HNHacker News
TopNewBestAskShowJobs

breadtk

381 karma · joined February 26, 2012

Security wonk.

https://surkatty.org/

submissionscomments
breadtk··on Ask HN: Who is hiring? (May 2017)
Amazon Web Services (AWS) Security team is hiring in Seattle (WA), Herndon (VA), Dublin (Ireland), and Sydney (Australia). We're looking for folks interested in the following areas:

* Penetration testing and general software breaking

* Application Security & Design

* Incident Response

* Compliance / Security Assurance

* General software engineering

Successful candidates are those that can not only break software, but are also able to build software. No formal education is required, but demonstrable technical prowess is encouraged.

Other particulars: Relocation is available. VISA sponsorship may be possible for qualified candidates. Remote work is not available.

Interested individuals should send their resume, professional/technical background information, and what areas you're interested in exploring career options to "b3NtYW5zQGFtYXpvbi5jb20K" (base64 decode it) and use the subject line "HN May 2017" to be considered. No recruiters.

breadtk··on ‘Routine’ Jobs Are Disappearing
Mirror: https://archive.is/Tltad
breadtk··on Major Investor Sues Theranos
Mirror: https://archive.is/v3sNR
breadtk··on Ask HN: Who is hiring? (October 2016)
Amazon Web Services | SEA | Security Engineer | ONSITE

In 2006, Amazon Web Services (AWS) began offering IT infrastructure services to businesses in the form of web services -- now commonly known as cloud computing. Today, Amazon Web Services provides a highly reliable, scalable, low-cost infrastructure platform in the cloud that powers hundreds of thousands of businesses in 190 countries around the world.

AWS's Application Security team is looking for security professionals interested working in the areas of:

  * Penetration testing
  * Application security
  * Automation
  * Building of security services
Ideal applicants have a strong passion in the field of computer security and have experience programming/scripting away problems. Professional experience and/or a degree from a university is not a prerequisite if the candidate is able to demonstrate his/her competency in other ways.

To learn more about these positions and others, please reach out to me directly at osmans _at_ amazon.com with a subject line of "HN Hiring (OCT 2016)" and information about what area of computer security listed above that you are interested in; alternatively you can also tweet/dm at me @surkatty.

breadtk··on Researchers crack open malware that hid for 5 years
There's been sufficient evidence that they are involved in hacking/rewriting HDD firmware. See: https://www.wired.com/2015/02/nsa-firmware-hacking/
breadtk··on Researchers crack open malware that hid for 5 years
> Is it possible though that corporate software could have similar objectives? I'm thinking corporate espionage type behaviour.

Yes, it is possible.

breadtk··on Researchers crack open malware that hid for 5 years
I believe it's less about fear mongering and more about understanding the level of sophistication of the software. Talk to anti malware analyst and they'll tell you how commoditized the malware game is nowadays. There's an endless stream of malware and ransomware which can be linked back to just a handful of frameworks. These types of malware families also fall under the spray-n-pray mentality for distribution. Spam, drive-by-downloads, infected torrents, etc.

Compare the mass of malware that is out there with the level of technical sophistication, OPSEC to prevent detection, and precise targeting of its victims. Along with other big name malwares (i.e. Stuxnet, Flame, etc.), this class of malware is very precise in its objective. It isn't trying to make money for its owners. It isn't trying to replicate itself across the internet endlessly. Rather it has a key objective of infecting a specific set of networks. So when researchers call out the fact that it is likely to be "state sponsored", they are saying the purpose of the malware is very different than your average piece of malware.

breadtk··on As ‘Slither.io’ Goes Viral, Game’s Creator Scrambles to Keep Up
Mirror: https://archive.is/RiGJD
breadtk··on I wrote a script that listens to meetings I'm supposed to be paying attention to
To be clear, this was not something I wrote/scripted. I'm quoting the comment. However due to title character limit, I couldn't make that clearer in the post title. :\
breadtk··on Martin Hellman and Whitfield Diffie Have Received the 2015 ACM A.M. Turing Award
Press release: http://awards.acm.org/turing-award-2015.pdf
breadtk··on AWS Certificate Manager: Deploy SSL/TLS-Based Apps on AWS
At the time of launch only ELB and CloudFront are supported.
breadtk··on SHA1 sunset will block millions from encrypted net, Facebook warns
It isn't _completely_ broken. That is why FB is still advocating for a two tiered approach (SHA2 when possible, SHA1 everywhere else). SHA1 hash collisions are indeed now within the range of well funded governments, but it is not within the range of your average script kiddie to find possible collisions. To prove my point, I'd ask you to find an arbitrary Root CA cert which uses SHA1 hash and attempt to clone it. I think you'll find that this takes still a considerable amount of effort and/or it is completely out of reach.

