HNHacker News
TopNewBestAskShowJobs

joshzayin

289 karma · joined September 6, 2010

I hail from the USA, am a CMU alumnus and current Google employee, working on cloud security.

My website is joshz.org

submissionscomments
joshzayin··on Ask HN: Should I Leave Google Engineering Residency?
Hey, I'm a SWE at Google currently hosting an eng resident. I'd encourage staying through the residency in general, but I of course don't know your specific situation. (I'm also not sure which rotation you're on, but it's worth noting that even if one of your rotation teams doesn't have headcount the other might, and that even if neither does right now they might by the end of your residency.)

If you want, feel free to contact me internally and schedule a 1:1 so we can chat in more detail. My google username is the first 5 characters of my HN username. If you want to make the meeting private, that's absolutely reasonable. I will not mention anything about it to your team or manager unless you ask me to.

joshzayin··on Even with 2FA, Google accounts can be hacked with just a phone number
Personally, I have a password that my password manager generated that I use for it. I had it written down in my wallet for a while, but after typing it multiple times a day for a while I memorized it and since destroyed the paper. It's a shorter password than what I use for my stored passwords, but I think it strikes a good balance. (And it's not a GUID, but if you think you could memorize that then it probably couldn't hurt. That's risky, though -- if you forget, there go all of your passwords for everything!)

I don't know of any off the top of my head, but there was that time a few years ago when Dropbox accidentally let anyone in without a password. This isn't to pick on Dropbox, but security lapses happen and it's wise to have multiple layers of strong defense to reduce your risk. (Also, if someone compromises the email associated with your CloudDrive, they can use that to get your CloudDrive by invoking a password reset.)

EDIT: Wolfram|Alpha estimates the entropy of a password generated using the constraints I used for mine as roughly 85 bits (the relevant space would take 14 trillion years to enumerate). It actually has a pretty information-heavy password strength estimator (though I can't attest to its reliability as I'm not familiar with the internals).

joshzayin··on Even with 2FA, Google accounts can be hacked with just a phone number
3 combined with 6 sounds like a recipe for disaster if someone manages to compromise your CloudDrive account (probably not by breaking the password, but by social engineering or a method similar to the one in this article). If they get that, they have your encrypted password database, and if that has a weak password... you're totally SOL. The password database's password is one you want to be /very/ strong.
joshzayin··on Strengthening 2-Step Verification with Security Key
If there's malware on your computer, it could just as easily keylog your password and one-time code the next time you try to log in to google, silently drop those packets on the floor (so you think there was just a connection issue), and then use your credentials to get access to your account.

If there's malware on your computer running as you, with access to things like USB devices, it becomes significantly harder (if not impossible) to do anything security critical on it.

joshzayin··on Zeroing buffers is insufficient
A few examples:

"Remote Timing Attacks are Practical" https://crypto.stanford.edu/~dabo/papers/ssl-timing.pdf

"RSA Key Extraction via Low-Bandwidth Acoustic Cryptanalysis" http://www.tau.ac.il/~tromer/acoustic/

joshzayin··on How PGP Works Under the Hood
Please file a bug report so that the issue can get fixed: https://code.google.com/p/end-to-end/issues/list
joshzayin··on True-color GIF with 32697 colors
It's because this is an animated gif. Presumably picasa only shows the first frame.
joshzayin··on True-color GIF with 32697 colors
That's just the animation -- the gif is constructed to animate displaying each block.
joshzayin··on Sharing secrets and distributing passwords
There's a more general proof at https://docs.google.com/viewer?a=v&q=cache:euFgQLUCTfwJ:... that looks reasonable at a skim.
joshzayin··on Does infinity exist?
Here's perhaps an easier to understand proof.

Let A be a countable set. Now, suppose that there was a surjective function (one that hits every element of P(A)) f: A -> P(A). (Note that f takes elements of A, and produces subsets of A.)

Now, define Y ⊆ A as follows: For all x in A, x is in Y if and only if x is not in f(x).

Thus, Y, which is in P(A), is distinct from every output of f, and so f is not actually surjective.

This means that no surjective function f: A -> P(A) exists.

This is a generalization of Cantor's Diagonal Argument (http://en.wikipedia.org/wiki/Cantor%27s_diagonal_argument).

joshzayin··on Live air traffic of the world
Cockpit view is generating an error: "The Google Maps API key used on this web site was registered for a different web site. The developer of this web site can generate a new key here.

