HNHacker News
TopNewBestAskShowJobs

jjguy

1,757 karma · joined April 4, 2008

ex-fed hacker turned startup guy. Co-founder & CEO at Sevco Security, previously CTO/COO at JASK, founding team of Carbon Black. San Antonio, TX.

@jjguy jeffrey.guy@gmail.com linkedin.com/in/jjguy

submissionscomments
jjguy··on Eric Schmidt: CNET gets it right on the NSA/Google issue
The referenced story: http://news.cnet.com/8301-13578_3-57588337-38/no-evidence-of...;

declan submitted his story https://news.ycombinator.com/item?id=5844091 but it languished.

It's a shame, because it's the first responsible piece of reporting I've seen on this mess. The media has been trolled by a Powerpoint brief from self-important USG bureaucrats.

jjguy··on No evidence of NSA's 'direct access' to tech companies
+1 for a well-grounded response, declan. I'm ashamed this didn't make it to HN's front page.
jjguy··on Good Old Games: gog.com and the DRM-Free Revolution
I still have original install media for Wing Commander III, but bought it again just for the modern OS remastering.
jjguy··on Why We’re Raising the Signature Threshold for We the People
I read it as evidence of the erosion of state's rights. Perception is reality and those folks clearly thought they needed Daddy DC's permission.

We nationalize too many issues on which our nation is deeply divided. If, instead of bickering for years over an issue in Congress, we pushed those decisions back to the states, then local initiatives would be put into place. With time, the right solutions would naturally develop. Competition is king.

Of course, doing so takes strength and wisdom from our Congressmen to admit they could not come to a national compromise. Many will call it failure. Thus, it will not occur.

jjguy··on Warren Buffett Buys World's Largest Solar Project from SunPower for $2.5 Billion
"If you can't explain it to a six year old, you don't understand it well enough yourself." -- Einstein

In other words, express your command of a subject by how simple you make it appear, not by demonstrating how impressive and complicated the subject is.

I remind myself of this concept routinely, and struggle to reflect it in my writing and peer communications.

jjguy··on Amazon.com criticising new iPad on homepage
My experience shopping on Amazon - a bit like browsing in a vast, chaotic and disorganized third-world marketplace - is not one I'd like extended to my computing platform.

Amazon and others can tout narrow features as much as they want, but I still prefer the better-managed end-to-end experience Apple provides in their ecosystems.

jjguy··on Browserver: A web server inside your web browser
If you re-read the early cyberpunk scifi from Gibson and Stephenson, one of the characteristics of their vision we're still missing is execution at the edges. There was a strong concept of "my virtual space" in which space owners control not just a visual presentation layer, but the full execution stack.

Our architectures are still dominated by central server farms, in which we give up our data and cede control to the server operators. There are few experiences where we have a true, decentralized experience with execution controlled by the clients. BitTorrent and it's predecessors are the closest we've come so far, but AFAIK it's all limited to peer to peer file transfer.

Every time I start to explore these thoughts, the browser is the obvious platform for the first iterations. I'm glad to see initial designs appearing, and look forward to seeing a truly decentralized and peer to peer service that don't have critical dependencies on central servers.

jjguy··on iPhone 5 First Weekend Sales Top Five Million
Android O&M is a disaster is not changing anytime soon. Quibble on features out of the box if you like, but in end-to-end support the iPhone is still the hands down winner.

See http://theunderstatement.com/post/11982112928/android-orphan...

jjguy··on Anonymous Donor Pays for College of Every Student in Kalamazoo
The words "donors" in that wikipedia page have remained unchanged since the original page shell in May 2006. Considering also the NYT article explicitly discusses donor vs. donors, I view the wikipedia characterization more as editorial convenience than evidence.

That said, my common sense tends to agree with you. Is there evidence elsewhere?

jjguy··on Journalist goes undercover making the iPhone 5 at Foxconn
What you're referring to is called cultural relativism [1], and is willfully ignored in most media reports of working conditions in foreign countries.

By not providing any context to the local norms, we tend to compare conditions to our norms and see it in stark terms, while the reality is more nuanced. FoxConn's compensation and work conditions may be imperfect, but are good enough relative to local alternatives they have sufficient supply of willing workers. The "exploitation by US consumers" is an effect of globalization.

Most criticism and remediation efforts should not be directed at the various firms, but at the country that allows it to occur.