I should be clear that SHA1 shouldn't be used for cryptographic purposes that require high amount of trust, but for your average everyday FB status updates it is probably fine when coupled with other protections.

breadtk··on SHA1 sunset will block millions from encrypted net, Facebook warns
Facebook's user base as of January 2014 was at 1.24B monthly users[1]. According to FB's post, up to 7% of their users do not support SHA2 certs. This would mean approximately 86.8m FB users alone would affected by full-stop SHA1 degradation. I'm happy to see FB has implemented a mechanism selective cert selection and other organizations that care about their user's security ought to look at them for a model on how to approach this methodically.

SHA1 isn't great, but it is certainly better than plaintext communications.

[1] http://thenextweb.com/facebook/2014/01/29/facebook-passes-1-...

breadtk··on Ask HN: Who is hiring? (July 2015)
AWS is looking for Security Engineers of all skill levels!

Locations: Seattle (WA), Herndon (VA), New York (NY), Sydney (AUS), and Dublin (IRL)

All positions are full time with benefits and possible international relocation/visa sponsorship for great candidates.

AWS is one of the world's largest cloud hosting environments and we're looking to scale up its existing fleet of security engineers. We're looking for engineers passionate in the areas of:

* Security engineering

* Red team / penetration testing

* Incident response

* Cryptography

* Network protocols

* Application Security

* Web application

* Large scale automation tasks

* And pretty much any other topic related to Information Security

No prior knowledge of AWS is required, however it would be preferable.

Interested candidates should send their resumes as a PDF to => osmans @@ amazon . com <= with the subject line "HN Thread".

(keywords: cloud, security, information security, and begrudgingly 'cyber')

breadtk··on OpenSSL Security Advisory
This is OpenSSL's response to the "Logjam" attack (https://weakdh.org/)
breadtk··on BIT Poised to Become Publicly Traded Bitcoin Fund
It's the same reason why you don't buy and own steel, but rather you buy stock in a mining conglomerate or a refinery. Owning a piece of a business in the long-run may be more less volatile than the commodity itself. Though the two can't necessarily be separated in terms of future outlook.
breadtk··on Multiple vulnerabilities released in NTP
The site appears to be non-responsive, here is a cached version of the page: https://webcache.googleusercontent.com/search?q=cache:jMcfip...
breadtk··on The NSA's Cyber-King Goes Corporate
> The total figures are way smaller than drug sales. But always overblown in the media

Source?

breadtk··on To Wash It All Away [pdf]
Direct link to the column hosted by Usenix (mirror): https://www.usenix.org/system/files/1403_02-08_mickens.pdf
breadtk··on [dead]
It looks like this is blogspam. Here is the original article: http://techcrunch.com/2013/06/09/hacker-faces-more-jail-time...
breadtk··on Gfycat - Jiffier gifs through HTML5 video conversion
Imgur is pretty profitable [1], they may even want to consider buying this company.

[1] http://www.businessinsider.com/imgur-is-officially-bigger-th...

breadtk··on Professor admits faking AIDS vaccine to get $19M in grants
Perhaps he will spend the next three years studying for a new field?
breadtk··on Who exactly is crawling my site?
Do you mind posting your old robots.txt?
breadtk··on Silk Road 2.0: A concept of a distributed anonymous marketplace
OPSEC, it's hard.
breadtk··on The 800 Pound Gorilla Amazon Tried to Kill is Google's Trojan Horse
Self-driving cars could free up delivery drivers to do other things, such as sorting packages for the next drop-off location. I can't how many times I've seen a FedEx/UPS driver parked and trying to sort through boxes for a particular stop.
breadtk··on Amazon S3 – 2 Trillion Objects, 1.1 Million Requests/Second
A blob of data, but in general people think about objects as files.