HN user

neduma

444 karma

security guy

Posts46
Comments238
View on HN
community.atlassian.com 1y ago

Why is the attachment button missing in comment box(still not fixed)

neduma
3pts0
www.flatcar.org 1y ago

Who is using flatcar? Why and How?

neduma
6pts0
news.ycombinator.com 1y ago

Ask HN: What is on going with WordPress world?

neduma
4pts3
www.politico.com 2y ago

With dueling approaches, the US and EU hit the tech giants hard

neduma
3pts0
www.wsj.com 2y ago

Performance Reviews Will Bite This Year. Be Ready

neduma
3pts0
news.ycombinator.com 2y ago

Ask HN: Does anyone use Phone Booth(Eg. Framery) as workspace at home?

neduma
1pts1
news.ycombinator.com 2y ago

Ask HN: Any recent trends of 'BeyondCorp' zero trust security model?

neduma
1pts0
news.ycombinator.com 2y ago

Tell HN: HN cannot handle the ongoing 'AI nerd drama'

neduma
4pts2
techcrunch.com 3y ago

Netflix’s ad-supported plan is finally here

neduma
2pts1
restofworld.org 4y ago

IN the Dark

neduma
2pts0
www.oit.uci.edu 4y ago

Inclusive IT Language Guide [pdf]

neduma
15pts41
www.airbnb.com 4y ago

AirCover by Airbnb

neduma
135pts125
en.wikipedia.org 6y ago

John Conway

neduma
3pts0
news.ycombinator.com 6y ago

Ask HN: How to apply Security Patches in production Bare metal servers

neduma
1pts1
www.nytimes.com 7y ago

Ariana Grande Was Updating Pop. Then Billie Eilish Came Along

neduma
12pts2
crypto.stackexchange.com 7y ago

Why is elliptic curve cryptography not widely used, compared to RSA?

neduma
4pts1
continuations.com 8y ago

Meltdown and Spectre Are Good … for Innovation

neduma
2pts0
www.redhat.com 8y ago

Ansible 2.4

neduma
1pts0
news.ycombinator.com 9y ago

Ask HN: What do you want?

neduma
2pts4
www.androidpolice.com 9y ago

Huawei P10 review: The start of something promising

neduma
1pts0
www.lambda.cd 10y ago

LamdaCD – BUILD PIPELINES AS CODE

neduma
2pts0
en.wikipedia.org 10y ago

Matrix of pain

neduma
2pts0
hashicorp.com 11y ago

Vault 0.2

neduma
1pts0
www.nytimes.com 11y ago

Attack Gave Chinese Hackers Privileged Access to U.S. Systems

neduma
2pts0
hashicorp.com 11y ago

Terraform 0.5

neduma
2pts0
bitcalm.com 11y ago

The “3-2-1” backup rule, part 1

neduma
1pts0
news.ycombinator.com 11y ago

Ask HN: What is your infrastructure secret management solution?

neduma
1pts1
news.ycombinator.com 11y ago

Ask HN: What is best alternative for Google Groups?

neduma
21pts5
www.vaultier.org 11y ago

Vaultier – Encrypted Team Password Manager

neduma
1pts0
news.ycombinator.com 11y ago

Ask HN: How do you manage your AWS IAM controls for AWS datacenter environments?

neduma
4pts1
Response to DHH 2 years ago

DHH claims to be an expert on open source, but his toxic personality and inability to scale teams means that although he has invented about half a trillion dollars worth of good ideas, most of the value has been captured by others.

Just wondering about ruby, linux, etc.

Poor Linus.

Here are some questions from Llama 3.1-405B

Here are some potential questions and topics to explore during the podcast interview, tailored to cater to a wide range of audiences:

Section 1: Cybercrime and Investigations

Can you share a fascinating case of money laundering through crypto that you investigated? How did you track down the culprits? What are some common tactics used by scammers, and how can individuals and organizations protect themselves? How do you collaborate with law enforcement agencies across different countries to catch cybercriminals?

Section 2: Critical Infrastructure and SCADA Systems

What are some unique challenges in securing SCADA systems, and how do you address them? Can you walk us through a particularly complex SCADA system security project you worked on? What were some key takeaways? How do you see the threat landscape evolving for critical infrastructure, and what can organizations do to stay ahead?

Section 3: Mobile Security and Emerging Threats

What are some emerging threats in Android software security, and how can developers and users mitigate them? You've worked on penetrating the latest Apple devices. What does this involve, and what can users do to protect their Apple devices from potential threats? How do you see the intersection of mobile security and IoT security evolving in the next 5-10 years?

Section 4: Brand Abuse and Online Threats

Can you share an example of how you caught brand abusers by scanning worldwide forums? What tools and techniques do you use? What are some common tactics used by brand abusers, and how can organizations protect their brand reputation online? How do you stay ahead of the evolving threat landscape in online brand abuse?

Section 5: Geopolitics and Cyberwar

How do you see the intersection of geopolitics and cybersecurity evolving in the next 5-10 years? Can you share any experiences or insights on how nation-state actors engage in cyberwarfare, and what implications this has for global security? What role do you think international cooperation and diplomacy play in addressing cyber threats?