1- http://en.wikipedia.org/wiki/Cultural_relativism

jjguy··on Never again be thwarted by restrictive “guest” wifi (e.g. on buses or airplanes)
Oskar, I didn't know you were an HN'er. Thanks for posting. I have studied malicious use of DNS for a long time and have not yet found any reference prior to your post in 1998. In fact, I used your original bugtraq post as a reference to kick off a whitepaper detection solution approach for enterprises: http://armatum.com/blog/2009/dns-part-ii/ I'd sincerely welcome your feedback.

HN'ers -- Despite Kaminsky's ego, all signs indicate Oskar invented DNS tunneling.

jjguy··on Google crackdown catches innocent devs in the crossfire

    Software isn't a fire and forget transaction anymore
There's a lot of insight in that soundbite. I wish more of the "enterprise!" crowd (and in this case, Daddy Google) realized that.
jjguy··on One Thing Outlook.com Mail Needs To Fix Immediately
If you create a new account, it will allow you to select an @outlook.com email address. There is no ajax on the account name, you'll have to enter the captcha to know if your chosen email address is available.

  - Click your username in the upper right, click sign out
  - click the 'sign in' button on the next page
  - click the white 'sign up' button on the bottom left
  - see @outlook.com text box four entries down
jjguy··on Windows Executable Walkthrough Graphic
For any new reverse engineers in Hacker Newsland, another win32 PE classic is Ero Carrera's diagram from 2005: https://www.openrce.org/reference_library/files/reference/PE...
jjguy··on Microsoft changes skype supernodes architecture to support wiretapping
Even if the sensational headline is accurate, it's not worth the conspiracy theories:

(1) Microsoft is a US Corporation

(2) With the Skype acquisition, Microsoft (arguably) becomes a telecommunications carrier.

(3) CALEA passed in 1994, "requiring telecommunications carriers and manufacturers of telecommunications equipment modify and design their equipment, facilities, and services to ensure they have built-in surveillance capabilities, allowing federal agencies to monitor all telephone, broadband internet, and VoIP traffic in real-time." [a]

My (unfounded, optimistic) speculation is the skype acquisition was strategic positioning in the mobile market: seamless cutover to skype when your phone has WiFi.

a - http://en.wikipedia.org/wiki/Communications_Assistance_for_L...

jjguy··on "X-" deprecated for HTTP headers
Appendix B:

    The primary problem with the "X-" convention is that unstandardized
   parameters have a tendency to leak into the protected space of
   standardized parameters, thus introducing the need for migration from
   the "X-" name to a standardized name.  Migration, in turn, introduces
   interoperability issues (and sometimes security issues) because older
   implementations will support only the "X-" name and newer
   implementations might support only the standardized name.  To
   preserve interoperability, newer implementations simply support the
   "X-" name forever, which means that the unstandardized name has
   become a de facto standard (thus obviating the need for segregation
   of the name space into standardized and unstandardized areas in the
   first place).
Most of your examples are covered under the "exception 1" clause, also in Appendix B:

   In some situations, segregating the parameter name space used in a
   given application protocol can be justified:

   1.  When it is extremely unlikely that some parameters will ever be
       standardized...
   2.  When parameter names might have significant meaning...
   3.  When parameter names need to be very short (e.g., as in [RFC5646]
       for language tags)...
jjguy··on Selling a used iPod can violate a copyright law
A note for college HN'ers: you don't need foreign relatives to mail you the books. amazon.co.uk will happily ship to US addresses. It costs a little more to ship and takes a week or so longer, but you can still save a substantial amount. I bought most of my engineering texts this way.
jjguy··on Flame is Lame
Ref Microsoft's Shared Source Initiative: http://www.microsoft.com/en-us/sharedsource/default.aspx

Enterprises w/ 10k+ seats, OEMs, MVPs and governments can get access to Windows source these days. Microsoft launched the program in 2006 or so to dampen the "Linux is more secure because we can see the source!!" FUD.

jjguy··on Flame is Lame
To paraphrase Edison, anything worthwhile is 99% perspiration and 1% inspiration. The novel md5 collision/windows update propagation is Flame's 1%. The rest is just what's made possible as a result.

