of the early employees, it can be much easier to say that’s enough to cover expenses. I have nothing against it as a policy and I think there are definitely benefits to it. I just think that the biases aren’t clearly talked about either.

I applied almost two years ago. I am excited about what Oxide is doing and it felt like a fun opportunity. While I respect what they do around comp, for where I was in my life and goals I had set, it was going to be rough. I applied anyway at the encouragement of a friend who worked there. I think the packet process is awful. So much unnecessary work and frankly by the end I just sort of phoned it in because I lost interest. It took about two months to hear back (I applied in December 2021 and heard back February 2022) and get rejected and got nothing more than a generic form rejection letter after all the time spent on preparing the packet.

———

We are so humbled by your application to join Oxide Computer Company. At this stage of the company we are hyper-focused on certain areas of the stack and when we need specific domain space experience such as yours, please engage with us. Our roles will be updated as we need them.

We are grateful you took the time to apply and put so much thought into the candidate materials, we loved reading them. We would absolutely love to work with you in the future and cannot wait for that stage of the company!

All the best, The Oxide Team

When using a resident/discoverable credential the authenticator is supposed to authenticate the user (using a pin, biometrics, etc.) This fulfills the multi-factor requirement. All passkeys/webauthn credentials are something you have and you can use a something to know/something to are to unlock the credential stored on the authenticator.

I have a similar experience (effectively failed out of CS and ended up with an BA in philosophy + minor in CS). For me it was the math courses more than anything else, I wasn’t interested, and preferred to spend my time snowboarding and partying. Did a bunch of hackathons and landed a handful of software engineering jobs and startups in quick succession trying to figure out what I wanted to do.

I didn’t have your visa situation and don’t know your financial situation. If you have the flexibility I’d recommend figuring out the things you would like to learn, find a startup (or company) that’s willing to hire you and spend time getting good at it on the clock. It worked well for me. I had pretty bad work life balance at the time, didn’t make anywhere as much money as I could have had I grinded out FAANG interviews but I don’t regret my path.

I’d caution against going and getting an advanced degree unless you really have no idea what you want and feel like that’s the only way you’ll get enough expose to different stuff to figure that out. I truthfully don’t think getting the degree will make a difference if you are a decent engineer and willing to put the work in. It just takes up more time getting you real world experience and takes more money.

FWIW I have little to no regrets about my path. It would have been nice to have made more money and I definitely have some gaps in my CS education but honestly, I loved my Philosophy program and had a blast in college. I have great relationships and friends I made there and am now in my mid 30s with a successful career that I’m really happy with on track to retire in my 40s-50s if I want.

My original option grant was for 0.00225%. I optimized for salary when I was hired, due to the stock at my previous two startups being worthless, and didn’t fight for more. Between series A and B we were going through some rough times as a company and I was granted a second grant of the same number of shares but not sure what the percentage turned into.

The current company I’m at just sold about a month ago for $140mil. I was one of the first engineers (the three of us originals all started at the same time) and started a few months after initial funding was raised. Between my purchased options and non-purchased vested options I made about $130k and have another about $40k in remaining options that are converting over. I was kept on by the acquiring company and given a new company package with about $40k of additional RSUs that vest over 4 years.

Prevoty | Software Engineer | Los Angeles/San Francisco | Fulltime

Prevoty is a Runtime Application Self Protection company founded in 2013 that builds language plugins to provide mitigation to security vulnerabilities without the need for modifications to applications. The plugins utilize instrumentation and middleware to automatically insert hooks into applications that perform detection and mitigation of common vulnerability classes such as many of those listed in the OWASP Top 10.

Open Roles

Senior Software Engineer (Java/JVM)

Software Engineer (Java)

Software Engineer (QA/Test/Automation)

Apply here https://www.prevoty.com/about/careers

Prevoty | Software Engineer | Los Angeles/San Francisco | Fulltime

Prevoty is a Runtime Application Self Protection company founded in 2013 that builds language plugins to provide mitigation to security vulnerabilities without the need for modifications to applications. The plugins utilize instrumentation and middleware to automatically insert hooks into applications that perform detection and mitigation of common vulnerability classes such as many of those listed in the OWASP Top 10.

Open Roles

Senior Software Engineer (Java/JVM)

Software Engineer (Java)

Software Engineer (QA/Test/Automation)

Apply here https://www.prevoty.com/about/careers

Prevoty | Software Engineer | Los Angeles | Fulltime

Prevoty is a Runtime Application Self Protection company founded in 2013 that builds language plugins to provide mitigation to security vulnerabilities without the need for modifications to applications. The plugins utilize instrumentation and middleware to automatically insert hooks into applications that perform detection and mitigation of common vulnerability classes such as many of those listed in the OWASP Top 10.

Open Roles

- Language Integration Engineer (Ruby, Python, PHP, Node.js, Lua, or Go w/ C, C++, or Rust)

Do you enjoy digging under the covers of languages and and their implementations? This role specifically is to work on integration of the sections of our engine written in C, C++, and Rust into the host languages (Ruby, Python, PHP, Node.js, Lua, Go, Java, .net). You will utilize their respective FFI support/extension APIs to hack on their runtimes and build instrumentation and the supporting functionality.

