HNHacker News
TopNewBestAskShowJobs

jbaviat

355 karma · joined October 15, 2015

CTO @SqreenIO • Devoted to making products secure • https://www.sqreen.io • Former Apple developer, reverse engineer, pentester.

[ my public key: https://keybase.io/jbaviat; my proof: https://keybase.io/jbaviat/sigs/NWU9ha5R0icf9TT_Pmhnlv3VPseVk1QzbChB_KYETvU ]

submissionscomments
jbaviat··on Create value for others and don’t worry about the returns
I _do_ believe the author implied universality on purpose.

That’s also close to the YC motto: “make something people want”.

Or as Paul Graham puts it: be good. https://paulgraham.com/good.html

jbaviat··on Migrating Dillo from GitHub
How about using tor to help with DNS redundancy? https://en.wikipedia.org/wiki/Tor_(network)
jbaviat··on Bose will brick SoundTouch speakers in 2026
Quoting Bose:

| Bose SoundTouch systems were introduced into the market in 2013. Technology has evolved since then and we’re no longer able to sustain the development and support of the cloud infrastructure that powers this older generation of products. We remain committed to creating new listening experiences for our customers built on modern technologies.

jbaviat··on Why don't we use awnings anymore (2022)
I used to live in France. We had no A/C, enough climate consciousness not install it, though our east-facing windows were bringing important heat at sunrise. We had awnings installed, with an HomeKit connection, so we could automatically have them closed before sunrise, and opened once the sun would leave this face of the building. We saved a few degrees in this way.
jbaviat··on Launch HN: Airhart Aeronautics (YC S22) – A modern personal airplane
> There’s a plethora of other problems that make flying cumbersome

How about CO2 emissions?

jbaviat··on Reviving PyMiniRacer: A Python <> JavaScript Bridge
PyMiniRacer (original) author here. PyMiniRacer is definitely a way to run insecure code, but as pointed, the several CVEs in V8 require measures beyond "just" relying on PyMiniRacer to make it safe.

For the record PyMiniRacer was victim of a CVE itself https://nvd.nist.gov/vuln/detail/CVE-2020-25489 - a heap overflow, my mistake.

1. Total control over what APIs the user's code can call: you kinda got it... users can just do plain JS 2. Memory limits: you got it 3. Time limits: you got it, but the current model is unreliable when used at high levels of CPU and a high number of threads.

And thank you so much bpcreech for taking back the ownership of PyMiniRacer!

jbaviat··on Ask HN: What side projects landed you a job?
I built a tool to extract ROP gadgets from binaries [0], which got noticed by a guy at Apple, and I ended up spending 4 years there. And this guy became Sqreen CEO and my (incredibly awesome) cofounder.

[0] https://github.com/aviat/skyrack

jbaviat··on Apple previews Lockdown Mode
[Disclaimer: I worked in Apple Red Team]

What if this isn’t a good news for 99% of Apple users?

That’s obviously an amazing measure for the 1% high targets out there.

But what about the other 99%? Does that create an incentive for Apple to strengthen Lockdown Mode security to the detriment of the regular mode (should we call it Unsafe Mode)?

I’m afraid that this architecture will make it harder to prioritize security features or fixes for the 99% users. Developers bandwidth is limited, they can’t fix all bugs. Hence if you have to choose between one bug impacting the 1% most important users (from a security standpoint) versus one bug impacting the 99% others, which would you choose?

Would such an architecture have led to the emergence of Blastdoor[1] - which attempts at mitigating iMessage attachement exploits, but is now useless in Lockdown mode?

My hope here is that by reducing attack surface, Lockdown mode will make exploits much easier to fix (as they’ll target a limited area), allowing to strengthen the system core while freeing bandwidth to implement longer term, Blastdoor like mitigations.

[1] https://googleprojectzero.blogspot.com/2021/01/a-look-at-ime...

jbaviat··on Ending Facebook Frictionless Sharing
Slides from the Center for Humane Technology, who authored the social Dilemma [0].

