HNHacker News
TopNewBestAskShowJobs

dionyziz

789 karma · joined August 20, 2011

Studying Electrical and Computer Engineering at the National Technical University of Athens in Greece.
submissionscomments
dionyziz··on Ask HN: Who is hiring? (January 2026)
Common Prefix | Software Engineers / DevOps | Greece | Remote | Full-time

Common Prefix is a blockchain research & development company. Blockchain technologies enable large-scale economic coordination through shared, programmable ledgers. Our mission is to solve the foundational scientific and engineering challenges standing in the way of mainstream adoption, particularly around interoperability, scalability, and usability. We combine formal scientific research with production-grade engineering. Our team publishes in top-tier peer-reviewed venues and builds open-source infrastructure used across major blockchain ecosystems. We have contributed to advanced systems including Axelar, XRPL, Sui, and Flashbots, and are trusted partners to protocols building critical infrastructure.

What we're looking for:

Software engineers who can solve problems, are smart, get things done, and enjoy working on the bleeding edge, learning about cryptography, and working from first-principles.

Tech stack: Doesn't matter, we'll teach you. But we work mostly with Rust, Go, and TypeScript.

Open roles:

- Software Engineer (mid): https://www.notion.so/commonprefix/Opening-Software-Engineer...

- Senior Software Engineer: https://www.notion.so/commonprefix/Opening-Senior-Software-E...

- DevOps: https://www.notion.so/commonprefix/Opening-DevOps-Engineer-2...

We offer:

- $50,000–$160,000 / year cash + stock grant + performance bonus (depends on level but not location)

- Local from Athens, Greece, or remote

- Conference participation in exciting scientific and engineering venues, 2-3 times per year

- The opportunity to work and learn from world-class scientists from major universities in the field of blockchains, cryptography, and consensus

Apply here:

https://commonprefix.notion.site/2b7bf672de828051b53cdd37811...

dionyziz··on Ask HN: Who is hiring? (September 2025)
Common Prefix | Software Engineers / Auditors | Greece | Remote | Full-time

Common Prefix is a science-first blockchain consulting company. Our vision is to make blockchains usable for mainstream users and everyday people – paying at the supermarket, remittances, moving money across borders, saving, investing – and solving the real problems of usability, scalability, and interoperability that come with it. We're a 30-person team, half scientists (cryptographer PhDs, post-docs, and professors) from renowned universities, half engineers with long web2 experience. A lot of our field is broken and we're trying to make a small contribution in fixing it, by introducing provable security and proper engineering practices across the board.

What we're looking for:

Software engineers who can solve problems, are smart, get things done, and enjoy working on the bleeding edge, learning about cryptography, and working from first-principles.

Auditors who can write and read code, especially low-level cryptographic implementation code (zero knowledge verifiers, signature schemes, etc), consensus (PoW, PoS), or smart contracts (everything DeFi).

Tech stack: Doesn't matter, we'll teach you. But we work mostly with Rust.

Open roles:

* Software Engineer, https://commonprefix.notion.site/sw-folk

* Auditor, https://commonprefix.notion.site/auditing-folk

We offer:

- $80,000–$160,000 / year cash - Local from Athens, Greece, or remote, preferably in Europe - Conference participation in exciting scientific and engineering venues, 2-3 times per year - The opportunity to work and learn from world-class scientists from major universities in the field of blockchains, cryptography, and consensus

If you're interested in joining our team, please reach out to careers<at>commonprefix<dot>com with the subject line "HN: <Job Title>".

dionyziz··on Where Sci-Hub Is
I'm a PhD student. To graduate, I need publications. The quality of my publications, and hence my possibility of graduation, is evaluated based on the reputation of the conferences I publish in. The same applies to a PhD graduate trying to get into a post-doc position, or a post-doc trying to get assistant professorship. For historical reasons, many of the reputable conferences are closed and ran by publishing houses that charge unfair money for them. We are trying to change that.
dionyziz··on Where Sci-Hub Is
I'm a researcher. I write the articles in their books. They don't pay me for that. All of the articles are written by people like me. All of the articles are reviewed and edited by people like me. I even do the typesetting. I get paid by a tax-funded university. Publishers (such as Springer) use their money not to produce knowledge, but to sue people, market their conferences and journals, and pay their administrators and shareholders.
dionyziz··on Ask HN: Anyone making 200k as a software engineer outside the US?
It does mean something. I'll make two indicative points.

