HNHacker News
TopNewBestAskShowJobs

danielweber

12,245 karma · joined April 30, 2012

Dan Weber. Software developer and security guy.

Reach me at <lastname><firstname> on gmail. First name has 3 letters.

submissionscomments
danielweber··on List of Sites Affected by Cloudflare's HTTPS Traffic Leak
I typically think of "encryption inside of encryption" as a boondoggle more likely to somehow break things than make things stronger.

My confidence in that has dropped slightly in the past day.

danielweber··on Alphabet's Waymo Alleges Uber Stole Self-Driving Secrets
https://github.com/GDSSecurity/EvilAbigail#scenario
danielweber··on Alphabet's Waymo Alleges Uber Stole Self-Driving Secrets
Many many years ago, I was at a software company, and a competitor popped up making very similar software. They made a presentation of their software at a conference, and had a slide showing a screenshot. Our typos were clearly visible.

Fun times, fun times. We got a few people fired, but that was about it.

danielweber··on Alphabet's Waymo Alleges Uber Stole Self-Driving Secrets
Their model was "trust the employee, and use the courts to enforce punishment if that trust was misplaced."

We are in phase two of that right now.

danielweber··on An Open Letter to the Uber Board and Investors
Really. You don't need to dump all your ammo on the very first day.

She said what needed to be said. If Uber challenges her account, she can post more information, assuming she is telling the truth (which I am for now).

danielweber··on An Open Letter to the Uber Board and Investors
She made accusations that specific incidents happened.

In general, someone who makes a specific accusation that can be disproven if not true probably isn't making it up.

I know we can all recall specific times when this hasn't been true. But as a general rule it works, as long as we remember we are still in the "judgment" phase and not the "punishment" phase.

danielweber··on An Open Letter to the Uber Board and Investors
Fowler's claims are statements of fact that can be easily proven if true or easily disproven if false.
danielweber··on An Open Letter to the Uber Board and Investors
Fowler made accusations of fact. They can be proven or disproven.

She didn't say opinions like "they were meanies to me" or "they gave a promotion to a man when I was the better performer." In that case, people would likely decide who to believe based on their priors.

Instead, she made specific accusations that, if false, Uber could easily show as false. Note that Uber has not even done that. Likely because she can prove the claims are true, in court if necessary.

danielweber··on An Open Letter to the Uber Board and Investors
Fowler had specific accusations of fact. Either the "got told six times it was a first offense" thing happened or it didn't. Either the leather jacket incident happened or it didn't. Uber can easily claim these things aren't true if they aren't.
danielweber··on An Open Letter to the Uber Board and Investors
A lawsuit would not really pay out that much. She got another job, so her damages are, what, a few tens of thousands of dollars? And it would mark her, for life, as someone who sues.

A friend has worked on sexual harassment suits and says it's unfortunate that, as far as he's experienced, every single one he's been involved in has been bogus. Meanwhile, he knows there are several people with good cases who don't bring them, because the social penalties are too high.

Part of the reason I believe her is that she isn't bringing suit. She's not trying to make a payday out of this. Further, she has alleged specific acts which can be definitely proven or disproven. If she made it up, it would be trivial for Uber to show she did so.

danielweber··on Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
Your hard work is appreciated.
danielweber··on Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
Good. They're trying to clean up all the private data leaked everywhere. I tempted to say "why couldn't they figure out this google dork themselves" but they've probably been slammed for the past 7 days cleaning up a bunch of stuff anyway.
danielweber··on Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
I get this argument. I have made it in the past.

But CF doesn't want to play Internet cop. Everyone who manages a service gets a constant barrage of "someone using your site did something offensive, I want you to kick them off your service!"

CF has decided they are just not going to play the game, at all. Because once they start, then all the piranha come to feast.

I'm not saying this means they aren't a racket, which is charging people money to solve a problem you made. But they do have some good reasons for simply refusing to censor what they offer.

danielweber··on Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
"Don't worry, the keys weren't compromised."

I know how to replace my TLS keys. I have no idea how to replace everything else.

