HN user

pupeno

182 karma
Posts13
Comments53
View on HN

I think for this crowd, haveibeenpwned.com for businesses is the best way to describe Unbreach. It even uses the haveibeenpwned.com API.

In Unbreach, after you signup, you upload a CSV with all the staff at the company (it’ll have integrations in the future) and Unbreach watches them all for breaches. For the owners/managers it provides a dashboard of all the staff and all the breaches showing you which ones are outstanding and which ones are closed. Here’s an example:

https://uploads-ssl.webflow.com/627d527181555e3edd9c2c5a/627...

For the staff, it provides a TODO list, where each breach is a password that needs changing. It looks something like this:

https://uploads-ssl.webflow.com/627d527181555e3edd9c2c5a/627...

Unbreach supports monitoring email addresses that don’t belong to a person (info@ for example) but are supervised by a person that gets the alerts for it.

If you are familiar with haveibeenpwned this might remind you of domain monitoring. It’s similar in that Unbreach monitors many different email addresses. What Unbreach adds on top of haveibeenpwned is the todo-list aspects and the dashboard.

I built Unbreach because I found myself constantly chasing people at the companies I work for to check that they changed their password after a breach. It’s still rough around the edges. If you give it a try and get stuck or something doesn’t work, please send me a message through the bubble on the bottom right and I’ll help you.

Hello HN. I've been working remotely since the early 2000s and managing teams since 2011 or so, mostly remotely (whenever I can). During the pandemic I helped the non-remote parts of my company become remote and then I jumped online to help anyone that I could with the transition (this wasn't a service, I did it for free, it was important to me and the world was hurting).

Out of those conversations I ended up with the table of contents of what then became this book. The writing part of the book is done, most of the proof reading has been finished, and I just sent it to be formatted for print and ebook.

I also bought a bunch of ISBNs and registered my consulting company as a publisher to _self-publish_. I don't know why, but I'm finding the process very interesting. I love learning about how other parts of the world work.

I think the process had two issues. The main one being several steps that though simple, were not specified anywhere, so, figuring them out took a lot of time and phone calls. It's like someone tells you to drive from point A to B, that's easy, but they don't tell you were the car is.

The second problem was a lot of jargon that was in my opinion unnecessary and was internal US government leaking to the end users and you had to learn it to understand the documentation about what to do. Figuring out what SNAP-R stood for took me way to long and it's nothing more than a website registration (from my point of view).

Apple requires the ERN because Apple is very US centric. For Google, there might be cases in which the ERN is not required because the app never leaves the US (because for other countries it comes from other countries).

Apple is required the ERN to cover their asses, I believe. The ERN is required by the US government, so, if you don't have it, you are breaking the law whether you are using Google Play or Apple. So, you should get it for Google Play too.

I talked to the export compliance department at Apple. There's a chance that they say "yes, get an ERN" because they have nothing to lose and it's safer for them and in fact, there's no need for it. But I doubt it. I will consult a lawyer to make sure my whole process is good if people want me to get ERNs from them (an idea some people floated with me).

They don't enforce it at all. Not even the US BIS really looks at your application to approve it as far as I can tell, because mine was approved instantly. They do have a lot of checks to make sure the record of your company and app are somewhat well formed.

When it comes to Apple, they don't check for this, they just want you to be on the record with either an ERN or the claim of no encryption, so that it's not their fault if the US government comes and says "hey, about all those apps you are exporting, are they using munition-level tech?"

This is true, and I think a lot of this applications are breaking the rules. You can easily claim your app doesn't use encryption and Apple will accept it. They don't check to see whether it does or doesn't use encryption. But should something happen, Apple is clear of guilt because they asked you and you would be the one producing a false statement.

I read a lot of blog posts and looked at a lot of information and there's a general advice of "just pretend not to use encryption" or "https doesn't count" which is just wishful thinking from people that didn't want to use ERN and when you go dig deep enough it doesn't hold any water.

I talked to a couple of people at Apple and they explicitly told me that use of HTTPS is not covered under the exception. I think that exception was designed to authenticate licences of software. Programs that phone home, get a toke, and decrypt it to verify you paid for it, but that's just a hypothesis.

Throughout the process I found left-overs from the previous processes and yes, it looked much worse. The worst part for me is that there were steps in the process than though simple, they were not defined anywhere and thus it required me calling various departments to ask for clarifications.

Yes, it does. I talked to legal as well as export compliance department at Apple and they confirmed this. Maybe they were being overly cautious but so was I.

With HTTPS, what puts you clearly out of every potential exception, is the fact that you are encrypting the requests. Someone asked about this in the blog and I replied with more information.

Last year I learned that to publish an app in the App Store or Mac App Store, if it uses encryption of any kind and yes, HTTPS and SSL count, you need an Encryption Registration (ERN) from the US Bureau of Industry (BIS). Some people claim it's fine to lie to Apple, claim no use of encryption and get in the app store. I'd rather do it the right way.

When I started the process of getting the ERN, I quickly notice it was going to be a long and arduous process and that other people could benefit from the lessons I was learning the hard way, so I decided to document it all in a long blog post.

This is probably one of my most researched pieces ever. The whole process took about two months from the start, researching this thing called ERN, to getting the app published in the Mac App Store, satisfying that what I did was (more or less) correct.

Yes, I tend to agree. I'll try to go in that direction. My problem is this: I say "We are a new startup, new product, market validation phase, yada yada", someone ask "Have you had any funding yet?" and reality would be "yes, $NNN, four years ago". When I'm just submitting in sites such as AngelList, where I just enter the information into small little boxes, that looks wrong, without me explaining: we are pivoting from other products that we launched and took us to profitability for the past four years. But I'll look into making that possible.

This was going to be my follow up. To demonstrate competency, you can participate in open source projects. I even got job offers out of my participation.

There are also bootcamp schools that will get you up and running quickly, some even that are free while you are there and they only charge you a percentage of your first year of salary after you finish.

It's never to late and definitely not at 24hs. Read some biographies, yes, some people were rich by 19th, but some struggled for years and years not finding their success or happiness until the 40s, 50s, etc.

Do you like coding?