HNHacker News
TopNewBestAskShowJobs

jenandre

433 karma · joined September 20, 2012

Software developer, with occasional opinions.

http://jenpire.com

submissionscomments
jenandre··on Treaty gives Hong Kong option to reject Snowden extradition to the US
I have no power to discredit him. I'm not famous, nor any access to a venue to do so.

This is totally personal speculation based on how I would have behaved if I were in his position as a whistleblower that was a strong human rights privacy advocate. To me, his actions are incongruous with his statements. If he's not being manipulated by the Chinese, the other option is that he is just naive or careless and picked Hong Kong without considering what kind of political implications it would have, and was either unaware of its history in human rights and privacy, or chose to ignore it.

I'm fully willing to believe my opinion will change if more facts come in; just as it it stands now, I remain skeptical.

jenandre··on Treaty gives Hong Kong option to reject Snowden extradition to the US
If he had connections in Hong Kong, why supply the weak excuse "oh, it's because of its history of dissidence and freedom of speech?"

He would have been much more convincing saying "yeah, I know that China doesn't have the greatest record on privacy, but I have several friends in Hong Kong that I hope will support my asylum case." Boom. Totally makes sense, and doesn't sound like a rehearsed rationalization that could have been scripted by the PRC.

It's the age of airplanes, dude. They aren't sending out the stagecoaches with deputies. Physical distance doesn't really matter if someone with access to the resources the US government has is out to get you. I think this guy is well aware of that (as you should be, too).

jenandre··on Treaty gives Hong Kong option to reject Snowden extradition to the US
lol, perfect example of why twitter is retarded.

I live in DC and know tons of people who work for the government. Guess what? They are people like you and I, and in a lot of cases less capable or bright (which is why they go for cushy government jobs). They get drunk and they act like assholes in groups, you hear them talking garbage all the time on the metro and in restaurants.

Just because these people (who in all likelihood are bureaucrats with no power at all) say they want this guy dead doesn't mean they have any power or ability to send out the hit squad, or killing reporters is now US Policy. It's just as meaningless as me randomly saying "god, I wish Karl Rove was dead."

jenandre··on Treaty gives Hong Kong option to reject Snowden extradition to the US
Sorry, but I don't buy this guy's story. Something is just incredibly fishy.

I don't buy this guy's argument for going to Hong Kong, e.g. that has a history of free speech, and its supposed autonomy from the mainland -- even after all of these years, Chinese pressure prevents Taiwan from international recognition. You think they are just letting Hong Kong do its own thing? He seems intelligent and must be aware of this, especially having worked in the intelligence world. The Chinese firewall is the most renowned internet chokehold in the world. The Chinese are known for hacking Google to spy on their own citizens.

I just have to think of it if I were in his situation. If I were a freedom-loving individual looking to seek asylum, I'd probably first look at countries that granted asylum in similar cases that weren't internationally renowned for suppressing freedom of speech. Assange has asylum with Ecuador, why not go there first? China is just such a weird choice for someone who is purportedly morally driven to his actions by privacy violations.

Not only that, this situation has nothing but upsides for the Chinese. It looks great for them to expose another world power is spying on their own citizens (and weakens any diplomatic arguments the US has when pressuring them to open up free speech and the internet). It's also a nice thorn to retort after all of the recent hubbub about Chinese government hackers. If he wasn't an active spy in the traditional definition feeding the Chinese information, he is certainly an asset by circumstance -- why wouldn't they manipulate him to their benefit?

Now, that's not saying the US did the right thing -- we kind of fucked ourselves here having PRISM in place first of all -- but I am not sure this guy is the lone ranger whistleblower hero is painting himself to be.

jenandre··on I long for the future where I can safely assume my passwords are stolen
The solution isn't intended as a measure to resist intrusion, I agree 100% with you that using PKI as a form of two factor for hardening authentication is a great idea.

