HNHacker News
TopNewBestAskShowJobs

geoffsanders

111 karma · joined February 5, 2012

Co-founder & CEO at LaunchKey. Developer, designer, science junky, and futurist. Creator of things.

LaunchKey: https://launchkey.com GitHub: https://github.com/launchkey Twitter: https://twitter.com/launchkey AngelList: https://angel.co/launchkey

submissionscomments
geoffsanders··on The F-35 Can’t Fight at Long Range, Either
This and similar criticisms of the F-35 are just silly. I can take any other aircraft in the U.S. inventory and put it in situations where it will lose engagements against other domestic or foreign aircraft and systems. Multi-role fighters like the F-35, Rafale, Viper, Hornet, and Gripen aren't meant to be dominant in any one specific area. They're meant to be flexible platforms that can be tailored for different operations and flight packages based on the needs of the mission at the time, and like most multi-role fighters, they each tend to be a little better at certain roles than others.

Additionally, most of these criticisms act as if the F-35 will be acting alone on these missions, and don't take into account the fact that other aircraft, radars, and offensive/defensive systems are meant to be utilized alongside the F-35. Such a micro view doesn't adequately account for the actual theater of war these aircraft will take part in.

Is the JSF program enormously expensive? Yes. Is it unnecessary? Maybe. However, expensive and unnecessary are separate issues from whether or not this is a capable aircraft, of which it empirically is. Does it have kinks to work out? Definitely, but this aircraft is still in testing phases, and like all other aircraft, it will go through iterations and variations. In time, as systems mature, bugs are fixed, and pilots become more experienced, we can be sure that the F-35 will at least be a capable tool to warfighters.

Argue the cost, argue the need, but making the argument that the folks at Lockheed all of a sudden forgot how to build capable fighter aircraft is absurd.

geoffsanders··on Yahoo wants to let you forget your Yahoo password
This is a gift to hackers, government snoops, and the like: access is now granted to anyone with the trivial ability to intercept SMS messages, spoof cell towers (Stingrays), or clone SIM cards.
geoffsanders··on Government-Linked Certificate Authorities in OS X
Why not use the blockchain model for decentralized CAs in place of trusted CAs?
geoffsanders··on The Spy Cables: A glimpse into the world of espionage
Maximizing ad profits under the guise of nobility and transparency. Yay capitalism.
geoffsanders··on Oliver Sacks on learning he has terminal cancer
This is one of the most honest and genuine observations I've ever heard; an observation that one can likely only fully appreciate in the face of mortality.

Beautiful, indeed.

geoffsanders··on Science behind common anti-depressants appears to be backwards, researchers say
From the sound of it, the important issue in question is depression itself, and not so much the efficacy of SSRIs. If the causes surrounding the physiological roots of depression are unknown or incorrect, no medicinal approach will be able to accurately address the issue, thus always leaving room for the placebo argument.
geoffsanders··on Dumb Ideas in Computer Security (2005)
Agreed. It would seem that unless your system is totally free of all forms of dependencies (including the human kind), arguing that patching is a bad idea simply because it shouldn't have to be patched in the first place is just poor advice.
geoffsanders··on Dumb Ideas in Computer Security (2005)
Mostly good points.

This point, "Unless your system was supposed to be hackable then it shouldn't be hackable." wasn't one of them.

geoffsanders··on Must startup ideas be revolutionary or just solving a simple problem?
Solve a problem simply, and it could be revolutionary.

Solve a simple problem, and it will not be.

geoffsanders··on Unknown orange-red glow over Pacific Ocean
While earthquake light does seem like one of the better explanations, the length of time it was observed (>30 min) would make it one of the longest observed earthquake light sightings.
geoffsanders··on Unknown orange-red glow over Pacific Ocean
Considering lava cools and darkens almost immediately under water, I'd imagine it would have to be an incredibly epic underwater eruption (and thus, detectible) for that much light to make its way through that much water and project itself onto the clouds above that location. Also, the light should diffuse as it makes its way through water, air, and onto the clouds above, so the seemingly neat circles of light don't seem to match up with a sea floor-based light source either.
geoffsanders··on Russian Gang Said to Amass More Than a Billion Stolen Internet Credentials
Article states it's from multiple compromised sources...
geoffsanders··on Image Protection on the Web
Instead of hiding or modifying the image entirely at tiny random intervals, why not modify subsections of the image at all times, rolling the imperceptible modification around the image itself, so that at no time interval is there ever an unmodified image?
geoffsanders··on Show HN: Show HN
I see what you did there...
geoffsanders··on BitAuth for Decentralized Authentication
Just use LaunchKey - https://launchkey.com or https://github.com/launchkey
geoffsanders··on But why can't I send people their passwords?
Or don't use passwords? https://launchkey.com

:)

geoffsanders··on So you didn't get into Y Combinator, now what?
Entrepreneurs make companies, not accelerators.
geoffsanders··on Ask HN: How Do You Securely Share Passwords in Teams?
We use KeypassX (https://www.keepassx.org/) and store the encrypted password database inside BTSync (http://www.bittorrent.com/sync), hosted on a secure internal server within our office. Both KeypassX and BTSync are free.
geoffsanders··on Tehran tracked, captured, studied, copied RQ-170
I'm prior Air Force.

Few pieces of military technology are so individually valuable to overall tactical and strategic capabilities that knowledge or possession of such technology would tip the scales one way or the other. An exception would be the nuclear bomb.

We may have embarrassingly given the Iranians a freebie, but their ability to dissect and understand it is far different from their ability to reproduce or manufacture it for any tangible military advantage.

