HN user

merijn481

283 karma

Goals are dreams with a deadline.

[ my public key: https://keybase.io/merijn; my proof: https://keybase.io/merijn/sigs/Ev6pG__grp4S_ATC7yFxI8OjUx7LWgZRX0mTtuTdE3A ]

Posts19
Comments10
View on HN
en.wikipedia.org 8y ago

Loss aversion

merijn481
1pts0
en.wikipedia.org 8y ago

Anna Karenina principle

merijn481
3pts0
www.wired.com 8y ago

At Google, Eric Schmidt wrote the book on adult supervision

merijn481
1pts0
www.mediabistro.com 11y ago

Twitter Fixes Flaw That Allowed Unauthorised Deletion of User Credit Card Info

merijn481
1pts0
www.zdnet.com 12y ago

New Internet Bug Bounty holds companies accountable, protects hackers

merijn481
2pts0
www.pentagonpost.com 12y ago

Comet Collisions In Solar System May Support Life By Creating Amino Acid

merijn481
2pts0
reason.com 13y ago

Why We Get the Police State We Deserve. And What We Can Do to Fix That.

merijn481
2pts0
www.online24.nl 14y ago

Users handing over their security, again (for in-app purchase hack)

merijn481
6pts0
newschallenge.tumblr.com 14y ago

Building a crowd-sourced data-graph of what the web knows

merijn481
5pts0
blog.singly.com 14y ago

How APIs should be: Drop in keys, running in 1 minute

merijn481
73pts14
blog.factlink.com 14y ago

Don't look for a UX guy, be a UX guy

merijn481
60pts41
news.ycombinator.com 14y ago

Every time an engineer joins Facebook, a startup dies

merijn481
16pts6
turing.cs.washington.edu 14y ago

Publications at the crossroads of NLP, data mining, Search, and the Semantic Web

merijn481
15pts2
www.cultofmac.com 14y ago

Apple's security team impersonated SFPD during illegal iPhone 5 search

merijn481
5pts2
abcnews.go.com 14y ago

24 y/o father dies of tooth infection: didn't have health care insurance

merijn481
10pts5
online24.nl 14y ago

A perspective on the Iranian hack of Google accounts and a certificate authority

merijn481
2pts0
smartenergyshow.wordpress.com 15y ago

Surprising effect of light could change solar power generation

merijn481
63pts4
www.alternet.org 15y ago

Rape Victim Arrested After Refusing TSA Pat-Down

merijn481
4pts1
news.ycombinator.com 15y ago

Ask HN: Some wise words on 'escalation of commitment'

merijn481
4pts0

Following the advice of this post can make a 10x difference in outcome for founders. This is because they will sharpen their skill to raise this way in every round. The reduced dilution compounds. The additional money in each round can help get you to critical mass first. It’s a powerlaw. One of the most important things to understand when you’re doing a startup. Growth is what makes a company a startup: http://www.paulgraham.com/growth.html. Process and leverage in fundraising is an absolute condition to get there. This post should have 1000 points.

Yahoo has fully embraced working with security researchers. For a company their size (they're no. 1 in web traffic!) with that many different services, they're doing an amazing job. No company that size has ever moved this fast. Yes, they're catching up but they do it fast!

You make some very interesting observations. I'm pretty sure the folks at Twitter spend a LOT of time working on user engagement and solving the signal vs noise problem in recommendations etc. What's been their response so far when you reached out to them? I would try to reach out to the people trying to solve this problem (developers) instead of to management first, in case it's not a matter of decision making but a more of an algorithmic problem.

Well, if you have the email, just reply to it and re-open the conversation and see what happens. If you can explain it correctly, they might be able to research if the bug indeed existed and was fixed. I did a follow up on a bug that I submitted before the whitehat program was in place and that I never got a response on. They looked up the bug, replied to me and paid me. Very diligent.

I'm surprised at how many people just assume the FB sec team doesn't want to pay and therefore tries to not pay if they can get away with it. Their history of paying out is completely the opposite. I've reported several bugs and they're always extremely helpful. They're not an insurance company that wants to reduce cost by screwing over users and there is no historical evidence of that. They want to pay for bugs and get as many of them as possible. What they don't want is for researchers to mess with other users' data. The guy could have just used two accounts to demo (he managed to create a new account after his own account was blocked). Using Zucks account doesn't make it more convincing from a tech perspective. It only makes the guy taken less serious as most researchers care more about how it works than messing with accounts of famous people. Not the smartest move. I understand the sec team draws a line and doesn't pay researchers that mess with other people's data. That's not sleazy, that's sane otherwise it gets exponentially worse as people try to outdo each other in terms of impact instead of focusing on explaining the technique behind a hack.

Ah, I see you did let them know and the vulnerability was fixed before you posted. Good. I recommend saying such a thing in your post because it helps people like me understand that you are in fact responsible about the disclosure.

Ryan, your post is NOT an example of responsible disclosure. You could have written your post and posted it AFTER alerting the Ice Box Pro guys and waiting until they had the main issues fixed. Your post would still be a good post. In fact, you seem to weigh the importance of your post getting on HackerNews above the security of the people who tried Ice Box Pro. The creators of Ice Box Pro had good intentions and messed up security (as almost any startup does to some extend). You are either ignorant to what security actually means or unethical, which at best is as bad as what the creators of Ice Box Pro did and maybe worse. Will you take responsibility if any of the users that tried Ice Box Pro get hacked as a consequence of your post?