In the title you have written 'Remote (Worldwide)" while on the jobs page it says "Remote (United States)" https://jobs.ashbyhq.com/Railway/6ddcfe47-6cce-469b-ba6d-4f0... and the same for https://jobs.ashbyhq.com/Railway/b8072f95-043f-404d-a313-f0b...
HN user
leftcenterright
but you use Cloudflare yourselves?
WOW! clealry you have no understanding of thoughts that might make their way to teenage minds or to children' minds in general. seriously, WOW!
Do you believe there exists such a thing as depression?
Can it finally make 10 sentences that end with a "w" or "p" or "o"? /s
She says "there is no language in nature" which does not seem accurate. Even though she might mean something else or a particular form of language but even then, bees and birds still use sound and something similar to language.
Is it just me?
for e.g. the form of communication used by bees is very well known now, it involves not just spatial movements but also "buzzing" which is totally similar tot he sounds we make, they just lack vocal cords.
What makes you consider it a "discovery" instead of a creation of us humans?
I am more on the side of seeing maths as a precision language we utilize and extend as needed, especially because it can describe physically non-existent things e.g. perfect circles.
So, no wealthy person is buying a physics lecture or investing in experiments to better understand the nature of this universe we live in? /s
btw does anyone know if places like Fermi lab, CERN receive donations from the super-wealthy?
What sort of access level / integration would you need to the businesses (repositories, CI systems, mobile app source repositories, Github admin) seeking to use Actory?
Despite modern VPNs, global CDNs, impractical technical level ban on any web service: how come X and others simply do what the government tells them?
Is it the fear of fines? That never deters them from collecting more data though.
Here is a nice talk by Byron Tau who has also written a book titled "Means of Control" detailing some of these flows covering ad tech companies, data brokers and how government contractors use them and serve as a key player to provide services to intelligence agencies.
- https://www.interface-eu.org/events/background-talk-with-byr...
I think they definitely knew that they are embedding code from US based ad agencies who might either be selling it to the NSA or just doing it in an insecure manner (plaintext protocols).
Mostly in such cases, direct involvement and paying dollars is a clear no-go for the intelligence agencies. They could instead be paying the ad agencies.
Also note that we are talking pre-Let's encrypt and TLS everywhere world, a lot of this traffic was also just plain text making it much easier to harvest.
Some interesting insights from this piece: https://web.archive.org/web/20180719081149/https://theinterc...
from an intelligence perspective, this is business as usual.
- Rovio sold data to ad companies (ad companies primarily based in the US)
- They used AWS (to which of course NSA has legal access)
- Data is not end to end encrypted, all metadata sits on servers in plain text and within AWS even moves from server to server in plain text
How much insight metadata can grant to someone like NSA is still wildly underrated.
- https://www.propublica.org/article/spy-agencies-probe-angry-...
does that also work with xlsx files without much pain?
could someone with legal/data-privacy expertise comment if this would be something they have to disclose under data breach disclosure laws?
Technically it might not be a "data leak", but it very well could result in one if arbitrary content (including js?) can be uploaded to these webpages?
Norton, Kaspersky, Zscaler, F-secure, NordVPN, Virustotal, Palo Alto: all of them marked these links as safe.
This is sad to see, these tools are forced down so many companies in name of "compliance" while totally not worth the maintenance and cost overhead. Apparently they haven't got any better in the last decade.
https://job-boards.greenhouse.io/soundcloud71/jobs/793367300...
Strong proficiency in Go or Scala. Familiarity with Ruby and JavaScript is a plus
works for me, would be interesting to see what IP addresses it is redirecting for you, hopefully you are not using a malicious/compromised DNS server?
I think it is more about finding a "perfect" fit, from the last hiring thread there was a job for which I thought I was a good fit except that I was lacking some prior experience in a specific domain i.e. anti-fraud, and that alone was the basis for not pursuing it further for the company.
Also this time, I see companies hiring "security engineers" with "Strong proficiency in Go or Scala". It is not like they are willing to offer much higher salaries for people who are both security engineers and full-stack software develpers, they just want it for the same market avg. salary ranges.
Is this for reporting bugs outside of the bug bounty platforms?
Nah, in this case they simply had no official bug bounty program/platform.
I would guess that a big factor is mindset and tech culture across different companies or having a bad head of something who doesn't get the point of bug bounty / promoting responsible disclosure.
Without feedback you don't know that the bug was fixed in reaction to your bug report.
In this particular case, they did say they will consider a reward for a severe bug (it was severe, DNS hijack) and then once I shared details, the next day I checked, they had fixed it and never wrote back.
Beg bounty hunters have damaged the field so much.
But even in 2025, I have come across companies who do not at all care about rewarding good security researchers who report issues. Hell, I have even been ghosted after reporting the bug which they promptly fixed and did not even write back to say a "thank you". Has anyone else also encountered this behavior from tech companies? (not talking about a non profit, hospital or gov agency here)
for ChatGPT try the "o" version: Write 20 sentences that end with "o"
Write 20 sentences that end with "p"
Just don't submit your data to everyone who asks for it. A lot of website ask for your phone number and date of birth for no reason whatsoever.
Why has this been flagged? People being detained for writing op-eds is definitely not just politics or irrelevant.
Isn't simply the act of going through one's phone offensive enough? 0 regard for human dignity and privacy and people defending it is shocking.
Another AFP source said that US authorities accused the French researcher of “hateful and conspiratorial messages”.
“This measure was apparently taken by the American authorities because the researcher’s phone contained exchanges with colleagues and friends in which he expressed a personal opinion on the Trump administration’s research policy,” the minister added.
I don't think this has been a basis for denying entry to people in past?
The links you shared in your original comment all pointed to "rejections", not "legal people being detained".
What has always been going on: people overstay their visa, depending on the scale and country, people get treated badly almost always in these cases.
What is happening now: people being critical of Trump are being rejected, legal visa holders are being detained because of the scale of the abuse.
These are clearly very different things and very much a fault of specifically Trump administration. Searching phones and messages to look for Trump critical messages .. unbelievable and totally new stuff is going on here: https://www.theguardian.com/us-news/2025/mar/19/trump-musk-f...