HNHacker News
TopNewBestAskShowJobs

jjguy

1,757 karma · joined April 4, 2008

ex-fed hacker turned startup guy. Co-founder & CEO at Sevco Security, previously CTO/COO at JASK, founding team of Carbon Black. San Antonio, TX.

@jjguy jeffrey.guy@gmail.com linkedin.com/in/jjguy

submissionscomments
jjguy··on Tell HN: John Friel my father, internet pioneer and creator of QModem, has died
I didn’t personally know your dad, but like many others here depended on his work with QModem during the late 80s and early 90s. The fact we are all on Hacker News is evidence of how it impacted our lives - and the relevance of the community here.

Thank you for posting - I’ve enjoyed reading the outpouring of history and stories and hope it brings you the same sense of wonder it has me. Godspeed to you and your family.

Similar to all the rest of you HN lurkers, especially the grey beards - thanks for being here and thank for keeping the “hacker” in “hacker news” alive.

jjguy··on 'United Healthcare' using DMCA against Luigi Mangione images
Hey look on the bright side. If this is legit, then it will inevitably become a reference in the bill to overhaul the DMCA when it (finally) gets introduced!

The beginning of the end, the moment when thr DMCA jumped the shark (for the broader world, not us tech geeks)

jjguy··on CrowdStrike representatives issue trademark infringement notice to ClownStrike
Based on how well CrowdStrike has managed their response to date, this is a plausible scenario.
jjguy··on Tesla Cybertruck may have a rust problem
All this, but there is also some negative PR getting funded, presumably by the incumbent car manufacturers threatened by Tesla.

Remember that NYT article came out in 2018 that painted such a terrible picture of Elon (1)? A year later it showed up on my Facebook feed as a paid advertisement. Who pays to promote a year-old news article?

jjguy··on Ask HN: I’m an FCC Commissioner proposing regulation of IoT security updates
For those of you unfamiliar with the specific challenges IoT patching brings, here is a blog post from just last week on one aspect of the topic: http://tomalrichblog.blogspot.com/2023/08/british-cuisine-de...

FTA:

> I assumed that device manufacturers update the software in their device about every month...he said they do it annually.

Those devices are at least _getting_ updates - there is a long tail of devices whose operational lifecycle [far] exceeds the vendor's support timeframe - in other words, they don't get patches at all N months after release.

The solution to these problems is straightforward - we've been managing it in software for a long time. EOL OSes, Long Term Support (LTS) OS releases, etc - but the device manufacturers are not as mature, and have not been making natural progress to do so.

And since this is HN - there is a startup hidden in the midst of all of this: an enterprise-grade IoT OS that "does security right." Sell to the device manufacturers, allow them to market it as "enterprise-ready" or some such. If the FCC guidelines here are approved, there will be a suddenly increased demand!

jjguy··on Elon Musk owns Twitter: The story so far
With respect to the name “X” - I’ll bet he revives the OG x.com brand - https://en.wikipedia.org/wiki/X.com
jjguy··on GitHub Copi­lot inves­ti­ga­tion
It’s called a hedcut. WSJ built a generator in 2019, but it's only available to subscribers. [1]. There are artists that offer commissions, including at least one WSJ artist. [2]

1 - https://www.wsj.com/articles/whats-in-a-hedcut-depends-how-i...

2 - http://www.hedcut.com/

jjguy··on Ask HN: Where to meet people who are interested in building a company together?
Join an existing startup in the same field. Not only will you learn a lot - on someone else’s dime - but you will meet plenty of people hungry to do the same.
jjguy··on Ask HN: What are good genealogy/family history/immigration search engines?
Ancestry.com is a very well designed product with lots of data and a powerful network effect. I designed a search products for incident response data - also high volume, noisy but highly relational data set - ancestry’s design is very thoughtful.

The monthly subscription carries no commitment and you don’t lose data when not subscribed. So don’t think of it as “$xx per month commitment is so expensive!” But instead as “I’d happily pay $20 this month to support the research I want to do. Next month, we’ll see.” I’ve subscribed / stopped / resubscribed several times over the years as the time I have ebbs and flows.

jjguy··on Boox Mira Pro – 25.3" E Ink Monitor
My view, you are describing the Kindle.

Amazon sees the same potential - and risk - and has been quietly iterating for over a decade in the segment.

If you want to go seriously explore it as a product, I’d start with a deep dive study there and develop a few theories how you think you could be different enough to blow it wide open.

jjguy··on Google outage – resolved
I like your anecdote, I might steal that one.

IANAL, but I negotiate a lot of enterprise SaaS agreements. When considering the SLA, it is important to remember it is a legal document, not an engineering one. It has engineering impact and is up to engineering to satisfy, but the actual contents of it are better considered when wearing your lawyer hat, not your engineering one.

e.g., What you're referring to is related to the limitation of liability clauses and especially "special" or "consequential" damages -- a category of damages that are not 'direct' damages but secondary. [1]

Accepting _any_ liability for special or consequential damages is always a point of negotiation. As a service provider, you always try to avoid it because it is so hard to estimate the magnitude, and thus judge how much insurance coverage you need.

