314 karma · joined May 5, 2014
The people behind Signal pioneered end-to-end encryption, and as is pointed out in the blog post, there's still a lot of novel cryptography development involved in building a privacy-first messenger. You can't do that without top-notch talent.
Notjustbikes posted a good video rebutting this argument a few days ago: https://youtu.be/REni8Oi1QJQ
I think ‘immigration’ is primarily used by English speaking New World countries which historically had large scale immigration (as in, settlement) programs after the world wars—although I don’t have a definitive source for this.
I've said this before, but even back in early 2014 Rob Pike had said that he regretted the term "systems programming" because people misunderstood him to mean it as a language for writing operating systems, when what he meant was a language for writing servers, although that later evolved to cloud infrastructure.
He answers this at 6:50 here, https://channel9.msdn.com/Events/Lang-NEXT/Lang-NEXT-2014/Pa...
There were 20-something handles they used over approximately a 6 month period of monitoring. I was always able to find a small piece of information to correlate these handles together. Sometimes it started with a hunch, such as the language (even slang) they would use, but eventually they'd slip up in some way and we'd have a pretty irrefutable link to the person.
This information helped us develop a motive behind the hack and the ongoing public info was then fed to national crime agencies. My employer never went through with prosecution, but as this person was of much interest behind other hacks they were eventually prosecuted and convicted. I always wondered if my occasional Echelog intelligence reports ever had a role in that conviction.
I just checked some Equifax domains against SSL Labs, and while their Canadian site (https://www.econsumer.equifax.ca) scores an A-, it has no forward secrecy. I'm surprised to see a modern web server not supporting FS today. Worse, the main entry point to their Canadian site (http://www.consumer.equifax.ca) as indexed by Google does not redirect to a TLS enabled page, although they do seem to have a TLS endpoint for that domain -- but not sure how people are expected to get to it.
Edited to add: The first link is only accessible through a redirect by clicking on the "Get Started" button on their main Canadian site. Furthermore, even selecting Canada from the drop-down on https://www.equifax.com/personal/ redirects to the insecure non-TLS site.
Rapidly expanding Canadian IoT company with new products in the works. Plenty of interesting problems to work on, from crypto, databases, highly concurrent software, performance tuning, to running infrastructure at scale.
Friendly culture, generous work from home/remote policy. Opportunity to work with industry experts and thought leaders in Toronto on some exciting new technologies. Email me directly, jari <at> ecobee.com, or browse our other postings here, https://www.ecobee.com/careers/.
Anyways this invites the question, are you allowing your production servers to make outbound internet connections? Generally, I would proxy outbound connections and/or use internal mirrors and repos for the installation of software.
Rapidly growing Canadian IoT company with new products in the works. Plenty of interesting problems to work on, from crypto, performance tuning, to running infrastructure at scale. Currently building an SRE team, other openings in hardware engineering and front-end development available.
For the SRE role we’re looking for developers and automation experts with strong knowledge of Linux internals, TCP/IP protocol operation and theory, and security. Internally the SRE team uses a lot of Python and Golang. Familiarity with C and Java is a plus.
Friendly culture, generous work from home/remote policy. Opportunity to work alongside industry experts and thought leaders in Toronto. Email me directly, jari <at> ecobee.com, or browse our other postings here, https://www.ecobee.com/careers/.
Edit: One of my fond memories of that time was actually greeting the refuelling truck and directing it to the point where he could plug a hose into a pipe on our building and start pumping.
[1] https://en.wikipedia.org/wiki/Northeast_blackout_of_2003
Edit: Rob mentions it here at 06:50: http://channel9.msdn.com/Events/Lang-NEXT/Lang-NEXT-2014/Pan...
As the outbound TCP SYN is manually crafted and sent over a raw socket, without any corresponding state table entry on the sender's kernel, incoming TCP responses will be rejected by the kernel with a RST.
I suggested to Julia that she manually publish an ARP entry for another IP which she could send and receive on. The kernel not having an interface with that IP assigned to it would ignore responses while also passing them to the raw socket. An alternative would be to use an iptables rule to drop incoming packets for the relevant flow - although that may be more difficult to manage depending on what you're doing.
I told him I had read his book and that I'm an aspiring entrepreneur, and so he proceeded to give me some advice, saying: "the right time to start a new venture is now", "go out and just do it". As we parted ways he tapped me on the shoulder and said, "go and do it, when you leave this shop go and register your business right now and start it. Don't delay. The right time is now."
Edit: I was just reminded that although he was filthy rich (as he described himself), he was also frugal in some ways and always after a deal. When we met, he mentioned that he had been wearing his suit for 20 years, but it no longer fit due to his illness, and so if I recall correctly, he bought at least 3 new suits from the tailor on that day. He would walk also around Central London, with his offices in Soho, and as of 2012 did not own a mobile phone.