HNHacker News
TopNewBestAskShowJobs

amlozano

256 karma · joined October 5, 2016

Hacker @ Block
submissionscomments
amlozano··on LAPD lets contract with surveillance giant Flock expire
I share the same thing. In fact, being a commissioner he was probably explicitly warned against taking any action into his own hands.

A commissioner can easily mess things up and get sued trying do work on their own. Say they try to “repair a playground” by replacing a missing bolt. Well, were they qualified to do that? Do they have insurance? Was the action approved by a properly filed motion? Etc etc etc

I learned this is why it costs my town egregious sums to do simple maintenance work; the only companies willing to put up with all the red tape of working with the government have to charge a premium.

The part about him being a commissioner smells like a simple publicity stunt.

amlozano··on Email experiments: filtering out external images
Maybe it’s ok to email a person after they click a button that says “mail me my 2fa” code? Not a lawyer but it feels right that if I say it’s ok to send me a one off email explicitly, it can omit an unsubscribe
amlozano··on Why I have to buy doughnuts with cash
This boarders on self-promotion but I'd like to say, "Bitcoin fixes this".

We're launching Bitcoin payments available to every Square point of sale with 0% transaction fees for next year. 1% after that. Available Nov 10th. [https://squareup.com/us/en/releases#bitcoin]

My sincere hope is it catches on and helps out small business. The difference in fees can really add up, and with near instant settlement to dollars on the backend, the merchant doesn't even need to hold or think about Bitcoin unless they want to.

The fine article talks about stablecoins, but in my biased opinion those are much more complicated than Bitcoin to deal with right now.

amlozano··on Block to roll out Bitcoin payments on Square
We built the pilot to show a standard lightning invoice with a QR code and NFC. Any wallet capable of paying that invoice could pay.

Whatever wallet you use did need to have liquidity on the network that can reach our routing node, c=, but we worked hard to make sure we had plenty of liquidity to all major wallets. I definitely recommended cashapp without shame at the conference, but I did a lot of testing with other wallets too. I never had much trouble, even with non-custodial lightning wallets.

amlozano··on An app to never talk to customer service support
Thanks for building this. I am going to try it out next time I can use it!
amlozano··on A Tour of WebAuthn
For anything that is important enough, I put passkeys on 2 separate FIDO2 key devices directly. Services that come to mind are things with recovery backdoors; like email or device backups. Unfortunately many banks and financial institutions don't support passkeys, but I'd consider using that solution there too.
amlozano··on A Tour of WebAuthn
This is the exact reason I self host vault warden. I get all the convenience of syncing passkeys, but know that I am the only one with access to the back-end.

I am also slightly paranoid as a security engineer, and admit that whole heartedly.

amlozano··on Show HN: I built a Iridium/LTE satellite GPS tracker and took it to the Arctic
This is a very cool project, happy to see the costs of this stuff coming down a little bit.

When I was an intern 15 years ago I worked on a software library for this https://www.embeddedts.com/products/TS-IRIDIUM Board that does a similar thing (though you would need to stack on a cellular board if you wanted cell modems).

We used them to help Arizona Department of Transportation collect traffic data in remote locations.

We had big plans at that company to make a much smaller, much cheaper 9602 transceiver replacement, but the company got bought out before that could launch.

amlozano··on Ask HN: Best practices for accepting Payments (Cards, BTC) in 2024?
Check out btcpayserver

https://btcpayserver.org/

amlozano··on YouTube is returning 403 to NewPipe and other 3rd party players
Of course, the customer is the advertisers, not the users.
amlozano··on Python wheel filenames have no canonical form
Python was first released in the early 90s. If you compare Python packaging to other languages of its time, its not so crazy. For comparison, C++ was released in '85.
amlozano··on Python's many command-line utilities
Or go a step beyond and get typer (which builds on click IIRC)

https://typer.tiangolo.com/

If you use Poetry and a pyproject.toml, you can even make your package installable with something like pipx straight from Github. Its a trick I use often for little command line utilities.

https://python-poetry.org/docs/pyproject/#scripts

amlozano··on Gov. Polis Signs Bill Mandating That Consumers Have Options to Fix Electronics
Is this sarcasm? I disagree vehemently. These are things that should be the most repairable.
amlozano··on Daylight Computer – New 60fps e-paper tablet
This is awesome, I ordered one.

