HN user

ksaitor

33 karma

Founder of https://cryptojobslist.com - largest job board to find and post blockchain and crypto jobs.

Maker of other things too.

Contact me: https://twitter.com/ksaitor

[ my public key: https://keybase.io/ksaitor; my proof: https://keybase.io/ksaitor/sigs/XLEwdkVOyRXK4-uEXcXmP1tUvFl8b6qYwN-MF4vhh-k ]

XLEwdkVOyRXK4-uEXcXmP1tUvFl8b6qYwN-MF4vhh-k

Posts15
Comments55
View on HN

Hey @caymanjim, author here.

Your comment doesn't add any value to uncovering the root of the issue and just blaming the author without having the full picture.

The author clearly wasn't using many security precautions prior to being compromised ...

Just because I don't mention the exact security precautions I use in the article, doesn't mean that I don't actually use them.

I spent 12+ years in tech. And started off my career by specialising in networks and security. And all my life I exhibited as much confidence as you are in your comment.

The moral of the story, is that if you are in tech, a security professional, or work in crypto - don't take for granted your security. No matter where you are in your career, what's your salary, or how many people report to you. Take time annually, bi-annually, or quarterly to review your online security. Especially if you've been on the internet since 90s. You might not even remember the websites you've sign up and emails you have.

So, what does this say about Apple security?

If you can explain how Apple 2FA call was bypassed that you be helpful. What wasn't mentioned in the article is that I spoke with two Senior Advisors from Apple and they've haven't been taking this very seriously, to say the least. "Consider reinstalling the OS" and suggestions alike. It's an obvious next step to take, but it doesn't answer the question of how 2FA was breached. Reinstalling the OS or taking any other common measures in such sophisticated incidents don't prevent future incidents alike.

Hi HN, the author of the article here.

Can someone explain how Telegram 2FA, Yahoo 2FA and Apple 2FA were bypassed?

Especially Apple 2FA - I received a 2FA call from Apple, picked it up, and the attacker logged in right after.

Please note, this was not a (typical) SIM swap. I was still receiving SMS and calls during the attack.

p.s. thanks for all the comments!

Actually, gave this a second thought…

Might be cool, if done right:

   - upload a few profile pics
   - GAN generates an optimized pretty profile pic for you,
     that you can used on Tinder and other social media
I'm pretty sure people would be willing to pay a couple of bucks for that.

How hard would that be to train a model like that?

What's the motivation? Give it a try… it's fun to vote.

I've posted this on Product Hunt and Reddit this week, and so far people did 33426 votes on pictures. Pretty crazy!

Interestingly, a few comments (yours and on Reddit) assume how "bad" people can be. Surprisingly, so far, overall voting behaviour been very positive. People have not been abusing votes, comments nor images in the past few days.

So far 170 users uploaded 218 photo pairs - and all of them are genuinely good.

Hi HN

I’m building this app to A/B test your (and mine) 1st profile pic on Tinder.

I tried relying on Tinder’s “Smart Photos” feature before, but it does not give any insight into which picture is actually better, and there is no control over the sequence of pictures in my profile. So I thought it would be cool to have a super simple web app where people can actually vote for you.

The way it works is:

  1. You upload your 2 pictures
  2. Community votes
  3. You get the results which picture is better (and some feedback too)
As you know, 1st pic is like ~70% of your success and impact on your ELO score. The higher your score, the higher up your position in the queue is and the hotter profiles you’ll be shown too.

I’ve been working on it for the past 3-4 weeks and would really like some feedback on it:

  - What can be improved? 
  - Trying to come up with a funny tagline e.g. “Facerank yourself & your friends” but think this can be improved LOL.
Hope you guys can roast this idea as much as you can.

Thanks!

Julia 1.0 8 years ago

We want the speed of C with the dynamism of Ruby. We want a language that’s homoiconic, with true macros like Lisp, but with obvious, familiar mathematical notation like Matlab. We want something as usable for general programming as Python, as easy for statistics as R, as natural for string processing as Perl, as powerful for linear algebra as Matlab, as good at gluing programs together as the shell.

… they forgot to compare Julia to JavaScript — the most popular programming language in the world.

Or is that because authors don't want Julia to be used by anyone?

¯\_(ツ)_/¯

[I'm joking, ofc. But I still find it weird how almost every modern language is mentioned, but JavaScript…]

@kialo requires 8 pros/cons for a discussion to be discoverable. That sounds like a draconian requirement that likely to damage the platform more, than it'll benefit it. I understand they are trying to keep the quality high, but if users cant discover new content daily, they wont be able to engage with it and will just churn…

Hope you guys will lower this limit, as the idea is truly great and Internet need a well-structured discussion platform!

back online! apparently HN effect downed the site on GCP :)

Hey HN. I'm the guy running Crypto Jobs List. Been having this networking issues ever since i've moved to GCP from AWS. I've set my instance's IPs to static (instead of ephemeral) and running dukku. Site is up and and running, for about a day and them around the sate time of the day gets disconnected and not accessible via domain name. SSH still works tho. This puts the site under risk. Anyone had the same issue? Would love your help, dear HN to keep Crypto Jobs List up!

Hi HN,

This week trading on several tokens got halted due to discovered & exploited vulnerabilities in two smart contracts. One of them lost about 90% of its value… and another one lost 26% - $40,000,000 in market cap.

We wanted to focus more on the technical analysis of the situation to shed some light on common vulnerabilities that still abound.

Would love your feedback, since we got some mixed reviews on whether we did a correct technical judgment of one of the contracts. Especially of the SMT token.

Yeah, it's been quite scary how many novice devs move into space and just copy-paste code. And they charge money for that "expertise". And they actually getting paid…

Also, those who discover those bugs afterwards get paid even more in the end. Sad story.

Hi HN,

Yesterday trading on several tokens got halted due to discovered & exploited vulnerabilities in two smart contracts. One of them lost about 90% of its value… and another one lost 26% - $40,000,000 in market cap. in

We wanted to focus more on the technical analysis of the situation to shed some light on common vulnerabilities that still abound.

Would love your feedback, since we got some mixed reviews on whether we did a correct technical judgment of one of the contracts.

Heya! Depends what's your definition of "successful", of course, but would like to plug in CJL - job board for blockchain companies.

- https://cryptojobslist.com

- current progress https://twitter.com/ksaitor/status/968690695031500800

- will share revenue figures shortly, but TL;DR — it's ramen profitable

Been running it solo and launched in October 2017. Previously did a few other consumer+saas startups with a team, funding, etc — and this simple job board seems to be having way more traction and revenue than other funded projects with fancy apps that I've built before. AMA :)

Hello HN!

Excited to share this job board with you! Launched just a few weeks ago, and it’s been getting some good attention from developers subscribing and companies posting. The site is pretty simple at the moment, but we have search and commenting features — and we are encouraging companies to reply, once there are questions. Hence making job application a bit more easy-going, open and friendly activity.

I intend to keep the site simple. But nonetheless, what are the features you've always been craving for in a job board, but no job board ever implemented them? Or, perhaps, there is something you really hate about other job boards or the application process, that we can fix?