HN user

sp_

514 karma

http://twitter.com/LambdaCube Android Security Team

Posts1
Comments77
View on HN

I co-manage https://hackerone.com/googleplay and the top contributor there probably makes 5x - 10x of an average software engineering salary for his home country.

Not a lot of hackers care about Android app security so there's barely any hackers participating and little competition. Most apps have never had anybody do a security review.

Additionally the scope of the program is so wide that you can look through hundreds of apps from companies that have no security posture at all. Finding bugs is easy and payouts are more than generous.

Great summary! By nature of my job (eng lead of a major mobile malware detection team) I have a lot of startups pitch their ML solutions to me. A couple of thoughts:

- There are no publicly available data sets for training available. There are a few small ones and a few old ones, but they don't reflect the reality of 2016. Companies that approach me and pitch me solutions to the malware of 2012 are not useful.

- The majority of mobile malware is based on some kind of social engineering. On a code level these are indistinguishable from legitimate applications (the same APIs are used in the same fashion). The only difference is whether app behavior meets user expectations or not. Making this decision automatically seems intractable so far.

- Malware is not really a well-defined term. There is phishing, toll fraud, Trojans, privilege escalation exploits, ... If you generically look for malware, the signals you will look for are going to approach the complete set of APIs made available by your OS. Your results will just be a giant blob where everything is connected. Pick a single malware category and focus on just that at a time. ML signals for priv esc will look very different from those for phishing.

- ML is sexy. Malware analysis is not. Startups seem to hire too many ML people and not enough malware analysis people. I've had startups pitch to me that had literally zero people on staff who knew what mobile malware actually looked like. They just did anomaly detection and then tossed the results over to my team to verify the results. That's not how it works. We're not your QA team. :)

I've had the exact same experience with Vint (https://www.joinvint.com/) - Go through personal trainers until you find one you like and then move off the app. The hourly cost will be lower but the personal trainer will still make more money.

I've also had Uber Black drivers give me their personal limo service business cards. The difference is that a cab is a commodity while a personal trainer is something that needs to click on a personal level.

I see no future for Vint even though I loved it when I used it.

I got the silent treatment twice when trying to interview at Yahoo and once with Google. In all cases it was at the stage between initial recruiter contact and agreeing on a date for the first phone screen. I later found out (by looking up the recruiters on LinkedIn) that both of the Yahoo recruiters had left Yahoo and now worked at Apple. Ever since then I started wondering how big the impact of recruiters turnover is on candidates getting stalled.

They do report the actual wage. Except that's the employer can choose to specify it as a range between a minimum and a maximum. This is optional, it's also possible to specify just one number.

We probably used the same dataset but when we developed, most DoL database dumps were 404 links and so salar.ly only has data for 2011 and 2012.

I sent an email to the DoL to fix their links but haven't heard back yet.

It's the actual wage data. Actually it's the maximum number of the range that an employer can report to the DoL.

Source: I am one of the two people behind the site and for my two H-1B visas the maximum salary that was reported for my visa was what I got paid.

About 2: You would have to copy the overwritten bytes to another place in memory to execute them later. As the length of x86 instructions is not fixed you would need a whole disassembler to find out what bytes belong to what instruction. Easier to have just two bytes you can overwrite at will. Saves the hassle of calculating how many bytes you need to copy.

No reference, but I'm a H-1B holder and I file FBARs. I am part of a German Expat forum and the opinion there is pretty cut and dry that H-1Bs have to file. Every year that forum has a big thread to make sure everybody is aware of it. Having my savings confiscated for screwing up FBAR reporting is literally my number one fear I have about living in the USA.

The first one was definitely a mantra of the Google-acquired start-up I used to work for. My boss was unhappy with existing software in our field of expertise, so we set out to build something that makes us happy, not other people. It helped that we (especially my boss) knew more about the field than nearly all of our customers, so our customers bandwaggoning on our software was not surprising to me.

I worked on the technical side of the RSA attack analysis and not the attribution/political side but some guy on Twitter (https://twitter.com/yuange1975) who pretends to be Chinese has claimed responsibility for the RSA 0-day and some other high profile 0-day exploits on his Twitter feed in a way that makes him the credible original source of those exploits.

I am sure the people on the attribution side dug deeper than this (for example they most likely tried to verify that this guy is really Chinese and not just pretend-Chinese) but I don't know anything about the non-technical side of things.

This is exactly why I moved from Germany to the US. I was tired of being on the end of the salary bell curve at international conferences. Higher salary and lower taxes mean that my disposable post-tax income is now 3.5 times what it was in Germany. And I am not even in the Bay Area yet!

From my point of view, the situation for software developers is particularly bleak though. You don't have to move to the United States to do much better. Going to Switzerland or Luxembourg is pretty good too.

I don't know about an NBA player that did that but Brazilian football player Marcelinho did that while playing in Germany. Despite having a seven-figures salary he was broke all the time and had to ask his club for loans because he financed the lives of literally dozens of his friends and family members.