It's more of a secondary measure for forensics and incident response purposes when the intrusion resistance measures fail. If your credentials can be hacked for any reason(your key AND your password are compromised, for example), when those credentials are used you have a useful audit trail of when it happened and can possibly even get some early notification. If I hack your laptop and use your valid credentials to log in to a site, even if you log in just to disable the audit logging, there will at least be one entry of that happening somewhere. If the audit collection system supports some early notification, you can potentially change your credentials or notify the service before the hacker does something bad.

jenandre··on I long for the future where I can safely assume my passwords are stolen
The usernames do not need to be part of the audit trail -- the unique URL identifies the site it came from. You know you your own logins, presumably, so it doesn't need to be there.

myaudithooks.com should not be centralized -- I 100% agree. You should just be able to put any old URL there. If I want my audit entries to go to my box, I absolutely should be able to.

You're right, some attacker could post bogus information if the know the url... however, the urls should be unique enough that they can't just be randomly "guessed" by an attacker. Another alternative is to provide a callback url, the way stripe does, so the service can "authenticate" the audit log entry before I consider it valid. For example, if I receive an audit log entry with id "abcd1234", I can hit http://mydogfriends.com/audit/abcd1234 to make sure it responds appropriately.

The idea isn't fully fleshed out yet, but I think it wouldn't take a lot of work to make it happen.

jenandre··on WebSocket proxy support added to nginx trunk
It looks comparable to me... I hadn't seen bouncy before though, so I'll have to check it out if I run into any problems with node-http-proxy.

I agree, having the power to write your proxy code in javascript is really nice, especially compared to having to struggle with getting some infrastructure's DSL to work for you (e.g. nginx, varnish's).

jenandre··on WebSocket proxy support added to nginx trunk
We're using this to reverse proxy websockets over SSL and it's simple and wonderfully stable.

https://github.com/nodejitsu/node-http-proxy

jenandre··on I am under surveillance by Canadian agents, my computer has been backdoored
If you have not shut down the machine, I would do a memory acquisition (http://code.google.com/p/lime-forensics/, can be analyzed with Volatility) and a raw disk acquisition (you can use dd) and get to someone for forensic investigation to look for rootkits and other evidence of tampering.
jenandre··on Chinese Hackers Infiltrate New York Times Computers
I don't think the RubyGems people were incompetent. The software serves its core purpose quite well (as a library delivery mechanism) and is quite reliable. But clearly they weren't thinking about security in decision, and what would happen if the repos were compromised.

Let's be honest here - no software is 100% secure. As developers and consumers, the idea that we all review all of the tools in our toolchain for security soundness is absurd. It's like saying that everyone using C made poor decisions because of security flaws in popular libraries (even security ones, like openssl) and therefore all of the C community has no engineering competence.

The fact is, China already has their eyes on GitHub and it's not beyond the planning capability to place backdoors in popular software to suit their future ends.

No matter who the attacker may be, you have to be prepared for the situation where your computers and data are compromised, period.

jenandre··on Chinese Hackers Infiltrate New York Times Computers
This story, and the recent RubyGems debacle should be teaching all of us one thing -- assume you can and will be hacked. Do you understand the implications (what data you are going to lose? what credibility?) Do you have a plan to deal with it?

Ruby Gems was lucky in that their hack was noisy. The chinese government, as illustrated above, won't play so nice.

This is why monitoring and incident response matter.

Remember the subtle backdoor that almost slipped into the Linux kernel in 2003[1]? That could be Ruby Gems right now. Hopefully, they are taking the proper steps to investigate exactly what the hackers did.

[1] http://kerneltrap.org/node/1584

jenandre··on How TaxCloud Stole My Code and How I'm Doing Something About It
I think the arguments here are weak. Using a builder is extremely common in API wrappers like this (I just did this myself wrapping an API in Ruby). In the second example, the code you pointed out was similar really wasn't that similar. Someone else made a good point: because this is an API wrapper there's really only a limited number of ways to do things.

