HNHacker News
TopNewBestAskShowJobs

medina

145 karma · joined December 8, 2010

submissionscomments
medina··on Three Generations in E7
Anyone else click this thinking they were going to an article about getting their family on Microsoft 365 https://www.microsoft.com/en-us/microsoft-365/enterprise/e7 ?
medina··on VulnHunter: Capital One's agentic AI code security tool
VulnHunter: Capital One’s open-source, agentic AI code security tool.
medina··on Michael Rabin has died
Hugely engaging, the margins of my notebook had many of his quips… there was an archive online somewhere.

e.g., x minus x is zero, even for Euler, so therefore…

Found on Archive, https://web.archive.org/web/20210509160248/http://www.eecs.h...

medina··on AT&T, Verizon blocking release of Salt Typhoon security assessment reports
https://www.commerce.senate.gov/2025/12/experts-agree-u-s-co...

> “The Chinese government's espionage operation deeply penetrated networks of at least nine U.S. telecom companies, including AT&T and Verizon,” said Sen. Cantwell. “They exploited the wiretapping system that our law enforcement agencies rely on under the Communications Assistance for Law Enforcement Act -- known as CALEA. These systems became an open door for Chinese intelligence. Salt Typhoon allowed the Chinese operation to track millions of Americans’ locations in real time, record phone calls at will and read our text messages.”

medina··on Almost every infrastructure decision I endorse or regret
> engineers at Weaveworks built the first version of Flux > Weaveworks donated Flux and Flagger to the CNCF

https://fluxcd.io/blog/2022/11/flux-is-a-cncf-graduated-proj...

> Weaveworks will be closing its doors and shutting down commercial operations > Alexis Richardson, 5 Feb 2024

https://www.linkedin.com/posts/richardsonalexis_hi-everyone-...

If the project has legs, it's now under CNCF.

medina··on Twitter’s mass layoffs have begun
MS led consortium (and underwrote largest), 21-27% each spread out across MS, BofA, Barclays, MUFG + smaller to others. (ref: https://www.bloomberg.com/news/articles/2022-10-07/morgan-st...)

(Edit: typo)

medina··on An AWS account just for getting into other AWS accounts
Re-discovering Active Directory Enhanced Security Administrative Environment (ESAE) / Red Forest design, in cloud :-)
medina··on Instagram, Twitter blame glitches for deleting Palestinian posts
More on this: https://www.lawfareblog.com/lawfare-podcast-israels-cyber-un...

[T]he Israeli government’s “Cyber Unit” [is] an entity that, among other things, reaches out to major online platforms like Facebook and Twitter with requests that the platforms remove content. It’s one of a number of such agencies around the globe, which are known as Internet Referral Units. Earlier in April, the Israeli Supreme Court gave a green light to the unit’s activities, rejecting a legal challenge that charged the unit with infringing on constitutional rights.

medina··on Robinhood Accounts Looted, No Customer Support
Not sure what you mean laws but there is certainly regulatory guidance that assessors will be using.

The agencies consider single-factor authentication, as the only control mechanism, to be inadequate for high-risk transactions involving access to customer information or the movement of funds to other parties. Financial institutions offering Internet-based products and services to their customers should use effective methods to authenticate the identity of customers using those products and services. The authentication techniques employed by the financial institution should be appropriate to the risks associated with those products and services. Account fraud and identity theft are frequently the result of single-factor (e.g., ID/password) authentication exploitation. Where risk assessments indicate that the use of single-factor authentication is inadequate, financial institutions should implement multifactor authentication, layered security, or other controls reasonably calculated to mitigate those risks.

https://www.ffiec.gov/pdf/authentication_guidance.pdf

medina··on How to use BeyondCorp to ditch VPN, improve security and go to the cloud
& add cross-link to things like google/huproxy ?
medina··on Project delays: why good software estimates are impossible (2015)
too sad, too true :-(
medina··on KnightOS – an open-source operating system for TI calculators
Which make me to check and... a TI-89 is still over $100.
medina··on Ask HN: Who is hiring? (September 2015)
MongoDB | NYC, Dublin | ONSITE | FULLTIME

MongoDB, Inc. is the company behind MongoDB, the open-source, document database designed for ease of development and scaling. If you're a systems administrator, infrastructure engineer, devops engineer, or in a similar role, we'd like to talk to you.

