HNHacker News
TopNewBestAskShowJobs

kkl

491 karma · joined July 12, 2014

he/him

https://kel.bz

https://argemma.com

submissionscomments
kkl··on You don't want long-lived keys
SSH CAs are not incompatible with my argument! An SSH CA can sign short-lived certificates for just-in-time generated keys.
kkl··on You don't want long-lived keys
> "we can't have service accounts"

To be clear: This is not my position! I advocate for service accounts in my post:

> It is much harder to reason about, say, the security of an arbitrary Engineer's laptop than it is an EC2 instance that exists exclusively to tell KMS to sign something.

> So every time we fire or lay off the person whose name is on the automation, we need to rotate the keys?

If a person previously had access to the key and knowledge of the key gives you control over that automated workflow, is that key (and by extension that workflow) still worth trusting?

kkl··on You don't want long-lived keys
Part of the threat model for an Engineering team is that people come and go. They move teams which have different levels of access. They leave the organization, in most cases, on good terms. I want to set up infrastructure where I don't need to remember that your SSH pubkey is baked into production configuration after you leave the company.

There are several options for setting up per-connection keys that are dispensed to users through the company SSO. That setup means you don't need to maintain separate infrastructure for (de-)provisioning SSH keys.

kkl··on A rogue AI led to a serious security incident at Meta
> "Had the engineer that acted on that known better, or did other checks, this would have been avoided."

<insert takes long drag tweet[1] here>

I personally find "LLMs can do $THING poorly" and "LLMs can do $THING well" articles kinda boring at this point. But! I'm hopeful that stories like this will shift the industry's focus towards robustness instead of just short-term efficiency. I suspect many decision making and change management processes accidentally benefited from just being a bit slow.

[1] https://waffles.fun/amy.png

kkl··on Every layer of review makes you 10x slower
> The job of a code reviewer isn't to review code. It's to figure out how to obsolete their code review comment, that whole class of comment, in all future cases, until you don't need their reviews at all anymore.

Making entire classes of issues effectively impossible is definitely the ideal outcome. But, this feels much more complicated when you consider that trust doesn't always extend beyond the company's wall and you cannot always ignore that fact because the negative outcomes can be external to the company.

What if I, a trusted engineer, run `npm update` at the wrong time and malware makes its way into production and user data is stolen? A mistake to learn from, for sure, but a post-mortem is too late for those users.

I'm certainly not advocating for relying on human checks everywhere, but reasoning about where you crank the trust knob can get very complicated or costly. Occasionally a trustworthy human reviewer can be part of a very reasonable control.

kkl··on Every layer of review makes you 10x slower
It’s also the case that someone you trust makes an honest mistake and, for example, gets their laptop stolen and their credentials compromised. I do trust my team, and want that to be the foundation to our relationship, but I also recognize that humans are infallible and having guardrails (eg code review) is beneficial.
kkl··on Fish Shell 4.0 released. Rust re write finished
Congratulations! Fish is such a wonderful shell. It’s been my daily driver for many years now but I’ve had a renewed appreciation for it now that I’m working in several different development environments. The default fish install Just Works so well that I don’t bother with trying to schlep my dotfiles around.
kkl··on Never buy a .online domain
I could also buy that the free domains were ran up by scammers which could have caused some of the hair trigger Safe Browsing denylisting.
kkl··on Minions – Stripe's Coding Agents Part 2
While there are compliance/security benefits it is not the primary motivation.

If you have fairly complicated infrastructure it can be way more efficient to have a pool of ready to go beefy EC2 instances on a recent commit of your multi-GB git repo instead of having to run everything on a laptop.

kkl··on Show HN: Evilpass – A slightly evil password strength checker
Losing control of your actual phone is not the same as losing control of your phone number.

