HNHacker News
TopNewBestAskShowJobs

secalex

2,525 karma · joined August 5, 2011

submissionscomments
secalex··on The White Hat's Dilemma
Thanks. Still my favorite game ever.
secalex··on The White Hat's Dilemma
The EFF's CFAA reform letter. They had folks in the room to gather paper signatures from attendees, and remote folks will eventually get a chance to sign electronically.

https://www.eff.org/deeplinks/2013/08/letter?utm_source=twit...

secalex··on Math Advances Raise the Prospect of an Internet Security Crisis
Original slide deck here: http://isecpartners.com/media/105564/ritter_samuel_stamos_bh...
secalex··on Mtgox stops trading for 12 hours
At least tulips had some innate utility.
secalex··on Open Source Events Get Burned By PayPal
Paypal is a long-time client of my consulting firm, and several of their trust and security people are good friends. They are not stupid or malicious. Unlike the author, they are cognizant of a basic truth about the Internet:

In any situation involving money, every loophole or mechanism for scamming people will eventually be discovered and then exploited to an extent you never believed possible. Just as the Internet has massively changed the basic economics of almost every industry, it has greatly reduced the risk and costs of widespread fraud to a level that would make Charles Ponzi cry with joy into his spaghetti.

There are teams of extremely intelligent and motivated people who spend their entire working careers figuring out ways to rip off Paypal (and Amazon, eBay, Google, Baidu, Bitcoin merchants, etc...) If a top tier company that deals with money on the Internet is problematic for a certain transaction, then you can be sure that is due to a real problem in the past that resembles that transaction.

Pydanny believes that Paypal's actions are without basis, so he has clearly identified a market inefficiency that is ripe for "disruption".

I think pydanny should take this opportunity to pitch his payments startup, PyPal, to pg and several other top-tier angels/VCs. Make sure to include a slide on fraud and loss prevention, and clearly outline the policy that will differentiate you from Paypal:

"The developer community is critical for the success of PyPal. In a situation where a PyPal account identified only by a Yahoo email address and with limited transaction history receives hundreds of thousands of dollars in deposits for a service that will not be delivered for months, we will not freeze that account under any circumstances. Especially if they self-identify as a Python developer."

Let me know how the pitch meetings go.

secalex··on How fast could you travel across the U.S. in the 1800s?
Try the Amritsar to New Dehli overnight. For the real experience, try second class, where my friend and I shared a small cubby with a family of five (all flights cancelled for weather, no first class left).

That'll make you appreciate the Shinkansen or ICE networks.

secalex··on U.S. now 'totally unified' in opposition to U.N. Internet governance
You clearly have never been to an ICANN meeting. The best part of that organization is that it is way too dysfunctional and inefficient to lead any kind of conspiracy.
secalex··on Surface with Windows 8 Pro – Pricing
iOS is made out of Unicorn feathers and does not take any of the iPad's advertised space.
secalex··on Surface with Windows 8 Pro – Pricing
To put it another way, you aren't going to see a lot of these at SXSW or at Ritual Coffee, but watch out National Association of Pharmaceutical Representatives!
secalex··on Surface with Windows 8 Pro – Pricing
If that price included a full version of Office I would definitely get it myself.

As priced, it's a no-brainer for the executive set who like to be seen with their iPads but get real work done on 5 pound, AD-joined, IT provisioned Dells. They already have volume licensed Office, and IT teams are going to make this a standard option for road-warriors and execs.

I think the Hacker News set doesn't understand what it's like to work at a non-tech Fortune 500 company. Microsoft's goal isn't to replace the iPad on teenagers' Christmas lists, it's to protect the highly lucrative corporate market from further iPad (and eventually Mac) penetration. On that measure, the Surface Pro is going to crush it.

secalex··on Motor Trend Car of the Year: Tesla Model S
What do you want to know?
secalex··on Motor Trend Car of the Year: Tesla Model S
I've had mine for 3 weeks, and so far I haven't been any more distracted than I was in my last Japanese semi-luxury sedan. The most common actions (media pause, volume, skip and climate control) are on the wheel, and using the map with multitouch is much easier than using a joystick or wheel in an Acura, Lexus or BMW.
secalex··on China Blocks Web Access to The New York Times After Article
Liberty University is in no way a "microcosm of the US". If anything, it is a Christian version of the Islamic Republic, hidden in Virginia.
secalex··on The Tesla Approach to Distributing and Servicing Cars
Yes, the Tesla charging port has a data link that allows Superchargers to speak directly to the battery's firmware. There is almost certainly "Tesla DRM" built into the handshake between the S and the Supercharger, although like all DRM it could probably be reversed engineered and compatible systems created. That's a lot of fun when you are trying to copy a Blu-Ray, less fun when you are dealing with 100kW.
secalex··on Apple Officially Reveals The iPhone 5
That doesn't seem clear from the coverage so far. Obviously it has to be USB in the box, but the name hints that there would be a Thunderbolt option at least.
secalex··on Apple Officially Reveals The iPhone 5
I'm totally stoked about people regularly plugging phones into their PCIe (Thunderbolt) port. Hottest talk at BlackHat USA 2013 will be an iPhone 5 -> MacBook exploit using DMA.
secalex··on Matasano Security acquired for £8.4m ($13m) - Congrats tptacek
I'm one of the founders of iSEC (acquired by NCC in Oct 2010) and I can confirm that we've had a lot more freedom than anybody actually expected. There should be a lot more collaboration between iSEC and Matasano as Tom pointed out, but they don't have to fear the NCC borg assimilating them just yet.
secalex··on My own private Internet: .secure TLD floated as bad-guy-free zone
This is why we are proposing an extension to HSTS that would make the redirect from one TLD to another permanent, which could help all of the new gTLDs.
secalex··on My own private Internet: .secure TLD floated as bad-guy-free zone
The UX should be the equivalent of the current EV UX, but the point is that if your browser supports DPF then you don't need to look. If you got there after typing bank.secure, you should be good. If the screen is red (and hopefully doesn't have an "accept this risk" button) then you didn't.

I should point out this is about more than TLS, and more than the web. We have a short window during which we can create an Internet category that is both clear to the user in it's goals and specific in its requirements for hosts. Our hope is to create an extensible protocol with DPF, one that can be extended to give domain registries and registrants the ability to choose higher privacy protections, limit risk to CA compromise, and secure other protocols like SMTP.

secalex··on My own private Internet: .secure TLD floated as bad-guy-free zone
Howdy, that article is about me, and I do agree that crypto trust systems need to become more decentralized. People seem to be reacting to the story without looking into the technical details, so I'll try to avoid http://xkcd.com/386/, but I will say that one of our goals with Domain Policy Framework (which we will release a draft of tomorrow) is to create the policy and identity that, combined with DNSSEC and DANE, allow for more granular (but not completely decentralized) trust relationships.

I think we agree about UX. One of the big picture goals of .secure is to invert the current security experience. These days you go to a site and then have to interpret the UI to see if you are safe. In our vision, when you type bank.secure you are telling your browser, OS and the server on the other side that you want to navigate there as safely as possible.

I'm going to post about the tech details more tomorrow and hopefully that clears some things up.

← PreviousPage 3 of 3