It is a cogent reminder of the fragility of the Internet's security infrastructure.

jjguy··on Android Fragmentation Visualized
Also: Michael DeGusta's chart from Oct 2011

http://theunderstatement.com/post/11982112928/android-orphan...

jjguy··on A 5 Minute Quickstart Guide to Python’s logging Module
This page http://wiki.python.org/moin/LoggingPackage gave me a lot of indirect insight into why the logging module is the way it is. The user "VinaySajip" is the author and maintainer of the package.
jjguy··on My 2 Co-Founders Are Being Head-Hunted By Apple, Google and Facebook. Advice?
The best people always have many opportunities. It's like Joel said in 2006 [1]: the good ones never "hit the market" because they simply pick up the phone and call in the outstanding offers.

Don't fret. View it as validation you've got a good team. For all of you, if your startup is successful the opportunities from Apple, Google and Facebook will only get better. If the startup doesn't go so well, those offers will still be there.

1 http://www.joelonsoftware.com/articles/FindingGreatDeveloper...

jjguy··on Why is reading lines from stdin much slower in C++ than Python?
Reminds me of Joel's Law of Leaky Abstractions. At some point, you must deeply understand the entire stack.

http://www.joelonsoftware.com/articles/LeakyAbstractions.htm...

jjguy··on The Little White Box That Can Hack Your Network
There are two new paradigms gaining momentum in enterprise environments:

  - Assumption of breach 
  - Bring your own device
Assumption of breach is driven by the industry's over-emphasis on protection, versus detection and response. The harsh reality is an attacker will always be successful gaining access. The detection and response capabilities are historically anemic due to repeated under-investment. That's why you see so many intrusions reported and the attackers have been in place for months or years.

One of the natural results of assuming breach is to shift focus from protecting _devices_ to protecting _data_. An attacker can always land on the secretary's machine, but you can put additional layers of protection around the organization's critical data.

Bring your own device (BYOD) is a natural extension of assuming breach and shifting focus from data to devices, and aligns nicely with the user desires to use their iPads and smartphones. The result in these environments is the IT shop becomes more ISP and less Dell technical support.

Many industries are adopting the assumption of breach and inevitability of compromise. RSA Exec Chairman at the RSA Conf a couple weeks ago: "We need to acknowledge once and for all that our networks will be penetrated." BYOD is harder - popular for universities and hospitals with significant user mobility, less so for governments and financials with higher protection thresholds and more static environments.

In another five years, these ideas will be common practice for many industries. If you HN'ers have some crafty plans in the enterprise space, take note.

jjguy··on The next SOPA
Technology's favorite lawyer, Lawrence Lessig, has a new book out advocating for campaign finance reform. Like most things from Lessig, his arguments are well-considered, balanced and thought-provoking.

He includes a quote I found particularly compelling, especially in the light of Marco's link between 'the next SOPA' and campaign finance reform: For every one striking at the leaves of evil, there is one striking at the root. - Thoreau. Marco wants us to strike the root.

Book: http://www.amazon.com/Republic-Lost-Money-Corrupts-Congress/...

NYTimes review: http://www.nytimes.com/2011/12/15/books/republic-lost-campai...

jjguy··on Are We in a Social Networking Bubble?
Efficiency is probably a better descriptor. How about The Internet allows us to make those connections more efficiently, and each generation of communications technologies increased both the efficiency and quality of our interactions.

I don't disagree with your assertion the internet has diminished the quality of our relationships. I'm a luddite in many ways, but that mindset is part of what has led my thinking down this path.

(1) Human beings are meant to connect, (2) the internet is a tool to facilitate connections, (3) each generation of connection technologies has improved upon the previous, (4) social networking is just the natural evolution of Internet communication technologies, (5) there is still significant room for improvement.

jjguy··on Are We in a Social Networking Bubble?
>For entrepreneurs, the key message is to be really careful about doing a social networking startup in 2012. The social networking wave is about to crest. There are very few ideas and opportunities in this space that aren’t crowded.

We take a too-narrow definition of social networking. If we want to find the next big thing in the Internet, we need to take a step up the stack of abstraction and think more broadly about connections.

Human beings are wired to connect. It's fundamental human nature, and the subject of the still-new social neuroscience field. [1]

Evidence of this is pervasive throughout our culture. Relationships, marriage, cities, tribes, fan clubs, Hacker News itself - _connecting_ in a meaningful way with other people is what we do.