I'm not sure about Microsoft, but Google supports several other 2FA mechanisms in addition to SMS.

kkl··on Differences between Heavy Metal, Thrash Metal, Black Metal, and Death Metal
I think this is true of "Second Wave" black metal bands but less true of more recent output.
kkl··on I'm giving up on PGP
What properties does email have that asynchronous messaging services (e.g. Signal) do not?
kkl··on I'm giving up on PGP
Signal does have a desktop application. I believe you can also register a Signal account using a phone number from a service like Twilio. I'm not 100% sure that will work with Signal desktop though.

https://whispersystems.org/blog/signal-desktop/

kkl··on I'm giving up on PGP
Most interesting e2e projects have abandoned email, specifically SMTP, as a secure messaging platform. I would look outside SMTP-based solutions if I were to start using a different project (assuming doing so is an option... I hope it is!).

My recommendation here is Signal: https://whispersystems.org/

kkl··on Ask HN: Who is hiring? (December 2016)
Praetorian | Security Engineer | Austin, Texas | REMOTE (For principal and staff positions)

Praetorian is different. We are a collective of highly-technical engineers focused on helping our clients solve their most difficult security problems. Rather than break things over and over, our goal is to have an actual impact in making the world a better place. 100% privately owned and self-funded, we are focused on doing the right thing over short term profits. Where other companies pay lip service to vision statements and principles, we are unwaveringly guided by our core values, which are:

* Put the client first - Everything else will work out.

* Enjoy the work you do - Passion eats education and experience for breakfast.

* Be humble - True significance is only achieved as a team.

* Embrace the wobble - There is existential urgency to our work. We need to move and adapt quickly.

* Walk with a swagger - Relish the new challenge.

* Default to open - The right decision is in the data. Share all of it.

* Orient to action - Do not wait to be directed. Engage.

* Performance matters - We are a small company intent on doing big things. Every individual effort counts.

* Stop evil - Our mission is to make the world a safer and more secure place.

* Make craters - Our time on this earth is short. Leave an impact.

Although small, we are growing rapidly, with 50% YOY growth for the past three years. That growth is based on fantastic clients and their support. Our annual net promoter score is consistently over 80%. By comparison, Apple is typically in the mid 70s, and Amazon is usually in the high 60s.

We are looking for experienced engineers that share our values. We offer our staff a generous benefits package, including:

* Competitive salaries

* Quarterly bonuses, 4% 401k matching, stock options

* Health insurance, and options for vision, dental, ADD, Short term disability, and life

* 20% Bench time for research, tool development, or training

* Flexible vacation policy

* Low travel requirements. Seriously. No more than 20% for those in network security and nearly 0% for those in application security.

* Company contributions to training and conferences

* Opportunities for rapid growth and advancement based on merit.

If you’d like to learn more, please visit our career page at: https://www.praetorian.com/company/careers. Take a look at our tech challenges too, as we’ll ask you to complete one early in the interview process: https://www.praetorian.com/challenges/

kkl··on Flaws in deterministic password managers
I think a password manager (minus some of the scary bits like browser plugins) is a much better option than a mental password generation scheme. Maybe some folks can handle this but I think this is a non-ideal general recommendation.
kkl··on GOST cryptography – Russian Federation’s cryptographic algorithms
That is called a "cipher cascade"[1] and practically speaking, no.

[1] https://en.wikipedia.org/wiki/Multiple_encryption

kkl··on Phasing Out SHA-1 on the Public Web
This is a common theme in this thread but I'll re-state it here:

Web browsers cannot reliably distinguish between a configuration mistake and an attack.

For this reason, I think hard HPKP fails are a good thing. For those who opt-in to HPKP, this is a risk one takes in exchange for greater control over certificate validation.

kkl··on Phasing Out SHA-1 on the Public Web
It depends on who you ask, but I personally don't think hard certificate validation failures are a bad thing.
kkl··on Phasing Out SHA-1 on the Public Web
As far as I know almost all browser security warnings are overridable. The only one that comes to mind that does not have a click-through option is when a HSTS-enabled site fails a validation check.
kkl··on The VeraCrypt Audit Results
I do not think your analogy applies here. Finding 8 critical-risk bugs in a project from an audit is bad news. It is highly suggestive that the codebase is riddled with flaws.