- Parser Engineer (C++, ANTLR)

Love parsers and semantic analysis? This role is to work on SQL parser, tree construction, and execution runtimes. You will work with large ANTLR grammars and their C++ backends to build trees for export to other programming languages where semantic analyses of SQL queries are performed.

https://www.prevoty.com/about/careers

Prevoty | Software Engineer | Los Angeles | Fulltime

Prevoty is a Runtime Application Self Protection company founded in 2013 that builds language plugins to provide mitigation to security vulnerabilities without the need for modifications to applications. The plugins utilize instrumentation and middleware to automatically insert hooks into applications that perform detection and mitigation of common vulnerability classes such as many of those listed in the OWASP Top 10.

Open Roles

- Language Integration Engineer (Ruby, Python, PHP, Node.js, Lua, or Go w/ C, C++, or Rust)

Do you enjoy digging under the covers of languages and and their implementations? This role specifically is to work on integration of the sections of our engine written in C, C++, and Rust into the host languages (Ruby, Python, PHP, Node.js, Lua, Go, Java, .net). You will utilize their respective FFI support/extension APIs to hack on their runtimes and build instrumentation and the supporting functionality.

- Parser Engineer (C++, ANTLR)

Love parsers and semantic analysis? This role is to work on SQL parser, tree construction, and execution runtimes. You will work with large ANTLR grammars and their C++ backends to build trees for export to other programming languages where semantic analyses of SQL queries are performed.

https://www.prevoty.com/about/careers

Prevoty | Software Engineer | Los Angeles | Fulltime

Prevoty is a Runtime Application Self Protection company founded in 2013 that builds language plugins to provide mitigation to security vulnerabilities without the need for modifications to applications. The plugins utilize instrumentation and middleware to automatically insert hooks into applications that perform detection and mitigation of common vulnerability classes such as many of those listed in the OWASP Top 10.

Open Roles

- Language Integration Engineer (Ruby, Python, PHP, Node.js, Lua, or Go w/ C, C++, or Rust)

Do you enjoy digging under the covers of languages and and their implementations? This role specifically is to work on integration of the sections of our engine written in C, C++, and Rust into the host languages (Ruby, Python, PHP, Node.js, Lua, Go, Java, .net). You will utilize their respective FFI support/extension APIs to hack on their runtimes and build instrumentation and the supporting functionality.

- Parser Engineer (C++, ANTLR)

Love parsers and semantic analysis? This role is to work on SQL parser, tree construction, and execution runtimes. You will work with large ANTLR grammars and their C++ backends to build trees for export to other programming languages where semantic analyses of SQL queries are performed.

https://www.prevoty.com/about/careers

Prevoty | Software Engineer | Los Angeles | Fulltime

Prevoty is a Runtime Application Self Protection company founded in 2013 that builds language plugins to provide mitigation to security vulnerabilities without the need for modification of applications. The plugins utilize instrumentation and middleware to automatically insert hooks into the application to perform detection and mitigation of common vulnerability classes such as many of those listed in the OWASP Top 10.

Open Roles

- Language Integration Engineer (Ruby, Python, PHP, Node.js, Lua, or Go w/ C, C++, or Rust)

This role specifically is to work on integration of the sections of our engine written in C, C++, and Rust into the host languages (Ruby, Python, PHP, Node.js, Lua, Go, Java, .net). You will utilize their respective FFI support to build and maintain the instrumentation and the supporting functionality.

- Parser Engineer (C++, ANTLR)

This role is to work on SQL parser and tree construction. You will work with large ANTLR grammars and their C++ backends to build trees for export to other programming languages where semantic analyses of SQL queries are performed.

https://www.prevoty.com/about/careers

Prevoty | Software Engineer | Los Angeles, Redwood City, or New York | Fulltime

Prevoty is a Runtime Application Self Protection company founded in 2013 that builds language plugins to provide mitigation to security vulnerabilities without the need for modification of applications. The plugins utilize instrumentation and middleware to automatically insert hooks into the application to perform detection and mitigation of common vulnerability classes such as many of those listed in the OWASP Top 10.

Open Roles

- Language Integration Engineer (Ruby, Python, PHP, Node.js, Lua, or Go w/ C, C++, or Rust)

This role specifically is to work on integration of the sections of engine written in C, C++, and Rust into the host languages (Ruby, Python, PHP, Node.js, Lua, Go, Java, .net) utilizing their respective FFI support and own the supporting plugins building an maintaining instrumentation and the supporting functionality.

- Parser Engineer (C++, ANTLR)

Developer to work on SQL parser and tree construction. Candidate will be dealing with large ANTLR grammars and its C++ backend to build trees for export to other programming languages to perform semantic analysis of SQL queries.

https://www.prevoty.com/about/careers