Don't just have a dedicated area, make it a place you want to work from. It seems obvious, but once you're working from home, it's easy to just cobble together a workspace in a room and call it an "office". Your office should feel comfortable, a place you want to spend a good amount of time in, but is not distracting. At the end of the day, it should also be a place you leave in favor of living life. I wrote about my home office just in case you want some ideas, https://medium.com/@9bplus/my-home-office-f531f662fc51. Been working from home for 2 years now.
HN user
x0ner
“That’s one of the problems he seems to be grappling with: more money, generally, means less struggle, and if it’s struggle that made him, how does he find that going forward?”
P1) I don't see the current naming model as any worse than the disjointed CVEs of today.
P2) What if all wide-impacting vulnerabilities were treated like this, regardless of theory or not; the vulnerability still exists.
P3) Names are fairly easy to come up with.
Some of my views on why this approach is beneficial, https://medium.com/@9bplus/why-i-love-marketing-vulnerabilit...
Just to end this out, I do agree. I was not suggesting this resource be paid, but that they should have someone dedicated, even a volunteer.
I agree with your general sentiment, but if it were that easy, we wouldn't even be having the discussion. Nation states going after a campaign are likely to succeed, it's limiting the exposure if they do. To your point, there are a number of no-brainer processes or technologies to make those compromises difficult or severely limit the damage and many do not require much to put in place. You do need someone on-staff though constantly monitoring and enforcing best practices.
Campaigns should be finding ways to work with professionals from the cybersecurity sector, not looking for ways to bolster defenses on their own. The adversaries these groups face far exceed the norm when it comes to industry standards––your security admin from off the street is going to be no match for a well-determined government. You need seasoned professionals who have background across active incident response, defensive efforts, intelligence and general best practices to even stand a chance.
People who match the description above don't need to be found as much as they need a point-of-contact to campaign staff. Many of us are more than willing to dedicate the time and resources needed to advise those who wish to take security seriously, free of charge. The issue lies in the shared opaqueness of the two parties that must come together; neither know quite who to contact and both are unsure how to engage. We should not let a lack of understanding get in the way of protecting our (anyones really) election process.
The word "passion" is charged these days, but as someone who has successfully completed a number of long journeys (opensource projects, sale of company, 15 years of cardio, etc.), I think that has been the key to my success. In other words, you have to love what you are doing and then your interests will dwindle less.
Even with love, it can be difficult to remain focused. A trick I do when I run is to constantly recalibrate my goals as I am going. If I am having a hard time a few miles in, I tell myself to get to the next quarter and then the next until it's a half. Eventually it's a mile and I start again if I need to or expand scope. I will apply this same technique to life and have found it can be very useful.
If you've tried all of those, consider the process of abstaining from something or extreme focusing for a set period of time, say drinking alcohol or performing a 1 min plank every day for 30 days. I will do these exercises and the feeling I get from them is similar to the dragging feeling at the final 25% of a project. It conditions you to push through it because at the end of the day, it's only 30 days.
And I guess as a catch-all, if you really want to see it through, make that your goal––To complete one single project from start to finish, no matter what.
While it's expected a technology company dealing with communication would be the target of external threat actors, I think there's value in Slack being very clear that eliminating the risks from a strongly motivated actor is not completely possible. As commonsense as that would seem, most of the public do not have a strong grasp on these more advanced cyber actors. What's nice in being proactive is that it opens up a proper conversation prior to a breach (yes, I know they were breached before) and could get us closer to coming up with a better solution for dealing with these attacks.
The security market is insanely hot right now and will continue to thrive. From my perspective, we are reaching a point where security is seen as a commodity, not some optional process––everyone needs to know about security, even if they aren't working in the field. From a job perspective, schools are not able to keep up with the demand and even then, those leaving academics are not showing strong practical skills they can apply.
SysAdmin/SRE/Dev is the perfect sort of person to transition to security. You are going to think about how the system functions, what is running on top of it and how to ensure it stays online. When I interview candidates, I like see an alternative background as it means that person is going to bring a new perspective. "Security" as a job doesn't really make as much sense to me––you specialize in a given area (i.e. network background folks may maintain appliances, rule sets, detection signatures, etc.) and apply security to that area. I see your area as a means to solve a lot of security problems. Configurations, deployments, etc. can be checked in and accounted for with code instead of relying on people; there's massive power in that.
