828 karma · joined December 29, 2016
I really like the ideas behind matrix.org but that is a dumpster fire of epic proportion.
Would be hard pressed to do that as I don't come from a place of privilege. Check your assumptions.
Who was paying you and could you not go do something else for money?
What would you say would be the biggest impediment here? I would think actually that just government regulation in and of itself would prevent any private company from achieving this feat. And even Federal and State governments are similarly encumbered by regulation.
HackerOne offering PCI-DSS approved auditor approved challenges gets you nowhere towards the claims you made in your first comment.
To review:
1. HackerOne would have to be a PCI DSS Approved Scanning Vendor - they are not AFAICT, neither is the CyberNews research team that did the scan AFAICT.
2. HackerOne would have to have conducted the scan - they did not. The CyberNews research team did.
3. The scan that HackerOne did would have to qualify as a PCI-DSS external scan - which ... do you get the part that HackerOne did not do the scan here or not? And nowhere did the CyberNews research team claim they performed a PCI-DSS external scan.
Please at least try to make an argument for your claims
Not anywhere on the page you linked. And a "PCI-DSS auditor approved organization" is not a "PCI-DSS approved scanning vendor" which if they were you could just quote the certificate number instead of link to HackerOne.
----
EDIT: I guess you are referring to this:
> Meet penetration testing requirements for PCI DSS and SOC2 Type II compliance certifications with our auditor-approved penetration testing methodology and Security Assessment Report.
This in no way is the same as claiming "we are a PCI-DSS auditor approved organization". Which again, would be irrelevant if it was the case.
----
Further, if you read the article, it is clear the "We" does not refer to "HackerOne".
> When we pushed the HackerOne staff for clarification on these issues, they removed points from our Reputation scores, relegating our profiles to a suspicious, spammy level.
As far as I can tell "We" refers to cybernews.com
And again even if cybernews was a PCI-DSS approved scanning vendor it would still have to qualify as an official external scan within the PCI-DSS framework.
Quote from your source:
> If your scan fails, you must schedule a rescan within 30 days to prove that the critical, high-risk or medium-risk vulnerabilities have been patched.
Scan in this sentence refers to "a PCI DSS external scan".
The list of approved vendors that can conduct PCI DSS external scans can be found here: https://www.pcisecuritystandards.org/assessors_and_solutions...
Please find cybernews' certificate number there and quote it for us, I have looked and can't find it.
I would guess that, contrary to your implication, they are not an approved scanning vendor. If this is the case then it really does not speak to the characteristics of PCI-DSS and your comment just seems wrong.
And even if they were an approved scanning vendor, from what little I know about PCI-DSS, these scans are part of larger process - so even if they were an approved scanning vendor the scan failure would still have had to be part of the larger process for this 30 day limit to apply.
I could go on and on about how much I hate PayPal and random other things, but just because I don't like something does not quite justify making false claims about it.
I did. I learnt vi when I was told go fix this file on that computer, you have ssh, x forwarding won't work because you have 3 hops (embedded devices that won't allow forwarding of any kind), there is only vi on the box.
So I figured out how to use vi. It is not rocket science, there is not that much to learn, vi muscle memory takes time but also not even that long I think.
And I feel this is a very similar situation with other tools. I edit code with vim, in a terminal. This is simple as dirt. I do it because it is simple as dirt. Visual Studio is incredibly complicated to me because to do the creating code part my job I need to understand the following:
- How code is built.
- How to build the code without using any graphical front end.
- But now when you bring VS into the mix I need to also understand visual studio. It does not remove complexity, it adds it.
Similar thing with debugging, I need to understand all the ins and outs of debugging but now bring VS into the mix and I need to understand it's stupid UI.
I like simple, my mind is simple. I can learn things, if there are rules and patterns it makes it easier to learn, but the less things I have to learn the happier I am. I don't have an option to not learn some things, like how to do build automation, how to debug code, how computers work, etc. But I do have an option to not learn something entirely useless like VS.
I think the lie being sold is that somehow you can be a programmer without actually knowing how to use a computer. And to know how to use a computer is not the same thing as knowing how to click on things in the UI with a mouse. To know how to use a computer you need to understand how to use it to do automation - and once you need to do this VS is just a nuisance.
Just a rant I guess.
People complain a lot. Engineers are people. People still do things they complain about. People die in crashes. Cars crash. Teslas are cars. What am I missing?