HN user

pkcsecurity

307 karma
Posts9
Comments28
View on HN

I think the problem with vector search is that it’s unbounded - is the 3rd result relevant at all? What about the 4th?

On top of that, I believe it’s clear with how Cursor and Claude converged on regex search after using vectors that asking LLMs to come up with similar terms to regex is more effective than searching for the user’s original term over a vector db.

It’s not just “seen as a bad deal by the company” - a business can’t give 100% of the value back to the employee because it has this pesky thing called “profits” it has to worry about :)

This is a pretty interesting approach.

We've been doing a similar pattern already, because we have our web app iframed and communicating with outlook (via Office.JS) and gmail (via InboxSDK.JS) in order to read changes to the To: field and insert contents into the compose page based on that:

* stimulus encapsulates the javascript logic that "bridges" to Outlook and Gmail, including initializing the To: field listener * stimulus actions can trigger the "bridge" as well

It's worked out very well - though I really hate dealing with native stuff in general - especially compatibility nightmares with older versions of Outlook. Probably less of a problem with iOS/Android.

Comment on the timing of this IPO: for a company to IPO "unfavorably" compared to previous valuations likely means ARM's hand was forced by timing considerations, unless they are running out of cash, which I don't think is the case.

My interpretation of this is that their investors suspect that whatever boost ARM is getting from AI optimism will likely peak soon, so the timing has to be now.

I know that's not fully rational because they're mostly unrelated, but certainly the optimism because of AI has to be good for them. Curious to see if this "signal" plays out - investors tend to be pretty savvy about timing.

What counts as “remote access”? Another device authenticated to Wi-Fi? Another device anywhere on the internet, with knowledge of the device ID? Another device anywhere on the internet with knowledge of email address?

These are vastly different criticality levels.

All the talk of IOCtl and assembly/bytes in the in the ButDefender report implies “another device on the Wi-Fi”, but I know wyze cams can be viewed over-the-Internet, ostensibly proxied via Wyze’s own servers, so maybe not?

I think part of that is the architecture and environment of the museum. They spend tons of attention to the high ceilings, sense of awe (a bit like a cathedral), and that can make all the difference compared to viewing something in your bedroom in the dark.

Moxie makes so many good critiques (some are so subtle, it might be worth a second read). I got the sense he’s trying very hard to be even handed and constructive about a situation he feels pretty badly about, but his true feelings are bleeding through in some of the side points / parentheticals.

One point that I disagree with is his almost axiomatic premise that decentralization is an inherent good and the implication that the Internet went wrong because it failed to stay decentralized. To hint at great cryptography as the solution, as he does im his conclusion, is baked deep in his bones as an amazing cryptographer, but I think he’s prescribing the wrong cure. The problems with the Internet are fundamentally not about decentralization - they’re about trust. It’s a people problem, not a technology problem. Because of this, cryptography (I do not mean crypto) simply cannot be the answer - even the best cryptography is, like a great legal system, only capable of dramatically reducing the overhead costs and risk of operating in a given environment. When it comes to what great cryptography can achieve, I think HTTPS and maybe some E2E stuff that’s happening with Signal is as good as it can get (interestingly, HTTPS is good in large part thanks to Moxie) - it cannot bring us back to some golden Internet age.

PKC Security | Senior Developers | ONSITE | Full-time | Huntington Beach, CA

PKC Security is a software consultancy focused on solving impossible problems. Custom software, MVP's, and design sprints are our primary offerings at this time. Cybersecurity has become a smaller part of our offerings, but we still definitely do code audits and white box penetration tests.

We're going through a growth spurt right now and are looking for developers. We're focusing on using Node.js in the backend and React.js in the frontend as our go-to, but are always in search of the best tool for the job in general. Due to this there are less specific technical requirements as to experience with certain stacks, and we are looking for strong developers in general.

Check us out at www.pkc.io, or if you're bored, try our "Choose your own adventure" game at https://game.pkc.io. We built this at one of our monthly in-house hackathons!

Finally, feel free to reach out to our hiring team with any questions at jobs@pkcsecurity.com - please attach your resume and cover letter if you intend to apply for a position!

