HN user

vabmit

1,236 karma

https://vab.mit.edu/

Posts29
Comments117
View on HN
venturebeat.com 6y ago

ProtonMail takes aim at Google with an encrypted calendar

vabmit
355pts145
protonmail.com 6y ago

ProtonCalendar beta

vabmit
157pts1
twitter.com 7y ago

Gab.com Booted from Hosting Provider Due to User Account

vabmit
63pts110
blog.mozilla.org 7y ago

Mozilla Announces Experimental Partnership with ProtonVPN

vabmit
167pts91
protonvpn.com 7y ago

Proton and Mozilla Partner for Privacy

vabmit
35pts12
protonmail.com 8y ago

OpenPGPjs v3.0

vabmit
199pts44
protonmail.com 8y ago

ProtonMail Security Advisory Regarding Yahoo Hack

vabmit
3pts0
protonmail.com 8y ago

Basic Tips for Preventing Email Hacking

vabmit
1pts0
protonmail.com 8y ago

ProtonMail Now Supports Bitcoin Payments

vabmit
336pts183
protonvpn.com 9y ago

ProtonVPN

vabmit
24pts11
protonmail.com 9y ago

Important lessons from the first NSA-powered ransomware cyberattack

vabmit
2pts0
protonmail.com 9y ago

CIA Leak – End Points Targeted Not Encryption

vabmit
5pts0
twitter.com 9y ago

ProtonMail Launches ProtonVPN in Closed Beta

vabmit
5pts2
protonmail.com 9y ago

Introducing ProtonMail's Tor hidden service

vabmit
322pts103
www.scribd.com 12y ago

Indictment: 13 Anon Members for Op Payback

vabmit
1pts0
rt.com 12y ago

Snowden: UK GCHQ Paid $150MM by NSA

vabmit
1pts0
keyserver.cryptnet.net 13y ago

Edward Snowden PGP Pubkey Wired Used

vabmit
5pts0
tech.mit.edu 13y ago

Aaronsw evidence to be released within 88 days

vabmit
4pts0
analysisintelligence.com 13y ago

Temporal Signatures of Hacker Organizations

vabmit
2pts0
www.the-digital-reader.com 13y ago

Amazon Bought Liquavista - Color Kindle to Follow?

vabmit
3pts1
www.ft.com 13y ago

CFTC Considering Bitcoin Regulation

vabmit
3pts1
web.mit.edu 13y ago

Swartz Incidents Prompt MIT to Boost Network Security

vabmit
7pts3
digitalshingle.mit.edu 13y ago

MIT Start-Up Directory: The Digital Shingle Project

vabmit
2pts0
www.media.mit.edu 13y ago

A remembrance of Aaron Swartz (March 12th)

vabmit
63pts9
www.facebook.com 14y ago

ValueYahoo: Leadership Change Social Media Campaign

vabmit
1pts0
www.blueseed.co 14y ago

The Blueseed Project - Opening Silicon Valley To The World

vabmit
75pts33
www.bloomberg.com 16y ago

Google to Trade Wholesale U.S. Electricity

vabmit
5pts0
web.mit.edu 16y ago

MIT report reveals biotechnology funding troubles

vabmit
2pts0
blogs.harvardbusiness.org 16y ago

The Digital Economy's Coming Subprime Crisis (AdRev Problems)

vabmit
5pts1

RIP, Dan. I work with a lot of very smart people. So, I've gotten a bit used to it and don't normally find myself in awe of many people's intelligence. Dan was a person that I was absolutely in awe of. The fist time I met him very long ago (almost 20 years), he showed me code he wrote to share movies through abused DNS slaves... building a p2p network like Napser/Gnutella from the technology. No one had ever thought of such a thing. I don't think anyone else in the world knew DNS well enough to be inspired to think of it. He was so kind and friendly to everyone. It was fun to talk with him about tech/security because he had such enthusiasm and excitement... like a little kid on Christmas or a puppy. :) I learned a lot from him. I have nothing but great memories of him. I remember once when someone hacked him. He even took that in good humor and didn't let it bother him.

