This entire piece and author lost me within the first paragraph.
“and soon Google” links to a complete unsupported fluff piece from November, drawing a loose connection to an activist investors letter.
HN user
This entire piece and author lost me within the first paragraph.
“and soon Google” links to a complete unsupported fluff piece from November, drawing a loose connection to an activist investors letter.
That would be a terrible business strategy.
If someone comes forward with legitimate good security vulnerabilities and you don’t pay out, you’re massively encouraging them to go to shady brokers next time.
The twice-linked brief article states that basebands have full OS memory access, which is not true in 2018. And the article is completely uncited.
Fortunately, Australia doesn’t make any phones or popular e2e software.
Agreed. If anyone thinks it’s a legitimately bad book, feel free to discuss why.
There are a load of criticisms you could call out about google, but suggesting that their “one primary platform and single focus (social media)” is about to collapse is not valid; they’re far too broadly invested (from mobile phones to search to email) to claim they’re about to become irrelevant.
Just go sit somewhere and turn your attention inwards
Perhaps you were born with a natural instinct for what meditation is, what to do when thoughts arise and you go off track, how to sit comfortably, what you’re aiming for and what you’re not.
But I didn’t, I needed to read books to start my development. I absolutely don’t think children should know this.
Given the posted article is about the poor security posture of most home routers, has anyone inspected ubiquiti?
I gather they have a bug bounty which is a good start, but so do Netgear and their routers are still full of bad vulns.
Yeah it seems like RCE in the context of Chromium, but not SQLite? I know it’s pedantic but if this is RCE in SQLite because it’s exposed to the network via other software, every vulnerability is “remote” because you may expose it via other software.
Remote implies it can be accessed remotely, is that true, or did they mean “remote if an attacker can remotely send data to SQLite”?
Good question, to which I don’t know the full answer. But if you look at their motto “move fast and break things”, insistence on pushing new features as fast as possible, and the recent clash and resignation of their CSO, I’d say google are just more mature about security, and understand their products are entirely reliant on trust of their users.
Agreed. If you’re trying that hard to build a relatable hook, maybe what you’re writing about just simply isn’t that important/useful?
I highly doubt this is a off the shelf Wordpress install. In fact, a standard WP is not > 1gb of data, which the post describes.
There will be a massive amount of customization, so revealing source code probably is a security risk. I’m willing to bet a competent code auditor could find secondary vulns in that code.
There’s IBB; the internet Bug Bounty. But it’s for widespread open source software. Typically FOSS that isn’t well funded yet is critical to massive parts of the internet. Popular libraries, email & DNS infrastructure etc.
Ebay being a private company with boatloads of money is definitely not a part of that.
I still don't understand what this has to do with blockchain.
Funding from VCs?
Sure, that’s a great idea. But your transport security is going to show vulnerability sooner or later (see: regular issues in TLS), and it’s worth having a slightly less compromised network fabric.
I agree with your general sentiment though.
Excuse my very basic question, but how do you manage spam when using mutt? Do you interface to a cloud-based service in mutt, or have some kind of other spam filter?
I’ve always liked the idea of moving my email to mutt and using personal domains, but not convinced I could manage spam well.
We recently had a 2nd hand copy shipped to NYC to bring a little bit of home back to the kitchen.
It’s almost like the Michelin: intended to sell more of a product (tires/flour), but ended up iconic in its own right.
Did you do the DLND? If so, they may have updated the videos, as the current explanation of conv2d_transpose seemed fairly clear to me. Or maybe it was some of the extra materials they provided that helped. I think I found a good video on YT also.
I don’t believe your statement that AI is just a subset of software. It’s almost entirely math. Furthermore, “somebody like yourself or anybody else can’t pick it up” is wildly untrue. You realize that the people in the articles are researchers, not practitioners, right? They’re the Albert Einstein’s of the industry dreaming up new deviations and architectures. I think you’re severely downplaying what they’ve achieved.
You might as well say that Michael Schumacher just drives a car pretty well, so most of us could spend a bit of time in training and win F1
The reason I go out of my way to insist I can’t do that is that I’m not in my 20s, and it would be delusional of me to think AI is “nothing magic” and I can watch some YouTube videos to become the worlds best.
At what point did it go from understandable to not for you? Do you understand GAN architectures? Basic ideas of the DCGAN paper?
I applaud the positive spin, but the responses are due to the headline which suggests these salaries are normal.
If an article said “supermarket checkout clerks are earning over $1m” and the article explained that a couple of retired property investors decided to work at a supermarket, would you respond the same?
The harsh reality is, very few people will have the tenacity, intelligence, and opportunities to become a top 20 AI researcher, especially in their 20s.
True, although what are they going to do with the data? If it’s primarily for selling to ad companies, a tiny slice of privacy minded people aren’t worth much.
This is a huge unsolved problem in journalism: reporting whether a company was wildly negligible and deserved to be punished, or did the right things and fell victim to “no org can be bulletproof”
Some standards like PCI attempt to do this, but to date they have no real teeth. GDPR may be the change we need.
I have deep concern that C-levels will learn that breaches don’t matter, just have a CISO you can behead and replace when it does.
I’ll take a wild guess:
* a lot of legacy kit that’s expensive and hard to upgrade
* lots of things rely on backward compatibility
* attacks are still too difficult/expensive to the point that only hushed adversaries are performing attacks
* lack of motivation from cell providers
Thanks, really appreciate the writeup. I might give the course a crack, given the positive reviews it’s getting in this thread.
Has anyone read her book and can comment on the differences?
I own the book and have half-read it twice, it’s very underwhelming. At no point am I thinking “that’s going to change my way of doing X”
It widely varies depending on skill level, and unfortunately I can’t compare easily as I don’t know developer salaries.
If you’re in a major tech hub in the US, 75k for a junior, 150 for a senior, and upwards from there for someone with decent experience. $300k isn’t crazy for someone really good. Those are technical roles outside of management.
But those figures are skewed toward better orgs; some companies will take a fresh grad, throw them at some junk automated tools, and call them a pentester. This area of the industry is booming with the increase of compliance mandated testing.
Yes, very poorly.
The scale you’d need to achieve to have even the most minor effect on facebooks vast infrastructure would be enormous.
I feel the effort you and countless opt-in people would expend could be redirected to much more fruitful efforts. Convincing people to delete their profiles, for example.