PKC | Huntington Beach, CA | Full-time | Onsite |https://pkc.io

PKC is looking for a Senior Frontend Developer with experience in React. You will be a critical member on our team of high-caliber, driven individuals. We value responsibility, learning, and ingenuity. We will be asking you to mentor our engineers and help them make wise decisions in our front end code.

PKC is a consultancy focused on helping visionaries achieve positive social impact. Our mission is to “solve impossible problems”, which we define as constrictive, coercive, and complex. We use our combined talent and creativity to accomplish this for our clients.

Just a few of our benefits - Monthly hackathons - Challenging work in a supportive environment - Healthy work/life balance - Professional development - Unlimited vacation - 100% Company sponsored medical, dental, and vision insurance for you, spouse, and dependents - SIMPLE IRA 3% company matching

To learn more about our company, please visit www.pkc.io. Or, if you're just bored, checkout our "Choose your adventure" game that one of our hackathon teams built recently at https://game.pkc.io/

PKC | Huntington Beach, CA | Frontend | Full-time | Onsite

PKC is looking for a Lead Frontend Developer.

PKC is a consulting firm that solves impossible problems. These impossible problems require high degrees of freedom in the work environment to come up with right solutions. If you've been itching to stretch your creative muscles and implement unique solutions, we'd love to chat.

We don't have specific requirements for the role, but you should have significant experience, be prepared to take ownership of decisions, and be an expert in modern frontend frameworks.

To apply, or inquire further, please email jobs@pkcsecurity.com and feel free to checkout our website at www.pkc.io

Another great crypto resource (though it's really an intro course) that's out there is the Cryptography course on Coursera: https://www.coursera.org/learn/crypto. It's taught by Dan Boneh who, in addition to being a genius, also happens to be incredibly talented at explaining crypto concepts in a way that leads to deep understanding. It's a great treat watching him write out and explain different proofs from memory.

After taking these two crypto courses, I signed up for CS155 https://crypto.stanford.edu/cs155/, which is his undergrad class on security at Stanford (they were offering it through their professional center, I don't think they still offer it, which is a bummer)

PKC Security | Senior Architect | Huntington Beach, CA | ONSITE, FULL-TIME | $160-$200k | https://pkcsecurity.com

PKC is looking for an experienced Senior Architect who loves to code but would also enjoy leading our growing team of excellent computer scientists and help us lay rail for an all-clojure toolset that we will be building out and sharing with the larger Clojure community in the near future. This job is a good fit for you if you enjoy mentoring and teaching the finer points of production-level Clojure, but also still enjoy getting your hands dirty and writing excellent code. There’s a more detailed job description here: https://angel.co/pkc-security-1/jobs/361725-senior-software-....

Location: on-site in Huntington Beach, California (we’ll cover your move): $160k-$200k/year base, depending on experience.

Benefits: - Strong entrepreneurial, empowering, and moral company culture - Make a major contribution to the Clojure ecosystem - Work with other excellent engineers - Work on interesting computer security problems

More about us: PKC was founded in 2014 and is located in Huntington Beach, CA (Southern California). We are a custom software firm that builds secure, cutting-edge software to solve our clients’ most wicked problems. Our work spans across the fintech, e-commerce, NGO, and education spaces. You can find out more about us and peruse our blog here: https://pkcsecurity.com

If you are interested, email Mike at jobs@pkcsecurity.com with your resume and any questions you may have. You should hear back quickly!

Hi All,

PKC (https://pkc.io) is looking for a Senior Clojure Architect who can lead our growing team of excellent junior+mid+senior computer scientists and help us lay rail for an all-clojure toolset that we will be building out and sharing with the larger Clojure community in the near future. This job is a good fit for you if you enjoy mentoring and teaching the finer points of production-level Clojure, but also still enjoy getting your hands dirty and writing excellent Clojure. There’s a more detailed job description here: https://stackoverflow.com/jobs/173809.

