HNHacker News
TopNewBestAskShowJobs

griffinmb

987 karma · joined April 18, 2014

byatt.griffin@gmail.com

[ my public key: https://keybase.io/griffinmb; my proof: https://keybase.io/griffinmb/sigs/u-6FMiNO_5m8QCpOTM-1WeHOnVBTJwx9YIjSIJFSsNY ]

submissionscomments
griffinmb··on Tinybox – A powerful computer for deep learning
This is not the same company. The OP Tiny Corp accused them of Trademark infringement on Twitter, due to exactly this kind of misconception.
griffinmb··on Launch HN: Corgea (YC S23) – Auto fix vulnerable code
Agreed that there’s no way to do this meaningfully and securely.

Looking forward to the archeological audits of LLM-developed apps x years from now that are a total mystery to the product owners…

griffinmb··on Launch HN: Corgea (YC S23) – Auto fix vulnerable code
Yeah, it doesn’t fix the issue at all. Rough to have a security product demo be fundamentally insecure.
griffinmb··on I gave commit rights to someone I didn't know (2016)
I created/maintained a popular project for years[^1], and recently passed ownership to someone else. It's been great seeing issues resolve, PRs merge, etc, after languishing for a while :)

[^1]: https://github.com/nccgroup/sobelow

griffinmb··on Is Haskell a good choice for software security?
The point is that with a powerful Effects system, devs calling the logger would have to account for the network call in their own code. Someone might have wondered why that was needed and gotten this addressed before it was ever widespread.
griffinmb··on Is Haskell a good choice for software security?
Effects can definitely help, but a strong type system allows you to encode security concerns for compile time feedback as well.

See https://gmb.is/refinement-types.html for a non-Haskell example.

griffinmb··on Replit used legal threats to kill my open-source project
Given that he's now un-retweeted it, it looks like even amasad agreed it wasn't a good look.
griffinmb··on Replit used legal threats to kill my open-source project
Based on your retweet[1], you still seem to be publicly punching down.

[1]: https://twitter.com/pnegahdar/status/1402018604233732098?s=2...

griffinmb··on Computer Science Curriculum in 1000 YouTube Videos
You probably know this, but correcting for anyone reading. C is generally considered statically but *weakly* typed.
griffinmb··on Auth0 JWT Auth Bypass: Case-Sensitive Blacklisting Is Harmful
It’s versioned, which is an improvement on “agility”
griffinmb··on Bypassing GitHub's OAuth Flow with a Head Request
Yep, that’s the way!
griffinmb··on Bypassing GitHub's OAuth Flow with a Head Request
This class of bug (CSRF bypass via route confusion) is probably more common in Phoenix apps. I’ve found a handful of apps vulnerable to this issue with Sobelow.

People create (for example) a get ‘/profile’ and a post ‘/profile’, and the action intended to correspond with post requests really just pattern matches against params.

I’ve also seen at least one app implement this properly, matching against the HTTP method as you described.

griffinmb··on Why Let's Encrypt is a bad idea
Sure, the "passive" was what I was calling out as incorrect. And as you noted, a compromised trusted CA affects all domains. Which is another thing this article gets explicitly wrong.

> If DigiCert’s Key Management System is compromised, all of their SSL certificates will have to be revoked and re-issued. But if one of the other CAs is compromised, it would not affect Medium’s site.

griffinmb··on Why Let's Encrypt is a bad idea
This is a horribly misinformed article, and is incorrect about the most fundamental arguments it is making. E.g. Among many other issues, it implies that a compromised CA would allow passive MitM.
griffinmb··on Getting 2FA Right in 2019
Agreed that you don't gain anything if you're using 1Password. But users may be required to set up MFA to access something like GitHub organizations, in which case having it available in 1Password is convenient.
griffinmb··on Its butterfly keyboard design has failed, but Apple has yet to admit its mistake
The docs don't seem to disagree with me.

> Besides, you shouldn't need to plug it that way to pair it either.

