HNHacker News
TopNewBestAskShowJobs

icanhasfay

69 karma · joined June 19, 2012

Security. @icanhasfay
submissionscomments
icanhasfay··on An update on two-factor authentication using SMS on Twitter
Nothing like putting a paywall on consumer security options.
icanhasfay··on The Scranton Iron Furnaces
Likewise, I must have driven past them a few dozen times without even knowing!
icanhasfay··on Jack Dorsey’s account was hacked
I think most of the suspicions so far have been pointing to a sim swapping attack.
icanhasfay··on Yelp Is Replacing Restaurants’ Phone Numbers So Grubhub Can Take a Cut
(Serious Q) What other good alternatives are out there for Yelp?
icanhasfay··on Ask HN: Who is hiring? (August 2019)
Braintree | Software Engineer, Security | Chicago, San Francisco, New York City, Austin | Onsite | Fulltime

At Braintree we provide the global commerce tools people need to build businesses, accept payments, and enable commerce for their users. It’s the simplest way to get paid for your great ideas -- across any device, and through almost any payment method. Merchants in more than 40 countries worldwide can accept, split, and enable payments in more than 130 currencies using Braintree. And we’re here for you -- with stellar support, innovative concepts, and simple processes -- from your first dollar up past your billionth.

The Role:

The Security Engineer's role is to protect sensitive data and applications in high-scale systems that are growing rapidly. We need you to be heavily involved in keeping security top of mind as we look to power our customers' most important transactions.

Types of projects we work on:

  Working with product teams on the security of their new features
  Building custom tools to scale security responsibilities 
  Maintaining the authentication and encryption capabilities of a fast growing payments platform
What we look for in you:

  Solid programming foundation; expect to spend a significant amount of time writing code
  Working knowledge of one or several object-oriented or functional programming languages
  Working knowledge of applied cryptography and how to effectively develop appropriate cryptographic solutions
  Knowledge of PCI-DSS is a plus
  Previous wide-ranging experience in application security and policy development
  4+ years experience developing software with particular interest in keeping things safe and secure
For more details and to apply in, check: https://grnh.se/59656d971
icanhasfay··on Ask HN: Who is hiring? (July 2019)
Braintree | Software Engineer, Security | Chicago, San Francisco, New York City, Austin | Onsite | Fulltime At Braintree we provide the global commerce tools people need to build businesses, accept payments, and enable commerce for their users. It’s the simplest way to get paid for your great ideas -- across any device, and through almost any payment method.

Merchants in more than 40 countries worldwide can accept, split, and enable payments in more than 130 currencies using Braintree. And we’re here for you -- with stellar support, innovative concepts, and simple processes -- from your first dollar up past your billionth.

The Role:

The Security Engineer's role is to protect sensitive data and applications in high-scale systems that are growing rapidly. We need you to be heavily involved in keeping security top of mind as we look to power our customers' most important transactions.

Types of projects we work on:

  Working with product teams on the security of their new features
  Building custom tools to scale security responsibilities 
  Maintaining the authentication and encryption capabilities of a fast growing payments platform
What we look for in you:

  Solid programming foundation; expect to spend a significant amount of time writing code
  Working knowledge of one or several object-oriented or functional programming languages
  Working knowledge of applied cryptography and how to effectively develop appropriate cryptographic solutions
  Knowledge of PCI-DSS is a plus
  Previous wide-ranging experience in application security and policy development
  4+ years experience developing software with particular interest in keeping things safe and secure
For more details and to apply in, check: https://grnh.se/59656d971
icanhasfay··on Ask HN: Who is hiring? (June 2019)
Braintree | Software Engineer, Security | Chicago, San Francisco, New York City, Austin | Onsite | Fulltime

At Braintree we provide the global commerce tools people need to build businesses, accept payments, and enable commerce for their users. It’s the simplest way to get paid for your great ideas -- across any device, and through almost any payment method.

Merchants in more than 40 countries worldwide can accept, split, and enable payments in more than 130 currencies using Braintree. And we’re here for you -- with stellar support, innovative concepts, and simple processes -- from your first dollar up past your billionth.

The Role:

The Security Engineer's role is to protect sensitive data and applications in high-scale systems that are growing rapidly. We need you to be heavily involved in keeping security top of mind as we look to power our customers' most important transactions.

Types of projects we work on:

  Working with product teams on the security of their new features
  Building custom tools to scale security responsibilities 
  Maintaining the authentication and encryption capabilities of a fast growing payments platform
What we look for in you:

  Solid programming foundation; expect to spend a significant amount of time writing code
  Working knowledge of one or several object-oriented or functional programming languages
  Working knowledge of applied cryptography and how to effectively develop appropriate cryptographic solutions
  Knowledge of PCI-DSS is a plus
  Previous wide-ranging experience in application security and policy development
  4+ years experience developing software with particular interest in keeping things safe and secure
For more details and to apply in with us check: https://boards.greenhouse.io/braintree/jobs/1493945.
icanhasfay··on Ask HN: Who is hiring? (March 2017)
Hulu | Santa Monica, CA | Onsite | Full-time

Hulu is a premium streaming TV destination that seeks to captivate and connect viewers with the stories they love. We create amazing experiences that celebrate the best of entertainment and technology. We’re looking for great people who are passionate about redefining TV through innovation, unconventional thinking and embracing fun. It’s a mission that takes some serious smarts, intense curiosity and determination to be the best. Come be part of the team that’s powering play.