[0] https://www.humanetech.com/the-social-dilemma

jbaviat··on A nasty bit of undefined timezone behavior in Golang
Je suis en train de me faire un devis pour
jbaviat··on iOS 15 Humane
This reminds me a lot about the goals behind the center for humane technology, and their amazing podcast https://www.humanetech.com/.

They also are the ones behind the Netflix documentary « the social dilemma ».

jbaviat··on Ask HN: What do you use to secure your _aaS?
I’m Sqreen CTO and co-founder, now working on building AppSec at Datadog. You can keep using Sqreen as we’re maintaining the service for at least a year. Right now we are focused on integrating Sqreen capabilities to Datadog, so you will be able to migrate at some point! Stay tuned for that, and please get in touch (https://twitter.com/jbaviat ) if you’d like to be a design partner.
jbaviat··on Ask HN: Who is hiring? (October 2020)
Sqreen | YC W18 | Product Security Engineer | Paris | Full-Time | Remote |

Sqreen | YC W18 | Data Engineer | Paris | Full-Time | Remote |

Sqreen | YC W18 | Agent Principal Engineer | Paris | Full-Time | Remote |

Sqreen | YC W18 | Principal Engineer, Platform Squad | Paris | Full-Time | Remote|

Sqreen (YC W18) is an application security platform made for both engineering and security teams. We use dynamic instrumentation libraries that monitor web applications internals to detect security anomalies and block triggered vulnerabilities at runtime. What Application Performance Management tools (like New Relic) do, but for security.

We are currently looking to fill a few critical roles in a European friendly timezone (+/- 2 hours) for our Product & Engineering team:

Product Security Engineer - a software engineer with a security focus who will help to secure our products for our customers.

Data Engineer - a backend engineer who is passionate about all things data processing, platform availability & performance and scalability.

Agent Principal Engineer - a technical lead who will be responsible for driving the overall technical vision across our entire agent library (7 languages and counting!).

Principal Engineer, Platform Squad - a technical lead who loves technical strategy, mentoring and anything architecture related.

All of these roles are open to full remote with a European compatible time zone.

You can find more details on our careers site:

https://www.sqreen.com/company#jobs

jbaviat··on OpenSSH 8.3 was released on 2020-05-27
One interesting thing is that it announces that ssh-rsa will be disabled due to price drop of SHA-1 collision attacks (~50k$).
jbaviat··on Ask HN: Who is hiring? (December 2019)
Sqreen | Java agent software engineer | Paris | Full-Time | Remote (Paris timezone) |

Sqreen | Backend engineer | Paris | Full-Time | Onsite |

Sqreen | Cross agent engineer | Paris | Full-Time | Onsite |

Sqreen (YC W18) is an application security platform made for both engineering and security teams. We use dynamic instrumentation libraries that monitor web applications internals to detect security anomalies and block triggered vulnerabilities at runtime. Pretty much what an Application Performance Management tool (like New Relic) is doing, but for security.

We are currently looking for Java agent engineers (e.g. you need to love byte code instrumentation [1]) and C/C++ [3] [4] [5] (remote anywhere in European timezone) to help us expand the capability of our agents, as well as a senior level Backend developer (knowledgeable or willing to learn Python) to build new functionality on our backend (based in our Paris HQ).

Also, we're looking to hire a Cross Agent Engineer in Paris too!

You can find more details on our careers site [5]

[1] [https://blog.sqreen.com/building-a-dynamic-instrumentation-a...

[2] [https://blog.sqreen.com/how-to-build-a-waf-at-the-applicatio...

[3] [https://blog.sqreen.com/how-we-built-v8-natively-on-arm/](ht...

[4] [https://blog.sqreen.com/building-a-native-add-on-for-node-js...

[5] [https://www.sqreen.com/company#jobs](https://www.sqreen.com/...

jbaviat··on Ask HN: Who is hiring? (August 2019)
Sqreen | C software engineer | Paris | Full-Time | Remote |

Sqreen | Low level Java software engineer | Paris | Full-Time | Remote |

Sqreen | Backend engineer | Paris | Full-Time | Onsite |

Sqreen | Product Manager | Paris | Full-Time | Onsite |

Sqreen (YC W18) is an application security platform made for both engineering and security teams. We use dynamic instrumentation libraries that monitor web applications internals to detect security anomalies and block triggered vulnerabilities at runtime. Pretty much what an Application Performance Management tool (like New Relic) is doing, but for security.