Possibly. There is very little to no private funding for true privacy products. I think this is one of the reasons that Proton had to initially rely on crowdfunding. Perhaps, this is because so many tech companies are stuck in the AdRev mindset where sharing customer private data is how they make their real money? If you look at the ecosystem, you see many privacy products are actually government supported either directly or indirectly. For example, the Tor Project has directly taken massive amounts of funding from the US Military and you may recall the story of how Microsoft was forced to buy Skype in order to open it up to surveillance or lose massive amounts US DoD software license contracts. Those are just two examples. But, there are really limitless cases. Trust Google? But, Google receives massive DoD/EU contracts. Apple? Same thing. Role your own? But, nearly all standard encryption and hashing algorithms were either developed by or reviewed by government funded academic researchers in the US or EU.

The way I think of the privacy ecosystem is that it makes dragnet surveillance much harder and it provides some protection if the government has specifically targeted you for data collection. So, companies/products like ProtonMail and ProtonVPN are good things. But, creating something that is 100% safe for the individual is impossible (or at best so impractical to be untenable).

This tactic has been used against companies friends of mine have started. I've only seen it used by large 20+ year old 1970s/1980s publicly traded companies, never someone like Tesla. The way it works is basically that you track where your ex-employees go after they leave. If they go to a competitor/disruptor start-up with out deep pockets, sue that competitor over trade secrets. It's nearly impossible to disprove in court. The competitor start-up exhausts its VC/Angel money on legal fees and goes bankrupt. Potential new customers are wary of using their tech because of the lawsuit. It's a lethal combination that ensures that you don't have to out innovate them. Stealing source code is one thing. I certainly understand suing over that. But, suing over stealing ideas about warehousing from a car company? Really? I don't see any justification for that other than a lack of faith in the ability of your own company to compete and innovate.

Full disclosure: I am shorting TSLA stock. I have worked on autonomous vehicles and do not believe Tesla's claims about their technology. I expect Tesla to go bankrupt sometime in the next few years. I'm even more convinced of this now that I see them using company-killer lawsuits against other competing start-ups.

OpenPGPjs v3.0 8 years ago

What do you mean "ProtonMail still doesn't support PGP"? You mean sending PGP encrypted e-mails to non-protonmail addresses?

OpenPGPjs v3.0 8 years ago

In case anyone that doesn't follow the development of the library closely missed it, the main improvement in this version is the introduction of ECC support. ECC tends to be able to provide equivalent levels of security as traditional "big prime" cryptography (like RSA) with less computationally intensive operations. This is especially important in a library like OpenPGPjs that is primarily meant for in browser based web usage because it should make things, like sending and receiving mail, faster when ECC is used over older PGP public key encryption systems. For people that use ProtonMail's web based crypto on mobile or tablet devices, a switch to ECC would result not just in similar performance improvements but also in lower battery usage.

Currently, ProtonMail uses RSA keys, but this addition of ECC support to their web encryption library may mean that they are about to start switching users to ECC keys. Because using "larger" (when compared with equivalent theoretical strength RSA keys, for example) ECC keys is less resource intensive than using higher security keys in some other forms of cryptosystems (like RSA) it may also be an indication that ProtonMail is preparing to upgrade users to higher security/stronger keys.

Many cryptographers and organizations, including the US Government, have recommended for a long time that people migrate from older "big prime cryptography" based cryptosystems to ECC based cryptosystems for increased security.

I wouldn't say no one. There are a number of companies that trust Bitcoin enough to use it in trade for their goods and services. For example, ProtonMail (a secure private e-mail provider) trusts Bitcoin enough to accept it in trade for its services.

So, the same thing that gives the Euro and Gold value (that people will take it trade for goods and services) is one of the components accounting for Bitcoin's valuation. The majority of Bitcoin's value at this point is likely speculation. However some percentage of the value is not derived from currency arbitrage or speculation.

