282 karma · joined January 14, 2011
Follow me at ainsleybraun.com
It's always good to have more eyes on security issues - Ruby or not - and keeping the community informed. Feel free to get in touch with us at support@tinfoilsecurity.com - we'd love to chat about any ways we can work together.
How I look at the Sunday test is less of a "are they like me" and more of a "will I get along with them many hours a day"? We work anywhere from 7 hours a day, up to 18 (especially during major code pushes) - we try to avoid this as much as we can, but sometimes (for us at our stage), it's inevitable.
I do have to enjoy working with my colleagues, and someone for whom I won't be willing to come in on a Sunday has a higher chance of bringing me down on a regular basis. That doesn't mean we work Sundays (we're typically in the office M-F), but it's important to be able to get along with people and it's a good litmus test, imho.
Not to mention, he's gotten a lot of good press from other media sources since (as he points out in his blog post).
If you run a scan from our homepage, you're actually looking for a lot more than just the YAML vulnerability (XSS, Mixed Resource, etc.) as our product isn't limited to just the YAML vulnerability.
If you run the scan from https://www.tinfoilsecurity.com/railscheck, then you'll get a quick check for just the YAML vulnerability.
Does that clarify it a bit?
Thus, you might be running an old version, but still actually be safe by disabling the vulnerable bits.
It's a travesty, and puts female entrepreneurs in a poor light, pitting them against each other and making them look petty.
What is the pricing for this? Seems there's a free download at the top, but the bottom says "Buy for $29.99". Might want to make the pricing structure clearer. :)
If you make a mistake, own up to it. Honesty is the best key to building a business, and I'm sure they've at least lost the HN trust for any product in the future.
Since whomever discovered the bug was able to access others' sensitive information, they have to disclose.
The best test to see how we differ from Nessus/Burp is to try it yourself! A lot of the vulnerability classes we scan for are very similar, but the ways in which we scan for them are different. We do offer our Standard Plan for a free 30 day trial. Would love to hear what you think :)
If you have any issues, ping us at http://tinfoilsecurity.com/supportchat
For full disclosure, I'm a young entrepreneur (<25), run a company that was started a few months after curebit (my cofounder applied and interviewed for the same YC class with a different idea), have raised pretty close to what curebit has raised, and am also a 500startups-funded company.
I'd just like to take a minute to hope that a couple of screw ups by others won't put companies like ours at a disadvantage. It makes me sad to think that "how old are you guys" is one of the first questions someone would ask, since I'm not sure physical age has anything to do with how people react to different situations. I'd sure like to think that if I screwed up people would chalk it up to me being me and not my generation.
I also hope people realize the big mouth investor with no taste (especially in what he wears ;) isn't the only person vetting 500startup companies. He has a whole investment team. Yes, Dave does pick a lot of the 500s companies himself (he was our biggest advocate), but the entire 500s team has a say. I also think you're overlooking the fact that curebit was also supported by YCombinator (and Dave has a lot of respect for PG's team and the companies they accept).
I don't condone what curebit did (far from it). I am close to positive someone at YC would have at least helped hash out ideas for design (and 500s' mantra is design, data, distribution), and, Dave has always said: running lean doesn't mean running cheap. But I hope that what one company does doesn't ruin it for the rest of us.
Yes, hiring is hard. Yes, as an early-stage startup it will take you a very long time to hire. But you have to remember those you're hiring today will make or break the company tomorrow. Their "5 yr plan" should have no bearing on whether or not they get a job at a very early startup, but by the end of the interview you should know not only that they're technically capable, but can roll with any changes you foresee the company making, and that they have the right personality to mesh with you and the rest of your team (you'll be spending a lot of time together - could you grab beers with them?). You should also know that they're so sold on the idea and vision of your company that their 5 year plan and your 5 year plan become one (or are at least related). Realistically, your startup probably won't even be alive in five years.
Of course I know a lot of people look at things differently, and I have complete respect for different opinions and methods (and love reading about them). We're still trying to figure out hiring ourselves, but I think the best engineers come with all sorts of non-corporate eccentricities. If we had followed the author's suggestions, we wouldn't have hired either of our two founders (including myself) or our first engineer. I'll leave it up to the reader to decide whether that would have been a mistake or not. :)
The show was supposed to portray TS in a good light, and even the Davids are taken back by this reaction.
As one of our investors (in the interest of full disclosure), Tisch is awesome. He's always looking out for the best for his companies, either as personal investments or TS companies. I'm also sure none of the TS companies would say the program was a net negative, rather than a net positive.
As for the mentoring aspect, what Bloomberg didn't show is that the entire 1st month of TS is spent with 40-60 mentor meetings so you find the best mentors for your company. Tisch and Cohen are there to keep you on track from an investor's perspective, but they heavily rely on their mentors to keep you on track.