HNHacker News
TopNewBestAskShowJobs

netik

422 karma · joined November 20, 2009

Once upon a time I helped build Twitter. Now I play music and advise startups.

[ my public key: https://keybase.io/netik; my proof: https://keybase.io/netik/sigs/gp4EeY8UT0l1f9kkZOyT4-IZLq_clsEVeST2k0J4Qtc ]

submissionscomments
netik··on [dead]
This is a interesting article but a veiled embedded advertisement for retool.
netik··on Ask HN: What feature would you want the web to “force” next, after HTTPS?
Key management would be a nightmare here. IPSec has very long setup times, and every destination would need a new crypto configuration. This is exactly the problem that TLS was designed to solve, and IPSec and the web are a bad mix.
netik··on What I Wish I'd Known About Equity Before Joining a Unicorn
The problem is that RSUs are still a joke and can be taken from you easily. ISOs have way, way more power.

https://www.retina.net/tech/rsus-vs-options.html

netik··on Show HN: Founderkit – Startup tool recommendations from 1,000 YC founders
Is there any reason why there isn't a single security utility, aside from password managers on this list?

It seems that security is an afterthought at most startups.

netik··on Theranos reportedly laying off 41% of its workforce
I've worked at a couple startups where the company was more-than-done out of business and we spent our last 6-12 months negotiating with creditors and trying to get rid of hardware, software, and various worthless IP.

But that takes a tiny skeleton crew, so maybe there's that.

Or, perhaps you're right and they're going to see if they can wait out the 2 year ban. Most likely they will change the name of the company to hide the bad reputation and then re-release the hardware testing platforms.

netik··on Theranos reportedly laying off 41% of its workforce
I guess my main question here, is if they have been banned by the FDA from doing any testing at all for two years, what exactly is remaining of the business, and why haven't they been completely shuttered?

Bloomberg seems to indicate there isn't much left for any employee to do.

https://www.bloomberg.com/news/articles/2016-07-08/theranos-...

netik··on Vuvuzela: private messaging system that protects metadata
Well, that's exactly the problem with systems like this.

If you transmit something that looks like noise, and no one else sends something that looks like that particular kind of noise, then you are raising a flag that says "No, really, please, capture this data, it's interesting."

netik··on Twitter beats estimates, cuts jobs with eye on 2017 profitability
Because the block button doesn't actually block. It poorly hides the user's content from your view while other users can still see the abuse.
netik··on Twitter Plans Hundreds More Job Cuts as Soon as This Week
The sad thing is that the market will love this and the stock will go up, while many engineers wonder where their job went, and mid-managers/execs will reap a profit.
netik··on Twitter Plans Hundreds More Job Cuts as Soon as This Week
You forget that Twitter purchased an SMS aggregator a few years back. SMS sending is near free for Twitter. I still remember integrating all of the VPNs to the carriers to support this mess.
netik··on Twitter shares drop as Salesforce reported to be out of the bidding process
Well, they bought Yammer which at the time was a direct Twitter clone (but made for small businesses.)

You know what would make for a better acquisition? Amazon.

Twitter has tons of customers, tons of dark fiber, lots of internal cloud technologies (mesos, etc.) and a huge international peering network of IP routers.

Amazon needs a way into social and real time news.

netik··on Twitter shares drop as Salesforce reported to be out of the bidding process
Yes, there was a stock sales window when I worked there and I assume there still is now.

Most publicly traded companies have lockout periods if you have access to "insider information." Given that Twitter is (was) fairly transparent about company financials, this is probably still true.

netik··on Bitwarden – Free and Open Source Password Manager
Well, that's a damn fine point. I guess I'll submit a pull request.
netik··on Bitwarden – Free and Open Source Password Manager
Yes, that's in the Snowden docs:

https://www.washingtonpost.com/news/the-switch/wp/2013/12/10...

http://www.digitaltrends.com/web/nsa-google-cookies/

netik··on US startup Geofeedia 'allowed police to track protesters'
Defaults are strong and powerful, though. This is the main issue which companies like this have taken advantage of.

Many users don't know that something is on by default, and if the default is to geotag, people will nearly always forget to disable the geotagging.

