HNHacker News
TopNewBestAskShowJobs

dstjean

43 karma · joined May 21, 2016

submissionscomments
dstjean··on Major Windows flaw was reportedly discovered by the NSA
"News of the security flaw comes the same day that Microsoft is ending support for Windows 7. The company has encouraged people to upgrade to Windows 10 to keep their PCs and laptops secure. " Hummmmm...
dstjean··on Banks deny compensation when hackers steal customers' money
At what point do they say that? Are those your assumptions? The bank might have failed to provide proper controls to secure the account. As example, 2FA is not common for banks in Canada. If the client's computer was compromised, 2FA should have secured the access to the account.
dstjean··on Deep packet inspection is dead, and here's why (2017)
IMO relying 100% on the end devices to protect themselves is too risky. Layered security seems to work best. Also I prefer to heavily monitor/secure two appliances/systems than heavily monitor thousands of end devices
dstjean··on Deep packet inspection is dead, and here's why (2017)
I don't think NOT performing packet inspection due to privacy concern is a good idea. (Good security controls should exist over its administration)

One reason why organizations use packet inspection is to protect its staffs, customers and vendors from malicious actors who could cause data breaches leading to huge privacy issues.

Privacy over Security? The right balance must be found

dstjean··on Deep packet inspection is dead, and here's why (2017)
In a corporate environment, managed devices can be configured to force the use of specific DNS settings. The same type of implementation (MITM) could be used to analyse the requests.

That being said, this is at the OS level. An app such as Firefox could still override those settings or provide their own implementation.

dstjean··on ForgJs – A lightweight object validator
Any attributes for required/optional fields?
dstjean··on Ask HN: Are advertisers stealing Christmas?
Wondering if the way to go is in Incognito mode from a different IP. But then the moment I authenticate with Amazon for example, my profile (and associated data points [All IPs used, cookies, etc.]) could be used to target advertisement.
dstjean··on LastPass Outage
Was wondering why I was seeing: "An error occurred while logging into LastPass. Please check your Internet connection" That would explain it.
dstjean··on Ask HN: What is your best advice for a junior software developer?
Make sure you don't stay in the same position for over 3-4 years. Make sure you get promoted or look elsewhere.

IMO: Being too comfortable in the same position is not good enough

dstjean··on Found hooked up to my router
To name a few: - ARP Poisoning - DNS Poisoning - LM Hashes gathering - Packet Sniffing - Packet Interception (and modification)
dstjean··on Ask HN: Codebase at my work is a complete mess, what should I do?
Are there tons of global variables?
dstjean··on Show HN: Hacker News job trends
Good job.

Why did you prefer using the HTML format instead of HN API? https://github.com/HackerNews/API

dstjean··on Canada legalises recreational cannabis use
?
dstjean··on Everyone is watching what you do online. How user tracking with cookies works
Thank you! Great vulgarization...

I'll share that with my non-IT colleagues!

dstjean··on HN should have a “bookmark” option along with the “favorite” option
Yes but I want my upvote to mean something therefore I to read the article before hand.
dstjean··on The Stuxnet worm may be the most sophisticated software ever written
I think, the number of zero-days included in Stuxnet is an important factor in making it sophisticated and complex.
dstjean··on No boundaries for Facebook data: third-party trackers abuse Facebook Login
Quite interesting!

It would be great if we could filter the lists (eg. I just want to see html and js)

dstjean··on Redesigning Hawaii’s Emergency Alert System UI
What I find astonishing is that there was not a Two-man rule security control in place.
dstjean··on IT Security Educational Video – Happy Holiday
Not sure what to think of the video
dstjean··on The XSS Game by Google
Level 6: You can exclude the protocol entirely (eg: "//news.ycombinator.com")

This will ensure the browser uses the "current protocol" as in if your website is browseable from http all request //www...com will be http and if your page is fetched using https, all resources starting with //www.hn.com will be loaded using https

if your website was reachable from protocol xyz://mydomain.com, all resources starting with // would be fetched using the xyz:// protocol

dstjean··on Ask HN: Is it possible to run your own mail server for personal use?
Ask Hilary Clinton
dstjean··on Ask HN: Who is hiring? (July 2016)
Banff, Alberta Canada - Senior Business Consultant, IT - ONSITE

https://chj.tbe.taleo.net/chj05/ats/careers/v2/viewRequisiti...

dstjean··on Ask HN: Who is hiring? (July 2016)
Banff, Alberta, Canada - Application Developer - ONSITE

https://chj.tbe.taleo.net/chj05/ats/careers/v2/viewRequisiti...