Even if Bitcoin trade participating merchants do not trust the market valuation of Bitcoin enough to be willing to hold Bitcoin for very long after they accept it as part of a transaction (and therefor immediately convert it to USDs) it is still valued by the participating merchant in line with the trade. The same could be said for the value of the electronic ledger recordings created by credit cards. They are generally viewed to have around equivalent value to USDs. But, they are not a currency either.

ProtonMail | Multiple Positions | Geneva, CH; San Francisco, CA; etc | https://protonmail.com

Senior Software Engineer (Front-end/Back-end/Mobile/Desktop)

Location: Geneva, Zurich, San Francisco, Prague, Macedonia, Lithuania, Ukraine

Description:

Javascript (ES6, AngularJS, React, etc), PHP, Python, Objective-C, Swift, Java, Go, .NET, and several other languages. Strong background in computer science (algorithms, data structure, software design, reliability, maintainability, etc).

Network Engineer/Systems Engineer/Site Reliability Engineer

Location: Geneva, Zurich

Description:

You will be responsible ensuring our infrastructure remains reliable and can scale quickly enough to match our growth.

Networking: BGP (IPv4/IPv6); MPLS; Cisco IOS; Netflow analysis; NOC experience; LIR experience; Network design

Sysadmin: Large Scale Linux Administration w/ Ansible; OpenStack, CEPH, MySQL, Python/Bash/C/SQL

We will hopefully support ZCash in the future. But, unfortunately, we don't right now. I am a member of the ZCash forum, though. I have been keeping a close watch on the project/coin and am very impressed with it. I don't know anything about Monero. I either hadn't heard of it before or just didn't give it any attention after seeing it because of the flood of coins lately. Thanks for the pointer and endorsement of it - I will take a look at it when I have a chance.

Try to relax a bit. It is good for your health. :) Both of those features are under development. If you would like to see them sooner rather than later, perhaps you know some great programmers that you could recommend to careers@protonmail.ch? Or, you could share ProtonMail's Careers page: https://protonmail.com/careers

ProtonMail is hiring!

Something similar happened to my dad. He had a pretty successful company providing security guard services mostly on government contracts. It wasn't very lucrative. He wasn't rich. But, it paid the mortgage and the bills and my siblings and I were well taken care of. Then, when I was around 9 or 10 or so, Wackenhut kind of raised a lot of money and became the Amazon of security guard services. They Amazon'd his company and everything he built just kind of slowly disappeared over the next couple years. He could have done OK getting a job as a security guard himself and working his way up or even changing careers (he was reasonably intelligent). But, something about his company failing broke him and he just kind of never did anything after that. My teen years were absolute chaos until I dropped out of high school and got a job driving a fork lift around 17 and moved out. I remember there being absolutely no food in the house for days and days. It was crazy.

I've had a bunch of friends/acquaintances that killed themselves (hung/shot/jumped off the GG) after their start-ups failed. But, they all did it during the first boom (90's). I haven't personally known anyone that's done it during this boom, yet. I think the difference might be that the bubble hasn't popped yet this time. People who fail can still easily go find work. Back then all the companies were laying people off. So, if your start-up failed there was basically no where to go but back home. Probably the majority of the people I knew in SFBA back when the bubble popped did that. It was crazy how suddenly highways that were packed with traffic could just be cruised down at the speed limit during rush hour with out touching your breaks until you got to your exit. It seemed surreal.

Well, side projects are different. I wouldn't really call them start-ups. I'm talking about a VC funded start-up or a start-up whose goal is to eventually be VC funded. You have to be all-in on that kind of thing or you will not be successful. That is so much the case that it is actually written into the Terms Sheet (funding contract). Usually, it says something like "100% of professional/employment activities".

