HN user

tomashertus

1,324 karma

Building Cybersecurity Products for Fun & Profit

https://twitter.com/tomashertus

Posts120
Comments213
View on HN
www.facebook.com 5mo ago

Messenger.com is no longer available for messaging

tomashertus
6pts3
www.euronews.com 9mo ago

Poland's president signs zero income tax law for parents with two children

tomashertus
10pts5
github.blog 9mo ago

Using Markdown as a programming language when building with AI

tomashertus
2pts0
economictimes.indiatimes.com 10mo ago

Trump to impose new $100k fee for H-1B visas

tomashertus
9pts1
www.sec.gov 11mo ago

Netskope Has Filed for an IPO

tomashertus
4pts0
www.calcalistech.com 11mo ago

Palo Alto Networks closing on over $20B acquisition of CyberArk

tomashertus
13pts3
github.com 2y ago

Tracking of Threat Actors Use of AI

tomashertus
2pts0
twitter.com 2y ago

Invision is shutting down at the end of this year

tomashertus
3pts0
www.dea.gov 2y ago

Emoji drug code decoded by DEA [pdf]

tomashertus
3pts1
www.forbes.com 3y ago

Robinhood is cutting 23% of its staff

tomashertus
3pts1
lots-project.com 4y ago

Living Off Trusted Sites Project

tomashertus
2pts0
world.hey.com 4y ago

DHH: The time is right for Hotwire

tomashertus
2pts0
www.businesswire.com 4y ago

NortonLifeLock and Avast to Merge

tomashertus
3pts0
techcrunch.com 5y ago

Thoma Bravo buys cybersecurity vendor Proofpoint for $12.3B in cash

tomashertus
1pts0
www.sfchronicle.com 5y ago

S.F. pays $61k/year for one tent to shelter the homeless

tomashertus
55pts27
www.msspalert.com 5y ago

Privacy Seekers Are Looking for Life Management Platforms

tomashertus
4pts0
techcrunch.com 5y ago

Datadog to acquire application security management platform Sqreen(YC W18)

tomashertus
10pts1
nikesh-50783.medium.com 5y ago

The Hunger Games – Advice to Leaders – Driving Innovation

tomashertus
1pts0
www.reuters.com 5y ago

Justice Department accuses Facebook of discriminating against U.S. workers

tomashertus
5pts0
sec.report 5y ago

C3.ai's S1

tomashertus
3pts0
www.ruby3.dev 5y ago

Why the Release of Ruby 3 Will Be Monumental

tomashertus
18pts10
www.twitch.tv 5y ago

AOC plays Among Us live on Twitch and has 330k viewers

tomashertus
28pts8
news.ycombinator.com 5y ago

Ask HN: Best practices for monitoring of 3rd party dependencies

tomashertus
2pts0
www.brendanfraser.com 5y ago

Original Brendan Fraser's personal website from 2004 is still up

tomashertus
2pts1
www.ft.com 5y ago

Warren Buffett’s Berkshire Hathaway to Invest $570m in Snowflake

tomashertus
1pts0
lukekanies.com 6y ago

Founder of Puppet on bootstrapping, burnout, and babies

tomashertus
3pts0
www.zdnet.com 6y ago

Ransomware deploys virtual machines to hide itself from antivirus software

tomashertus
7pts0
www.matthewball.vc 6y ago

Esports and the Dangers of Serving at the Pleasure of a King

tomashertus
3pts0
en.wikipedia.org 6y ago

Sun Gun

tomashertus
3pts0
www.cnn.com 6y ago

Iranian teen shocks chess grandmaster Magnus Carlsen

tomashertus
19pts0

Just guessing, Czechia? The Central European software engineering market seems to be softening as well, likely due to second-order effects from the U.S. tech layoffs and decreased demand for remote roles from SV companies.

