HN user

mh_

8,204 karma

http://blog.thinkst.com

Posts315
Comments75
View on HN
canary.tools 10mo ago

It's our birthday – so we built everyone this retro game

mh_
1pts4
blog.thinkst.com 1y ago

Caring

mh_
1pts0
blog.thinkst.com 1y ago

Vendor Booths don't have to suck (and why your startup should reconsider them)

mh_
1pts0
blog.thinkst.com 1y ago

Hacking as a pathway to building better Products

mh_
3pts0
blog.thinkst.com 1y ago

Unfashionably secure: why we use isolated VMs

mh_
305pts243
twitter.com 2y ago

Wrong on the Internet

mh_
1pts0
blog.thinkst.com 2y ago

Be careful of the examples you use. They stick

mh_
199pts128
blog.thinkst.com 3y ago

Seasonal themes, delighting users and small UX touches

mh_
1pts0
twitter.com 3y ago

Is Elon Beyond Reproach?

mh_
22pts34
blog.thinkst.com 3y ago

Always Be Hacking

mh_
2pts0
blog.thinkst.com 3y ago

Apples AT&T demo was a good example of pg's “relentlessly resourceful”

mh_
2pts2
news.ycombinator.com 4y ago

Ask HN: Will referral codes cheapen honest referrals?

mh_
1pts2
blog.thinkst.com 4y ago

Building WireGate: A WireGuard front to detect compromised keys

mh_
8pts0
blog.thinkst.com 4y ago

Use a fake kubeconfig file to detect attackers

mh_
1pts0
blog.thinkst.com 4y ago

Using a SQL Injection attack to detect attackers

mh_
1pts0
blog.thinkst.com 4y ago

Good attacks make good detections make good attacks (a MySQL booby-trap)

mh_
1pts2
thinkst.com 4y ago

Grab quarterly reports/summaries on current Information Security research

mh_
1pts0
thinkst.com 4y ago

A (free) quarterly selection (and review) of security research / papers / talks

mh_
2pts0
blog.thinkst.com 5y ago

We bootstrapped to $11M in ARR

mh_
387pts217
blog.thinkst.com 5y ago

We Bootstrapped to $11M in ARR

mh_
6pts0
blog.thinkst.com 5y ago

SolarWinds (and the terrible state of enterprise security)

mh_
1pts0
blog.thinkst.com 5y ago

Why the SolarWinds incident should scare you (even if you aren't running it)

mh_
2pts0
twitter.com 5y ago

Quick Points on the SolarWinds Hack (a Twitter thread)

mh_
1pts0
blog.thinkst.com 5y ago

New features are not the same as solved problems

mh_
2pts0
blog.thinkst.com 5y ago

Why Pareto optimality might be wrong for building products

mh_
3pts0
blog.thinkst.com 5y ago

Security Products and Terrible Design

mh_
1pts0
blog.thinkst.com 5y ago

We tamper with all outgoing API calls. Here’s how (& why)

mh_
1pts0
blog.thinkst.com 6y ago

A Steve Jobs masterclass from a decade ago

mh_
339pts149
news.ycombinator.com 6y ago

Ask HN: Can you source this pg quote?

mh_
1pts2
blog.thinkst.com 7y ago

It's probably not your companys bureaucracy stopping u from doing great things

mh_
2pts0

I wrote this about 13 years ago (a little tongue in cheek) but it held up:

https://sensepost.com/blog/2009/twitter-killed-the-infosec-b...

-snip- There’s something liberating about saying “here’s a link”, as opposed to taking the time to formulate your thoughts into a full blown posting.

We were curious if this twitter-effect was real, imaginary or only applicable to lazy people like us.. Thanks to python-twitter and a few lines of script we can look at the the blogging habits of some info-sec superstars (and maybe confuse correlation and causation to jump to conclusions while we at it). -snip-

You can wave the encoding away (with a tick-box) but in general, people over-estimate what attackers will "notice". In cases like this, many are as desperate to get the loot as users are when they get phished. dialogue boxes and browser warning fade into the background as they hit "accept" to move closer to their goal.

I think it would depend on how those experts roll.