Related, those paragraphs also contain a limitation of liability clause, often at capped at X times annual cost. Doesn't make much sense to sign up a client for $10k per year but accept $10M+ liability exposure for them.

This is just scratching the surface -- tons of color and depth here that is nuanced for every company and situation. It's why you employe attorneys!

1 - https://www.lexisnexis.com/lexis-practical-guidance/the-jour...

jjguy··on LinkedIn’s Alternate Universe
That is a per-user privacy setting. You can flip your profile to public.
jjguy··on Ask HN: Where to meet non-technical cofounders?
I’d recommend joining an existing, early stage startup in the same/similar niche you eventually want to build your own product in. While there, make an effort to network with the non-technical staff.

Not only will you learn a ton about shipping product in a startup (risking someone else’s money), but you will also grow your own network - including non-technical founder types.

This model worked for me. I spent twelve years with the US federal government. I had great tech and business skills, but it was all federally focused.

I joined the founding team of a startup, using my tech background. We got acquired 15 months in by a later stage startup. The resulting company IPO’d four years later. I joined another startup in the same industry as CTO just after their Series A, we got acquired two years later. Then I launched my own - 8 years after leaving the federal government.

It is a ton easier now, with all the relationships from the last two. (Not to mention the depth of knowledge on everything)

It is easy to think startups are all about the product & technology. But it is so much more!

jjguy··on How to sell a B2B product
I frequently recommend https://openviewpartners.com/blog/founder-led-selling/ as a good early stage enterprise sales framework. It is addressing a different, but complementary, set of questions to this post. If you're at a stage to need this kind of feedback, you should read it too.
jjguy··on E Ink smart screen puts a newspaper on your wall
Reading all the negativity here reminds me of the iPod reception back in 2001! This is prescient y’all. This is the technology future I want, not that dystopian blade runner world!
jjguy··on D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models.

This applies to every "connected device:" printers, cell phones, home routers, refrigerators, thermostats -- you name it. Michael DeGusta did a great infographic demonstrating this for Android phones in 2011 [1, 2]. Sadly, this hasn't materially changed in the eight years since. Just this year, Google added new terms to the Android license requiring security patches, but even then only for "popular devices." [3] Imagine those dynamics in the secondary and tertiary markets of printers and refrigerators.

As an industry, we've been to this rodeo before. The advancements we've made in operating system and core applications security over the last 20 years have more about patching speed and agility than shipping fewer bugs. However, those areas have backing and control from Apple and Microsoft, managing the end to end ecosystem. There is not a similarly equipped manufacturer of embedded operating systems with the scale to provide post-sale/post-deployment patching infrastructure.

Since this is Hacker News, I'll point out the enormous opportunity to anyone who can address that problem. Can you provide an "enterprise class embedded OS" to device manufacturers and address post-deployment updates? Can you provide infrastructure device manufacturers can use to manage post-deployment updates themselves? Do you have a better approach to it? There's a burgeoning multi-billion dollar market waiting for a few leaders to take it over.

1 - https://theunderstatement.com/post/11982112928/android-orpha...

2 - img link is broken in his post, the graphic itself: http://media.theunderstatement.com/016a_android_orphans.png

3 - https://www.theverge.com/2018/10/24/18019356/android-securit...

jjguy··on Ask HN: I need ideas to impress fifth graders with technology
http://www.mathmaniacs.org/lessons/01-binary/socratic.html

That exercise is excellent to teach kids how to count in binary and why computers are based on it.

jjguy··on Ask HN: What was your experience using a graph database?
Graph databases are the NoSQL of this half decade. Move cautiously. Just because you conceptualize it in your mental model does not mean you need a graph database. Further, recognize most (all?) implementations are not yet as performant or scalable as traditional data storage solutions.

Design your data schema first, then design your queries and finally your data lifecycle pipeline. Run some estimates on the order of magnitude for inserts, query rates, query types and storage sizes - then compare those numbers to the real-world perf of the various graphdb solutions. In general, compared to more typical solutions, you have more expensive inserts, query costs and storage sizes in exchange for more expressive queries. There aren't many application where those cost tradeoffs make sense.

Source: Twice now (2012 and 2018) I've reviewed available graphdbs for storage of enterprise security data when doing the initial platform technology selection. Both times the team fell back onto more traditional approaches.

jjguy··on Ask HN: Reading recommendations for understanding food allergies?
I have an unusual food allergy to poultry. I had the same question - seeking deeper understanding so I could better manage my life.

I searched online, had family in the medical research hunt for papers and finally made an appointment with a renowned allergist in DC - I flew there just for the appointment.