Please bring this display technology to larger formats if it ever makes sense economically, this is like the dream for a wall calendar.

amlozano··on Police in Austin, San Francisco skirt facial recognition ban
If I recall correctly the ordinance only barred the city's police from "acquiring or using" the software without approval and reports to a committee. Merely asking someone else to use it on their behalf is probably ok (per the ordinance). Its kind of hard to actually ban any particular technology, if it is useful, people will find a way to use it.
amlozano··on Cops can force suspect to unlock phone with thumbprint, US court rules
Those tools are expensive. Forcing someone to use their thumb or face is free.
amlozano··on All-cash offers, wealthy buyers push Southern California home prices to a record
It means at the very least that the buyer is affluent enough to have that kind of liquidity available. That's out of reach for a lot of people, but yeah, it does summon this image of suitcases full of cash unnecessarily. Maybe its the modern equivalent of that, with less criminal overtones?
amlozano··on Rust for Embedded Systems: Current state, challenges and open problems
Complicated video games, especially ones with transactions or multi-player aspects, require a lot more security code than you might expect.
amlozano··on Prioritizing software right to repair: engaging corporate response teams
While I agree with you, this is an inherently political discussion. Having a phrase thats easier to remember (due to alliteration) and easier to conceptualize (of course I should be able to repair something!) might give it ever so slightly more of a chance to get past the collective apathy.
amlozano··on Starlink's laser system is beaming 42 petabytes of data per day
The Iridium satellites are in what you might call "parallel" orbits, if you stretch the meaning of the word a little bit.

The wikipedia link above explains it well:

""" Orbital velocity of the satellites is approximately 27,000 km/h (17,000 mph). Satellites communicate with neighboring satellites via Ka band inter-satellite links. Each satellite can have four inter-satellite links: one each to neighbors fore and aft in the same orbital plane, and one each to satellites in neighboring planes to either side. The satellites orbit from pole to same pole with an orbital period of roughly 100 minutes.[8] This design means that there is excellent satellite visibility and service coverage especially at the North and South poles. The over-the-pole orbital design produces "seams" where satellites in counter-rotating planes next to one another are traveling in opposite directions. Cross-seam inter-satellite link hand-offs would have to happen very rapidly and cope with large Doppler shifts; therefore, Iridium supports inter-satellite links only between satellites orbiting in the same direction. """

The 'seams' have interesting implications for latency when I was working on Global Data Broadcast.

amlozano··on Starlink's laser system is beaming 42 petabytes of data per day
There were some experiments with communicating over Iridium to small cube-like sats back in the day, but we couldn't make the system on a chip beefy enough to do the Doppler shift calculations on the fly and survive a launch; it was close though. I think its possible to do now.
amlozano··on Expensive fridges are dying, leading to fraud claims
More concerning to me is that there isn't anything better out there to buy anyway.
amlozano··on Comcast says hackers stole data of close to 36M Xfinity customers
Protip, use something like a https://diceware.rempe.us/#eff password with 6 words.

They never seem to mind when you just say "litmus secrecy ruckus nest reason send", they don't even skip a beat.

amlozano··on Suspects can refuse to provide phone passcodes to police, court rules
That doesn't work with iPhones, the Secure Enclave in the only thing that can unlock the phone, and after the attempt limit is exceeded, passcode-protected data is erased by Secure Storage.

I guess if they really wanted to they could attempt to decap the chip and do something with a hardware attack, but thats difficult and dangerous.

amlozano··on Maybe getting rid of your QA team was bad
This point is brought up in the article but I think it is at the real heart of the issue.