Claude Design 3 months ago

Are they, though? My thinking is that their roadmap is heavily focused on the SDLC and solving problems related to software development, so their model will be optimized for that domain. That leaves room in the market for models that are specialized in other areas of expertise.

These decisions always depend on the lifecycle of the product. I assume that at Basecamp’s level of maturity, where it has reached a certain saturation point and growth and usage are fairly predictable, it makes perfect sense to make a strategic decision like this and commit to a long-term bet.

Regardless, kudos to DHH and team for being so vocal about it, it's a great case study for product teams in similar lifecycle.

This is a bit of a puzzling "announcement". Does anyone have more details on what’s actually changing?

I don’t really use Facebook itself anymore, I’ve mostly kept Messenger for messaging. Curious whether this is an attempt to push users back toward the main feed experience.

The article is surprisingly missing the most important part: a cost comparison. I understand and share the frustration with rising prices and ads creeping into paid plans, but for people who value optionality and broad access, streaming is still meaningfully cheaper than owning content.

In many cases, the price of a single movie is comparable to an entire month of a streaming service, which gives access to thousands of titles. Ownership can make sense if you repeatedly watch a small, fixed catalog over many years, but for most casual or exploratory viewing, the economics still favor streaming.

[dead] 8 months ago

Can we remove this? While this war is a horrible tragedy, I’m of that opinion that we should not discuss geopolitics on this site unless it’s directly impacting the core topics we are all here for.

It’s too soon to know, but this could make 3-year H-1B renewals hugely problematic. That would be a major blow to the program. I was fortunate to get mine in 2014 without a single problem. There’s no way I’d expect someone to get through this process today. And realistically, most companies aren’t going to pay such a large premium just for a typical software engineer.

It’s ultimately a numbers game. The more malicious seeds are planted, the higher the likelihood that one of them will be pulled into a real-world build pipeline. Platforms like GitHub, NPM, and other open repositories are ideal staging grounds because very few engineering organizations are willing to block traffic from them. That makes them near-perfect hiding spots for malicious content.

And the asymmetry is stark: attackers only need to succeed once. It takes just a single developer installing a compromised package to trigger a breach with potentially massive downstream consequences. So while I agree that quantifying impact is critical, dismissing large-scale seeding campaigns because “no one might have downloaded it” ignores the risk.

This is a surprisingly common issue. In my day-to-day work, we analyze millions to look for malware, and it’s well-known in the security community that attackers frequently leverage “trusted” websites to host and deliver malware as an evasion tactic.

The technique is so pervasive that I did an extensive research on it. In fact, there are several well-funded and widely used applications, some generating millions in revenue, that unknowingly host malware on their infrastructure. In more concerning cases, these platforms are even repurposed as command-and-control servers for data exfiltration. We're increasingly seeing enterprises take the proactive step of blocking traffic to these high-risk domains entirely to strengthen their security posture (e.g. it's completely common to block all traffic from network to Dropbox or other file hosting services).

To illustrate this in dollar terms, consider an acquihire exit. At 1% of $10 million, the acquihire nets the Founding Engineer around $100,000, enough to buy a nice Tesla. Meanwhile, the founders net $4.8 million, enough to buy a house in Palo Alto, a small yacht, and two nice Teslas.

I stopped reading after this paragraph. Why to take advice from articles that is presenting delusional scenario about the returns? $100k after tax is good enough for Model 3.

Heh, a couple of years ago, I had an idea for an "Uber for Experts." It would provide a similar experience to Uber, but instead of a ride, you'd get 30 minutes with a domain expert of your choosing. I never got around to working on it, but there might still be an opportunity for something like this.

In my day-to-day work, we analyze millions of files every day, and it's well-known and well-utilized detection evasion techniques to host and serve malware from "trusted" websites. It's so widespread that I did extensive research on that issue. There are well-known apps with $Ms in funding and revenue with a plethora of malware hosted on their servers. Some are even used as C2 servers for data exfiltration. I see an increasing number of companies proactively blocking all traffic to those notorious sites to increase overall network security.

