HNHacker News
TopNewBestAskShowJobs

jenandre

433 karma · joined September 20, 2012

Software developer, with occasional opinions.

http://jenpire.com

submissionscomments
jenandre··on Why There Will Never Be Another RedHat: The Economics of Open Source (2014)
This article has already been proven wrong... e.g. what about Elastic
jenandre··on Early Warning Detectors Using AWS Access Keys as Honeytokens
The idea is to use private repos on Github, not public ones, which just tell you that yes, someone can read a public repo and misuse a key. Not that your private repos have potentialyl been compromised.
jenandre··on Ask HN: Who is hiring? (May 2016)
Komand (ONSITE Boston, US)

What: We are building a cybersecurity automation platform (IFTTT for security). We have an awesome, technically savvy team that has built multiple products and companies in the infosec space. Work with Go, Docker, and React to build a modern platform for security teams. PS: we're also fun. We routinely make breakfast together in the office, we're a diverse team across a wide age range + genders.

Culture: Team players, world class talent, no brilliant assholes. We have a culture of ownership + responsibility. We are all experienced devs and have great tooling/process even for a company so young.

Jobs: https://angel.co/komand/jobs. We're hiring primarily software engineers. Security background not required, but an interest helps.

Interview Process: We have a very collaborative interview process. We are looking to measure skills, not whiteboard ability. First, after an initial phone call, do a coding exercise offline and then come meet the team and pair with us.

Want to learn more? http://www.komand.com, jobs@komand.com

jenandre··on Show HN: Codetainer – A Docker container in your browser
Sure, contact me. There are some issues / feature requests you can start working on and others I need to flesh out more.
jenandre··on Manual Memory Management in Go
"Imagine doing lots of small allocations - you can cause a lot of fragmentation resulting in needlessly having to resize your heap which in dire scenarios can result in thrashing."

The article repeatedly talks about how managing memory manually increases the risk of fragmentation. And that this risk somehow goes away with gc managed heaps.

...so garbage collectors don't also have to manage their own internal heaps and have fragmentation issues? Hm, not sure I buy this.

jenandre··on Fundraising While Female
> Are there seriously investors that only back purely female teams? That seems ridiculously sexist and financially stupid to eliminate so many good startups that aren't all female.

I meant this to mean they have invested in all-female founding teams, not JUST all female teams. I have edited it to hopefully reflect that better.

Regarding your second point: I don't think the author's goal was purely to stop sexism in VC. She was describing her own experience. It's not a waste of time to educate people about the poor behaviors you see, regardless of whether or not she has a solution for it.

jenandre··on Fundraising While Female
I sympathize with you, having also experienced subtle sexism in both the tech and investment world (I'm a technical co-founder, and I've fundraised successfully). Here's a couple of points I hope are helpful.

- You should look to connect with partners at firms that have female founders (ideally purely female-founding teams) among their portfolio. There are also a few female partners out there as well -- get access to them, with your YC network it should not be hard. Listen hard and press them to get honest, specific feedback when given "no"s.

- While the sexism is unfortunate and it's hard not to get frustrated, you may want to look long and hard at your pitch and company. If you've really talked to 40 investors and sent out ~500 emails, and this is a hot space for disruption, it's very unlikely that all of them are dismissing you due to gender; something isn't connecting. I's very easy to dismiss all feedback ("their feedback means nothing; they are rejecting me because I am a woman") just because you are soured by your bad sexist experiences.

Ask yourself these questions honestly: Are investors giving the same criticisms and feedback for saying no? Are there questions you struggle with in the pitch about your business? Is the value prop clear? Is the product demo well orchestrated? Try to examine all of the feedback you've gotten objectively, and see how can you improve the pitch. Find someone who is ideally involved in the venture community (e.g. as a partner, associate, EIR) that you can trust, that can give you brutally honest feedback on your pitch and business.

- Fundraising is hard for everyone. It's going to be harder for you. It sucks, but that's the truth of life. You are one of those pioneering women who are paving the path for others so hopefully in 20-30 years, it's not even an issue. It would be great if you didn't have to deal with this, but that's not the reality of the world. What doesn't kill your company will make you AND your company stronger.

jenandre··on How I cracked NQ Vault's “encryption”
hahhaha (sadness)
jenandre··on The Need for Open Research in Software Security
I saw a good job post for a modern security engineer the other day from slack https://jobs.lever.co/slack/dfd75111-97a6-4edb-a21a-b8388a46...
jenandre··on The Need for Open Research in Software Security
IMO as long as the research in these tools are being funded by corporate entities (e.g., Microsoft) then there's little hope of any open research.

Fortunately, there's money to be had for open source and research projects that are willing to organize and look elsewhere for some cash. Look at projects like Bro and Suricata -- commercial security tools which are government and educator funded.

jenandre··on Look, no hands
you may want to look into finding someone who teaches alexander technique: http://www.alexandertechnique.com/

helps lots of musicians and others with repetitive injuries.

jenandre··on DMCA Takedown Notice for Popcorn Time and Time4Popcorn
It seems to still be available from popcorntime.io in a local Stash repo: https://git.popcorntime.io/stash/projects
jenandre··on Ask HN: Would a .Net back-end put off potential acquisitors?
I would be more worried about the costs of licensing as a startup. What kind of sprawl will your architecture have? Do you have to pay for SQL server? Acquisition is sooo far ahead of where you are.
jenandre··on Spotting Patterns in C Disassembly
awesome, ok, then you try to go reconstruct a vtable and want to kill yourself
jenandre··on Dear Github, can I go home now?
so... you want customizable metrics/views for your github page?