First, if I'm looking to make money that I want to put into global investment, it doesn't matter where I earn it. The absolute number is what matters. In reality, the number that matters is how much I can save, in absolute numbers, after taxes and cost of living have been deducted, but still the salary does not scale with cost of living. In that case, if I'm willing to maximize my investment, it's possible that I'm willing to move to the best paying country (i.e. the country where I can earn the maximum absolute number after taxes and cost-of-living has been deducted) for a while. "Global investment" may be quite broad and may include, for example, effective global altruism (i.e., asking the question "If I want to maximize my life's impact in improving others' lives, where should I work and where should I donate globally?").

Second, if we're talking about a job that is a seller's market, i.e., where I have has some very specialized skill, then the fact that the company is willing to pay double the amount if I happen to live in Silicon Valley but only half the amount if I happen to live in Romania, is pretentious. The reason is that the company is in need of my skill regardless of where I live and my acceptable business cost to them is a Silicon Valley salary. The difference from paying me less just because I happen to live in Romania is simply money that goes into their pockets. Why shouldn't it go into mine? In fact, if my skill is specialized enough, I should be able to negotiate for that, since their best next alternative may be a Silicon Valley hire.

(For clarity, the above are illustrative examples. I'm not an effective altruist, do not have such a specialized skill, and do not live in Romania.)

dionyziz··on Ask HN: Are you working on interesting technical problems?
I'm doing a PhD on cryptography/blockchains and working on the Cardano cryptocurrency (https://cardanoroadmap.com/). It's very technically interesting and challenging (though it pays a fraction of what I used to earn as a Software Engineer in a big company in Zurich.)

I spend most of my time thinking about mathematical problems that I feel are impactful and important. The solutions make use of theoretical computer science (computational reductions and such). Validating the results requires running small Monte Carlo style experiments typically written in C++, Python, or Javascript. This isn't rocket science code, but it's still challenging to think what kind of assumptions and constraints to put in the model / code and which ones to leave out (although the coding part itself is pretty standard.) Other than that I mostly write TeX :)

But our solutions are implemented by the IOHK software engineers that are working on the production software implementation of Cardano. It's quite interesting to guide that work through our papers, as it handles a multibillion dollar market cap and the responsibility for making sure everything is secure is big. As for social impact, this people may disagree with, but I feel we're building next generation economies and this will impact the whole of society in making it more egalitarian, giving access to money to everyone, and making salaries more equal across the globe.

dionyziz··on Securing Email Communications from Facebook
Not sure what you mean, but good encryption algorithms (including GPG's RSA and DSA) are not vulnerable to known-plaintext attacks. Even if you know the plaintext and the cryptotext shouldn't help you in cracking the key in any way.
dionyziz··on Hacking Starbucks for unlimited coffee
If you want to look at it rationally, he has pretty good chances of getting a good job in security now. It's likely he's looking at proposals by Google, Facebook, etc. Good recruiters love these kinds of things (and should, as they are a great measure of who is a passionate hacker).
dionyziz··on Government-Linked Certificate Authorities in OS X
The article is somewhat wrong in that for google.com in particular the browser would show an HSTS warning and disallow access completely, as it is a pinned cert.
dionyziz··on Government-Linked Certificate Authorities in OS X
Apple can also push new certs through system updates.
dionyziz··on Government-Linked Certificate Authorities in OS X
We should be moving to systems that cannot be abused instead of systems that "we won't like it" when they get abused. PKI is broken.
dionyziz··on Does Work Really Work?
The article is nice. But the point about bartering is wrong. The argument seems to go like this:

- Each thing has a different value based on the person judging it. - Therefore, we cannot barter.