Location: 🇺🇸 on-site in Huntington Beach, California (we’ll cover your move) : $160k-$200k/year base, depending on experience Benefits: Strong entrepreneurial, empowering, and moral company culture Make a major contribution to the Clojure ecosystem 100% PPO Health/Dental/Vision Work on interesting computer security problems

More about us: PKC was founded in 2014 and is located in Huntington Beach, CA (Southern California). We are a security-focused, custom software firm that builds cutting-edge software to solve our clients’ most wicked problems. Our work spans across the fintech, e-commerce, NGO, and education spaces. You can find out more about us and peruse our blog here: https://pkc.io.

If you are interested, email Mike at jobs@pkcsecurity.com with your resume and any questions you may have. You should hear back quickly.

Hi All,

PKC (https://pkc.io) is looking for a Senior Clojure Architect who can lead our growing team of excellent junior+mid+senior computer scientists and help us lay rail for an all-clojure toolset that we will be building out and sharing with the larger Clojure community in the near future. This job is a good fit for you if you enjoy mentoring and teaching the finer points of production-level Clojure, but also still enjoy getting your hands dirty and writing excellent Clojure. There’s a more detailed job description here: https://stackoverflow.com/jobs/173809.

Location: 🇺🇸 on-site in Huntington Beach, California (we’ll cover your move) : $160k-$200k/year base, depending on experience Benefits: Strong entrepreneurial, empowering, and moral company culture Make a major contribution to the Clojure ecosystem 100% PPO Health/Dental/Vision Work on interesting computer security problems

More about us: PKC was founded in 2014 and is located in Huntington Beach, CA (Southern California). We are a security-focused, custom software firm that builds cutting-edge software to solve our clients’ most wicked problems. Our work spans across the fintech, e-commerce, NGO, and education spaces. You can find out more about us and peruse our blog here: https://pkc.io.

If you are interested, email Mike at jobs@pkcsecurity.com with your resume and any questions you may have. You should hear back quickly.

PKC Security | Senior- engineer | Huntington Beach, CA | ONSITE, FULL-TIME | $120-$160k | https://pkcsecurity.com

PKC Security is a small, elite custom dev shop. Our engineers build cutting-edge, innovative products to solve our clients’ most wicked problems. Our work spans across the fintech, e-commerce, NGO, and education spaces. We are looking for a senior dev who can lead other excellent, experienced engineers. We need someone who is capable of making tough engineering decisions on the fly for greenfield projects, and then guide a team to implement them effectively. We offer great benefits and have a strong, empowering company culture. Our company’s mission is “to make new ways in the wilderness for the weak to know truth and live free.”

Our stack is Clojure + reagent for web and mobile, and Heroku or AWS with terraform for DevOps. Knowing Clojure is not required. We have also been known to experiment with other randomly assorted languages, frameworks, and infrastructure :)

If you are interested, email Mike at jobs@pkcsecurity.co

PKC Security | Mid- or Senior- engineer | Huntington Beach, CA | ONSITE, FULL-TIME | $120-$160k | https://pkcsecurity.com PKC Security is a small, elite custom dev shop. Our engineers build cutting-edge, innovative products to solve our clients’ most wicked problems. Our work spans across the fintech, e-commerce, NGO, and education spaces. We are looking for a strong mid-level dev or a senior dev who can lead other excellent, experienced engineers. We need someone who is capable of making tough engineering decisions on the fly for greenfield projects, and then guide a team to implement them effectively.

We offer great benefits and have a strong, empowering company culture. Our company’s mission is “to make new ways in the wilderness for the weak to know truth and live free.”

Our stack is Clojure + reagent for web and mobile, and Heroku or AWS with terraform for DevOps. Knowing Clojure is not required. We have also been known to experiment with other randomly assorted languages, frameworks, and infrastructure :)

If you are interested, email Mike at jobs@pkcsecurity.com with your resume and any questions you may have!

PKC Security | Mid- or Senior- engineer | Huntington Beach, CA | ONSITE, FULL-TIME | $120-$160k | https://pkcsecurity.com PKC Security is a small, elite custom dev shop. Our engineers build cutting-edge, innovative products to solve our clients’ most wicked problems. Our work spans across the fintech, e-commerce, NGO, and education spaces.

We are looking for a strong mid-level dev or a senior dev who can lead other excellent, experienced engineers. We need someone who is capable of making tough engineering decisions on the fly for greenfield projects, and then guide a team to implement them effectively.