The Internet's success is it's ability to facilitate connections, making them easier, more personal and more meaningful: email, IRC, instant messaging, gopher, the web, facebook, twitter - it's not just facebook and twitter that are "social networking," every successful Internet communications technology has improved the state-of-the-art in allowing us to connect with each other.

So don't consider "what's next for social networking" -- or "the social networking wave is about to crest." The label restricts your mind. Ignore labels, think big. Consider human nature, relationships and how you can connect us to each other in a more meaningful way. Perhaps you'll find the essence of what the pundits will call 'web 3.0.'

1 - http://www.thedailybeast.com/newsweek/2006/10/22/how-to-read...

jjguy··on The Critics Rave... for Microsoft?
> Microsoft has to do something that's _compellingly_ better, to someone, somewhere, on some basis that makes money.

$20 says Microsoft will take over the mobile enterprise market from the now weak grasp of RIM, by focusing on security and enterprise features.

Enterprises care about security. They want someone who owns the platform they can thump in the head when something goes wrong. They want complicated features to centralize control. They want the operating systems quickly patched when vulns are published.

The Android ecosystem is a disaster, in this regard. By separating the roles into OS developer, manufacturer and carrier (Google, HTC/Samsung/etc, Verizon/AT&T/etc respectively), it's created an environment with too many mixed incentives -- many that are at odds with the customer's needs.

Google produces the operating system, the manufacturer adds their customizations to differentiate, then also adds per-carrier tailoring. The carriers then have to validate/test and release.

Motorola detailed this process as an excuse/apology/statement in early December. [1]

New OS upgrades and security patches become the responsibility of the manufacturer, but the manufacturer's incentives to support the hardware platform for the long-term are weak -- in fact, if the platform is doing poorly, they are incentivized to do the opposite: cut their losses and move on. As customers, our influence is limited, since our relationships are with the carriers.

This if further complicated by the manufacturers rapid iterations with various hardware designs, to try and find the right price points to compete with the iPhone. They're shipping hardware platforms barely capable of running the current version of the OS, with no roadmap for future software upgrades.

Apple has done a great job managing the platform, but they do so in their typical Apple style: with little communication and inconsistent rapidity of responses. Being held at arms length and kept in the dark is not reassuring to any CISO whose enterprise data dependent upon the platform's security.

Of course, I think it's a safe bet those CISOs are more comfortable with Apple's silence than Android's clear security failures.

DeGusta's chart from October [2] captured much of this. There are hardware platforms where we sign two year agreements with the carrier, but receive only four months of security patches from the manufacturer. In whose world is that acceptable?

There are signs Microsoft recognizes the security updates problems and is putting the infrastructure in place to manage updates themselves, independent of carrier. [3] There are also signs they recognize the challenges Android's laissez faire hardware specs brings, and are more tightly controlling the hardware requirements. [4]

Microsoft's focus so far has been consumer-oriented, initial traction and to establish the ecosystem to allow _any_ platform. Ars had a writeup last week that captured current status in typical Ars completeness. [5] They'll work it out eventually. Microsoft can't fail in this, and the carrier and hardware manufacturers _want_ an alternative to the Apple gorilla. The next year will see some pivots, compromises and changes -- but ultimately they'll work it out.

And by then they'll have taken over the enterprise market.

1 - http://www.motorola.com/blog/2011/12/07/motorola-update-on-i...

2 - http://theunderstatement.com/post/11982112928/android-orphan...

3 - http://arstechnica.com/microsoft/news/2010/11/windows-phone-...

4 - http://www.pcworld.com/article/243268/microsoft_quietly_chan...

5 - http://arstechnica.com/microsoft/news/2011/12/is-windows-pho...

jjguy··on “When you get right down to it, most security is based on the honor system.”
It wouldn't be very interesting. Here's what real hacking looks like: http://imgur.com/YAnUh

(sorry for the reddit-esque share, originally there. But it's relevant and accurate)

jjguy··on “When you get right down to it, most security is based on the honor system.”
The noise is incredibly annoying. There's no industry-accepted way to distinguish between a security expert and the guy with the A+ cert. We really need to raise the bar and instuitionalize better standards.

Your points re: difficulty of enterprise sales are hard-learned, I assume. My intuition says there's an opportunity to exploit there, given the disconnect between users and industry. Of course, the same is true of cell providers, but no one has managed that one yet either.

← PreviousPage 3 of 5Next →