When it comes to certifications, I think there's two schools of thought. There's folks who look at the paperwork and make sure you can check the box, giving way too much value to certifications. For those who have been around a bit, they see the certification as practical, though no substitution for real-world experience. If you are being cost conscious, check out some of the free resources online for Network+[1] and Security+[2]. The important take away in those materials are not that you _need_ a certificate, but that you should understand the content and be confident in speaking out it.
If the red/blue side is more your style, I can't recommend enough to check out the Offense Security courses [3]. The tool set is free, the course is reasonably priced, it's a lot of fun and will give you real-world experience that is far more favorable than the standard certificates. Skip the whole CEH program as it has a poor reputation.
You mention six figures, but don't provide a scale, so it's hard to know how much a pay-cut you would potentially take. That said, security pays well and it's not uncommon to see salaries in the ranges of $100-200K even with less experience. All salaries are relative, but in general, a lot of my peers are not exceeding 200K on the base, though clear a lot more when factoring in other incentives like stock, or bonus.
Background: Been in security my whole career (started in networking and morphed into security) totaling close to 15 years. Like you, I have a set of skills outside of security (sys admin, networking, dev) and it's played in my favor a lot. Reach out to me direct if you have more questions!
[1] https://www.cybrary.it/course/comptia-network-plus/ [2] https://www.cybrary.it/course/comptia-security-plus/ [3] https://www.offensive-security.com/
Having just finished the book, this article runs counter to what's discussed in Why We Sleep.
During the early part of high school, a few friends and I began attending community college night classes for subjects we got exposed to in our day classes. By the time I graduated, I was half-way through a AAS degree and considered continuing locally a no-brainer.
Ended up transferring 70 credits or so over to a four-year institution 1 year after graduating high school and managed to walk away with a BS degree earlier than my peers and with no debt. Without community college, there's no way I would have achieved this; I owe a lot to that part of the system.
For many years, I felt like an imposter because of my community college background. The irony in it all though was that for a much cheaper, often more flexible schedule, and sometimes better teachers, I walked away with a lot of the same opportunity as my peers. Naturally, my "network" wasn't filled with ivy-leaguers, but I'd later rub shoulders with them in my employment and be considered equal.
More details around hacking through education: https://medium.com/@9bplus/hacking-the-education-process-1be...
Unfortunately, the legal process has not caught up with the speed in which malicious actors can conduct their attacks. In some cases, infrastructure is used for merely a few hours before swapping to something new. It's a constant game of wack-a-mole and without the provider's help, there's no way to stop it.
I'd assume so. More potential fake "subscribers" mean more bounced email and higher volumes which could be used as a early warning indicator for spam or reputation flagging. Slightly related, but I've noticed countless delivery issues with Mandrill, Mailchimp's transactional service. Their portal claims messages have been delivered, but many organizations relay back to us that their message never made it past the mail gateways.
I'd like to see OVH take a stronger stance on actioning abuse requests for hosts serving malware before hearing about some paid protection offering. For those not fortunate enough to deal with OVH, if you report abuse, your information and report often find their way directly to those committing the malicious actions - the "customer". This results in the actor simply removing their content to appease OVH and then continuing business as usual. In the face of clear evidence, OVH will often cite privacy issues for why they can't or won't take action. At this point, anytime I see their infrastructure in an investigation, I know it's a waste of time.
Acceptable, no. People not following rules, it happens.
This is pretty nifty. Cracking the extension open reveals a fairly basic API you can use to skip the extension. Here's some code to use it.
https://gist.github.com/9b/f5fe434bf9965d673963884b56d93d9a
On the privacy side, I could see concern from those using the extension. When the site is not found in their database, the full HTML of the page appears to be submitted to the servers and processed. This is a bit of what you would expect, but may present some concern for cases where a new site is submitted and PII is sent to WhatRuns servers.
Planes work wonders for development too. After several trips and being on a deadline, I built my dev environment to be offline friendly (cached data, local libraries, etc.). Airports became the most productive locations for me because I could shut everything off and just focus on finishing the development work. Not having an answer at my fingertips ended up being a fun constraint too.