For infosec for example, i think if your product did "X amazing thing", then you'd definitely get a seasoned experts attention if you tweeted "hey, we built a thing that does X amazing thing, give me 5 minutes and i'll show it to you"

I think theres a part of this that means your products has to convince them in the 5 minutes they give you (or at least has to convince them to give you 5 minutes more)

I've previously pondered how we would have approached our early steps if we were completely unknown, and the best option i can think of is a kind of sincere, influencer marketing approach.

i.e. if you dont have the voice in the industry that people will listen to, find people who do, and get them to see your product. Most industry leaders are constantly looking to up their game, so you should be able to catch their eye, and if your product is awesome, they will say so

We do average to above average salaries, and all share a profit share bonus at the end of the year. Everyone gets a company credit card to buy books/tech needed to do their jobs. Everyone gets side benefits like an audible subscription, other mini stipends.

It's worth noting that we couldn't always do this (starting off we just went with "decent salaries and smart ppl to work with").

We try to keep doing this right so that we all do well as the company does.

We were a little bit lucky in this regard, because we had some authority in the niche (2 members of our original team had spoken at security conferences internationally for the previous 10 years).

I have lots of thoughts on this though. I think with a low enough burn rate, you can overcome this with a great product, and taking just one bite at a time. ie. one happy customer, then another. Actual customer happiness is so low, that you just have to do a little better to have people talk about you, and over time it compounds nicely.

What they (we) are talking about, is that nobody caught the attacks.

The article then goes on to explain why, even with hundreds of thousands of ppl doing incident response investigations, nobody caught / correctly attributed these attacks.

Port knocking 6 years ago

To defend Canarytokens here (and I’m totally biased because we make it) some tokens can’t be easily avoided. Ie. If the token is a Slack/AWS/something API key, then the only way for the attacker to profit is to use it, and the moment they do, they tip their hand. The joy of Canarytokens is not having to set up infrastructure to get the alerting win, with very little effort.

(just to play devils advocate) How do you figure "the evidence contradicts him" ? His attitude: launched & maintains the largest free collaborative dev known to man (?) which has generated squillions as a by-product. Yours/My attitude: makes some friends

seems to me he has some runs on the scoreboard (and some facts on the ground)

The disclosure process is always fraught with peril (and pain) and its a safe bet that no matter what a discloser does, there will be some person or group who thinks they should have handled it differently. In a case like this, when reasonable time is given, and the world gets to benefit from a great deal of work (effectively done for free), i tend to simply say thanks, and make notes..

I'm assuming that when you point towards the story of Asma Bint Marwan you acknowledge that classical scholars have rejected this story? It also pretty amazing that you would complain about an ad hominem when your comment led with "what did you expect an islamist to do?" (I also note your silence on the fact that draconian Internet silliness seems ok when done by non-"islamists")

Again: There is certainly a lot in the OP's post relevant to HN, but i would submit that sweeping statements on religions are not

Your statement: "islam means criticism of the government = criticism of the religion = punishable by death" is patently untrue (and is really better saved for clan meetings than HN). Do you have citations for: "The prophet executed people for that"? (Its kinda interesting that with all the recent documentation of states using the Internet to infringe on peoples rights, the moment Turkey does it, the response is: "see.. islam!")

Be the best? 13 years ago

I must confess to finding this answer pretty insulting (but i guess in truth, you are calling everyone monkeys, and just distinguishing between those that climb to the top and those that don't)

I guess the counter-thought would be that of exploration & discovery, where we need trailblazers to set the path that others will follow later..

Thanks. There are a manual ways to do it (through booting off a live-cd) and there are some companies selling it as a service, but we are aiming for quick, painless but useful..

Would love to hear your thoughts (humans@phish5.com)

a) this comment is annoyingly simple minded and pretty plainly racist. ("Those people"? Really?) b) with all the talk of un-warranted wiretaps, and the state of surveillance building up in the US/Europe, it's probably a bad time to throw stones c) it's worth spending some time to investigate how "those" countries have had democracy deliberately crippled for decades by western powers needing puppet dictators to guarantee their flow of oil (try a YouTube search for "secrets of the seven sisters")