HNHacker News
TopNewBestAskShowJobs

ejcx

2,871 karma · joined April 26, 2015

Evan Johnson runreveal.com evan at runreveal dot com

Former Cloudflare sr director of security engineering, first security hire at Segment.

submissionscomments
ejcx··on Ask HN: Who is hiring? (March 2025)
RunReveal | Engineers, Customer Facing | Full-Time | REMOTE, SF, Austin | runreveal.com

We're helping companies manage their security logs. We've built a fantastic product for a company our stage and signed up some amazing customer logos in the process. We're working on moving up-market and building a product that can displace some of the enormous vendors in the space.

Email evan @

ejcx··on SQL pipe syntax available in public preview in BigQuery
We made pql.dev that works with the different sql syntaxes by translating kusto like queries to sql (using CTE). It's worked really well thusfar and I wish someone would make a standard pipelined query language that gets supported across most databases

I know prql exists, but the syntax is pretty cumbersome and not something I enjoyed writing, but I do understand why folks would gravitate towards it

ejcx··on Why is Cloudflare Pages' bandwidth unlimited?
We're incredibly biased since several members of our team worked at Cloudflare, but we spend ~$20 a month on Cloudflare for our startup and it is fantastic.

- Marketing videos on stream

- Pages for multiple nextjs sites

- DNS + Domain Reg

- cloudflared / tunnels for local dev

- zaraz tag manager

- Page rules / redirect rules for vanity redirects we want to do.

The list gets longer every day and the amount of problems we can solve quickly is amazing. The value to money is unmatched

ejcx··on Pql, a pipelined query language that compiles to SQL
We do use raw sql, but we're a security business which tends to have heavy reliance on other languages that have a similar syntax to pql
ejcx··on Pql, a pipelined query language that compiles to SQL
The main goal was to help security engineers / analysts, who _loathe_ sql (for better or worse).

I tend to think this is a little more user friendly, personally, and it's nice to give some open-source competition to the major languages that are used in security (SPL, Sumologic, KQL, and ES|QL).

We were surprised that there weren't syntactic competitiors (i.e. -- while prql has some similar goals, the syntax and audience in mind were very different)

ejcx··on WiFi without internet on a Southwest flight
I have a similar program I run that does this stuff for United flights: https://github.com/ejcx/uwc/blob/master/uwc.go

The code is horrendous but it has worked for years and I guess when I wrote it originally I didn't want to use a go struct for some reason?

ejcx··on Cisco Acquires Splunk
I hate to shill in this thread, but that's exactly what we built at runreveal, so I completely agree! We saw the power of clickhouse when we were at segment and cloudflare, so built a company around it.

And since clickhouse is open source, we hope that people will stop giving their security data to vendors who then charge you rent for it. I think the future is writing this data to clickhouse, but also our customer's clickhouses

ejcx··on Cisco Acquires Splunk
Founder of runreveal here, if anyone is interested let me know. The news today was big, but not necessarily too surprising.
ejcx··on Kawa: The Event Processor for the Grug Brained Developer
The json parsing library that parses the config file allows either syntax. That was intentional since we get in the habit as go programmers of ending lines in structs/maps with commas, it's just for convenience.
ejcx··on Wazero: Zero dependency WebAssembly runtime written in Go
Happy wazero user here in production. The team supporting the project has been really helpful and it's a very solid project.
ejcx··on I fixed a parasitic drain on my car in 408 days
I'm happy you fixed it. I would have nearly lost my mind too. Hopefully figuring out the issue and fixing it is as rewarding as the problem was maddening
ejcx··on Magnus Carlsen resigns against Hans Niemann in the second move
That's not necessarily how I feel, but I think it's a possible explanation for the way Magnus feels.
ejcx··on Magnus Carlsen resigns against Hans Niemann in the second move
There have been instances in chess where cheaters get caught and they receive light bans and many top players say the punishment is too weak. It's intuitive, if you've been caught cheating then you should be banned from competitive chess. I think that's more likely what Magnus thinks.
ejcx··on Twilio's lack of consistency in security documentation
Where's the lack of consistency? They do it once per year, but have the option to do it more and aren't limited to once per year. One is clearly a policy, while the others are written not in legalese.
ejcx··on Hijacking Email with Cloudflare Email Routing
What was missing was the server side ownership check. We decide which customer owns the real "example.com" which is very battle tested logic, but had missed the check in this new service. The client side validation is expected too, though
ejcx··on Hijacking Email with Cloudflare Email Routing
I lead Product Security at Cloudflare, thanks for the writeup Albert and the fantastic security research throughout the past year.

Once this issue was fixed we investigated all prior email routing configurations to ensure that this had only been found as part of Albert's responsible disclosure to us.

Since some comments are addressing that this happened 7 months ago. Our disclosure policy is to allow researchers to write about us once the issue is fixed, but give us a week heads up before they publish so we aren't surprised, can coordinate any public comms we want to make, FAQs that need to be written for inbound questions from customers, and can tailor our response to the issue at hand. Can answer other questions if you have any.