(here links to https://developers.google.com/maps/)

joshzayin··on Dropbox Introduces 2-Factor Authentication
More details: https://www.dropbox.com/help/363/en

It looks like they support any app that uses the TOTP protocol, so google authenticator, among others, works with this seamlessly.

joshzayin··on Khan Academy: Computer Science
We also do already have some more theoretical material.

For instance, I just published a Turing Machine simulation (http://www.khanacademy.org/cs/turing-machine/938201372) and we have a random walk simulator (http://www.khanacademy.org/cs/random-walk/803118438).

joshzayin··on Tardis--Haskell package for sending state backwards and forwards through time
The readme does in fact make that claim: "The Reverse State monad allows you to do the reverse: send information backwards to the past, or receive information from the future."

I'm curious as to what exactly that means, but without further explanation I'm going to assume that the thing running in the "past" just waits for information from the "future". It's possible they mean something else, of course, but that's my first guess.

joshzayin··on How a Tech Non-Profit Became the Hottest Ticket in Silicon Valley
(Current KA intern here.)

That video assumes that nonprofit jobs aren't high-paying, but that's not always the case. KA, for instance, pays competitively. If you can both have a high-paying career that enables you to donate while also using your skills to help advance causes you care about (especially if the skills in question are skills that many or most people don't have), then by the reasoning in the video, that's better than either option they present.

joshzayin··on A better git log
I think that's just what you're supposed to type in.

(I see that too, with JS enabled, and if you view source you can see that that was intentional based on the > and <.)

joshzayin··on Mathematics for Computer Science
This is assuming you don't count the algorithm design and analysis class as math, or any of the "logic and languages" (Intro PL, constructive logic, Automated program verification, basic logic, computability and incompleteness) as math.
joshzayin··on Mathematics for Computer Science
I find it somewhat strange that generating functions are introduced significantly before recurrences are (and that recurrences are introduced last!). Does anyone know why the authors did that?
joshzayin··on Is My MacBook Pro Always Listening?
They already do this for the camera, though I'm not sure if it's hardware or software.
joshzayin··on Mathematicians Solve Minimum Sudoku Problem
I think they addressed this in the edit they made:

>Correction: this post was edited on the 6 January to reflect the argument that if an n-clue grid is uniquely solvable then adding a digit to make an n+1-clue grid must also be uniquely solvable. So if there are no uniquely solvable 16-clue grids, there cannot be any grids with fewer clues that are uniquely solvable. Thanks to RealMurph and abooij.

joshzayin··on What are the odds that you exist?
While this is technically true, it's one hell of a selection bias. Clearly, my ancestors all existed and got together. If they didn't, I wouldn't be reading that poster. So, I don't really see the point of it...
joshzayin··on Did a reporter just solve the bitcoin mystery?
Likely something like http://theory.stanford.edu/~aiken/moss/, I'd guess.
joshzayin··on PassMyWill Is A Will For Your Online Assets And Passwords
Well, you could keep the USB stick and give the lawyer the decryption key.
joshzayin··on PassMyWill Is A Will For Your Online Assets And Passwords
What benefit would this provide over simply having an encrypted memory stick (or similar) containing all of the necessary account information and leaving the password with someone trusted (e.g., lawyer responsible for will, family member friend, etc)? (or, as troels suggests, leaving the password or even the stick in a safe)
joshzayin··on Show HN: Use your mac as an alarm clock without any special alarm clock apps
I don't have that problem on my MBP with 10.6.8. How are your Energy Saver preferences set up? Trashing the plist and resetting it to how you like it might work--it's possible that the plist is corrupted.
joshzayin··on Show HN: Use your mac as an alarm clock without any special alarm clock apps
For reference, to set the volume, one would use something like:

   set volume 10
joshzayin··on Show HN: Use your mac as an alarm clock without any special alarm clock apps
You can still set it to boot at a certain time with OS X, and if you set up auto-login and have that as a login item, it'll accomplish the same task.
joshzayin··on Changes to our policies
I agree. At least on the Mac client, there's already an "Advanced" preference pane. Why not create an option there for the user to manage their own encryption key, and possibly what folders it applies to? (For example, they could exempt shared and public folders but encrypt everything else.)
joshzayin··on Depixelizing Pixel Art
For reference: http://www.youtube.com/watch?v=o2Fd-4NzB0w
joshzayin··on High school grad builds 8-bit computer from scratch
Also see http://news.ycombinator.com/item?id=2667357 for his website documenting this.
Page 1 of 3Next →