This is unfounded: The subjectivity of value does not make bartering impossible. Bartering is possible if one judges their own work to have less value or equal value to some other work that they are willing to exchange it for; and vice-versa.

However, I agree with the article that bartering may be undesirable; but the value argument is incorrect.

dionyziz··on Firefox Hello
Why is this even a thing?
dionyziz··on How to go from a nobody to a somebody
Why does the article assume that everybody wants to be "a somebody"?
dionyziz··on Wifiphisher: Fast automated phishing attacks against WPA networks
It's a proof-of-concept to illustrate that users will put their passwords anywhere they are asked to and click through any warnings that may appear on their screen.
dionyziz··on Wifiphisher: Fast automated phishing attacks against WPA networks
Where does it say that this is testing the security of a setup?
dionyziz··on Ask HN: What have you accomplished in 2014?
- Finished a software engineer in product security internship at Twitter.

- Ran a security class [0] in Greece.

- Presented my master thesis on decentralized transaction identity and trust [1] for my Electrical and Computer Engineering degree, but didn't complete the degree yet.

- Talked about BREACH [2] at the SFHMMY [3] and FOSSCOMM [4] conferences.

- Did a talk about computer security at a local community high school.

- Attended FOSDEM [5]

- Invented an anonymous decentralized marketplace system [6] and joined the OpenBazaar [7] team as a core developer.

- Traveled to the Turkey (Istanbul), Greece (Alexandroupolis, Ioannina, Athens, Ikaria, Thessaloniki, Lamia, Corfu, Drama, Komotini), Austria (Salzburg, Vienna), UK (London), Belgium (Brussels).

- Hiked through the Vikos Gorge, the Astraka Refuge and Drakolimni in Greece. Sailed in Preveza and in the Saronic Gulf in Greece [8]. Snowboarded in Zell am See in Austria.

- Tried two different interesting mind-altering chemical substances.

- Spent quite a long and nice time with friends, family, and lovers often doing nothing at all with them.

- Bungee jumped for the second time in my life, this time in Corinth and double the height (78m) of my previous jump.

- Got hired as a full-time software engineer at Google.

- Moved from San Francisco, US to Zurich, Switzerland.

- Started my private pilot license.

- Taught math, physics, programming, algorithms, web development, and security to many students privately for free.

- Donated more money than any other year in my life to charity.

- Started learning guitar.

- Lived in a share-house for the first time.

- Learned many things about security and software engineering, realized I'm a noob in so many things and fields and I want to improve a lot!

[0] http://security-class.gr/

[1] https://gist.github.com/dionyziz/e3b296861175e0ebea4b

[2] http://breachattack.com/

[3] http://www.sfhmmy.gr/

[4] http://lamia.fosscomm.gr/

[5] https://fosdem.org/2014/

[6] https://mailman.stanford.edu/pipermail/liberationtech/2014-M...

[7] https://openbazaar.org/

[8] https://mapsengine.google.com/map/viewer?hl=en&authuser=0&mi...

dionyziz··on OpenBazaar is a decentralized Dark Net market that's 'untouchable' by police
OpenBazaar developer here. This is the "nothing to hide" argument that we've seen used to much by the NSA and governments.

The answer is that we believe people simply have the right to privacy in trade. Here's a discussion by the OpenBazaar team on the matter:

https://github.com/OpenBazaar/OpenBazaar/issues/189

Do you want your credit card company to know exactly where you've shopped for the past two years? Would you like your employer to know what porn movies you enjoy? Would you want your neighbourhood burglars to know exactly how much money you spent on your brand new Swiss watch this month? Is it OK if your super-market chain only offers discounts to you on the condition that you don't buy anything from other super-market chains?

Should your wife be able to scrutinize what trips you went to and how much you spent on expensive chocolate and alcohol without your permission? Discover before her birthday that you bought her a ring as a present? Would you feel alright if Google used all your shopping history to show you targeted ads? As a seller of rare books, do you want the prices of all purchases to be published to potential candidate sellers instead of being treated as trade secrets? Would you want your annoying jealous nephew to know you've booked snowboarding tickets to Austria without inviting him?

