HN user

nookiemonster

61 karma
Posts0
Comments25
View on HN
No posts found.

Drama.exe

There's this thing called sequestration going on that's disrupting the budgets of all the federal agencies.

The feds are cutting budget for ridiculous things like the blue angels.

But they're totally going to be maintaining the budget for hacker cons in Las Vegas.

This is all about street cred for defcon & nothing to do with "taking a break." Jeff Moss is too sophisticated to be throwing away all those relationships. This is a stunt circle jerk.

Mobile operators have to certify devices, even if they don't include them in the portfolio.

This is a consequence of commitments to a country's spectrum management organizations.

If an operator expresses commitment, I would take this is a very important initial step, but not necessarily an indicator of full blown embracement of a platform. Operators will schedule time for a device to go through their certification labs. This means that a device can get approval from the regional spectrum bodies for qualifications that ensure the device doesn't interfere with authorized spectrum devices. Lab certification is not free- the operators are eating a cost. But certainly it's not the same thing as buying pallets of devices and trying to sell them to consumers.

Something I didn't understand at 18 (that I do at 35) is that your 'enemies' may be dealing with things you simply cannot understand.

If a coworker is belligerent to an 18 year old, they are assholes. To a 35 year old (at least to me), the first thing I think of is that I have no idea what their home life is like.

People endure crazy life experiences. I am working with them on a problem that results in revenue for both of us. Just because we're making money, doesn't mean that they're dealing with problems of personal identity, cancer, financial ruin, etc.

Age matters, kid. It fucking sucks. It's cool that you're punk rock about this. But you will achieve more & achieve faster when you realize that age really does matter.

(p.s.- age is not a way to measure wisdom, but it is a wisdom indicator)

On windows mobile 6.0, you could send wap pushes that linked to signed apps which would auto-execute/install.

right now, there aren't any vulns which are similar in danger that I am aware of. SMS isn't a super friendly medium for stack manipulation, and most modern mobile OS'es implement ASLR.

The browser is the more likely vector today.

I work for a carrier. People simultaneously depend on our services and actively hope for our demise. So I hope you understand the context when I say you need to thicken your skin.

The motivation for an attack is irrelevant. Threats are things that need to be planned for appropriately in a business plan. Pretending the entertainment industry is not as ridiculously overpowered relative to the revenue it generates only works with the hyperbole you have injected. Well done, but I am not falling for it.

I doubt your friends are as naive as you. So if it is any solace, you should find great comfort in the fact that the industry is sophisticated enough to survive for a few more paltry tablescraps for the next 20 years or so.

+1

I can only use trello for mumdane work tasks or personal work if there is no self hosted solution.

This decision is a mistake, Joel. I love trello, but i cannot trust a hosted solution with my plans for taking over a market. Please give us an installable version. anything else is amature hour or naive.

Code signining is a control that is intended to restrict the software that can run to only those apps which have been granted the right to run.

Your second question is a good one, but given is context, it is unrelated. If apple signs a python interpreter, they do so at their peril, for obvious reasons.

Charlie is one of the founders of the controversial "no more free bugs" movement.

The amount of skill necessary to identify AND exploit bugs is so great that the bug reports themselves have value,far beyond attribution in the patch notesand a T-Shirt. This is especially true when there is in fact a lack market of bad people willing to pay good money for 0 day vulns.

thus, reporting vulns that way doesnt necessarily make sense. Charlie's walking a fine line: He is not a BadGuy, but he also isn't giving away security consulting to companies with 200 billion market capitaliazations. Apple should pay him good money to look at this stuff. Otherwise, its going to be only BadGuys.

Defcon is cheap to attend. You should go sometime and get a feel for the event. If a trip to Vegas is out of your price range, go check visit Hot Topic. You'll get the proper feel.

The Defcon crowd is awfully touristy. I mean that professionally.

In fact, it's far more the marketing success of defcon that should get attention from hacker news. They have been building quite an empire over the last 19 years.

Well positioned: 1) They have a constrained ecosystem which could insure that the quality experience for apps is better than the current average in android apps

2) I haven't owned a wp7 device for over a year, so I don't know where things are now, but for the months following launch, the apps were a crapshoot & expensive. There were no angry birds, no hipstamatics, etc. Twitter, Facebook & that's about it.

So the quality problem I am referring to is akin to the choice between walking into a flea market (Android), a Nordstrom (iPhone) or a jc penny (windows phone 7).

Platforms that tightly coordinate with carriers were highly successful in the previous mobile cycle (prior to wm 6.1- so anything before 2008 really).

The model has changed, however. Today, it's android & iphone that are driving the industry forward. These are platforms that don't coordinate as tightly with carriers.

Frankly, RIM's problem is that their leadership is stuck in the old model. There was a generation of senior executives in the mobile industry who truly knew better than the nerds: Regardless of your passion for development & openness, it was the carriers who make or break you. RIM's risk now is to replace one extreme attitude with another extreme (too open, too independent) and then completely self-destruct.

IMO, the key to success is not anything listed in this letter. They need to reboot their leadership structure with folks who understand that a good relationship with carriers is critical, but you don't cling to them for survival. Android & iPhone are vulnerable in this space. They're spending too much time giving carriers the finger.

IMO, the only company that really has a shot at relevance is Microsoft: They're still playing nice with carriers & they have an incredibly easy development environment, but they're also exploring territory that hasn't been authorized by the carriers.

In the sense that they're 'failing', they're failing because they're not nurturing the development ecosystem with funding. If Microsoft set aside 50 million dollars or so for investing in INTERESTING mobile application developers, they could solve their appstore app quality problem and really make a move on the industry. Microsoft should take advantage of the fact that the carriers aren't thrilled with Apple or Google. They're really well positioned to strike, if they can just get the app quality problem solved.

"Android phones are available for free from carriers."

I can't find a way to interpret this statement and have it be true.

There is no fee to use the o.s. The devices cost the carriers a great deal. They purchase them in bulk from the oems and then sell them to customers. The cost is then recovered over the life of the contract.

This is why it's hard to know exactly how many windows phones are active in the ecosystem. The only public data is the bulk sales to carriers by oems.

Wrt your other points, I don't have any nits to pick. :)