HNHacker News
TopNewBestAskShowJobs

jtakkala

314 karma · joined May 5, 2014

submissionscomments
jtakkala··on Mythos social engineering AISI INC-2026-07-28-01
They're almost certainly not genuine accounts, maybe used for karma farming, phishing, social engineering, future malware distribution?
jtakkala··on Mythos social engineering AISI INC-2026-07-28-01
Not going to comment on the PR commentary, but the victim GitHub account is suspicious itself, recent account, a few fresh repos, following 14.5k others, and I count three surnames on the account (the username, plus two in the README history).
jtakkala··on QUIC is not quick enough over fast internet
Rogers and Teksavvy support IPv6
jtakkala··on Privacy is priceless, but Signal is expensive
$660k total comp (including benefits) is probably right in the median of what an e6 earns at Meta. I don’t know where you’re hearing otherwise.
jtakkala··on Privacy is priceless, but Signal is expensive
There's definitely top-notch software and security engineers making well north of £150k in the UK. As you go up in levels, it's indeed a small set of people, but FB / Google comp for a top L7 engineer working in the same space as Signal engineers can be $700k+ in the UK. Just have a look at levels.fyi, and you'll see that even finance will pay over $500k in London. Furthermore, given how small the group of people are at the top of these companies, very few will self-report their incomes publicly, which is why you'll rarely hear about the engineers making $1M+ – but those cases do exist.

The people behind Signal pioneered end-to-end encryption, and as is pointed out in the blog post, there's still a lot of novel cryptography development involved in building a privacy-first messenger. You can't do that without top-notch talent.

jtakkala··on 66% of Americans say they want extended European-style vacation policies at work
I left out the company-wide holidays, which in 2022 amounted to 4, and the 10+ public holidays.
jtakkala··on 66% of Americans say they want extended European-style vacation policies at work
On top of that, there are roles in FAANG companies and Silicon Valley that give ~5 weeks PTO. For example, Facebook historically has had a fairly good PTO policy in the US, and for the past several years gives at least 23 days (plus there's the whole extra month off every 5 years). I heard that as a result of that, Google had to increase their PTO in recent years.
jtakkala··on Maps distort how we see the world
The size of Canada really isn’t a valid excuse for Canada’s poor public transit, nor is Canada’s population.

Notjustbikes posted a good video rebutting this argument a few days ago: https://youtu.be/REni8Oi1QJQ

jtakkala··on Zstandard – Fast real-time compression algorithm
Here’s a recent talk by Yann Collet at Stanford which leads into an interesting Q&A about his development of Zstandard: https://youtu.be/gZikN5hhlxA
jtakkala··on Sauna use as a lifestyle practice to extend healthspan
Did you even read the comment above? Sauna usage in Finland has basically no correlation with socioeconomic status. Pretty much everyone has access to a sauna and the time to use one. Not only is it a tradition, but Finland goes to great lengths to prioritize the health and welfare of all its citizens, regardless of ones wealth.
jtakkala··on Countries that have accepted the World Passport
Correct, and generally known as ‘passport control’ in Europe and many other countries.

I think ‘immigration’ is primarily used by English speaking New World countries which historically had large scale immigration (as in, settlement) programs after the world wars—although I don’t have a definitive source for this.

jtakkala··on Europe's night trains are on track for a resurgence
I've done Surat Thani to Bangkok in a first class sleeper, and indeed recall sleeping blissfully. One of my most memorable train journeys.
jtakkala··on Rob Pike interview
> Go was originally envisioned as a systems programming language. It was often called "a better C". This exposed Rob Pike's lack of experience in the area (IMHO) because anyone who had done any systems programming at all knew that garbage collection made any systems language a nonstarter.

I've said this before, but even back in early 2014 Rob Pike had said that he regretted the term "systems programming" because people misunderstood him to mean it as a language for writing operating systems, when what he meant was a language for writing servers, although that later evolved to cloud infrastructure.