It's not as important to be in SFBA as it used to be. But, it is still a major factor in success. I consulted for a start-up that had to move there despite not wanting to just because the potential employment pool was so poor in my area (Boston). In SFBA, $40K/yr to $50K/yr is probably not enough to cover just rent, taxes, and utilities. You still need to worry about food, transportation, health insurance, etc. And, you'd have to convince other people to join your "start-up" that was only a part time hobby for you. Attracting the first employees is one of the hardest parts because that is when your ability to cover their paychecks is most uncertain. I imagine it would be very hard to do if they see you're not all-in and absolutely convinced the company was going to be successful. And, who the first employees wind up being is one of the most risky parts... hire the wrong people and you're done.

I know a lot more people that founded a start-up and did not do well than I know people that did. The stories about the failures are usually not that bad (but some are terrible). A joke among that circle of friends and I is that a start-up is basically a really really expensive job application to a more successful start-up that someone else pays for.

I encourage people to apply to YC. Because, I believe entrepreneurship is good and the people I know that did well did very well. But, be honest with yourself - Do you have wealthy parents/a wealthy spouse/close friend? Will they support you while you get back on your feet? If so, for how long? That's a discussion you can have with them and get a verbal commitment before you just go for it.

I had a good long-time friend, that I was supportive of, start a start-up and fail. He wound up sleeping on my couch for an extended period of time. We're around the same age... I have health insurance, a pretty fat 401K and IRA, a vested pension, an emergency fund, and a lot of seniority at my job. He does not have those things.

As you get older, the choices you make now will look like they were very very different choices. Don't romanticize them- really think them through.

I think there's some truth to the family support part of this. I was just racking my brain trying to think of any founder I knew (and I know a ton of them) that was in the position of "success or potentially homeless". But, I can't. I think there's some variable confounding going on when YC and others talk about people in their early 20's being better positioned to do startups because they're less risk averse due to youth. I think they're less risk averse because it's not such a big deal for them to move back in with their parents if they fail. And, their parents are usually still working and therefor able to handle the strain of that.

Nearly every successful founder I know of had either very wealthy parents, very supportive family and friends, or both.

I don't see any shame in admitting that it's not about some romanticized risk taker ideal alpha geek, but rather about upper class kids lucky enough to have a bunch of built in risk arbitrage supports that they lucked out on being born with.

The most recent information visible in search about this guy's company shows he was making a little over $20,000/year. A recent traffic related arrest of someone with the same name as his in the same area where he is reported to live shows a residence in a cheap beach condo high rise in a low cost part of southern Florida.

All that misery he put out into the world and he probably only made around $20K/yr (probably from mentally vulnerable/disabled populations). Have any of you ever actually purchased a cruise vacation from a robo-caller that spammed you in the middle of the night?

Caller ID is a completely unauthenticated protocol. The system asks you what number you're calling from and you can tell it anything you want. It just believes you.

Contrary to what other people said, you don't need a special line or to involve a specialized company. Almost all opensource VOIP systems allow you to spoof caller ID with a configuration setting or a little scripting/programming.

It's not illegal to spoof caller ID in the US. Many companies spoof a main call-in number from all of their employee's desks. Some morally bankrupt companies like the New York Times have been found to spoof invalid phone numbers when they harass people through their phone system.

These robo-callers call my cellphone at all hours of the day and night. It really reduces my quality of life. I have to have my phone on at night because I'm perpetually on call. There was a span of nearly a month where I was woken up between 1AM and 3AM by someone telling me I won a cruise vacation.

Caller ID spoofing is probably the technology that best shows how poor engineering when thinking through communication protocols can have a massive negative impact on the world.

Caller ID spoofing is also the technology that allows people to "SWAT" celebrities all the time (using just a home PC) with virtually zero chance of ever getting caught.

The kind of odd thing is that these robo-calls have programmed such a gut negative reaction in me to anyone calling me that I will now go to great lengths to not do business with any company that calls me on the phone. Due to getting unrequested phone calls from them, I've dropped a domain registrar, an x86 server manufacturer, and an insurance company. One voice call is all it takes and I am done with the company... even if it is during business hours. I just cannot, and will not, work with a company that calls my personal cell phone with out first being asked to.

