HN user

reagent_finder

262 karma
Posts0
Comments54
View on HN
No posts found.

Don't disagree with anything there.

There's no reason they couldn't do both, really. They could have spaces for traditional ads, and they could have those direct partnerships.

Direct partnerships might be nice in theory, but it will always require a separate decision and process from the company to partner with Reddit. Considering there are hundreds of different avenues people could be advertising on, I'm guessing Reddit is kind of low on the list.

The biggest problem with Reddit is that their only source of revenue basically demands you to create a completely new ad for ONLY that platform. For everything else you can just make an iframe, drop whatever malicious blinking crap you want, send it to the wild and let ad networks sell and resell space and sometimes drop your ad in it, pay pennies for clicks and even less pennies for each time it's been served.

They haven't tried to enter any ad ecosystem, haven't tried to monetize the massive amount of creativity or anything on the platform. Granted, it's really hard to say "Hey, we've shown your news article to 10 million people, pls pay us" when the news site itself is struggling to get any revenue from those millions of clicks. Not to mention the site might have a question reddit reeeeallly doesn't want to answer "So, was it in a neo-nazi subforum or a porn subforum?"

Yeah, there's just been nothing in ten years. An IPO at this point is nothing but a cash grab awaiting the death of the platform.

I feel that's pretty disingenuous. Like you noticed the server-side code is active, and changing server address would be a niche-of-a-niche activity. Also, what would be the point of going after Signal's servers? Even if a/the government got a hold of all the data in there, it's encrypted with client keys. I mean sure, if they took over secretly and became a malicious MITM that's different, but it's still only for any future messages, not history. Not to mention I'd be inclined to believe they'd get the word out.

Signal's research and protocol is already used in, well, basically each and every discussion/video platform. WhatsApp, Telegram, Skype, Facebook Messenger, Google Messages, Duo... so it's hard to see Signal becoming more ubiquitous. Seeing the app more will probably happen naturally when events happen (like the WhatsApp privacy change) to drive people towards more secure platforms, but honestly I don't really see a major shift anytime soon.

Apparent timeline:

2018 Nov: Company breached, seems most likely database of 40,000 mental health records including PII (duh), contact information and treatment history and notes was stolen at this time.

2019 Mar: Another breach. This causes Vastaamo to increase security and close the holes the hackers used.

2019 Apr/May: Independent security company (not named) performs audit since the company was to be sold. Some improvements were suggested, no major security flaws were found.

2020 Aug/Sep: Vastaamo receives threat from hacker if they will not pay 40BTC the hacker will release the database. Until they do the hacker will release 100 records per day.

2020 Sep/Oct: Infosec company Nixu researches Vastaamo systems, reporting that the breach that stole the database was probably made in November 2018, possibly single records in subsequent breaches.

2020 Oct: Individuals whose information was not in the already-leaked records have been contacted and extorted individually.

After that, in no particular order:

* 300 records have been leaked. The hacker seems to have stopped, though.

* Single records not included in the 400 have surfaced on TOR web

* A site on TOR was up for a while with several similarly-named files, one a 10GB tar that is rumored to be database. Partial downloads have been reported. Edit: Also program snippets etc included, with possible 'digital fingerprint' according to Mikko Hyppönen, a well-known Finnish security expert.

* An IP address related to the hack has been traced to Inkoo, Finland.

CEO claims the 2020 Nixu report was the first time he heard of the breaches and that's why the new CEO or board were not informed -- which seems awfully sus, considering several breaches were made and a reactionary battering down the hatches as well as an external audit were made.

Further, people who work or used to work at Vastaamo have come out claiming toxic work environment, threats of lawsuits if they speak out against the company, bad working conditions and a large number of ethical violations (like using as advertisement names and reputation of people who don't work for them). It also appears they've been sending social security numbers in plaintext over email. Claims have also been made that the database and system were outdated and only had default passwords and no real attempt at securing the data or even servers have been made, but of course nothing is public yet. Possibly never will be.

All in all, looks like the previous owner is a bona fide scumbag with all the bells and whistles that entail. And, of course as is fashionable, when asked about these things his responses have been "I have no knowledge of that" and "I do not recall." And, of course, affected people have found out about this from the news and not Vastaamo themselves.

My heart goes out to the people affected, it takes courage and effort to start working out mental health problems and this has probably been a devastating blow to many.

Oh man, THANK YOU for this. What an amazing article!

He grew up on Manhattan's Upper East Side, the son of a pioneering necktie manufacturer, James Lehrer

That's just hilarious. I can't think of anything more appropriate than a necktie manufacturer family.

In any case, if anyone is unfamiliar with Tom Lehrer, I encourage you to take a wiki dive and then listen to his music. This guy taught mathematics at Harvard, then accidentally sold 10,000 copies of a vinyl of his songs in a few weeks, then went on to tour the US and the world.