He answers this at 6:50 here, https://channel9.msdn.com/Events/Lang-NEXT/Lang-NEXT-2014/Pa...

jtakkala··on Freenode IRC logging archive Echelog is shutting down
Indeed, and in that respect Echelog was a great source of OSINT material for the anecdote I described above. That, along with `whois` data and other public databases can reveal a lot without putting oneself at legal risk.
jtakkala··on Freenode IRC logging archive Echelog is shutting down
A long time ago parsing Echelog logs was how I was able to monitor the IRC activity of an attacker at a company I used to work at. I didn't normally sit on these channels myself, but Echelog enabled me to look back and collect data on the various handles that this person operated under.

There were 20-something handles they used over approximately a 6 month period of monitoring. I was always able to find a small piece of information to correlate these handles together. Sometimes it started with a hunch, such as the language (even slang) they would use, but eventually they'd slip up in some way and we'd have a pretty irrefutable link to the person.

This information helped us develop a motive behind the hack and the ongoing public info was then fed to national crime agencies. My employer never went through with prosecution, but as this person was of much interest behind other hacks they were eventually prosecuted and convicted. I always wondered if my occasional Echelog intelligence reports ever had a role in that conviction.

jtakkala··on A Fighter Pilot’s Guide to Surviving on the Roads
The EU has required DRL's on all new cars since 2011. As an EU member state this applies to Croatia too.
jtakkala··on Apache Struts Statement on Equifax Security Breach
I've got HTTPS Everywhere running and it doesn't appear to have a rule since I'm still hitting the non-TLS site.
jtakkala··on Apache Struts Statement on Equifax Security Breach
I completely agree about having a dedicated team, and I'd expect a company of their nature to be at the forefront of security best practices.

I just checked some Equifax domains against SSL Labs, and while their Canadian site (https://www.econsumer.equifax.ca) scores an A-, it has no forward secrecy. I'm surprised to see a modern web server not supporting FS today. Worse, the main entry point to their Canadian site (http://www.consumer.equifax.ca) as indexed by Google does not redirect to a TLS enabled page, although they do seem to have a TLS endpoint for that domain -- but not sure how people are expected to get to it.

Edited to add: The first link is only accessible through a redirect by clicking on the "Get Started" button on their main Canadian site. Furthermore, even selecting Canada from the drop-down on https://www.equifax.com/personal/ redirects to the insecure non-TLS site.

jtakkala··on Ask HN: Who is hiring? (March 2017)
ecobee | Software Developer | Toronto | https://www.ecobee.com

Rapidly expanding Canadian IoT company with new products in the works. Plenty of interesting problems to work on, from crypto, databases, highly concurrent software, performance tuning, to running infrastructure at scale.

Friendly culture, generous work from home/remote policy. Opportunity to work with industry experts and thought leaders in Toronto on some exciting new technologies. Email me directly, jari <at> ecobee.com, or browse our other postings here, https://www.ecobee.com/careers/.

jtakkala··on Syscall Auditing at Scale
Great idea. I always thought that it's essential to log events in realtime to a remote system that is secure and harder to compromise to modify the logs post-intrusion. Way back in the day it was suggested to do this to an entirely offline system by cutting the rx pins on a parallel cable, thereby only allowing the one-way transmission of logs to the log server. I don't know if anyone ever did that in practice though.

Anyways this invites the question, are you allowing your production servers to make outbound internet connections? Generally, I would proxy outbound connections and/or use internal mirrors and repos for the installation of software.

jtakkala··on TCP Puzzlers
When a process exits abnormally or not and if there's unread data in the receive buffer then the kernel will send a RST, otherwise it would send a FIN.
jtakkala··on We’re pretty happy with SQLite and not urgently interested in a fancier DBMS
I gained a newfound respect for SQLite recently after reading Dan Luu's post on file consistency (http://danluu.com/file-consistency/). I had always thought of SQLite as a bit of a toy database, but having read that post I was surprised by how rigorously it appears to have been developed.
jtakkala··on Ask HN: Who is hiring? (June 2016)
Thanks! Fixed.
jtakkala··on Ask HN: Who is hiring? (June 2016)
ecobee | Toronto, Canada | Full-time | ONSITE (remote work up to 25% of the time possible)

Rapidly growing Canadian IoT company with new products in the works. Plenty of interesting problems to work on, from crypto, performance tuning, to running infrastructure at scale. Currently building an SRE team, other openings in hardware engineering and front-end development available.