Smoke, fire, yadda yadda.

kkl··on Disappearing messages for Signal
LG G2 to a Nexus 5X.
kkl··on Disappearing messages for Signal
My Signal phone audio issues went away after I upgraded hardware. Not a great solution (obviously) but something worth noting.
kkl··on Ask HN: Who is hiring? (October 2016)
I am bummed that you got the impression that you felt ignored for not having security expertise. I am not certain when you applied but I know our focus lately has been on senior engineers so that likely contributed to our response. Regardless, if we didn't do a good job relaying that information to you that is not good and I personally apologize (it was likely my fault as I handle a good chunk of the initial responses to applicants).

Thanks for the feedback though. It is appreciated.

kkl··on Ask HN: Who is hiring? (October 2016)
Praetorian | Austin, Texas | REMOTE (For principal and staff positions)

Praetorian is different. We are a collective of highly-technical engineers focused on helping our clients solve their most difficult security problems. Rather than break things over and over, our goal is to have an actual impact in making the world a better place. 100% privately owned and self-funded, we are focused on doing the right thing over short term profits. Where other companies pay lip service to vision statements and principles, we are unwaveringly guided by our core values, which are:

    * Put the client first - Everything else will work out.
    * Enjoy the work you do - Passion eats education and experience for breakfast.
    * Be humble - True significance is only achieved as a team.
    * Embrace the wobble - There is existential urgency to our work. We need to move and adapt quickly.
    * Walk with a swagger - Relish the new challenge.
    * Default to open - The right decision is in the data. Share all of it.
    * Orient to action - Do not wait to be directed. Engage.
    * Performance matters - We are a small company intent on doing big things. Every individual effort counts.
    * Stop evil - Our mission is to make the world a safer and more secure place.
    * Make craters - Our time on this earth is short. Leave an impact.
Although small, we are growing rapidly, with 50% YOY growth for the past three years. That growth is based on fantastic clients and their support. Our annual net promoter score is consistently over 80%. By comparison, Apple is typically in the mid 70s, and Amazon is usually in the high 60s.

We are looking for experienced engineers that share our values. We offer our staff a generous benefits package, including:

    * Competitive salaries
    * Quarterly bonuses, 4% 401k matching, stock options
    * Health insurance, and options for vision, dental, ADD, Short term disability, and life
    * 20% Bench time for research, tool development, or training
    * Flexible vacation policy
    * Low travel requirements. Seriously. No more than 20% for those in network security and nearly 0% for those in application security.
    * Company contributions to training and conferences
    * Opportunities for rapid growth and advancement based on merit.
If you’d like to learn more, please visit our career page at: https://www.praetorian.com/company/careers. Take a look at our tech challenges too, as we’ll ask you to complete one early in the interview process: https://www.praetorian.com/challenges/
kkl··on Ask HN: Who is hiring? (September 2016)
Praetorian | Austin, Texas | REMOTE (For principal and staff positions)

Praetorian is different. We are a collective of highly-technical engineers focused on helping our clients solve their most difficult security problems. Rather than break things over and over, our goal is to have an actual impact in making the world a better place. 100% privately owned and self-funded, we are focused on doing the right thing over short term profits. Where other companies pay lip service to vision statements and principles, we are unwaveringly guided by our core values, which are:

    * Put the client first - Everything else will work out.
    * Enjoy the work you do - Passion eats education and experience for breakfast.
    * Be humble - True significance is only achieved as a team.
    * Embrace the wobble - There is existential urgency to our work. We need to move and adapt quickly.
    * Walk with a swagger - Relish the new challenge.
    * Default to open - The right decision is in the data. Share all of it.
    * Orient to action - Do not wait to be directed. Engage.
    * Performance matters - We are a small company intent on doing big things. Every individual effort counts.
    * Stop evil - Our mission is to make the world a safer and more secure place.
    * Make craters - Our time on this earth is short. Leave an impact.
Although small, we are growing rapidly, with 50% YOY growth for the past three years. That growth is based on fantastic clients and their support. Our annual net promoter score is consistently over 80%. By comparison, Apple is typically in the mid 70s, and Amazon is usually in the high 60s.