It's like people who think losing my credit card number is the worst thing. No, it can be a hassle, but once I replace it I'm okay. It's everything else.

danielweber··on Cloudflare Reverse Proxies Are Dumping Uninitialized Memory
Yeah.

"We leaked information from Customer A to Customer B by accident" is the first order problem.

But the existence of web caches means that all that private information of customer A is potentially fucking everywhere now.

How do you even clean this up? How do you even start?

danielweber··on Announcing the first SHA-1 collision
There are many areas of security where you can genuinely get by with obfuscation, hoping the attacker looks elsewhere, or general security-through-obscurity.

You can't in crypto. When the entire system relies on an axiom being true, you need to make sure it's true. The attacks are only going to get better. The attacks are going to come from the future. The embedded systems will not be replaced in time.

danielweber··on Announcing the first SHA-1 collision
No, that's irrelevant. You don't hold off showing the first SHA-1 collision to have it have MD5 collisions as well.

I don't think anyone in the field is surprised that the MD5 signatures are different for this file.

danielweber··on An Email Thread Between a Developer and Gigster
Continued employment counts as consideration in many states.
danielweber··on An Email Thread Between a Developer and Gigster
> I've gone through this before and the law is very clear that continued employment is not a valid compensation for changing the terms of your employment.

Please do not say things like this. A worker in Massachusetts, Illinois, or New York may read what you said, believe you because you said "the law is very clear," sign a new agreement thinking they got one over, and then roll out the other side to realize "oh, shit, that guy on Hacker News didn't know what he was talking about."

Whether continued employment counts as consideration is a state by state issue.

danielweber··on An Email Thread Between a Developer and Gigster
Employers need to be able to make sure they own the code you write for them. Otherwise nothing works.
danielweber··on An Email Thread Between a Developer and Gigster
> We've received very similar feedback recently

So why was the line "We have yet to have a disagreement (much less a legal battle) over the terms here" issued to the developer?

danielweber··on An Email Thread Between a Developer and Gigster
> mentions that I received no valuable consideration for signing it

Them hiring you counts as consideration.

danielweber··on An Email Thread Between a Developer and Gigster
As bad as I think Gigster's agreement is, this clause is a good place to start from. It means that they don't have someone shoving GPL code into a project that must remain closed source.
danielweber··on An Email Thread Between a Developer and Gigster
This is why everyone should demand to see the IP agreement during negotiation.
danielweber··on An Email Thread Between a Developer and Gigster
Maybe they are bluffing, maybe they are not.

If you are willing to lose your job, I applaud anyone who does this fight. But lots of people are not able to do the same fight.

What does work is demanding to see the employment contract before joining the company. They can present you with a different contract on day one, but contract law requires a meeting of minds, and if they snuck a new clause in without calling it out, there wasn't a meeting of minds.

danielweber··on An Email Thread Between a Developer and Gigster
Follow him how?
danielweber··on Four Column ASCII
You have control characters for the characters from 64 to 95.

    Control-@ is 0.  
    Control-A is 1, through control-Z is 26.
    Control-[ is 27, escape.
    Control-\ is 28.
    Control-] is 29.
    Control-^ is 30.
    Control-_ is 31.
danielweber··on Four Column ASCII
> Why isn't "&" (ligature of "et") not in the same row as "e"? "$" ("dollar") is in the same row as "d".

It matches old mechanical typewriters. I have one with the shift-characters over the numbers being exactly what was 16 characters (one bit flip) away in the table.

danielweber··on An Email Thread Between a Developer and Gigster
I've experienced #2 once and seen it happen to a colleague once.
danielweber··on An Email Thread Between a Developer and Gigster
In my experience, it's very unusual for a company to simply state that it won't talk about it at all.

I get one of these two patterns:

1. "Oh, okay, we see your point. We'll cross out clauses X and Y."

2. "Oh, thank you, we'll take this very seriously. Now we will have people talk at you for hours about why you can trust us and everyone else here was dumb enough to sign up."

← PreviousPage 3 of 34Next →