Hulu’s Information Security Team is seeking an Application Security Engineer as a new addition to the team. You can find the description for the role at the link below.

Application Security Engineer - https://www.hulu.com/jobs/positions/o4vg2fwr

And of course you can check out the rest of Hulu's open positions at https://www.hulu.com/jobs.

icanhasfay··on Ask HN: Who is hiring? (February 2017)
Hulu | Santa Monica, CA | Onsite | Full-time

Hulu is a premium streaming TV destination that seeks to captivate and connect viewers with the stories they love. We create amazing experiences that celebrate the best of entertainment and technology. We’re looking for great people who are passionate about redefining TV through innovation, unconventional thinking and embracing fun. It’s a mission that takes some serious smarts, intense curiosity and determination to be the best. Come be part of the team that’s powering play.

Hulu’s Information Security Team is seeking an Application Security Engineer and an Information Security Architect as new additions to the team. You can find the descriptions for the two roles at the links below.

Application Security Engineer - https://www.hulu.com/jobs/positions/o4vg2fwr Information Security Architect - https://www.hulu.com/jobs/positions/onlr4fwn

And of course you can check out the rest of Hulu's open positions at https://www.hulu.com/jobs.

icanhasfay··on Ask HN: Do I have to go through recruiters nowadays, how do you find new jobs?
A little late to the party but I just recently created a job board that aims for organizing the tech job market. https://www.zeroinjobs.com

I know it's a bit misaligned with the ask in the thread but thought it could be a good resources for job seekers. Personally got sick of creating pseudo regex's on job search sites.

icanhasfay··on Typing the Letters A-E-S Into Your Code (2009)
Obligatory Doom principle link. http://www.thoughtcrime.org/blog/the-cryptographic-doom-prin...

Encrypt Then Authenticate, dammit!

icanhasfay··on Lizard Squad attacks Brian Krebs
Not my finest word selection on that one :/
icanhasfay··on Lizard Squad attacks Brian Krebs
My favorite might have to be the time when someone cut down a tree in his front yard. https://twitter.com/briankrebs/status/334422653475627008
icanhasfay··on Your best passive income? (2015 Edition)
I'll be quite honest, I didn't even know that was a problem to begin with. It makes sense, I just haven't seem to run into it yet.
icanhasfay··on Your best passive income? (2015 Edition)
Just what some of the other replies are stating, serving ads. Mind you it's not generating that much income but it is most definitely passive. :)
icanhasfay··on Your best passive income? (2015 Edition)
http://hashallthethings.com/

Tiny web app for hashing strings using different algorithms.

It's really just a tiny project I threw together when learning CherryPy. Covers itself in hosting and provides a small bit of extra change.

icanhasfay··on Show HN: SecurityOverboard, a job board for information security positions
Thanks! Unfortunately, the current aim is to keep the job board to mainly hands-on/in-the-field InfoSec positions. However I would have to say that the companies that do make the job board list would be a much better starting point for you than scraping around generic job boards for positions.
icanhasfay··on Show HN: SecurityOverboard, a job board for information security positions
Hah! Gotta say, that is a great tagline. Might have to use it at some point :P
icanhasfay··on Show HN: SecurityOverboard, a job board for information security positions
Hah, I definitely see how you can get that from the name. I was aiming for a mashup between Information Security and JobBoard without making the domain name too long or too bland. I think the site will have to rely on a little of both for it to really take hold. Thanks for checking out the site.
icanhasfay··on Show HN: SecurityOverboard, a job board for information security positions
Thanks for checking out the site. I can definitely attest to the difficulty in finding InfoSec positions on generic job boards as I was in the same position around a year and a half ago. As you mentioned, most of the positions on those job boards were either old postings, not actually relevant to InfoSec or posted through a recruitment agencies. This led me to practically writing regex's through the sites' filtering systems just to get back relevant postings. Having run through the problems firsthand, I wanted to try and solve these pain points by creating a community-driven job board for InfoSec positions, aka SecurityOverboard.
icanhasfay··on Flappy Bird Creator Dong Nguyen Speaks Out
Just something itching me wrong about purposefully making a game excruciatingly difficult and then getting so emotionally affected by their reactions to that difficultly that you are distraught.
icanhasfay··on Spotify – security team response time
Have to disagree with a few points here.

"Hmmm, let me 'test' random website X for something that could cause a DoS"

The author was testing reflected XSS which is inherently client side, there should be no case of concern for DoS here.

"Building a "security portfolio" against websites is a stupid idea with some potentially huge negative consequences."

The author mentions Apple, Linkedin, Amazon and AT&T all of which have some type of vulnerability notification program. (See https://bugcrowd.com/list-of-bug-bounty-programs/ for a great list of programs) I would have to say that as long as the researcher was performing within the scope of the respective program, there should be no worry. I think it's the exact opposite of a stupid idea. Building out a portfolio within the scopes of the programs is a great way to build some security reputation.

icanhasfay··on Stripe-CTF 3 Writeup
Didn't catch that, thank you.
icanhasfay··on Stripe-CTF 3 Writeup
Anyone else seeing links to empty repos?
icanhasfay··on Source of the famous “Now you have two problems” quote (2006)
Today's relevant xkcd: http://xkcd.com/1171/