Keep in mind, the global dominance of the U.S. Air Force isn't rooted in any one aircraft or technology, rather it comes from the massive network of supporting technologies (e.g. global radar networks, manufacturing technologies, communication and satellite tech, etc.) and personnel (e.g. intelligence agencies, engineers and scientists, pilots, etc.) that support such advanced aircraft.

geoffsanders··on Introducing Anonymous Login and an Updated Facebook Login
If you want truly anonymous login, might I recommend https://launchkey.com

Obviously there's nothing truly anonymous about this service if Facebook knows everything about you...

geoffsanders··on The End of the Password Age
While I completely agree with you that the end of the password age has arrived, I disagree that biometrics is the solution; at least not on a broad level.

The problem with biometrics isn't a matter of its ability to authenticate an individual; they make great credentials. Rather, the problem is that once that uniquely personal data is leaked or hacked (in security, we must always plan for future malicious attacks/vulnerabilities), you can't simply replace or revoke those credentials. e.g. Say a cloud service holds a copy of one of your fingerprints. If that data gets leaked, you can't simply remove or replace your fingerprint. What happens when you've lost all 10 of your fingerprints to hackers?

In reality, biometry is so powerful that we must be responsible in how we employ this most intimate form of identification. Using biometry within truly closed systems (think iPhone 5s TouchID) is the only responsible way to utilize biometry, as the data is encrypted and stored locally in a partitioned drive, and made unavailable to everything else. Of course, this architecture generally limits usage to the device it's on.

My last point is that you don't need biometry for true multi-factor authentication (MFA), which is what everyone should be striving for. Biometric factors are also known as inherence factors (something you inherently are), which means you can replace biometric factors with inherence factors like geofencing (your location on this planet is something inherent only to you).

You should look into services like LaunchKey (https://launchkey.com) or view the FIDO Alliance (https://fidoalliance.org) to see what the next generation of authentication looks like.

geoffsanders··on LaunchKey: Anonymous Multi-Factor Authentication Platform
Hey pedalpete, unfortunately we don't support legacy Windows Phone yet, but we do support Windows Phone 8+.

As for your question regarding a stolen phone, in addition to built-in device security (such as a PIN lock or remote wipe) we've provided a number of features that should help users in such a situation: First, the LaunchKey mobile app comes with two in-app knowledge factors (a numberless combo lock and a standard PIN lock) that can be enabled to prevent access to the LaunchKey app itself. Second, a user can enable geofencing or add a Bluetooth factor to prevent the device from authorizing outside specific geographical zones or when unconnected to specified Bluetooth devices (a FitBit, iBeacon, etc.).

While in theory an attacker could disable these services within the app, we've assigned 60 minute delays to creating or removing geo-fences and Bluetooth device factors. The idea being that you should realize your phone/device is gone within an hour, and within that time you can use our third protection: remotely unpair a device via the LaunchKey website or via another paired device, thus disabling that device.

Thanks for your feedback and please let us know if you have any other questions or comments!

(disclosure: I'm a co-founder of LaunchKey)

geoffsanders··on Empty F-16 jet tested by Boeing and US Air Force
This is hardly news. The Air Force recently ran out of the old F-4 Phantoms we used to use for target practice, so they've moved on to converting the aging (and plentiful) F-16 fleet. That's all.
geoffsanders··on Why is encryption so hard?
For anyone interested, we have encryption examples in Python (PyCrypto & M2Crypto library), Ruby (OpenSSL), PHP (phpseclib), Java (Spongy Castle) and Objective-C (CommonCrypto) here: https://launchkey.com/docs/api/encryption

disclosure: I'm a co-founder of LaunchKey

geoffsanders··on Show HN: Developers, Kill Passwords today with LaunchKey.
While LaunchKey relies of physical possession as an authentication factor at its most basic level, LaunchKey provides and encourages the use of multi-factor authentication through additional factors such as a knowledge factor (PIN or Combo Lock) and inherence factor (geographic location). Comparing a single factor of authentication, as is the case with a password (knowledge) or Inkan (possession), to that of the multi-factor authentication found in LaunchKey (possession + knowledge + inherence) is a fallacy.
geoffsanders··on Ask HN: Those of you who who have had PRK, how was the recovery?
I had PRK when I was 19 (almost 10 years ago) so I can say with confidence you'll want to go the LASIK route if you can. With PRK, they scrape away the outer layer of your cornea so a laser can reshape its surface. With LASIK, they cut open your cornea and operate on the lens itself.

While cutting may sound traumatic, it doesn't affect your vision (they put a protective contact lens over it afterwards, it heals very quickly) and you come out of the operation seeing 20/20. With PRK, your cornea has to re-grow the cells that were scraped away during the operation which causes your vision to be cloudy for around a week. During this time your eyes will be painfully sensitive to light and you likely wouldn't be able to use a computer for 4-7 days. Another downside to PRK - you don't know how well the operation went until your eyes have fully recovered 2-3 weeks after surgery.

geoffsanders··on Ask HN: Best payment processor for marketplace webapp
Have you tried using Stripe? (http://www.stripe.com)
geoffsanders··on YC Interview Advice, Question 1
Great advice Matt, thank you!
geoffsanders··on Ask HN: Do employers care whether my Computer Science degree is a B.A. or B.S?
How does a degree in computer science be anything but a B.S.? It would seem a bit contradictory the other way, or in the least a misnomer...
geoffsanders··on Potential Goldmine: Branded Artist Apps Could Make Money and Please Fans
I actually applied to this summers YC batch with an idea regarding just this thing! I'm the co-founder of Fangible (http://www.fangible.com) and we've been at work since January addressing this vary subject.
Page 1 of 2Next →