Agreed. And glad that's not necessary for the latest generation.

griffinmb··on Its butterfly keyboard design has failed, but Apple has yet to admit its mistake
> You missed charging the Apple Pencil on the ipad pro.

You plug the Pencil into the iPad to pair it. It comes with an adapter that you use to charge it with a regular cable.

griffinmb··on Ask HN: Starting a career in security at 40?
I made the switch from web development to security a few years ago and initially took a 10-15% pay cut. I didn't get any certs and wouldn't necessarily recommend them. Instead, I joined various bug bounty programs to get practical (and resume-lite) experience.

Having implementation experience (via webdev) in addition to the bug bounty experience was a plus when I was interviewing.

If you're in a tech hub like SF or NYC there is plenty of security work. But, yeah, I would expect some kind of a paycut since you are moving from a (potentially) senior position to an entrylevel position.

griffinmb··on Two years of Elixir at The Outline
I mean, I read the codebase, which is why I'm saying it's small and easily understood. Sure, it has some specific things to know, and some ("magical") helpers like automatic view functions. But it's no more its own platform than any other micro-framework.

I'd be interested to know what you believe the ups and downs are, aside from speed.

griffinmb··on Two years of Elixir at The Outline
Phoenix is really a very small framework, and its codebase can be easily understood in just a couple of days. Phoenix being "large" is a common (but unfounded) criticism that seems to stem from Elixir's superficial resemblance to Ruby.
griffinmb··on Amazon scraps secret AI recruiting tool that showed bias against women
*college

Also, it isn't entirely clear what you are trying to say. If you are suggesting that school-based screening is also problematic, then you are probably on the right track.

griffinmb··on Unpatched WordPress vulnerability allows code execution for authors
It has been more than 7 months since the issue was reported, I don't see how this lacks professionalism. They even created a temporary fix.
griffinmb··on QuitGenius (YC W18) raises $2M to help people quit smoking
> Since launch Quit Genius has grown to 300,000 registered users, with over 20,000 people officially smoke-free in the app (which Quit Genius defines as having not smoked for over 28 days).

I'd be interested to know how "smoke-free" time is established. Are users self-reporting that they have or haven't smoked with the app? And 28-days of not smoking is great, but it feels dishonest to call that "smoke-free".

> Healthy employees save the company money and are more productive, and Quit Genius thinks it can not only help employees get healthier but give employers a way to track that progress.

Dystopian.

griffinmb··on EFail – Vulnerabilities in end-to-end encryption technologies OpenPGP and S/MIME
I think the issue is more that nonce reuse with stream ciphers like GCM result in a more catastrophic failure (i.e. secret key disclosure), whereas reusing the IV with CBC will only disclose whether some plaintext was encrypted multiple times. In an embedded platform where there is no easy way to ensure a nonce is not reused, the potential info disclosure may be preferable.
griffinmb··on An Interview with the Creator of Ruby (2001)
In general, I think Ruby does a good job of being unsurprising. I like that most things work as I'd expect, with the syntax I'd expect. But then you've got weird things like `File.read("|ls")` that are entirely surprising.
griffinmb··on Image Uploads with AWS S3, Elixir and Phoenix
I'm sure it's possible to do this securely, but in general this seems like a sure-fire way to expose your secret keys.
griffinmb··on An analysis of the Nomx secure communications device
Their response (on their homepage) is awful: http://nomx.com/

"nomx Passes Security Tests After Blogger Claims to Have Penetrated nomx

- UK blogger makes false claims he can access nomx remotely

- UK blogger fails to access nomx remotely"

griffinmb··on Show HN: Send POST requests via simple URLs
Could be useful for proof-of-concepts. Though, if you are a site-owner and your form can be submitted with this, you should probably consider implementing anti-csrf protections.
griffinmb··on How is team-member-1 doing?
Unless I'm misreading it, the t-shirt is internal only, and only for the team that specifically handled the issue.
griffinmb··on Open-sourcing Chrome on iOS
I believe that the real reason is that Webkit needs privileged APIs and unique executable memory regions for the jit. Giving third-party developers that access would make jailbreaking a simpler process.
Page 1 of 4Next →