We disclosed the issue here earlier this week once Albert told us he was writing a blog: https://hackerone.com/reports/1419341

ejcx··on Hijacking Email with Cloudflare Email Routing
I lead Product Security at Cloudflare (and I'm one of Albert's biggest fans, he's contributed a lot to our bug bounty, thank you Albert).

Once he reported the issue we investigated all prior email routing configurations to ensure that this had only been found as part of Albert's responsible disclosure to us.

We disclosed the issue here earlier this week: https://hackerone.com/reports/1419341

ejcx··on Exposing a web service with Cloudflare Tunnel
(I work at Cloudflare). You can sign up just a subdomain (sub.foo.xyz) as an enterprise customer and then add an NS records from your DNS provider to Cloudflare for that subdomain.

Tunnels also has a testing domain you can use. It should give you a subdomain like xxx-xxx-xxx.trycloudflare.com for basic "How do I get this thing working" testing.

ejcx··on Alpaca Attack
Yes, you do in fact need CORS to set the arbitrary header in the example if it's even possible to send from a browser. I suppose it might be possible to send as `HELP xss:` which is close

Like you said, you can send requests, but not the one listed in the example and you're severely limited in cross protocol interactions to valid http where you don't need to receive a response... (which some of the example attacks require btw)

I think this is an interesting issue to consider, but the examples are based on wildly different threat models that include TLS being hijacked, maybe DNS if it was performed with rebinding, the FTP server being hijacked for one of the attacks. It is not at all concrete. Interesting, but not really worth worrying about.

The interesting cross protocol attacks that I've seen involved SSRF talking to memcached, as a classic example. Something private. In practice I think they would struggle to find a single real world instance where they can pull off an attack enabled by this behavior. Which is fine, it's academic. Just not what I expected given the coverage.

ejcx··on Alpaca Attack
In the example image, why is ftp.bank.com:990 responding with CORS HTTP headers allowing attacker.com to establish a cross origin connection?

The whole thing seems a bit impractical to me.

ejcx··on Spreading Jam
Congrats on the launch. As someone who has used this and denied it the product has a ton of potential
ejcx··on How I bypassed Cloudflare's SQL Injection filter
(I work at Cloudflare and manage the Product Security team, so...disclaimer).

WAFs definitely help. No WAF is perfect, but having an additional layer to make exploitation harder, and having a tool designed to block specific attacks (like when a new CVE is issued for a CMS) is powerful.

Not to mention that WAFs are a requirement in regulated industries. PCI mandates it. And your SOC2 + ISO auditors probably will ask about it too.

ejcx··on Apple Acquires Fleetsmith
Nothing changes. No matter what certification, there’s a scope of what parts of the business and product are in and out of scope of the audit. Fleetsmith having SOC2 doesn’t bring the rest of Apple into scope
ejcx··on San Francisco, Silicon Valley rents plunge amid downturn
Mission Bay apartments were built after 1979 (or whatever the exact date is). It's all new construction, which isn't subject to rent control: https://www.sftu.org/rent-control/
ejcx··on Zero Trust Networks
I'm a Cloudflare employee, so obviously biased (shilling incoming).

Cloudflare Access is worth having on the list (and it's free right now [1]). It is a pretty flexible identity aware proxy, and ssh gateway. We use it internally for those two things for basically all of our infrastructure and internal applications.

If it works for you that's awesome, if not (or you have just general questions) I'd love to hear feedback about why not / what else you might be interested in. I work on our security team but work really closely with the access team, so would be happy to pass on feedback to them.

1 - https://blog.cloudflare.com/cloudflare-during-the-coronaviru...

ejcx··on The SOC2 Starting Seven
Very good post. This ticks all the boxes on the fundamentals when spinning up a security program.

SOC2 Type2 is really where you want to be, but it takes time. Navigating compliance for startups is pretty challenging and I see so many not having a clue how to navigate sales without certs but it's super doable, and getting these things finished get you pretty far along towards Soc2 type1, and shows a lot of goodwill to share these practices even _before_ you have any certs

ejcx··on Erdős–Bacon number
I’ve never heard of Erdos Bacon numbers. My university professor Dr Tjaden pioneered the Bacon Number and it was a pretty obscure claim to fame he had.

I’m guessing his Erdos Bacon number was 3+1=4. He appeared in a documentary with Kevin Bacon about the 6 degrees of Kevin Bacon, and has a peer at the university with an Erdos of 3. What a world we live in!

ejcx··on Launch HN: Deviceplane (YC W20) – Update and Manage Devices Running Linux
I've worked with both Josh and Cyrus at DevicePlane and can say I'm really looking forward to what these folks deliver. Really great engineering talent all around working on a solution to a non-obvious but hard problem that exists.

I can't wait to get the time to sit down and play with it!

ejcx··on The Cruise Origin
This is probably the last thing to knock Cruise on. They've hired a lot, a lot, a lot of good people on the security front
ejcx··on Flan Scan: Lightweight Network Vulnerability Scanner
Definitely a little cynical =]. I think the same thing about a lot of 3rd party security consulting.

OpenVAS is free, but the big issue we've had with it is the complexity of setting it up and maintaining it. We are a security team, and would rather not spend our time managing servers, especially since we aren't the best people to do that at Cloudflare.

Page 1 of 15Next →