We are currently looking for low-level Java (e.g. byte code instrumentation) and C/C++ developers to help us expand the capability of our agents, as well as backend developers (knowledgeable or willing to learn Python) to build new functionality on our backend.

Also, we're looking to hire our first Product Manager to define & work with the squads to keep delivering more value to our users.

You can find more details on our careers site:

https://www.sqreen.com/company#jobs

jbaviat··on Launch HN: Sqreen (YC W18) – Securing Web Apps
You are correct, our content security policy is not perfect, and we are gradually improving it. Security is a journey and there is no such thing as perfect security. We are striving to incrementally improve everything we are doing as our team is scaling.
jbaviat··on Amendment: Possible Remote Code Execution Exploit in Rails Action View
What was supposed to be a file disclosure turned into a remote code exécution.
jbaviat··on Angora, mutation-based coverage guided fuzzer was open sourced
Research paper about Angora was published here: http://web.cs.ucdavis.edu/~hchen/paper/chen2018angora.pdf
jbaviat··on Ask HN: Blocking os.urandom calls in Python = 3.6
Let's assume I'm using Python 3.6. All my calls to os.urandom (such as uuid.uuid4) can block if my system's entropy goes down. Let's assume as an attacker, I can reduce the system's entropy up to making all calls to e.g. uuid.uuid4 blocking, potentially making my Python blocking everythime.
jbaviat··on The First Security Engineer’s 100-day Checklist
Being the first security engineer in a startup that already operates for a few months or even years can be quite daunting. Starting up security is hard. Starting security in a company that has already gathered a huge security debt is even harder. This security checklist aims to help security engineers and CISOs in early stage companies to prioritize their efforts in the first months of their new job.

Any security engineers that were in this situation? Do not hesitate to share your feedback!

jbaviat··on Ask HN: Who is hiring? (September 2018)
Paris | France | full-time | on-site | https://www.sqreen.io/

What is Sqreen? - Sqreen is a developer platform which detects security anomalies in web applications and provides automated responses and protection from attacks in real-time. Put another way, it’s New Relic, but for security.

And the good news is, we’re hiring engineers for our Paris office! (Relocation possible). Work on our dashboard, strengthen our core platform, or develop the next Sqreen agents (Go, PHP) from scratch: https://www.sqreen.io/jobs/

Why work for Sqreen?

Be part of an incredibly talented team who are passionate about democratising security Join at a crucial stage of our development (just post series A) Contribute tangibly and significantly to our core product, bringing value to our customers each and every week Join a product-focused company, with a deep commitment to learning Sqreenity sessions - one week per quarter to focus on a subject of your choice and leverage for communicating about it Attend your 'dream conference' each year financed by Sqreen, including travel A relaxed working environment with regular social activities Beautiful 'Sqreenhouses' in central Paris (Sentier), and San Francisco. An international, English speaking work environment with trips to SF for our engineers minimum once a year

Questions? Answers -> jobs@sqreen.io

jbaviat··on Show HN: An open source security page to easily integrate on your website
Hey Hacker News,

I'm Jb the CTO and co-founder of Sqreen (YC W18).

Privacy/status pages have become a standard on the web. But nothing is really made to answer to the increasing security concerns of users.

In the SaaS world, some companies integrate a detailed security page on their website, but most companies are still missing one today.

The goal of this open source security page is to change that.

It's not perfect, but we made it really simple for anyone to add it on their website.

The goal of the page is also to help developers think about security and maybe improve the status quo.

We are open to contributions → https://github.com/sqreen/security-page

You can read the full content here: https://raw.githubusercontent.com/sqreen/security-page/maste...

jbaviat··on The DevOps Security Checklist
Hey HN, I’m the co-founder and CTO of Sqreen (YC W18) [1].

After publishing the SaaS CTO Security Checklist 2 months ago [2], I’m excited today to share the DevOps security checklist with the HN community.