MongoDB is hiring in NYC and Dublin for infrastructure engineering positions:

• Systems Engineer (Core Infra, NYC): https://www.mongodb.com/careers/positions?gh_jid=66414

• Systems Engineer (Core Infra, Dublin): https://www.mongodb.com/careers/positions?gh_jid=82452

• Systems Engineer (Build, NYC): https://www.mongodb.com/careers/positions?gh_jid=75637

• Systems Engineer (Cloud, NYC): https://www.mongodb.com/careers/positions?gh_jid=71693

• Information Security Engineer (NYC): https://www.mongodb.com/careers/positions?gh_jid=66561

For a list of positions across all teams, please visit https://www.mongodb.com/careers If you have questions about the positions listed above (I'm the hiring manager or can put you in touch with one) or want to reach out for anything else, you can contact me at (HN username) @mongodb.com.

medina··on How a bug in VS2015 exposed my source code on GitHub and cost me $6,500
http://ghcc.io - Tool used to continuously monitor a Github org for mistaken public commits (& lets you monitor repos you care about but might not be able to enforce commit-hooks for).
medina··on Ask HN: Who is hiring? (August 2015)
MongoDB | NYC, Dublin | ONSITE | FULLTIME

MongoDB, Inc. is the company behind MongoDB, the open-source, document database designed for ease of development and scaling. If you're a systems administrator, infrastructure engineer, devops engineer, or in a similar role, we'd like to talk to you.

MongoDB is hiring in NYC and Dublin for infrastructure engineering positions.

• Systems Engineer (Core Infra, NYC): https://www.mongodb.com/careers/positions?gh_jid=66414

• Systems Engineer (Core Infra, Dublin): https://www.mongodb.com/careers/positions?gh_jid=82452

• Systems Engineer (Build, NYC): https://www.mongodb.com/careers/positions?gh_jid=75637

• Systems Engineer (Cloud, NYC): https://www.mongodb.com/careers/positions?gh_jid=71693

• Information Security Engineer (NYC): https://www.mongodb.com/careers/positions?gh_jid=66561

For a list of positions across all teams, please visit https://www.mongodb.com/careers

If you have questions about the positions listed above (I'm the hiring manager or can put you in touch with one) or want to reach out for anything else, you can contact me at (HN username) @mongodb.com.

medina··on Ask HN: Who is hiring? (July 2015)
MongoDB is hiring in NYC, for infrastructure engineering positions.

• Systems Engineer (Core Infra): https://www.mongodb.com/careers/positions?gh_jid=66414

• Systems Engineer (Build): https://www.mongodb.com/careers/positions?gh_jid=75637

• Systems Engineer (Cloud): https://www.mongodb.com/careers/positions?gh_jid=71693

• Information Security Engineer: https://www.mongodb.com/careers/positions?gh_jid=66561

For a list of positions across all teams, please visit https://www.mongodb.com/careers

If you have questions about the positions listed above (I'm the hiring manager or can put you in touch with one) or want to reach out for anything else, you can contact me @mongodb.com.

medina··on What's new in purely functional data structures since Okasaki?
Also had him, PLT and SoftE. I regret not "getting" what the was talking about at the time, also having the "dazed and confused" experience, as it was so at odds with most of the "Java school" stuff I had experienced in the program up to that point.

You might want to see http://www.eecs.usma.edu/webs/people/okasaki/pubs.html for updated publications from him.

medina··on Slowloris - the low bandwidth, yet greedy and poisonous HTTP client
See also "A. Kuzmanovic and E. W. Knightly. Low-Rate TCP-Targeted Denial of Service Attacks (The Shrew vs. the Mice and Elephants). In Proc. ACM SIGCOMM, 2003." and related papers -- http://www.cs.northwestern.edu/~akuzma/rice/shrew/