Is it acceptable for these things to be posted on the Internet and commented-on by Redditors?

Please, I invite you to post your credit card records for the past year here. We'll be happy to look over them and leave some comments for you. After all, you've got nothing to hide, yes?

Anonymity is important for people. For some people, it's more important than others. Different people have different needs. Sometimes anonymity is a matter of life and death, sometimes it's just a matter of personal privacy and the right to be left alone. Users can use the anonymity feature as they see fit, but we need to be there to protect them if they require so.

And, yes, some trade can be only marginally legal or completely illegal. Sometimes illegal trade is ethical, and laws vary from country to country. At least at the trade level, we should be free and anonymous. What if your Internet provider disables the Internet in your country by secret warrant request of the government if you live in North Korea, or Turkey in the times of Twitter-censorship, or Egypt in the time of the revolt, or Iran at times of war? Is it OK to leak to your government that you purchased an antenna off of OpenBazaar to access the Internet through mesh networks? Sometimes the penalty can be death.

Not everyone lives in free regimes where privacy is a matter of a warm, cozy feeling and convenience. People need privacy in trade to be free.

That said, freedom comes at a cost, and the price for being free is not low :)

dionyziz··on Stanford Driving Software (2011)
Someone please convert it to git and put it on GitHub...
dionyziz··on HSTS for new TLDs
I'm surprised no one here is talking about Namecoin [1]. It has become obvious that the PKI system is failing, and the main issue is centralization.

I don't know if Namecoin itself will be the solution, or some other blockchain-based method that achieves decentralization such as the more generic Ethereum [2], but as engineers we should be supportive of such systems, as they provide better security and true -not just delegated- domain name ownership.

[1] http://namecoin.info/

[2] https://www.ethereum.org/

dionyziz··on HipHop: A "Popcorn Time" for music
Spotify doesn't have everything and it has ads.
dionyziz··on BLAKE2: “Harder, Better, Faster, Stronger” Than MD5
Standardization is a way. SHA2 and SHA3 are standardized. Unfortunately, with the recent RSA shortcomings, this may no longer be trustable.
dionyziz··on BLAKE2: “Harder, Better, Faster, Stronger” Than MD5
md5 is fine for filesystems and databases. I'm talking about using hashes for cryptographic purposes.
dionyziz··on BLAKE2: “Harder, Better, Faster, Stronger” Than MD5
These reasons don't matter. What matters is that you use a widely used hash function through a widely used software library. Most security issues are implementation-related, not cryptography-related. And if there are problems with a scheme, more people should look for them. SHA2/3 are better options under this light.
dionyziz··on God's Number is 20
I'm surprised we couldn't have proven this analytically.
dionyziz··on EpicEditor – An embeddable JavaScript Markdown editor
Shift+tab should unindent
dionyziz··on EpicEditor – An embeddable JavaScript Markdown editor
Tab doesn't work.
dionyziz··on The Face Behind Bitcoin?
Bullshit.
dionyziz··on Critical crypto bug leaves Linux, hundreds of apps open to eavesdropping
Nobody claimed that we can fix all security problems with unit testing. Unit testing should be used in addition to auditing, reviewing, and other techniques. However, unit testing can dramatically improve the quality of code, including avoiding security pitfalls and mistakes.

What we need to do is to include mandatory unit testing in all security-critical code, and ensure good coverage.

This particular bug is a bug that would have easily been caught by anyone writing rudimentary unit tests.

It's sad that there are no regression tests for these changes either, meaning we remain susceptible to such bugs in the future.

dionyziz··on The new PHP
Twitter's code is "enterprise" code in that it has to satisfy the organization's needs and a huge part of it is not user-facing, but targeting other enterprises (for example, Twitter ads). At Twitter, we use Scala.

So, no, you're not necessarily stuck between these two options (or Java, which is another popular choice in the enterprise scene). Scala was chosen specifically, among other things, because Twitter had a lot of Ruby developers who would cringe at the idea of PHP, Java, or .NET.

Page 1 of 3Next →