HN user

stephendicato

55 karma

stephendicato.com

Posts2
Comments46
View on HN

WatchGuard Technologies | Full-Stack Engineers | Wakefield, MA | ONSITE | https://watchguard.bamboohr.com/jobs/view.php?id=226

We are looking for two engineers that are interested in helping design and develop new products to help extend WatchGuard's enterprise-grade security to every endpoint. Our customers routinely ask for improved ways to protect employees who work off the corporate network – you’ll be a big part of delivering that solution.

As part of this role, you will work on both the endpoint application and the backing cloud services. You will be part of a small engineering team located in Wakefield, MA (~15 minutes North of Boston) that truly values building high quality solutions to customer's daily security challenges.

To apply, please visit: https://watchguard.bamboohr.com/jobs/view.php?id=226

Percipient Networks | https://strongarm.io | ONSITE | Wakefield, MA | Full-time | Engineering, Marketing, and Technical Sales positions

We are building Strongarm, a cloud-based anti-malware solution that is designed specifically for small and medium businesses. Protecting your business doesn't need to be complicated or expensive!

Please see our hiring page for more information (https://strongarm.io/careers/) or email us directly at jobs@strongarm.io

Percipient Networks | Wakefield MA (remote possible) | Full-time & Summer Internships

https://strongarm.io/careers/

We're building strongarm.io - the best way to stop malware from damaging your business - and are seeking software and operations engineers to help us build and scale our services.

Last summer, we had four successful hires from Hacker News. Now we are looking for a couple more. You'd be joining a small team of passionate engineers and security experts dedicated to helping secure businesses of all sizes. We love Python, Django, and Twisted and run on AWS.

Please email jobs@strongarm.io for more information and to apply.

You're right. I agree. In practice I'd heavily weight the decision based on whatever is best supporting in the Python libraries they are adopting.

Although, Linode's email isn't what notified is, it was our intrusion detection system.

Are you able to elaborate on this? I understand you may not want to name specific vendors/products in the name of operational security but it sounds like in this scenario whatever is in place actually did its job.

To add to that, bcrypt is not the best recommendation if choosing a password hash today. In theory they should be adopting Argon2 (or maybe scrypt).

In practice, I suspect that either the bindings for Argon2/scrypt don't exist or aren't easily adoptable given their use of ColdFusion. They do exist in Python.

Either way, it seems like a sub-optimal decision.

(Full disclosure: I run a service that blocks and intercepts malware communication using DNS! https://strongarm.io)

Blocking via your hosts file has some great benefits; it works regardless of network and is relatively easy to update. Unfortunately, it doesn't scale easily to many systems or give you any insight into whether or not you are trying to connect to blocked domains.

Blocking via DNS is a good alternative and is suggested multiple times in this thread. You can easily protect a whole network by setting your recursive resolvers and it works across any system.

If you are interested in this and don't want to operate and maintain your own DNS (as well as pulling down various domain lists) check out https://strongarm.io. We manage DNS, aggregating lists of bad domains, and (most uniquely) will alert you if you try and talk to a blocked domain.

It's free for personal use. We are a growing startup and love feedback from HN. Feel free to contact me directly as well! stephen[at]strongarm.io

Technology Transfer[1] is one of the mechanisms that enables collaboration between federal labs and the commercial sector.

Caveat, I am not affiliated with YC. However, technology I invented at an FFRDC was licensed by an investment firm. I choose to follow the work, co-found a startup, and focus on bringing the technology to a wider audience. I'm happy to talk about my experiences.

[1] https://en.wikipedia.org/wiki/Federal_Technology_Transfer_Ac...

GitHub is popular. More people will come in contact with the development of Python by Python being on GitHub. That's a significant benefit to any open source project; one that I believe outweighs the concerns of a private company valuing business over developer ideals.

Google Cloud Shell 11 years ago

Ah, makes sense! Thanks for the clarification.

This could be a nice way to isolate operations of production infrastructure. You could go as far as issuing Chromebooks dedicated to the task.

Google Cloud Shell 11 years ago

This doesn't actually appear to be new; at least not that I can tell.

Google Cloud has supported being able to open an SSH session to any of your instances right from the browser for awhile. I've found it to be a killer feature and am really surprised Amazon Web Services does not offer the same thing.

Eat healthy food. Exercise. Get enough sleep.

You will feel better; both physically and mentally. Positive habit leads to more positive habit. Pay attention to how you feel. You don't need scientific studies to prove these things are "good" for you.

Percipient Networks (https://percipientnetworks.com) - Boston/Wakefield, Massachusetts - Full Time (Remote possible)

At Percipient Networks, our mission is to secure your business and prepare you to respond to security threats. Our service, STRONGARM, seamlessly integrates with existing systems and saves you time by automating security operations, discovering compromised systems, and providing in-depth, accurate, and relevant information during an incident to help eliminate threats.

You can read more about our open positions on our site: https://percipientnetworks.com/pages/careers

We are young, small, pre-revenue, and extremely passionate. If you are passionate about cybersecurity and solving hard problems, please contact us.

That quick hack is exactly the approach we've taken with new technical hires this summer. We are a "vagrant up and go" shop, but there are a bunch of steps between handing someone a laptop and running your app in vagrant. We took the time to document the process and used it in onboarding. We made it explicitly clear that if you notice issues, please fix them, which has the intended side effect of familiarizing the new hire with our development practices (pull requests, reviews, etc).

It worked extremely well!

Knowing if your application's dependencies have released security patches isn't just valuable, it's necessary. It's very painful and time consuming to monitor email lists, websites, RSS feeds, and GitHub issues for relevant information.

In my opinion, providing that information in a timely and actionable way, such as telling me when and how to update, is a useful service. When looking for a solution for Python applications I found https://requires.io/. It's a clever implementation since it reads a requirements file and is therefore easy to "deploy" and get immediately value from.

Your marketing leans towards 0-day protection. The challenge is doing anything actionable with knowledge of a new 0-day. Unless there is a patch available, which implies the discloser worked with the project/vendor, or a known workaround in lieu of official patch, how is your service doing to help?

What's your plan for supporting more operating systems, languages, and ecosystems? Are you curating information about security disclosures and software releases, or simply checking if newer versions of packages are available?

Congratulations!

I'm always curious; what drives you to do these challenges? It is the competition? The collaboration? The general enjoyment of solving puzzles?

  not sure how them hosting public projects adds directly to the bottom line
They get a ton of feedback and insight from non-paying users. The usage and feedback can drive both the product and business roadmap for their enterprise offerings.

Every developer who enjoys using it for personal or open source is also likely to recommend it to their employer as well. I know I have helped drive adoption in a few organizations.

If you are familiar with Apple routers and have liked them in the past, I'd say stick with them and buy another.

They perform well, as easy to setup, and regularly receive updates from Apple.

If you decide you want something more powerful, with more features, or generally want to learn more about networking and security, I'd recommend buying an official pfsense device. See: https://www.pfsense.org/

Leave your technology at home and actually meet people. That's the biggest benefit of not having your laptop and primary phone with you.

Granted, the crowds and general culture of the conference doesn't always support this, but to me it's the best part.

Is the issue that there was a lack of technical investment in security or a shortcoming in their ability to communicate with their customers?

I'd argue many of the companies mentioned have invested heavily in security. Whether their investment will prevent a compromise from a determined adversary is likely unrelated to their investment.

Unfortunately, I suspect many of the mentioned companies had not equally invested in how to properly communicate a compromise with their customers.