With the “DevSecOps” movement, security is more and more a topic for DevOps engineers and this checklist is here to help.

Have feedback? Please share it!

[1] https://www.sqreen.io/ [2] https://news.ycombinator.com/item?id=16615593

jbaviat··on Writing a Python C extension in 2018
I'm the author of https://github.com/sqreen/PyMiniRacer, used as example in this deck.

I introduce how I leveraged ctypes + Python manylinux wheels (PEP513 / PEP571) in order to allow loading V8 easily into Python, without requiring local compilation on install nor having us maintaining a huge test matrix:

    $ pip install py-mini-racer
    $ python
    >>> from py_mini_racer import py_mini_racer
    >>> ctx = py_mini_racer.MiniRacer()
    >>> ctx.eval('1+1')
    2

So this shared object could be used in any language allowing to interact with arbitrary shared objects (e.g. Ruby with fiddle).
jbaviat··on An in-depth look at CVE-2018-8878 or why integer overflows are still a thing
As a former security researcher, I am amazed that integer overflows are still a thing in 2018, in the Ruby core - so probably everywhere... About 10 years ago, integer overflow vulnerabilities were trending in the security community. Plenty of nice vulnerabilities and exploits have been found with them - like in all PDF readers, ... I guess when the momentum of such vulnerabilities goes down, this class of bugs goes unnoticed. Secure programming is hard, it's too bad we don't keep the learning we had in the past.
jbaviat··on Saas CTO Security Checklist
I’m the CTO at Sqreen and I do love Matasano (cryptopals... awesome crypto challenge https://cryptopals.com/). Realistically, security audits or bug bounty are not doable in seed startups - where most of the time no one has any security knowledge, and no money :) Thanks for the missing things we will update! By the way this is open source, feel free to contribute: https://github.com/sqreen/CTOSecurityChecklist (not sure this is 100% today with the version on Sqreen.io, we’ll get there this week).
jbaviat··on The Tangled Web: A Guide to Securing Modern Web Applications (2011)
This book has a clever approach to explaining what's at stake regarding web app security, in particular the browser security model. That's how I would have structured my book if I had written some regarding web app security.
jbaviat··on Ask HN: Who is hiring? (December 2017)
Sqreen - https://www.sqreen.io | Full-time Onsite engineers | Engineering team in Paris (France)

Sqreen is a security tool built with developers in mind (we are like New Relic, but for security).

We develop solutions that combine instrumentation, defensive algorithms and machine learning.

We are recruiting new engineers to join the team creating Sqreen agents for all technologies, and ship our incoming products.

Our most researched positions are within the agents team. You will join the guys that are writing the best instrumentation agents ever, and in all technologies (so far Ruby, Python, Node.js, PHP). These agents are protecting hundreds of thousands of applications, gazillions of HTTP requests per months...

- a C software engineer. The responsibility includes developing the PHP version of the Sqreen agent. PHP is written in C, we need an extension able to manipulate PHP internals to do PHP instrumentation), have you ever written something this cool for production usage?) https://www.sqreen.io/jobs-c

- a Java software engineer. This one is all about being the core maintainer of the Sqreen Java Agent. You need to be super comfortable of the JVM internals for this one (we are relying on the Byte Buddy library for instrumentation: http://bytebuddy.net/). https://www.sqreen.io/jobs-java

- a DevOps engineer. We have cool challenges like duplicating our infra to other zones (e.g. US, Asia), we are currently moving to DynamoDB, and we plan to do innovative usage of CDNs such as Fastly (https://www.fastly.com/blog/beacon-termination-edge/) https://www.sqreen.io/jobs/sqreen-aws-devops.html

Sqreen is already live for Ruby, Python, Node.js, and PHP.

You can find our other job offers here: https://www.sqreen.io/jobs/

Email: jobs@sqreen.io

jbaviat··on Content Security Policy by API
So actually I've asked WebAppSec about any similar project, let's see how it goes (http://lists.w3.org/Archives/Public/public-webappsec/2017Nov...).
Page 1 of 3Next →