HNHacker News
TopNewBestAskShowJobs

somethingnew

638 karma · joined March 20, 2012

https://twitter.com/itspeterc

[ my public key: https://keybase.io/petercollins; my proof: https://keybase.io/petercollins/sigs/yeZIba2qpUOE6XzgjubdowDhvETHlA7rcczXFu-u9c8 ]

submissionscomments
somethingnew··on Ask HN: Who is hiring? (October 2026)
Discord | Senior Software Engineer, Application Security | REMOTE (US West Coast) or San Francisco, CA | $196K-$245K base + equity

Discord is where communities and friend groups spend time together, on desktop, mobile, and now more and more inside games and third-party apps built on our platform. That surface area, plus a huge, engaged, occasionally adversarial user base, makes application security a genuinely hard and interesting problem here.

We are hiring a Senior Software Engineer to join the Application Security team. This is hands-on product engineering: building security features that protect user accounts, strengthening authentication and session security, and improving security-critical services. You will work directly with product teams to ship user-facing account security tools and address emerging threats.

Stack: Python primarily, some TypeScript/React, some Rust, occasional JavaScript. Runs on GCP.

Looking for: hands-on AppSec experience (not just compliance-flavored security), comfort reading and writing code across languages, experience shipping production software, and sound judgment on prioritizing real risk over checklist security. Experience with authentication, passkeys, MFA, or session management is especially relevant.

Location: Remote from the US West Coast. If you are in the Bay Area, our SF office is an option. Relocation to the Bay Area is not required.

Interview process: recruiter call, coding round, HM interview, virtual onsite, decision.

Apply: https://discord.com/jobs/8656854002

somethingnew··on Ask HN: Who is hiring? (September 2026)
Discord | Senior Software Engineer, Application Security | San Francisco, CA | ONSITE | $280K–$330K TC

Discord is where communities and friend groups spend time together, on desktop, mobile, and now more and more inside games and third-party apps built on our platform. That surface area, plus a huge, engaged, occasionally adversarial user base, makes application security a genuinely hard and interesting problem here.

We're hiring a Senior Application Security Engineer to join the Product Security team. Responsibilities include threat modeling and secure design review with product and platform teams, building and improving AppSec tooling (SAST/DAST/dependency scanning), and working directly with engineering teams to remediate findings.

Stack: Python primarily, some TypeScript/React, some Rust, occasional JavaScript. Runs on GCP.

Looking for: hands-on AppSec experience (not just compliance-flavored security), comfort reading and reviewing code across languages, and sound judgment on prioritizing real risk over checklist security.

Interview process: recruiter call, coding round, HM interview, virtual onsite, decision.

Apply: https://job-boards.greenhouse.io/discord/jobs/8656854002

somethingnew··on Understanding and Hardening Linux Containers [pdf]
Here's a summary from the Docker perspective https://blog.docker.com/2016/04/docker-security/
somethingnew··on Show HN: Hacker News Tab
Source: https://github.com/somethingnew2-0/hacker-news-tab
somethingnew··on Re: Proposed Statement on "HTTPS everywhere for the IETF"
Besides Session IDs and Session Tickets[1] which already exist in the TLS protocol. He could be referring to the Token Binding Protocol Draft[2] which, quoting from it's summary, "allows client/server applications to create long-lived, uniquely identifiable TLS bindings spanning multiple TLS sessions and connections".

[1] https://en.wikipedia.org/wiki/Transport_Layer_Security#Resum...

[2] https://tools.ietf.org/html/draft-ietf-tokbind-protocol-01

somethingnew··on GRPC: A high performance, open source, general RPC framework
Not having to worry about calculating the length of the message before transferring it?
somethingnew··on [dead]
How does it work? Brute force? Rainbow tables?
somethingnew··on Online Storage Provider Box Prices I.P.O. at $14 a Share
My university uses them for file storage and sharing, so I imagine they have many large enterprise clients.
somethingnew··on Consul.io – Service discovery and configuration made easy
Has this never been posted before?
somethingnew··on Americans’ Cellphones Targeted in Secret U.S. Spy Program
https://www.kickstarter.com/projects/1760935672/android-ciph...
somethingnew··on Lawrence Lessig Interviews Edward Snowden [video]
Running Google Hangouts through Tor would work well as it uses https by default. As long as he's using a throwaway Google account, it seems good to me.
somethingnew··on Show HN: Crypt – Secure Configuration Storage in Etcd or Consul
Exactly, the wikipedia articles for BREACH and CRIME are good starting points if nothing else.

[1] http://en.wikipedia.org/wiki/BREACH_(security_exploit)

[2] http://en.wikipedia.org/wiki/CRIME

somethingnew··on Bad news about Shellshock
Yes Ubuntu is still vulnerable to 7169, but it looks as if the release has been pushed. http://people.canonical.com/~ubuntu-security/cve/2014/CVE-20...
somethingnew··on PayTango
Reminds me of Square Invoices https://squareup.com/invoices
somethingnew··on How a Raccoon Became an Aardvark
http://xkcd.com/978/
somethingnew··on TeamPostgreSQL 1.07 – PostgreSQL web interface
How does this compare to PostgreSQLStudio[1]?

[1]http://www.postgresqlstudio.org/

somethingnew··on TLS/SSL implementation in Haskell
According to Adam Langley, a Go contributor, it can still be side-channeled. https://twitter.com/agl__/status/453370970552532992
somethingnew··on Cunningham's Law
Yes, I believe that is the answer.
somethingnew··on 64 Terabyte RAM computer from SGI
That's my question too... There's a reason there's such a thing as a cache hierarchy.
somethingnew··on 64 Terabyte RAM computer from SGI
If you want to see something awesome HP has done "recently" check out this talk on memristors. Other than that I don't know... https://www.youtube.com/watch?v=bKGhvKyjgLY
somethingnew··on MtGox LTC ticker still online
Here's a more interesting chart http://bitcoin.clarkmoody.com/
somethingnew··on Operating Systems: Three Easy Pieces
UW Madison represent! I took the course with this book, not with Remzi though. He is an amazing professor and this book gives a very good introduction to OS, especially Linux OS internals.
somethingnew··on Announcing The Matasano/Square CTF
Me too! I must be missing something...
somethingnew··on 1000x Faster Spelling Correction: Source Code released
This is really cool! It reminds me of BiDirectional BFS for path finding. In this case searching from both directions cuts down the search space by three orders of magnitude. Genius.
somethingnew··on Gate Tower Building
Was this posted in reaction to the Hyperloop post? https://news.ycombinator.com/item?id=6999556
somethingnew··on Secret contract tied NSA and security industry pioneer
Reminds me of http://xkcd.com/538/ except instead of a $5 wrench, it was $10 Million and a few handshakes.
somethingnew··on The Saddest Moment: Byzantine fault tolerance [pdf]
You posted a duplicate, what's the other link?
somethingnew··on Linear algebra tutorial in four pages
Wow, I just read that entire paper. Thank you for linking, it was super helpful!
somethingnew··on Linear algebra tutorial in four pages
That literally made more sense than anything I've learned this semester. :)
somethingnew··on Walmart Node.js Memory Leak
The opposite of wrinkly.
Page 1 of 2Next →