If you take the offer, do yourself a favor and bake some extras into your employee contract or add them into the deal. Not sure of the terms, but if you need to stick around, don't underestimate how long a year is when handcuffed. Ask for a delayed start, X% bonus and a hefty salary. Even though you didn't exit at some insane rate, you can't ignore you have a skillet or at the very least, accomplished something most have not; that's worth more than your average salary. Once you're locked in, it's a lot harder to adjust and it can leave you frustrated.
I've done a significant amount of research on these threat actors. Despite the high tech exfiltration method and nation state support, researchers were still able to easily find their infrastructure. Satellite communications were encrypted via self-signed ssl certificates. Using internet scanning, we could track their IP addresses and associated domains using the SHA-1 of their certificate (map certificate to hosting IP). Happy to answer questions, but you can also read more here. https://blog.passivetotal.org/snakes-in-the-satellites-on-go...
I wouldn't quit without a firm idea of what you want to start; leaving your current role without an idea is likely to leave you more bored and questioning your decision. Having sold a company and worked at Facebook (not Google, but a great place), I'd suggest a long travel where you disconnect and think about what you want. As others have mentioned, you're young (29 here) and have plenty of time to work it out.
Talk to your co-founder if you have one. If not, your wife is she's understanding. Having sold a company, it's one of the hardest processes to go through. It's not clear if your pain is from multiple years or the sale though. That clarification would help in the advice you get
I'd be interested in volunteering some time or access to data sets to help protect these sorts of things. Feel free to DM me.
Information security.
Worked at the same company. Watched his workflow, built tools to speed it up. Years later, started a company around the same concept. Sold to a bigger company and spend our time moving that forward. Hit it off right away and are like brothers now.
Paid. Always worth supporting fellow devs.
Google seems like they have been pushing more into this "experience" space with the creation of their local guide program. They've effectively introduced a review-based system for anything inside of maps and incentivize people through earned points for reviews, photos and other items. Google has been sending emails out to local guides to conduct meet-ups and other inputs from the users. Wondering how long before you can start contacting local guides directly from the maps application.
While all devices have security issues, not too comforted by this:
http://thehackernews.com/2016/11/google-pixel-phone-hacked.h...
Suggested targeting:
"...attacks were merely a test, and claimed that the next target will be the Russian government for committing alleged cyberattacks against the U.S. earlier this year."
Curious if these upgrades include any addressing security.
* Disclosure: I used to work for Facebook's security team and focused on threats that impacted users on the platform. *
The post outlines in some detail a common attack done by some actors known as BePush/Killim. I made a request for help in fighting these clowns months ago on a private security working group. Here's the post below which outlines a good amount of detail about the hacks and motives. If you are interested in tracking these actors yourself, it's pretty easy once you find one of their command and control servers.
Example: https://www.passivetotal.org/passive/userexperiencestatics.n...
From there, we can see the actors are using Cloudflare to obfuscate their infrastructure, but we can make a pivot based on the WhosAmongUs IDs (dsafagegg2 [1] and dsafagegg [2]) in order to find more websites owned by these guys. It's a rats nest that extends to hundreds of domains registered weekly. Servers are typically hosted in places where legal action is difficult meaning the attacks seldom stop or go down completely.
[1] https://www.passivetotal.org/trackers/WhosAmungUsId/dsafagegg2
[2] https://www.passivetotal.org/trackers/WhosAmungUsId/dsafagegg
-----------------------------------------------As promised, below is a quick high-level summary of the malware outlined in the subject. We've been dealing with the malware for months and while some would call is spam, we consider it malware simply because any of the executables or Chrome extensions could be changed to steal passwords, credit cards or every document off a system. We welcome any help in dealing with these actors and would also be interested in new ways to combat malicious extensions, both Chrome and Firefox as those are only increasing in usage.
If you would like more information on the technical details of the binaries, extensions or other loaders, feel free to shoot me a message. If there's enough interest, I will just spam the list, but would prefer to keep this to the higher level points, so others gain a better understanding of the threat.
-= Summary =-
BePush is a set of Turkish-based actors who use innovative techniques to spread malicious code and spam through social networking sites and ad-based networks. Those involved in the development of BePush malware are constantly adjusting their TTPs to account for changes in detection or disruption. Actors favor multiple levels of obfuscation through the use of short-url redirectors, third-party hosting providers and multi-stage payloads. Despite high infection rates, local law enforcement has yet to take an interest in pursuing those actors involved.