His works remain some of the brightest, most convivial, most haunting and poignant works of song to date. He sings clever happy songs of things like pollution, patricide, nuclear holocaust, arson, murder, racism, plagiarism, criminal boy scouts, disease and crime in Mexico and, of course, the eternal desire of the common man to poison pigeons in the park.

Like "Weird Al" Yankovic says in that article, Tom Lehrer remains the modern Tom Lehrer today. There's just no one like him and the way his songs have remained so relevant up to this day is something I find myself in awe of. He just... took a look at society, grokked it on a primordial level and wrote songs that I will end up teaching my kids and they'll go "Wait, they had these things 80 years ago?"

EDIT: Also, OP title is wrong, Lehrer simply released his LYRICS to the public domain. My copy of "Too Many Songs by Tom Lehrer" with musical notation remains relevant, yay!

I was going to make approximately this point. However, I think it's also important to have some of those "shut up and trust me" phrases codified and have them available for the layman via Google. Because sometimes those people demand "proof" or they'll go searching for it themselves and if it's right there to be found and most major sources agree... well, the discussion can then be "Is this just obscurity where security is needed?" AS IT SHOULD BE.

If you get right down to it, passwords are just obscurity. Usernames are just obscurity. In this very thread people are dismissing port knocking while it's functionally equivalent to a password.

I will personally stand by "security through obscurity is not security" forever because that way we can get to the actually interesting question -- what level is needed for this service?

Let's take a simple example from the public Internet -- you want to share something. So you put it on a server with Apache. You add TLS and PFS. You hide it in a folder structure somewhere. You add a single-use token or just htaccess.

Any of those individually would be obscurity, but put together they are most likely more than enough for... well, anyone. So is it still obscurity or actual security? That's a debate for the ages, but I think most people would agree all of those put together are fine-ish, but pick just one method and it's just obscurity.

This whole thread is basically just a philosophical debate where half the people haven't read the article, the other half disagrees with minutiae in the article, the third half disagrees with major points of the article, the 4th half is sharing anecdotes and the 5th half just wants to participate.

Pretty much each point raised in this post(?) are correct, current and relevant even 26 years later.

POSIX is a monolith and really deserves to be improved. It's been around forever, yes. It will probably keep on being around forever, yes.

    Take the tar command (please!), which is already a nightmare where lower-case `a' means "check first" and upper-case `A' means "delete all my disk files without asking" (or something like that --- I may not have the details exactly right). In some versions of tar these meanings are reversed. This is a virtue?
Raise your hand if you've never broken Grep because the flags you gave it didn't work. Anyone? Congratulations, you've worked on a single version of grep your entire life. Have a cookie.

Pretty much the only consistent grep flag I know is -i. There's never been a standard for naming and abbreviating flags, which means that for EACH program you will have to learn new flags.

This becomes truly terrible when you get around to, say, git and iptables. Have you ever tried to read git documentation? It is the most useless godawful piece of nonsense this side of the Moon.

There's Google now, which means that the fundamental design issues of POSIX will probably never get issued. "Just google it and paste in from stackoverflow" is already standard, and people are already doing that for 5-10-year-old code/shell commands. What about 10 years from now, will googling best DHCP practices still find that stupid post from 2008 that never got actually resolved? How about 20 years?

I have honestly no idea how to even start fixing the problem. A proper documentation system would be a start.

Additionally, they point out that A True Story was written in response to another work that also contained science fictional elements, that is Antonius Diogenes’ lost Of the Wonderful Things Beyond Thule, whose protagonist also reached the Moon.

Well no, it's the earliest SURVIVING work. It's certainly interesting and a fascinating insight to how people have always looked to the stars.

Also, it was the one that got lucky and remains. I guess have to give it credit for that.

I actually got used to the mobile web, it's okay IMO. Certainly better than the new web layout.

What's terrible is the beta tests they constantly run on small variations of the populace, without your knowledge and without any way of giving feedback. They honestly don't give a crap.

They also actively hide the ways to give feedback and ignore it when it's given.

That said, it's someone's day job to clock in, fiddle with the mobile web UI according to manager and C-level concerns and clock out, with the occasional "So what is it that you actually do here?" meeting. I'd probably stop giving two shits after a month or so.

Really, Brad? Software Engineers need a hippocratic oath?

This is the most hypocritical, low-minded dirty blow, pass-the-buck mentality I have seen in a long time. That's even counting most of what Trump has said. You should be ashamed of yourself, Brad.

How dare you make that remark when your WHOLE PLATFORM is built on shady business practices and monopoly leveraging? How dare you try to shunt the blame on software engineers when YOU YOURSELF profit from lack of ethics and participate in systematic blacklisting of engineers? You earn seven figures a year AT LEAST and are trying to blame people just doing their jobs, and telling them they should look at the big picture and they should "have principles" to basically refuse to work or quit? While at the same time actively preventing these kinds of people from finding ethical work elsewhere?

Put your money where your mouth is or stop spewing Trumpian bullshit, Brad. Anybody who buys this needs to have their head examined. With a cactus.

