HN user

libdjml

137 karma
Posts1
Comments49
View on HN

That would be a terrible business strategy.

If someone comes forward with legitimate good security vulnerabilities and you don’t pay out, you’re massively encouraging them to go to shady brokers next time.

The twice-linked brief article states that basebands have full OS memory access, which is not true in 2018. And the article is completely uncited.

There are a load of criticisms you could call out about google, but suggesting that their “one primary platform and single focus (social media)” is about to collapse is not valid; they’re far too broadly invested (from mobile phones to search to email) to claim they’re about to become irrelevant.

Just go sit somewhere and turn your attention inwards

Perhaps you were born with a natural instinct for what meditation is, what to do when thoughts arise and you go off track, how to sit comfortably, what you’re aiming for and what you’re not.

But I didn’t, I needed to read books to start my development. I absolutely don’t think children should know this.

Yeah it seems like RCE in the context of Chromium, but not SQLite? I know it’s pedantic but if this is RCE in SQLite because it’s exposed to the network via other software, every vulnerability is “remote” because you may expose it via other software.

Good question, to which I don’t know the full answer. But if you look at their motto “move fast and break things”, insistence on pushing new features as fast as possible, and the recent clash and resignation of their CSO, I’d say google are just more mature about security, and understand their products are entirely reliant on trust of their users.

Agreed. If you’re trying that hard to build a relatable hook, maybe what you’re writing about just simply isn’t that important/useful?

I highly doubt this is a off the shelf Wordpress install. In fact, a standard WP is not > 1gb of data, which the post describes.

There will be a massive amount of customization, so revealing source code probably is a security risk. I’m willing to bet a competent code auditor could find secondary vulns in that code.

There’s IBB; the internet Bug Bounty. But it’s for widespread open source software. Typically FOSS that isn’t well funded yet is critical to massive parts of the internet. Popular libraries, email & DNS infrastructure etc.

Ebay being a private company with boatloads of money is definitely not a part of that.

Sure, that’s a great idea. But your transport security is going to show vulnerability sooner or later (see: regular issues in TLS), and it’s worth having a slightly less compromised network fabric.

I agree with your general sentiment though.

Excuse my very basic question, but how do you manage spam when using mutt? Do you interface to a cloud-based service in mutt, or have some kind of other spam filter?

I’ve always liked the idea of moving my email to mutt and using personal domains, but not convinced I could manage spam well.

Did you do the DLND? If so, they may have updated the videos, as the current explanation of conv2d_transpose seemed fairly clear to me. Or maybe it was some of the extra materials they provided that helped. I think I found a good video on YT also.

I don’t believe your statement that AI is just a subset of software. It’s almost entirely math. Furthermore, “somebody like yourself or anybody else can’t pick it up” is wildly untrue. You realize that the people in the articles are researchers, not practitioners, right? They’re the Albert Einstein’s of the industry dreaming up new deviations and architectures. I think you’re severely downplaying what they’ve achieved.

You might as well say that Michael Schumacher just drives a car pretty well, so most of us could spend a bit of time in training and win F1

The reason I go out of my way to insist I can’t do that is that I’m not in my 20s, and it would be delusional of me to think AI is “nothing magic” and I can watch some YouTube videos to become the worlds best.

I applaud the positive spin, but the responses are due to the headline which suggests these salaries are normal.

If an article said “supermarket checkout clerks are earning over $1m” and the article explained that a couple of retired property investors decided to work at a supermarket, would you respond the same?

The harsh reality is, very few people will have the tenacity, intelligence, and opportunities to become a top 20 AI researcher, especially in their 20s.

This is a huge unsolved problem in journalism: reporting whether a company was wildly negligible and deserved to be punished, or did the right things and fell victim to “no org can be bulletproof”

Some standards like PCI attempt to do this, but to date they have no real teeth. GDPR may be the change we need.

I have deep concern that C-levels will learn that breaches don’t matter, just have a CISO you can behead and replace when it does.

Has anyone read her book and can comment on the differences?

I own the book and have half-read it twice, it’s very underwhelming. At no point am I thinking “that’s going to change my way of doing X”

It widely varies depending on skill level, and unfortunately I can’t compare easily as I don’t know developer salaries.

If you’re in a major tech hub in the US, 75k for a junior, 150 for a senior, and upwards from there for someone with decent experience. $300k isn’t crazy for someone really good. Those are technical roles outside of management.

But those figures are skewed toward better orgs; some companies will take a fresh grad, throw them at some junk automated tools, and call them a pentester. This area of the industry is booming with the increase of compliance mandated testing.

The scale you’d need to achieve to have even the most minor effect on facebooks vast infrastructure would be enormous.

I feel the effort you and countless opt-in people would expend could be redirected to much more fruitful efforts. Convincing people to delete their profiles, for example.