Still, there's a good chance that someone looked at it to see how you did things -- these things are hard to prove. Regardless, I think your response is a bit over the top? Does it warrant this nasty blog post, or could you have just emailed the dude and said, "Hey, I noticed you guys may have been inspired by my code, a lot of appeared similar. I am licensing under GPLvXXX [or whatever your license is] and it requires some attribution if you guys did use some of my code." I suspect they would have happily given it to you. If they refused, well, then maybe then would have been the time for the rant. :)

No offense, but the way you handled this, you are coming off like some guy having a temper tantrum on the internet, instead of a developer with valid grievances handling this maturely.

jenandre··on On sexism in the tech industry - rebuttal
"As an example, after university I discovered that when I'd been struggling alone to do my assignments and assuming all the guys were just finding it easy, all the guys were going round to each other's rooms, hanging out together, discussing work and looking at each other's code. They didn't think to invite me, possibly out of fear that I'd misinterpret it as a date or that I'd ruin the boys' club atmosphere, and I rarely asked them about work for fear of looking like I wasn't up to their level." - this x1000. It doesn't help when you're attending a super competitive CS program with a bunch of people who seem (or give the appearance of) knowing everything. I'm not saying they really could have done anything about it, or it's anyone's fault I felt excluded. In fact, it was entirely my fault I did all my group assignments alone; had I overcome my introversion, I have no doubt I would have gotten friendly responses. However, I think CS is going to be attractive for a higher proportion of introverted people than not. How do we make those environments friendlier to sensitive outsiders like this? It's not an easy problem to solve.
jenandre··on On sexism in the tech industry - rebuttal
I think "even out" was a bad/lazy choice of words on my part. What I mean is, it will get to a point where the ratio of women in tech will be more or less equivalent to the ratio of women that WANT to be in tech. This may or may not be exactly 50%. It could be 25%. I don't know myself. It's getting better in certain areas, but when you talk about "technical" positions e.g. programming, sysadmin, etc the ratio seems to be pretty bad and far less than what it could be.

Right now I suspect too many women that are kind of interested and may want to do this kind of work are scared off/intimidated (or worse, they never even consider it because of the thought "I'm not that kind of person") by the stereotypes/culture/etc and that's too bad.

jenandre··on On sexism in the tech industry - rebuttal
I'm not saying her opinion is more or less valid than Faruk's, but in terms of the antecdotal "arguments" of her blog her authority may be less meaningful than, say, someone who works with 99% male neckbeards hacking linux kernel for 15 years (just as his anecdotal arguments would be less valuable than hers).
jenandre··on On sexism in the tech industry - rebuttal
I agree, it's a valid problem to deal with, but the wrong time/place for it. Remember, at an interview, you are putting the impression in that young person's mind: "wait, people won't take me seriously as a female?" -- that's something they carry with them beyond the interview.
jenandre··on On sexism in the tech industry - rebuttal
That's like saying "I work as a nurse in a hospital in the 1950s". Sure, you may see some sexism second hand, but if you're a female doctor in the same position, it's a totally different experience.

The primary thing I didn't like about the author's article was that her criticism of the original article (which were totally valid, by the way) kind of concluded with the impression (given by her anecdotal experience) that "sexism isn't as bad as it's made out to be, look, I haven't seen any."

The truth is it is there, and it can be pretty bad in some cases, although these scare articles by the author she was criticizing isn't really giving any meaningful advice on how to do deal with it.

Interesting she works in a big shop... coincides with my experiences that larger orgs tend to be more comfortable/friendly to women.

jenandre··on On sexism in the tech industry - rebuttal
Ehh... Yeah. The original article was kind of a pile of crap, but it's hard to give this any credibility either.

1) She's only worked for 6 months 2) She works in UX, which is actually pretty well represented by women.