We offer great benefits and have a strong, empowering company culture. Our company’s mission is “to make new ways in the wilderness for the weak to know truth and live free.”

Our stack is Clojure + reagent for web and mobile, and Heroku or AWS with terraform for DevOps. Knowing Clojure is not required. We have also been known to experiment with other randomly assorted languages, frameworks, and infrastructure :)

If you are interested, email Mike at jobs@pkcsecurity.com with your resume and any questions you may have!

PKC Security | Mid- or Senior- engineer | Huntington Beach, CA | ONSITE, FULL-TIME | $110-$140k | https://pkcsecurity.com PKC Security is a small, elite custom dev shop. Our engineers build cutting-edge, innovative products to solve our clients’ most wicked problems. Our work spans across the fintech, e-commerce, NGO, and education spaces.

We are looking for a strong mid-level dev or a senior dev who is as passionate as we are about working with other excellent, experienced engineers. We need someone who is capable of making tough engineering decisions on the fly for greenfield projects, and then guide a team to implement them effectively.

We offer great benefits and have a strong, empowering company culture. Our company’s mission is “to make new ways in the wilderness for the weak to know truth and live free.”

Our stack is Clojure + reagent for web and mobile, and Heroku or AWS with terraform for DevOps. Knowing Clojure is not required. We have also been known to experiment with other randomly assorted languages, frameworks, and infrastructure :)

If you are interested, email Mike at jobs@pkcsecurity.com with your resume and any questions you may have!

Our team used Om for our app (balboa.io) for the first 3 months of development. We switched to Reagent and have been using that for the last 8 months.

We ran into the same problems with Om as the CircleCI guys, specifically: 1) our front-end data model wasn't complex enough to merit a heavy-weight data access system that required a huge amount of extra digging to get right. We spent far too much time arguing about how to structure app-data, and it only got worse as the app got more complex. The cursor system in its first iteration was just too cumbersome (for exactly the reasons this author states). We kept trying to restructure the data model in order to get it to do what we needed. To be fair though, this is well known, and David Nolen has done a lot to alleviate this in recently releases (ironically by making it more Reagent-like). 2) our app is end-to-end encrypted and requires pulling down potentially hundreds of blobs, decrypting them, and inserting them into the dom. Under these conditions, Om would kick it and the UI would grind to a halt.

We switched to Reagent, and found that it was far faster and "got out of the way" of development. Add-watch is amazing too. Our app is quite large (front end SLOC is around ~50k lines), and Reagent has scaled beautifully and is a beast at large-scale insertions (on the order of 1000).

Om has some delightful features (undo ability is very powerful, routes coupled with Secretary is also great for Om), and David Nolen is a genius, but I think even the author has to acknowledge that the app-data/cursor construct is more of a pain than it's worth...

Hi HN, Balboa dev here,

Just as a bit of background of where we're coming from: we've been working on Balboa for the past year or so, after realizing that there wasn't a good end-to-end collaboration product out there that we felt we could use with our clients. In terms of how we're a "Slack alternative", we think Slack is a fantastic product, especially in terms of workflow, so we decided to model our chat interface off their good work. As you'll quickly see, we're not nearly as feature-rich at Slack at this point (nor are we aimed at the same audience). Features that define Slack, like search, are harder to pull off in an end-to-end system, but they're areas of growing research, and we're excited to try our hand there.

Also, we wanted to just give a shout-out to some technologies we've had the pleasure of using:

1) Clojure. Our entire backend is in Clojure, and our frontend, Clojurescript.

2) Zerotier. A great and simple way to get our backend services to talk to one another with end-to-end encryption.

3) Emscripten/Asm.js for transpiled, fast in-app crypto.

4) Skein/Threefish and TweetNaCl.

5) Cassandra and Redis for our data store and key management, respectively.

6) ZeroMQ for communicating between our services.

Thanks to all involved in the projects above who are helping us get to secure collaboration!

Thanks! Yeah, the major motivation behind this was to fill in some missing gaps in the documentation. There unfortunately is a bunch of incomplete and/or inaccurate info that's out there (maybe because the spec is still in flux).