We are looking for experienced engineers that share our values. We offer our staff a generous benefits package, including:

   * Competitive salaries
   * Quarterly bonuses, 4% 401k matching, stock options
   * Health insurance, and options for vision, dental, ADD, Short term disability, and life
20% Bench time for research, tool development, or training * Flexible vacation policy * Low travel requirements. Seriously. No more than 20% for those in network security and nearly 0% for those in application security. * Company contributions to training and conferences * Opportunities for rapid growth and advancement based on merit.

If you’d like to learn more, please visit our career page at: https://www.praetorian.com/company/careers. Take a look at our tech challenges too, as we’ll ask you to complete one early in the interview process: https://www.praetorian.com/challenges/

kkl··on Ask HN: Who is hiring? (August 2016)
Nope! Whatever language your prefer.
kkl··on Ask HN: Who is hiring? (August 2016)
Praetorian | Austin, Texas | REMOTE

Praetorian is different. We are a collective of highly-technical engineers focused on helping our clients solve their most difficult security problems. Rather than break things over and over, our goal is to have an actual impact in making the world a better place.

100% privately owned and self-funded, we are focused on doing the right thing over short term profits. Where other companies pay lip service to vision statements and principles, we are unwaveringly guided by our core values, which are:

  * Put the client first - Everything else will work out. 
  
  * Enjoy the work you do - Passion eats education and experience for breakfast. 

  * Be humble - True significance is only achieved as a team. 

  * Embrace the wobble - There is existential urgency to our work. We need to move and adapt quickly. 
  
  * Walk with a swagger - Relish the new challenge. 
  
  * Default to open - The right decision is in the data. Share all of it. 
  
  * Orient to action - Do not wait to be directed. Engage. 

  * Performance matters - We are a small company intent on doing big things. Every individual effort counts. 

  * Stop evil - Our mission is to make the world a safer and more secure place. 

  * Make craters - Our time on this earth is short. Leave an impact.
Although small, we are growing rapidly, with 50% year-over-year growth for the past three years. That growth is based on fantastic clients and their support. Our annual net promoter score (a measure of customer satisfaction, see more here: https://en.wikipedia.org/wiki/Net_Promoter) is consistently over 80%. By comparison, Apple is typically in the mid 70s, and Amazon is usually in the high 60s.

We are looking for experienced engineers that share our values. We offer our staff a generous benefit package, including:

  * Competitive salaries Quarterly bonuses, 4% 401k matching, stock options Health insurance, and options for vision, dental, ADD, Short term disability, and life 

  * 20% Bench time for research, tool development, or training 

  * Flexible vacation policy 

  * Low travel requirements. Seriously. No more than 20% for those in network security and nearly 0% for those in application security. 

  * Company contributions to training and conferences 

  * Opportunities for rapid growth and advancement based on merit.
To Apply: Please apply through our portal here (All emails go directly to me): https://www.praetorian.com/company/careers. Part of the interview process involves the completion of one of our technical challenges. If you would like to get a head start, please view our tech challenges at http://www.praetorian.com/challenges/.
kkl··on CloudFlare, We Have a Problem
Considering:

* Golang's TLS stack is far less complex in comparison to other projects.

* Golang's TLS stack is written in a "safe" language.

* Golang's TLS stack is written by individuals with lots of experience in SSL/TLS (and its flaws!).

* Contributions to the project are held to very high standards.

Why do you believe the inverse is true?

kkl··on Don't use JSON web tokens for sessions
If you don't believe `tptacek maybe you will believe James Kettle:

http://blog.portswigger.net/2016/05/web-storage-lesser-evil-...

Page 1 of 3Next →