My two cents from a woman who actually works in a technical position (I'm a developer) for > 10 years now. Also working in infosec, which is one of the least represented when it comes to gender balance. Note: this is all totally anecdotal.

IMHO, "Imposter Syndrome" is one of the primary reasons we don't have more women in the industry, and it's reinforced heavily because of the culture of most workplaces. Why? When you emphasize a "brogrammer" and "rockstar" culture it's hard to believe that you can step in there and be just as "good as the guys."

When I'm talking about brogramming culture, I am not talking about silly shit like they turned the woman's bathroom to a man's one (lol, they did this at one company I worked at) or that you need to stop making fart jokes etc. I mean the idea we are all super awesome rockstars that sling amazing code and everyone else around you is shit and an idiot for not knowing something that you (and the other guys) know. When you're already feeling kind of alienated for being different, this can be really intimidating (and it's worse when people point it out -- I was asked an interview for a programming teaching position at a university BY A PROFESSOR "how will you handle it if people don't take you seriously as a female?")

I struggled with this for many years. I always assumed everyone around me knew more about computers (they didn't) and their code was 100% perfect (lol, it wasn't).

The effect for me was I was afraid to ask questions and when I wanted to figure out something, I did the research/reading on my own because I felt I had to prove that I was 110% competent - imagine how much time I could have saved and how much faster I would have progressed if in those early days I had just felt more comfortable asking people for help.

Because of this, I think corporate environments are an easier more comfortable place for a woman to work in a programming job than startups and small companies (again, this isn't universal). Which is sad, because I love working at a small company. And the startup space could benefit from women (since there are so few people usually in a startup, esp if you're building a product that will be widely used by women, it is invaluable to have that perspective).

2) What can you do about it? Well, if you're a woman, and you want to be in the tech field because you love working with computers, and you continue to pursue it, you're doing something already. You're an example to every other woman. I think only in this way, eventually the gender balance will even out. If you're a guy, and you want to hire a woman to join your technical team, emphasize the collaborative nature and how much they will learn on the job. Hire for smarts and ability to learn, not just knowing how to write a rails app in one day and knowing how to debug a deadlock with gdb etc.

jenandre··on Democratizing Security
oh, ok, that makes it a lot more clear. thanks!

If I were you I would consider a model where I would be to do a full scan, display only the top X vulnerabilities found, and simply charge more to show the rest of the results.

Another thing I'm curious about: does this work on a pure client-side web application (e.g. my app is just one html page + javascript that loads all the html from templates)? Are you including static urls or somehow tracking "clicks" into a web app? Actually, most of the things I would concerned about in my web applications are things like not validating that I'm correctly doing correct validation in POST-requests. I'd be interested in seeing if you guys are doing that kind of "fuzzing" in that respect (though not sure if there is an automated way to do that safely). Additionally, I'd be curious to see what you detect Nessus/BurpSuite etc doesn't in terms of web application security.

Anyway, neat idea, perhaps I'll check it out a bit more thoroughly and do a comparison.

jenandre··on Democratizing Security
"The direct comparison to competing tools just begs questions you don't want to answer."

I agree. Additionally, I'm not sure who would actually subscribe to the paid version of this. Startups generally don't have a plethora of websites for testing. Someone with 250 urls to scan per month is likely going to be asking: what about my other (non-website) assets? Furthermore, if I were the IT person on site for a 250+ website installation I would be asking: what do I get out of this I don't get out of running another free tool such as Nessus (the answer, I'm afraid is going to be "less")? Sure, having to to go through the Nessus install process is kind of a pain (although this realistically represents < 5 minutes of my time); but as soon I saw that I had to add some kind of website verification I stopped there as well.

jenandre··on Ask HN: Help, I'm a developer who can't pay rent
dude, send me an email. I work for an infosec firm that would hire you in a sec, provided you aren't crazy (well, at least not crazier than the rest of us ;). jandre@gmail.com
← PreviousPage 2 of 2