-= Infection Process =-
Based on our logs, primary infection processes tend to occur through direct traffic, followed by Facebook and various ad providers. Shortened URL links are shared among users which typically traverse through a series of redirects to a landing page mimicking Facebook infrastructure and using porn as a lure to install a plug-in. Depending on the attacker behavior, payloads may be delivered in the form of a Google Chrome extension (hosted within the store) or through an executable (likely AutoHotkey, but could be Pyinstaller based) that later replaces Chrome with a version of Chromium with their malicious extension.
Once installed, malicious code will make use of the Facebook Graph API in order to make requests/posts on behalf of the infected user using a stolen access token. In order to establish a high infection count, the malicious code will often create pages with malicious links, post statuses/comments to the user's friends and spam within certain application pages. Once the spreading routine completes, the process generally begins again with the infected user's friends.
-= Motives and Capabilities =-
It appears the primary motivation for the BePush actors is the money gained through the sale of Facebook likes, followers or various ad-network and affiliate partners. In some cases, Facebook observed BePush actors including a bundled bitcoin miner, but it never appeared to gain much popularity.
From a capabilities perspective, actors involved with BePush appear to pay attention to how their code is detected. When numbers begin to dwindle, changes to the code or 3rd-party providers are made. Actors demonstrate a level of understanding in .Net programming, Python, JavaScript and techniques used to detect spam. We have also observed the actors repurposing browser exploits, but we never saw these used against users.
-= Third-Party Provider Usage =-
BePush favors the use of free and open infrastructure in order to keep their campaigns alive long enough to get a strong infection foothold. The following providers have been observed in some capacity:
- Amazon AWS - Used for hosting content
- Dropbox - Used to host binaries
- Box.com (http://box.com/) - Used to host binaries
- Bitly - Used for redirection
- Tinyurl - Used for redirection
- Godaddy - Used for redirection
- WhosAmungUs - Used for campaign tracking
- Stellar - Used for bitcoin wallet hosting
- Imgur - Used for redirection
- Dot.tk - Used for redirection
- Google - Used for redirection, Chrome extensions and binary hosting
- CloudFlare - Used to obfuscate real infrastructure
- Microsoft Azure - Used to host binaries
-= Detection and Research =-BePush has a limited set of providers they prefer to use and through industry relationships, we have been able to put pressure on the attackers. Here are a couple items we noticed when doing disruption work that helped in making a larger impact against the group.
Using passive DNS data to identify other domains sitting on the same IP address (these guys don't use a lot of unique servers) Use ESET (Facebook) or Microsoft (Kilim) AV signatures to identify new binaries being used Polling whos.amung.us (http://whos.amung.us/) tracking pixels in order to identify/gauge recent campaigns Reaching out to 3rd-parties with domain and hash combination for takedown
-= Reference Hashes and Domains =-
www[.]filmgetir[.]com
https://www.virustotal.com/en/file/9e4484240df6e891b2a07c1ff2345e0864dd8b54e005c58388c6556cdc7cc120/analysis/
www[.]kingtr[.]click
https://www.virustotal.com/en/file/9e4484240df6e891b2a07c1ff2345e0864dd8b54e005c58388c6556cdc7cc120/analysis/
www[.]pornokan[.]com
https://www.virustotal.com/en/file/c5eeef4da2c64e8633b1f00745fecb0b692be27d4b615df086201754b07ebe60/analysis/
https://www.virustotal.com/en/file/3566452da48ba0fa31b11deae561b4d5f2a1385e83fd5537a021e75b649664b6/analysis/
https://www.virustotal.com/en/file/1a0163780f07aeaafd9e94fbe628b3f354b25afbec1f7c6e6e401cc7c06d909a/analysis/
https://www.virustotal.com/en/file/b216915643628834acd60e7ae9647e51baca636d8b05ea66857d40c9d04172a8/analysis/
https://www.virustotal.com/en/file/80d9d1df0d859fe6759bba7077be1a15eea477774c91e789e9d5988f19f0a023/analysis/
https://www.virustotal.com/en/file/940bc772a2e301e15a326e667a318942dd840149afa4031245dd125c645330ab/analysis/