HNHacker News
TopNewBestAskShowJobs

_tk_

3,955 karma · joined November 12, 2019

Information Security Officer at Fortune 50 global corporation.
submissionscomments
_tk_··on Ask HN: HIPAA for AI vs. Licensed Providers, your thoughts?
Maybe edit the post for more clarification.
_tk_··on Playing whack-a-mole is losing
If producing secure software with AI will be more expensive than producing buggy software with AI, then I'm sure where software will be headed.
_tk_··on VMs won't contain cyber-capable agents
I think this is mostly in line with "all software is now easily exploitable by agents given enough tokens". However, in the long run we should really see software that is more secure than today. I do wonder though how the procedural flaws that exist today - bugs patched upstream, but not in the distro - will be fixed reliably.
_tk_··on Being ambitious and being a dad
I kinda miss the argument why so many “ambitious” people are bad parents. Maybe because it is too obvious? If you are not present for your child at the time your kid grows up (before and after school, weekends, etc) you are not a parent at all. You’re a roommate with certain privileges, but no child is interested in that.

People who work 60+ hours a week will be “worse” parents than others.

_tk_··on [dead]
Well, this surely is a productive post.
_tk_··on Italy's cheese banks hold Parmigiano as collateral
Original title:

Italy’s $4.7 billion cheese economy is feeling the heat as climate change threatens its cheese banks that hold Parmigiano wheels as loan collateral

_tk_··on Fastmail offers EU data region
There are certainly exceptions, but a lot of European Governments use Azure or Google for their office applications, including different law enforcement agencies and militaries.
_tk_··on Fastmail offers EU data region
Unfortunately, even if all data lives in the European Union, as long as a company is conducting business in the US, the Cloud Act makes it possible to compel them to hand over any information. This can include making administrative personnel sign NDAs or face heavy repercussions. Conducting business in the US includes advertising to US citizens e.g through maintaining a website in English.

At this point it’s unclear what a future digitally sovereign infrastructure should look like. Even if a company or a European state somehow manages to store data that is out of reach for the US Government, an amendment to FISA or the Cloud Act is something that any Congress should be able to put together.

_tk_··on Danube's record low levels force shutdown of Hungary's only nuclear plant
Related: https://news.ycombinator.com/item?id=49107044
_tk_··on The biggest gamble in the U.S. economy is starting to look riskier
https://archive.ph/2026.07.31-091636/https://www.washingtonp...
_tk_··on Google's Design Ethicist Testimony [pdf]
I’m missing a little context here.
_tk_··on OpenAI and Hugging Face address security incident during model evaluation
I’m a little surprised with one of the statements given in huggingface‘s report.

“To understand what a swarm of tens of thousands of automated actions did, we ran LLM-driven analysis agents over the full attacker action log, comprised of more than 17,000 recorded events.”

17,000 events? Big whoop. Security teams of medium sized companies process millions of events daily.

There’s a big debate in the cyber industry about the AI SOC and whether or not it’s necessary. It seems to me they are using that report to push that idea.

_tk_··on Big Banana Car
Alternative title:

Person who wants to get noticed indeed gets noticed

_tk_··on Sergey Brin told Google staff that working 60 hours a week is the 'sweet spot'
Dated August 2025
_tk_··on Stateless Actors
You mean APTs that are not state sponsored…? Oh.
_tk_··on EY Canada published a cybersecurity report and most citations were hallucinated
Same goes for lockdown mode on iOS.
_tk_··on Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
I was part of several third party risk management audits from a corporate perspective.

We regularly audited and questioned SMBs (and big corps) with regards to their security posture. We knew that small shops wouldn’t be able to be fully compliant to SOC2 Type 2 or have an ISO27001 certified environment. If it was clear that our business wanted the product, we either tried to help the company with the questionnaire or created a risk report that was then signed by the business. In other words: even if your customer asks you to be compliant, you don’t have to be if they care enough about your product.

If you seem intent on getting things right, that’s a big plus. Most of your competitors don’t even know what SOC 2 is.

_tk_··on Paper Factory
https://bsky.app/profile/pengzell.bsky.social/post/3mldozsh4...
_tk_··on Ransomware Is Growing Three Times Faster Than the Spending Meant to Stop It
I think this article mostly shows that publicly announcing a successful ransoming of a company is now more popular than a couple years back.
_tk_··on NSA and IETF – The Structure of the Debate
Part 1 here:

https://blog.cr.yp.to/20251005-modpod.html

_tk_··on The U.S. spent $30B to ditch textbooks
Full headline:

The U.S. spent $30 billion to ditch textbooks for laptops and tablets: The result is the first generation less cognitively capable than their parents

_tk_··on Opus 4.6 uncovers 500 zero-day flaws in open-source code
The system card unfortunately only refers to this [0] blog post and doesn't go into any more detail. In the blog post Anthropic researchers claim: "So far, we've found and validated more than 500 high-severity vulnerabilities".

The three examples given include two Buffer Overflows which could very well be cherrypicked. It's hard to evaluate if these vulns are actually "hard to find". I'd be interested to see the full list of CVEs and CVSS ratings to actually get an idea how good these findings are.

Given the bogus claims [1] around GenAI and security, we should be very skeptical around these news.

[0] https://red.anthropic.com/2026/zero-days/

[1] https://doublepulsar.com/cyberslop-meet-the-new-threat-actor...

_tk_··on We asked 15k European devs about jobs, salaries, and AI [pdf]
Agree with the sentiment that the numbers for Germany - and I would say Switzerland as well - are not on the level.
_tk_··on Classified Whistleblower Complaint About Tulsi Gabbard Stalls Within Her Agency
https://archive.ph/FftH3
_tk_··on Euro firms must ditch Uncle Sam's clouds and go EU-native
Take a look here: https://wero-wallet.eu/
_tk_··on CISA’s acting head uploaded sensitive files into public version of ChatGPT
Yes.
_tk_··on CISA’s acting head uploaded sensitive files into public version of ChatGPT
I’m a little surprised by the takes in the comments. Obviously, heads of departments or agencies, CEOs, or similar personnel are generally not in the same league as normal employees when it comes to compliance.

Productivity and efficiency are key for their work. I am sure there are lots of Sysadmins here, that had to disable security controls for a manager or had to configure something in a way to circumvent security controls from actually working. I have been in many situations where I have been asked by IT colleagues if doing something like that was fine, because an executive had to read a PowerPoint file NOW.

_tk_··on Break Me If You Can: Exploiting PKO and Relay Attacks in 3DES/AES NFC
People just don’t talk about Blowfish.
_tk_··on Break Me If You Can: Exploiting PKO and Relay Attacks in 3DES/AES NFC
Not to be rude, but it seems to me that you are engaging in some hairsplitting. In general, security people do not recommend to use 3DES or RC4 - even if RC4 is broken in other ways than 3DES.
_tk_··on The only moat left is knowing things
Big LinkedIn post on a concept with little proof.
Page 1 of 7Next →