how far til this becomes `myspace for code`?

jenandre··on Apple's SSL/TLS bug
the gotos actually make sense in this case. unless you'd prefer some insane tree of if/else?
jenandre··on How YC Companies Found Employee #1
not true if they are taking on money. any investor will require a vesting period over 4 yr w/ usually a 1 yr cliff (which resets every time you take money)
jenandre··on Does the next decade belong to Go?
It's missing some key features (Generics anyone?) that put it somewhere in terms of usability between C and Java, and it has nowhere near the same tooling or performance characteristics as the JVM. So, it has a while to go yet I think but would love to see a serious JVM competitor here.
jenandre··on What I Didn't Say
I would be interested in the stats of 'successful' startup investments (for YC and otherwise), how many of those technical founders actually started programming at age ~13 (vs 17 or 18).

Would also be interested in seeing what the relative success/failures of investments with startup founders at 23 w/ 10 years experience (started programming in teams), vs 28 (who started programming at 18).

jenandre··on Why does it seem like threading and fibers in Node have been abandoned?
+1. If you want threads, build a node c++ addon that manages your threads/high performance work (and try not to pass too much back and forth with your Javascript, because of the performance overhead of marshaling described above). Which means you are just writing a lot of C++, and your javascript simply becomes a convenient interface to start/stop the processing and script actions on values emitted from your c++ addon.

Or, like everyone else recommends: use processes and ipc (e.g., the cluster module).

jenandre··on Walmart Node.js Memory Leak
What library is missing the symbols? You may be able to tell by the stack trace. You should get symbols for something at least before it's lost. Examine that frame to see what it's doing. Linking some non-debug library w/ a debug executable just means that gdb won't display the symbols when it enters code for that library. But if your addons are built with -g you'll get the symbols for the addon before it starts calling the other library it is using.

Btw, people often write javascript wrappers that manually refer to the build/Release/.node version instead of the debug version (which will get added to build/Debug/.node). Check that first.

Even if you are using dynamically linked libraries (like the zmq addon does), you can always build debug versions of those to get all of the symbols (try CFLAGS=-g when ./configure).

jenandre··on Walmart Node.js Memory Leak
Crashes (that can be reliably reproduced) should be way easier to debug than memory leaks.

a) build a `debug` version of node (building node from source creates a node_g version which is a debug version)

b) build a `debug` version of all of the c++ addons in your node_modules folder (node-gyp build -d for each addon)

c) start gdb with the debug version of node: `gdb ./node_g`

d) in gdb, run your node script using `run <script.js>` -- add any other options

e) wait for it to crash, and then type `bt` - you'll see the location of the crash which should give you a good starting place.

jenandre··on Why is cycling so popular in the Netherlands?
I don't know, plenty of cities are flat.. NYC is mostly flat?

Biking in .nl was actually quite arduous for me the few times I've been. One word: wind. No mountains or anything to break it, it's like being on an endless hill. I did a few short out of town trips (<15km) and I highly underestimated how long it would take because of the wind...

jenandre··on Freedom Hosting sites compromised, founder arrested
"Exploiting an unknowable amount of users of a service as to hunt them. Using illegally harvested data from botnets, while others get hunted and prosecuted for coding them. This tiered society where the legally immune can profit off acts that get others jailed."

Not that I disagree with this sentiment, but how is this different from the fact the government is "legally immune" from using/possessing weapons and firearms that the average person can't possess or use?

jenandre··on NSA director heckled on stage at Black Hat security conference
Defcon and Blackhat were founded by the same dude. Why didn't they exclude feds from BlackHat as well? Guessing it was probably because that is their big money maker with all the corp/fed support.
jenandre··on Show HN: Echelon – A safe way to manage your company’s Twitter accounts
They don't use https anywhere, not even on the oauth redirect back with the token in the header... isn't that.. bad?

How much you want to bet they are doing 0 encryption of the tokens they are storing on their servers.

jenandre··on Getting More - What You Should Know About Negotiating Start-up Job Offers
If you're not pushing for equity, why are you doing a startup? I'm talking about an earlier-stage startup where there isn't a lot of money for salaries (i.e., you are getting below-market rates regardless).
jenandre··on Goodbye node-forever, Hello PM2
I use supervisor with all of my node.js deployments... It seems straightforward for me just to drop a new .conf script in, it's agnostic to what code it's starting/monitoring (I use it with ruby as well) so I'm confused as to what problems have you had using it with node?

That said, this looks pretty cool, I'm going to try it out.

jenandre··on Former NSA Employees Praise Edward Snowden, Corroborate Key Claims
Yeah, my point is, we don't really know what the scope is -- we have Snowden's word and some slides that mention direct access to servers. But the engineers who worked at the companies and performed the integrations know and probably have evidence if it was just standing up a box they scp'd data to manually upon request, or a more elaborate automated system. If some of those people would step forward with evidence, we could could confirm or refute Snowden's claims.
jenandre··on Former NSA Employees Praise Edward Snowden, Corroborate Key Claims
I would find it really interesting if some employees at companies like Google, Microsoft, etc would come forward and corroborate Snowden's claims as well. At some point, SOME engineering work was involved on their side to make it happen, and there is likely documentation. I would love to see design documentation on how the collection systems work so we can confirm exactly the government has automated access to.
Page 1 of 2Next →