The outcome of my research was the following:

- Disjointed content moderation and cybersecurity departments: Not many companies have content moderation teams equipped to perform malware analysis or make cybersecurity-related decisions (the only company that does an exceptional job in this regard is Meta).

- If hosting malware doesn't impact the company's revenue and reputation, the content moderation team has other priorities.

- Section 230: Companies will refer to Section 230 when asked about hosting malicious content or scanning the content for potential malware.

I use Github's Trends (https://github.com/trending) for discovery, and for all other searches, I use their search and tags. It never failed me to find what I was looking for. The star system already provides you with ratings for open-source projects, and Github's search has powerful filtering. I don't anticipate a general need for such a project.

If you are junior developer interested in learning development or a specific technology, it would be great project to build and open source though.

These are exciting times in the cybersecurity industry with the recent growth of open-source security tools (osquery, Fleet, Wazuh, etc.). Anyway, I'm skeptical about the detection efficacies, usefulness, and scalability of those products. I do not see them widely adopted either. These are my observations from your pitch:

Your pitch mentions large costs for traditional SOAR products and that you want your solution to be focused on smaller companies that don't have money to pay for expensive SOC tools. Nevertheless, the market reality is that if a company has a SOC team (who is the traditional end-user of SOAR tool), they don't care about $100k for a SOAR because they will spend hundreds of thousands a month for log storage, security tools, and HR. It's much more common for your target audience to use ITSM as a security incidents management tool. Just look at what ServiceNow is doing in this space for example: https://docs.servicenow.com/bundle/washingtondc-security-man.... Based on this one fact, I think that you didn't spend enough time understanding your target customer who are in this case not SOC/Security teams, but IT teams.

Incident management is a critical process for every SOC team and its effectiveness is tracked by measuring the mean-time-to-resolve metric. How do you want to convince SOC teams to use open-source tools for their mission-critical process rather than buying one of the established SOAR tools that are integrated with their security stack? (& there are many options in the SOAR space) How can your product help companies lower the operational costs of case management? (improving the mean-time-to-resolve KPI)

Please, don't get discouraged by my comments. SOAR is an essential part of every security stack and the current offerings have flaws. But the narrative in your pitch is flawed and indicates a lack of understanding of current security buyers and personas.

I understand and agree with your point that you can't just "buy" cybersecurity by throwing money at the problem. It's more like building a well-defended castle, where multiple elements work together to create true security. Cybersecurity is a company-wide process that needs to be powered by specialized tools.

The fact that one of the fastest-growing markets is omitted by YC is shocking to me. The opportunity to build $1B companies, which seems to be one of YC's acceptance criteria, is enormous.

I don't know how far or close you are to the security field, but I do share your sentiment that many tools and so-called security solutions are useless and don't solve the problem. So it's now even more necessary to go and build new solutions. The problem persists and grows.

I apologize, but I don't understand your point. Could you please explain to me what you mean by that or how the fact that you "can't buy cybersecurity" contradicts what I wrote?

The cyber security market was valued at USD 153.65 billion in 2022 and is projected to grow from USD 172.32 billion in 2023 to USD 424.97 billion in 2030, so apparently people are buying cybersecurity solutions.

The fact that YC overlooks the dire need for next-generation cybersecurity solutions is quite shocking. In the coming years, cybersecurity, trust, and safety will be essential needs of every customer and enterprise application. For example, the whole fiasco with the spread of fake Taylor Swift's nude images is just the beginning of the exploitation of internet data on an industrial scale. We can already see attempts to commercialize services similar to ransomware-as-a-service that, for a small amount of money, generate atrocious content about every possible person and spread it online automatically. We are on the edge of a new revolution that will bring malicious tools and services even closer to regular consumers and make them more affordable. I think that our cybersecurity tool chain is far from ready for what is coming.