I left disappointed. My allergy is too unusual, there is no research available. What I need does not exist. For the common allergies - like kids and nuts - there are plenty.

The net/net from my experience is seek out an allergist, and be very specific in your requests.

jjguy··on Ask HN: Do you cover the camera/mic on your computer/phone?
No. It is an unreasonable paranoia, to steal kenneth’s words.

In addition to kenneth’s very practical perspective on the technical challenges, the other consideration is that you are simply not worth the trouble.

Grabbing audio, video or picture content worth blackmailing someone with is time-consuming, above and beyond the technical challenge. There is not an at-scale monetization path for an attacker to make it worth his time for the general user.

High-profile folks like Comey and Zuckerburg change that decision calculus - they are likely to be individually targeted for many reasons. You are not.

jjguy··on Smugmug Acquires Flickr
This is why I continue to hang out on HN. Is there anywhere else on the internet this kind of connection would happen?
jjguy··on Towards a world without Facebook
For those of you who read this article and believe there may be a thread of a good idea within, go read Neuromancer.

Gibson had a vision of an Internet with decentralized social media, including decentralized code execution, 35 years ago, and we have not yet realized it - or anything remotely close.

jjguy··on How Hotmail changed Microsoft and email
If you like history like this, you should also read “showstopper: the breakneck race to create Windows NT” (1). It profiles Cutler’s team as they go through the period described briefly in this article to make Windows NT an actual contender to the Unix-based OSes.

1- https://www.amazon.com/Show-Stopper-Breakneck-Generation-Mic...

jjguy··on Computer latency: 1977-2017
You forgot the last part: “how f’ed up is that?”

https://twitter.com/id_aa_carmack/status/193480622533120001

jjguy··on Flush times for hackers in booming cyber security job market
This will change with time. I have thought, studied, talked, and written extensively on this general theme. What comes to mind to frame it for you is my "four principles:" [a]

1. Compromise is inevitable 2. Default-allow products always fail 3. 1 and 2 are not opinion or marketing spin, just simple truths 4. As an industry, we are still learning 1 and 2

Security is slowly shifting from an administrative IT function to an operational function. In IT, the business value comes from the products and people are a tax required to administer the products. In security operations, the business value comes from the people, products are just tools in their toolbag. [c]

Keep walking this dog and you realize basic IT activities for core infrastructure are critical for security, to the point the CIO will report to the CISO -- unless the CIO steps up. [b]

So - in short - your frustrations are accurate, but the winds are shifting. Companies will incresingly value top people for their internal staff/blue teams. It's going to take a few more years, but I believe it is inevitable.

[a] - https://www.linkedin.com/pulse/my-four-cybersecurity-princip... [b] - https://www.linkedin.com/pulse/cio-report-ciso-j-j-guy [c] - https://www.linkedin.com/pulse/cio-report-ciso-why-j-j-guy

jjguy··on Lessons from the CIA’s classified guide to good writing
For many years, I have used "Words of Estimative Probability" - a similar CIA "on writing" piece: https://www.cia.gov/library/center-for-the-study-of-intellig...

Also written in the 60s, it reflects upon their experience with how to convey uncertainty in prose, in a meaningful and consistent manner. Imagine an analyst writing a two pager for the President, who is going to use it to decide go/no go on a covert action. It's a big, ugly and complex situation - with a mixture of highly confident assessments, educated guesses and total speculation. Synthesizing it into something simpler is The Art of Writing; doing so while not losing the anecdotal quantification of uncertainty of the discrete issues is a more unique skill.

If you are in a position where you write about uncertain situations, it's worth the read. I'm a security guy and frequently find myself in that role (think annual risk assessments and estimating the likelihood of a successful attack). It's been a go-to reference for many years to refresh my thinking.

jjguy··on I mean, why not tell everyone our password hashes?
PSA to everyone responding to the title: please RTFA, it's sarcasm.
jjguy··on Car Cost per Year - New vs Used
You're giving "the data" too much credit. There are only a few variables:

- new cost

- depreciation per year

- increasing maintenance costs per year

The "F-150" assumption was used to estimate new cost and depreciation over time.

You should not discount the data based on a single model, but it is wise to recognize those three variables can diverge significantly between models - enough to change the outcome.

jjguy··on How much do hackers at the CIA/NSA/FBI make?
USG employees vs. contractor is an important distinction. Your ranges imply your friends are contractors. See techjuice's post for USG ranges.
jjguy··on How much do hackers at the CIA/NSA/FBI make?
Assuming by "pretty good hackers" OP means the developers actually doing the work, they are typically GS-12 or GS-13 - so $80k to $120k. GS-14 slots and above are reserved for management and spend much less time doing the real work.

A lot of the teams employ contractors alongside the USG employees, with higher pay ranges.

Page 1 of 5Next →