Actually, you're the target group. The Wii-WiiU-Switch are all based on "hey, that looks neat, let's try it" with a massive number of games designed for the casual crowd.

People like you aren't vocal in gaming communities or anything but boy do you buy games.

The disconnect becomes obvious in cases like Pokemon Sword/Shield where the community was OUTRAGED about a number of things (some complaints valid, some less so), threatening boycott... then the game comes out and sells millions in the first day. Do you realize that most people don't go to r/switch, r/nintendo or r/pokemon daily? Who knew!

You should try Zelda: Breath of the Wild or Mario vs Rabbids: Kingdom Battle, they're single player games and a lot of fun.

Egg-and-chicken debates aside, I can absolutely see this. In any reasonably-sized town or city you'll find a dozen similar establishments a walking distance away. So while you might debate picking between the 3.5 and 4.5-star ones, the restaurant with 1-2 stars is just not going to draw a crowd.

Bitwise hacks in production code? Seriously?

This is a nice gimmick to show off in an interview because the interviewer is definitely not going to get it, however it might backfire because the interviewer might realize a) you'll be out to get his job b) you might actually want to put stuff like this into production.

The idea is solid, don't get me wrong, and clever code is always clever code. Also like u/kevingadd mentions, the principle behind the thought is an important one, knowing when and how to handle data in bulk since you are looking for a needle in the haystack. For instance SQL and streams in Java are places where you need this kind of thinking.

But please, for the love of Gord, never put this bit of code in production.

"N^2 is bad, except when it isn't" is my take on it.

In uni I maybe had one week of doing O-evaluations, it never came up and I never got interested. I've seen 20,000-word debates on Reddit on whether something is n, n2 or logn... and to my knowledge nobody ever learned anything from those.

In the workplace I've several times ran into the problem of "This is taking way too long," developing tools and methods to measure and drill down, then figure out if it can be improved upon or should be left as-is for now.

Honestly discussions and articles like this leave me absolutely terrified of interviews. My first and only technical interview was my future boss leaving me alone for 30 minutes in a room with a laptop "Code something you like yourself."

That man was brilliant.

It's a "foot in" problem, I feel. Shit companies have shit interviews and give out shit workloads to MAYBE get a foot in the door.

You can follow along or be proactive, for instance start a new github account just for interviews, do code wars challenges, write a blog and just link your writeups, github and blog to applications. Along with your CV with major projects etc. of course.

Most people I know who work at big firms got calls from friends or friends of friends to interviews, so spending time socializing the local hacker circles is probably going to be worthwhile as well.

If you have life, hobbies and family, you should still be able to schedule 1-4 hours a week to job hunting, much more if you don't have a job of course.

It's not pretty or much fun, but it's certainly doable.

Not the worst approach, and as long as it's in the spirit of cooperation might even be good.

UX people could tune or at least comment on the interface, security people could fuzz or pentest the library... however, for a lot of actual problems in actual open source libraries it requires a crapton of internalization -- again, for free. Granted, it's for open source but it could be argued it's even WORSE approach for the company, since they're getting free benefit from expertise and work.

Also, I'm a private person, I have splintered online identities, I'm not going to give my 'hobbyist' github account in a professional context, and I'm also certainly not going to make a github account just for interviews and applications.

I'm lucky enough to have connections that will probably keep me employed as long as I like, and the tales of interviews and free work that's required to put up just to get a chance seems insane.

4 hours... okay, I can sort of see that, I might set myself a limit of 1 hour and tell them this was my approach, this was how far I got. I've heard of 30-60 hour workloads given to applicants to 'top five' companies and it's just ridiculous. As are the stories of interviewers who have no technical skills themselves and are just looking for a canned response (Google, looking at you).

I was going to say that the best approach I've seen are companies that put up interesting puzzles and security challenges on their website. The technical skills required aren't _that_ high, but certainly require an amount of ingenuity, persistence and just plain being interested in tinkering that they feel suits their company profile. The applicants can solve or try to solve these challenges, do writeups and probably get interviews just based on those.

Granted, I can also understand someone looking at 50 companies all giving them 4-10 hour workloads to MAYBE get an interview might feel frustrated and overloaded. It's a classic egg-and-chicken problem. If I were to start looking for a job from scratch I'd probably solve a bunch of code wars challenges and security CTFs, make a blog and just link my writeups and blog to applications.

"Reasonable" is a stretch, "interesting" is the right word. Personally I'd put this in the "Oh, huh" box along with quantum crypto. It's interesting, it's complex and it's got way too many engineering hours behind it... but ultimately for 99% of people or even 99% of computer scientists or HN readers, it's just fascinating trivia.

I absolutely appreciate these posts, this guy spent WEEKS delving into the depths of SnapChat just for the joy of discovery.

Maybe a good classification would be that part 1 is detailing a number of obfuscation techniques and the key thing to take away is that all of them CAN be bypassed.