You or I might know what it means when the 'place' icon is highlighted during a tweet. Non technical users might not understand the implication of thier actions.

netik··on Bitwarden – Free and Open Source Password Manager
If you do that, it should be one of the first questions asked when the plugin first starts up and be absolutely transparent about what data is collected.

It's less about 'making a fuss' and more about 'providing additional data to adversaries.' Remember, the NSA piggybacked on Google Analytics tokens for years to track users.

netik··on Bitwarden – Free and Open Source Password Manager
Sure, but that doesn't help everyone, that only helps me.
netik··on Bitwarden – Free and Open Source Password Manager
It would be really wonderful if the password manager didn't contain surveillance software, monitoring every time the plugin has been opened via Google Analytics. Can you remove that?

https://github.com/bitwarden/browser/tree/master/src/scripts

netik··on An Important Message About Yahoo User Security
Harvard Business review has a pretty good paper on this.

https://hbr.org/2015/03/why-data-breaches-dont-hurt-stock-pr...

netik··on Twitter: It is too late for it to become the giant people expected
(ex-employee #13 over here.)

They could start by incorporating every single feature that BlockTogether has as abuse mitigation.

Encrypted end-to-end DMs (which were blocked numerous times by useless product managers) would have been another excellent feature to protect users.

netik··on Startups, let’s act: Make Nov 8 a Holiday
I guess this will happen right around the time that startups actually give people 'unlimited vacation time', which generally means 'don't take it or you'll be fired/left out.'
netik··on [dead]
This is a poorly justified solution to a real security problem, which is the elimination of password logins. The author assumes that the weak point in logins is the password hash, and rarely if ever is this an attack vector in modern Linux.

Disabling password logins, moving to SSH public key based login and hardware tokens (such as the SSH private key stored in Yubikey) is a much better solution than the one proposed here.

netik··on Ask HN: Anonymous person sent proof of SSH access to our production server
A user can always start their own SSH server. Just because you've decided to move it to a different port doesn't really encourage them. I suppose you could make this a bit more difficult for them by removing compilers (no really, you don't need compilers everywhere) and making sshd owned by root, mode 700...

However, proper ingress filtering or local iptables/pf rules would stop any unwanted inbound traffic from reaching your server, and you should definitely be using ingress and egress filtering on your network.

netik··on Sharkey: a service for managing certificates for use by OpenSSH
It seems like you are reinventing the wheel here.

Did you look at RFC4255?

https://tools.ietf.org/html/rfc4255

netik··on Ask HN: Does anyone here use OS X as a webserver?
Oh, back then it was a wall full of XServes. These days, if they run Macs, they're probably racking Mac Pros.
netik··on Jacob Appelbaum Leaves the Tor Project
As far as I know he never went to college, so he's going to have to pursue his BaCS and MaCS first.
netik··on Ask HN: Does anyone here use OS X as a webserver?
You're correct in that Apple doesn't manufacture server hardware like the Xserve anymore, but OS X, Server edition is still available and it will manage Apache for you (albeit in a terrible way, I don't like the excessive configuration they apply)

Many of Apple's own web sites run Apple hardware for outward facing, large scale serving (I used to work there).

At the end of the day, Unix is Unix.

I run nginx on OS X on a number of Mac Minis without issue and long uptimes.

netik··on Notifying Our Users of Attacks by Suspected State-Sponsored Actors
CISA is a terrible bill and not a solution to this problem. Security teams have been able to manage this data on their own for years without government intervention.

There have always been other methods for determining if an attacker is state sponsored. One example: Seeing your account, and a number of dissident or activists being attacked from a block of IPs or similar password attempts, probably means the attack is state sponsored.

That being said, in security, attribution is a very hard problem, and the methods used to determine state sponsored attacks are also quite hard to design.

There's a reason why companies won't elaborate on how they do this, but it is usually a combination of login/account intelligence and threat feeds.

netik··on Kazakhstan to MitM all HTTPS traffic starting Jan 1
If you don't trust them, turn them off. That's what I do, at least. I've disabled the vast majority of those roots in Keychain Assistant.
netik··on Kazakhstan to MitM all HTTPS traffic starting Jan 1
Western companies sell them hardware and software to process the traffic that they Capture. Cisco, et.al is complicit in this work, including the firewall itself.
← PreviousPage 4 of 5Next →