ProtonVPN 9 years ago

Search has been dramatically improved. Difficulties with large mailboxes are often a complex function of many variables with things like client side javascript decryption speeds often playing a large role. While testing is done with large mailboxes as part of the development process, the ultimate solution for people with extremely large boxes will likely be the use of the Bridge program with an IMAP mail client such as Microsoft Outlook. There are unofficial export programs available that call pull all mail out through Proton's API. An official, supported, export (and import) program is planned for the future.

ProtonVPN 9 years ago

Please report your difficulties to the Support Team: https://protonmail.com/support-form You don't need to be a paid user to do this. They will respond to your ticket. I have done this before - some time ago. But, perhaps a bug was introduced somewhere in the code or there is some other issue that you are running into (perhaps some configuration with the local platform). It should be possible and work correctly.

ProtonVPN 9 years ago

ProtonMail would be happy to implement more of the OpenPGP encryption standard. Specifically, it would be great if someone would contribute ECC support to the opensource OpenPGPjs project that ProtonMail currently maintains. There are just not cycles to do it internally, right now. ProtonMail is far from idle. A number of new features and offerings are being worked on. For example, take the bridge application (currently in beta testing) that will allow integration with IMAP based applications like Microsoft Outlook.

If there's something that is a high priority for you personally to see (such as OpenPGP ECC algorithm support), I would ask that you take the time to submit it to the ProtonMail UserVoice page [ https://protonmail.uservoice.com/forums/284483-feedback ]. That page is monitored and the feedback received through UserVoice is considered and strongly influential. UserVoice has a great end user application and clarification effect that is difficult to experience through interacting with users through e-mail or traditional forum comments.

I don't believe I've seen the Reddit exchange that you are referring to (I don't personally visit that site very often). If someone using an official company account was rude to you, I sincerely apologize.

Bridj shuts down 9 years ago

The buses that they are currently using hold just over 50 people. I made a very conservative guess for how many people would leave the existing bus service. There are more than 10 bus trips each morning down Interstate 93 that could be considered "commuter" (400-500 people): http://bostonexpressbus.com/images/stories/schedules/I93.pdf

There are similar bus schedules from the next city over to the west, Nashua, down Route 3 and another similar schedule from the next city over to the east, Portsmouth. There are additional bus companies that service different cities and towns in Massachusetts. However, they all go to the bus station on the south side of the city.

You would have to lease the buses. The drivers would be the most expensive part of the model, though. There is a shortage of people with commercial licences in this area. The drivers can make anywhere from $45K-$60K per year in salary (not counting benefits). Brijd had already purchased shuttles/buses and had drivers. The Brijd buses were much smaller - probably 25 to 30 seats. But, had they discovered the potential business model early enough they could have bought different vehicles. There is enough demand in the area to deploy double decker buses (80-100 seats). I, and probably many others, would pay a significant premium over the existing $315/month to load/unload on the north side of the city and avoid the additional hour of commute and MBTA subway pass costs.

It would be much more difficult that a cloud based software start-up due to the capital outlays. But, it could definitely be done and be profitable.

Bridj shuts down 9 years ago

It seems like they did fail to really analyse the potential in the Boston market. I live in Southern New Hampshire and like nearly everyone that doesn't hold a minimum wage job here, I work in Boston and commute into the city every day (because the New Hampshire corporate tax system is terrible). The commute is an absolutely miserable experience.

I used to drive but finally gave it up when my employer changed the way they compensated commuting expenses. Now, I take Boston Express Bus which costs me $315/month. The buses are always over full. There's probably about $100K per month for the Bus Company just in work day commuters. They also do a large number of air port runs through out the day.

The problem with the buses is they go to a train/subway/bus station on the south side of the city. But, many (if not most) of the commuters work on the north side of the city. So, they have to buy an additional $65/month subway card and waste an additional 45-75 minutes a day travelling through the congested city to get to and from the buses. Using the subway system in Boston is even more miserable than driving because it is horribly managed and badly maintained. Most riders would love to avoid it.