For the SRE role we’re looking for developers and automation experts with strong knowledge of Linux internals, TCP/IP protocol operation and theory, and security. Internally the SRE team uses a lot of Python and Golang. Familiarity with C and Java is a plus.

Friendly culture, generous work from home/remote policy. Opportunity to work alongside industry experts and thought leaders in Toronto. Email me directly, jari <at> ecobee.com, or browse our other postings here, https://www.ecobee.com/careers/.

jtakkala··on FPGA Webserver
Yes, it exists, and widely used in HFT. A few years ago Arista even introduced a switch with a built-in FPGA specifically for this purpose.
jtakkala··on Inside Equinix's NY4 data center where Wall Street trades
Where I used to work we had refuelling agreements with multiple vendors. Yes, hospitals and critical infrastructure are prioritized first, but we ran on generators for an extended spell during the Northeast Blackout of 2003[1] (the outage affecting our facility only lasted a couple of days, but due to the utilities' appeal to reduce load on the grid until it was fully functional we decided to run on generators for over a week).

Edit: One of my fond memories of that time was actually greeting the refuelling truck and directing it to the point where he could plug a hose into a pipe on our building and start pumping.

[1] https://en.wikipedia.org/wiki/Northeast_blackout_of_2003

jtakkala··on Go 1.4 is released
I think it was Rob Pike who later said he regretted using the term "systems programming" to describe Go. They never meant the phrase to mean purely operating system tools and programs (ie. not web applications or interactive end-user applications), which would be rather limiting. Instead, he said he said they meant it as a language for composing systems, as for example a typical SOA web site may be, or even for application development as you've alluded to.

Edit: Rob mentions it here at 06:50: http://channel9.msdn.com/Events/Lang-NEXT/Lang-NEXT-2014/Pan...

jtakkala··on What happens if you write a TCP stack in Python?
I think you'll find that either publishing an ARP entry or filtering incoming packets in the kernel is required for handling a TCP stream over raw sockets.

As the outbound TCP SYN is manually crafted and sent over a raw socket, without any corresponding state table entry on the sender's kernel, incoming TCP responses will be rejected by the kernel with a RST.

I suggested to Julia that she manually publish an ARP entry for another IP which she could send and receive on. The kernel not having an interface with that IP assigned to it would ignore responses while also passing them to the raw socket. An alternative would be to use an iptables rule to drop incoming packets for the relevant flow - although that may be more difficult to manage depending on what you're doing.

jtakkala··on Oz magazine publisher Felix Dennis dies
I had the fortune of meeting Felix a couple of years ago. I bumped into him at a small tailor off Carnaby Street in London. I wouldn't have recognized him if it weren't for the shop owner. He had lost a significant amount of weight due to cancer and was out purchasing a new set of suits. He was in good spirits however, boasting that he had beaten cancer, and was on his way to pick up one of the last hand made Maybach cars.

I told him I had read his book and that I'm an aspiring entrepreneur, and so he proceeded to give me some advice, saying: "the right time to start a new venture is now", "go out and just do it". As we parted ways he tapped me on the shoulder and said, "go and do it, when you leave this shop go and register your business right now and start it. Don't delay. The right time is now."

Edit: I was just reminded that although he was filthy rich (as he described himself), he was also frugal in some ways and always after a deal. When we met, he mentioned that he had been wearing his suit for 20 years, but it no longer fit due to his illness, and so if I recall correctly, he bought at least 3 new suits from the tailor on that day. He would walk also around Central London, with his offices in Soho, and as of 2012 did not own a mobile phone.