QA is almost always seen as a 'cost center' by the business and upper management. I have a hypothesis that you never ought to work in a department that is seen as a 'cost center'. The bonuses, the recognition, and the respect always goes to the money makers. The cost center is the first place to get more work with less hands, get blamed for failures, and ultimately fired when the business needs to slim up. I think the same thing applies to IT.

This spiral is why QA will always be a harder career than just taking similar skills and being a developer. It self reinforces that the best people get fed up and switch out as soon as they can.

amlozano··on Microsoft pulls OneDrive update that would quiz you before letting you quit
The last line of the article is just a stunningly good summary:

"But it's just one more annoying default you need to change to make sure that modern Windows stays out of your way."

Microsoft is constantly pushing the limit of what users will tolerate. I switched non-technical people to Linux OSes after hearing about this, and heard no complaints from them. It's almost like Microsoft wants to lose whatever footholds they have left.

amlozano··on Data accidentally exposed by Microsoft AI researchers
The problem is security is a "Market for lemons" https://en.wikipedia.org/wiki/The_Market_for_Lemons. Just like when trying to buy a used car, you need someone who is basically an expert in selling used cars.

In order to purchase a reputable pentest, you basically have to have a security team that is mature enough to have just done it themselves.

I can throw out some names for some reputable firms, but you are still going to need to do some leg work vetting the people they will staff your project with, and who knows if those firms will be any good next year or the year after.

Here's a couple generic tips from an old pentester:

* Do not try and schedule your pentest in Q4, everyone is too busy. Go for late Q1 or Q2. Also say you are willing to wait for the best fit testers to be available.

* Ask to review resumes of the testing team. They should have some experience with your tech and at least one of them needs to have at least 2 years experience pen-testing.

* Make sure your testing environment is set up, as production like as possible, and has data in it already. Test the external access. Test all the credentials, once after you generated them, again the night before the test starts. The most common reason to lose your good pentest team and get some juniors swapped in that have no idea what they are doing is you delayed the project by not being ready day 1.

amlozano··on Ask HN: Who wants to be hired? (July 2023)
Location: Phoenix, AZ. USA

Remote: Yes (USA timezones)

Willing to relocate: No but occasional travel OK

Technologies: Python, Java, C#, C++, AWS, Terraform, and many more

Résumé/CV: email or message me for a pdf.

LinkedIn: https://www.linkedin.com/in/amlozano1/

Email: recruitme@tlozano.com

I am a seasoned security engineer with over 13 years of experience in the tech industry, encompassing roles as a product security engineer, penetration tester, security consultant, and software engineer. I've provided consulting services for a diverse range of companies, from innovative startups to esteemed Fortune 100 companies. I take pride in combining deep technical knowledge with exceptional communication skills.

amlozano··on GitHub Packages no longer planning Python PyPI support
Warehouse (https://github.com/pypi/warehouse) uses the Apache 2.0 License, I wonder how easy it would be to set up a PaaS company to do this.
amlozano··on Hacking my “smart” toothbrush
As a security professional, I often get asked whether adding a root check is advisable. My general recommendation is to go ahead and implement it, but with a focus on data collection rather than taking action. For instance, you can log if a user is using a jailbroken or rooted device, without interfering with their experience. The responsibility for running a secure operating system lies with the users themselves, not the application. Applications that attempt to restrict how users utilize the app can be likened to malware.

Now, there might be instances where a business executive argues in favor of DRM or ensuring that certain coupons are limited to specific regions. In such cases, its sometimes suggested as a requirement to verify if the app is running in a simulated environment or is rooted. However, I can assure you that if you lock some kind of value behind this check and then rely solely on the operating system to provide this level of security, there will eventually be clever hackers who find ways to bypass the protection. The same principle applies to business-to-business apps that demand extensive control. In such situations, you need to rely on other software solutions or provide dedicated hardware. It's important to refrain from attempting to take ownership of my device, considering it's already under the control of Apple or Google anyway... /sarc. If you require stronger guarantees, I suggest reaching out to them.

Page 1 of 3Next →