Section 6: Career Advice and Industry Trends

What advice would you give to young people starting their careers in cybersecurity? What skills and areas of expertise should they focus on? What are some emerging trends in cybersecurity that professionals, entrepreneurs, and executives should be aware of? How do you see the cybersecurity industry evolving in the next 5-10 years, and what opportunities and challenges will arise?

Section 7: High-Tech Expert Insights

What are some advanced threat vectors that high-tech experts should be aware of, and how can they stay ahead of these threats? Can you share any insights on the latest advancements in cybersecurity research, such as AI-powered security or quantum computing? How do you see the intersection of AI and cybersecurity evolving, and what implications will this have for the industry?

Section 8: Final Thoughts and Recommendations

What's the most critical aspect of cybersecurity that you think is often overlooked, and how can we address this? Are there any books, resources, or conferences that you'd recommend for our audience to stay updated on the latest cybersecurity developments? What's the most important takeaway you'd like our audience to remember from this conversation?

Link: https://meta.ai/s/H5rYSSSgBnvGxWuM/

Foundational Security | Full-time, Part-time | Remote (CA PST)

Foundational Security is stealth mode research and consulting corporation helping clients achieve rapid regulatory compliance and cybersecurity resilience. Foundational Security is seeking software engineers with consulting experience to join our growing Security Engineering team.

Responsibilities:

- Design, develop, and maintain security-focused software applications using languages like Python, Golang, or Rust.

- Collaborate with cross-functional teams (Security, IT, Product Development) to identify potential threats, vulnerabilities, and problem areas, proactively building robust security solutions.

- Work closely with multidisciplinary teams to understand technical requirements, identify security gaps, and implement tailored, efficient solutions.

- Actively participate in architecture, design, and code reviews, emphasizing security best practices and improvements.

- Consult with clients on potential security risks, solutions, and best practices to position Foundational Security as a trusted advisor.

Qualifications:

-10+ years of professional software development experience in Python, Golang, or Rust (in lieu of a degree).

- OR Bachelor's degree in Computer Science, Engineering, Math, or a related STEM discipline and 8+ years of professional development experience in Python, Golang, or Rust.

- Experience in modern security best practices (TLS, Zero-Trust, etc.).

- Experience in areas like SAML/OIDC, mutual TLS, networking, firewalls, vulnerability identification, threat hunting, or container security.

- Expertise in automation between tools and systems.

- Demonstrated consulting and sales support experience in a technical environment.

Reach out at hello [at] foundationalsec.com

* Unfortunately we unable to sponsor H1B/transfers at this time

[dead] 3 years ago

you can follow what openai does with respect to nytimes complaints recently.

From ChatGPT:

> To catch up with the current state of Artificial Intelligence and Machine Learning, it's essential to look at the latest and most influential research papers. Here are some categories and specific papers you might consider:

1. *Foundational Models and Large Language Models*: - Papers on GPT (Generative Pre-trained Transformer) series, particularly the latest like GPT-4, which detail the advancements in language models. - Research on BERT (Bidirectional Encoder Representations from Transformers) and its variants, which are pivotal in understanding natural language processing.

2. *Computer Vision*: - Look into papers on Convolutional Neural Networks (CNNs) and their advancements. - Research on object detection, image classification, and generative models like Generative Adversarial Networks (GANs).

3. *Reinforcement Learning*: - Papers from DeepMind, like those on AlphaGo and AlphaZero, showcasing advances in reinforcement learning. - Research on advanced model-free algorithms like Proximal Policy Optimization (PPO).

4. *Ethics and Fairness in AI*: - Papers discussing the ethical implications and biases in AI, including work on fairness, accountability, and transparency in machine learning.

5. *Quantum Machine Learning*: - Research on the integration of quantum computing with machine learning, exploring how quantum algorithms can enhance ML models.

6. *Healthcare and Bioinformatics Applications*: - Papers on AI applications in healthcare, including drug discovery, medical imaging, and personalized medicine.

7. *Robotics and Autonomous Systems*: - Research on the intersection of AI and robotics, including autonomous vehicles and drone technology.

8. *AI in Climate Change*: - Papers discussing the use of AI in modeling, predicting, and combating climate change.

9. *Interpretable and Explainable AI*: - Research focusing on making AI models more interpretable and explainable to users.

10. *Emerging Areas*: - Papers on new and emerging areas in AI, such as AI in creative arts, AI for social good, and the integration of AI with other emerging technologies like the Internet of Things (IoT).

To find these papers, you can check academic journals like "Journal of Machine Learning Research," "Neural Information Processing Systems (NeurIPS)," and "International Conference on Machine Learning (ICML)," or platforms like arXiv, Google Scholar, and ResearchGate. Additionally, following key AI research labs like OpenAI, DeepMind, Facebook AI Research, and university research groups can provide insights into the latest developments.

The long history and dominant ecosystem on x86 makes containerization more seamless today. ARM64 support is evolving quickly but still has maturity gaps that can make safe and efficient container deployment more challenging. Careful testing and validation is required.