HNHacker News
TopNewBestAskShowJobs

merijn481

283 karma · joined September 25, 2010

Goals are dreams with a deadline.

[ my public key: https://keybase.io/merijn; my proof: https://keybase.io/merijn/sigs/Ev6pG__grp4S_ATC7yFxI8OjUx7LWgZRX0mTtuTdE3A ]

submissionscomments
merijn481··on Process and Leverage in Fundraising
Following the advice of this post can make a 10x difference in outcome for founders. This is because they will sharpen their skill to raise this way in every round. The reduced dilution compounds. The additional money in each round can help get you to critical mass first. It’s a powerlaw. One of the most important things to understand when you’re doing a startup. Growth is what makes a company a startup: http://www.paulgraham.com/growth.html. Process and leverage in fundraising is an absolute condition to get there. This post should have 1000 points.
merijn481··on Flickr: Invitations disclosure (resend feature)
Yahoo has fully embraced working with security researchers. For a company their size (they're no. 1 in web traffic!) with that many different services, they're doing an amazing job. No company that size has ever moved this fast. Yes, they're catching up but they do it fast!
merijn481··on Twitter’s Root Injustice
You make some very interesting observations. I'm pretty sure the folks at Twitter spend a LOT of time working on user engagement and solving the signal vs noise problem in recommendations etc. What's been their response so far when you reached out to them? I would try to reach out to the people trying to solve this problem (developers) instead of to management first, in case it's not a matter of decision making but a more of an algorithmic problem.
merijn481··on Facebook vulnerability 2013
Well, if you have the email, just reply to it and re-open the conversation and see what happens. If you can explain it correctly, they might be able to research if the bug indeed existed and was fixed. I did a follow up on a bug that I submitted before the whitehat program was in place and that I never got a response on. They looked up the bug, replied to me and paid me. Very diligent.
merijn481··on Facebook vulnerability 2013
They didn't pay because he messed with other peoples' data. That's a clear no-go.
merijn481··on Facebook vulnerability 2013
I'm surprised at how many people just assume the FB sec team doesn't want to pay and therefore tries to not pay if they can get away with it. Their history of paying out is completely the opposite. I've reported several bugs and they're always extremely helpful. They're not an insurance company that wants to reduce cost by screwing over users and there is no historical evidence of that. They want to pay for bugs and get as many of them as possible. What they don't want is for researchers to mess with other users' data. The guy could have just used two accounts to demo (he managed to create a new account after his own account was blocked). Using Zucks account doesn't make it more convincing from a tech perspective. It only makes the guy taken less serious as most researchers care more about how it works than messing with accounts of famous people. Not the smartest move. I understand the sec team draws a line and doesn't pay researchers that mess with other people's data. That's not sleazy, that's sane otherwise it gets exponentially worse as people try to outdo each other in terms of impact instead of focusing on explaining the technique behind a hack.
merijn481··on All calls in the Netherlands are stored, indexed and searched for keywords
The newspaper that published this, 'Telegraaf', is notorious for publishing bullshit. The article is very short, the journalist wouldn't be able to check if it's true, and the newspaper hungry to publish anything that attracts readers. Offline version of link-bait.
merijn481··on Never Give Your Information To 10 Minute Old Startups
Ah, I see you did let them know and the vulnerability was fixed before you posted. Good. I recommend saying such a thing in your post because it helps people like me understand that you are in fact responsible about the disclosure.
merijn481··on Never Give Your Information To 10 Minute Old Startups
Ryan, your post is NOT an example of responsible disclosure. You could have written your post and posted it AFTER alerting the Ice Box Pro guys and waiting until they had the main issues fixed. Your post would still be a good post. In fact, you seem to weigh the importance of your post getting on HackerNews above the security of the people who tried Ice Box Pro. The creators of Ice Box Pro had good intentions and messed up security (as almost any startup does to some extend). You are either ignorant to what security actually means or unethical, which at best is as bad as what the creators of Ice Box Pro did and maybe worse. Will you take responsibility if any of the users that tried Ice Box Pro get hacked as a consequence of your post?
merijn481··on How APIs should be: Drop in keys, running in 1 minute
Re-posted to the Factlink blog at http://blog.factlink.com/