Instead of doing local uber-like shuttles in a city already over served by subway and bus routes that compete with each other (in additional to taxis, uber, employer shuttles, etc), Bridj could have charged $350-$500 per month per person to do a run from southern NH with a Kendall Square drop off and pick up. People would have loved it. Similar routes could have been set up from the South and and West. I think they easily could have done $300,000 to $600,000 per month in revenue with that model.

It's a shame they didn't take a good look at the market. The roads in and out of Boston are hopelessly overloaded. They could have made a ton of money and improved people's quality of life significantly. I assume many other large cites (SF, LA, NYC) are the same. Employers locate in the large cities and don't pay their employees enough to live in the cities. That is a problem calling out for a business like Bridj to address.

ProtonMail | Multiple Positions | Geneva, CH; San Francisco, CA; etc | https://protonmail.com

Senior Software Engineer (Front-end/Back-end/Mobile/Desktop)

Location: Geneva, Zurich, San Francisco, Prague, Macedonia, Lithuania, Ukraine

Description:

Javascript (ES6, AngularJS, React, etc), PHP, Python, Objective-C, Swift, Java, Go, .NET, and several other languages. Strong background in computer science (algorithms, data structure, software design, reliability, maintainability, etc).

Network Engineer/Systems Engineer/Site Reliability Engineer

Location: Geneva, Zurich

Description:

You will be responsible ensuring our infrastructure remains reliable and can scale quickly enough to match our growth.

Networking: BGP (IPv4/IPv6); MPLS; Cisco IOS; Netflow analysis; NOC experience; LIR experience; Network design

Sysadmin: Large Scale Linux Administration w/ Ansible; OpenStack, CEPH, MySQL, Python/Bash/C/SQL

Unless things have changed recently, YC leverages former YC founders to do the initial application review. The founders that participate are from both currently operating companies and companies that closed or exited. So (if the review process has not changed in the last few years) there is a chance that a senior individual at a startup or an employee at a larger company that competes in the same space will see the details disclosed in the answers to the new questions about an applicant company's financials.

The goal of providing a tor gateway is not to protect the contents of the messages from being traced back to a specific ProtonMail account. It's also not to prevent the contents or metadata of those messages from tripping dragnet surveillance programs (such as PRISM). The goal of providing a tor gateway is to protect the individual, through their IP address, from being associated with the ProtonMail account and the metadata and contents of messages sent to and from that account.

For example, say that an individual would face a death sentence for religious preaching activity in the country where they live. They are unconcerned about people discovering the content of their messages or whom is receiving them. But, if they are discovered to be the person responsible for them they would likely be killed. Their sending of the messages through ProtonMail would be protected from observation by ProtonMail's TLS w/ PFS HTTPS encryption. But, their local ISP or government could observe all of their traffic. They could then, through traffic correlation, determine that specific individual was sending encrypted packets to ProtonMail's servers at the exact time various messages were sent. Using Tor would protect this individual's identity. The observers could determine tor traffic and attempt to correlate that with messages if they suspected the individual. But, if he was generating additional tor traffic by running as a relay or browsing other sites with tor the correlation would be extremely difficult.

The reason that ProtonMail set up the .onion site is because accessing ProtonMail over congested exit nodes that may be far from ProtonMail's servers is very slow. The .onion site has dedicated bandwidth directly to ProtonMail's webservers and is located close by in Switzerland. It should be expected that it much faster for users to use the .onion site than exit nodes to access ProtonMail.

ProtonMail's verification requirements are determined by a complex system of IP reputation and other factors that are analysed in realtime when the sign up page is rendered. As an e-mail service, one of the most challenging things for ProtonMail is preventing abusive accounts from damaging the service's SMTP sending IP addresses' reputation to the point where deliver-ability becomes impossible with other e-mail service providers. This is especially difficult for e-mail providers that work to deliver privacy, and potentially pseudoanonymity, to users.