HNHacker News
TopNewBestAskShowJobs

sp_

514 karma · joined January 12, 2011

http://twitter.com/LambdaCube Android Security Team
submissionscomments
sp_··on Exploring the Durability of IP Connections from Android Devices
It's definitely the case for me too. I am using a T-Mobile MyTouch 4G.

There is something rotten with the cell phone networks in the USA because when I lived in Germany the situation was much better. Good to see my gut feeling being backed up by data. However, I thought the difference would be more than roughly 30%. Maybe the difference between T-Mobile USA and T-Mobile Germany is just bigger than the national averages of the two countries.

sp_··on Darpa: US Geek Shortage Is National Security Risk
German, Romanian, Vietnamese-American (1st generation immigrant), Chinese-American (1st generation immigrant), Spanish, Iranian, French, Australian, South African, Indian, British, Russian. What's that? The nationalities of the people who sit in my hallway in the computer security department of one of the biggest software companies in the United States. OK, admittedly there also four or five true red-blooded Americans in the hallway but they are definitely a small minority.

We are absolutely feeling the lack of US geeks. They are rare enough in software development but even rarer in computer security. We have several open positions but it's mostly non-Americans who apply. We are basically excited about every application from a US citizen we get. This makes hiring much easier and we do not have to wait until October 1st when the new H-1B visa period kicks in.

Now, I have speculated that maybe the company I work for is just unpopular with US citizens but then I recently interviewed with a Bay Area company with a much sexier public image and it's even worse there. I talked to members of a team of 12 people. 11 of them were not Americans.

In fact, we spent the lunch interview speculating about the causes of this situation. In the end we considered it most likely that the title of engineer is simply not sexy in the United States. In other parts of the world like some countries in Europe and especially Asia the job title of engineer carries a good amount of social respect and commands a respectable salary. That is not the case in the United States (well, the salary is actually good, but not the reputation) where the reputation ladder is topped by jobs like doctor or lawyer. It is not surprising that the smartest students would rather get into those jobs.

Anyway, in the light of all this I keep being amused that the US three-letter agencies are advertising their computer security positions so aggressively. With the current US talent I am seeing in the wild there is no way they will be able to fill these positions in any way that can compete with, say, the Chinese hacker legions. Rather, I foresee national interest waiver greencards for people like those in my hallway.

sp_··on The Hidden Cost of Letting Workers Telecommute
First, you are confusing visas. The tourist visa is not the same as the visa waiver. There is a tourist visa, it's called B-2 and it does not allow you to do any business or work. Visiting with the visa waiver program means visiting without a visa.

Next, for short trips, visiting without a visa is equivalent to having a business visa (B-1). It allows you to meet with US clients, customers, partners, and so on and it allows you to go to conferences. It does not allow you to work.

See as a recent example from Hacker News: http://www.noop.nl/2011/06/american-learning-experience.html

sp_··on The Hidden Cost of Letting Workers Telecommute
As far as I know there is no visa that allows foreigners to travel to the US and work remotely back home. It would be a breach of the Visa Waiver program (or any other visa) which can lead to deportation.

I'd like to hear from people who did this, told the immigrations officer about their plans and were not turned back on the border.

sp_··on Differences between German and British manners
Hm, this uncanny valley idea is actually really interesting. Thank you very much for bringing it up. I'll think about this for a while.
sp_··on Differences between German and British manners
Being German, I find it fascinating that so many people on both sides of the Channel are so fascinated with the differences between the Brits and the Germans. Coming from a German perspective, I don't think there is any other country whose manners the German media is so obsessed with. Similar feelings seem to exist in Britain with big Sun front pages about German misbehavings once in a while covering all aspects of life (see "two world wars, one world cup" for example).

I also like how they used the lack of a German word for smalltalk in the article. Whenever I explain differences between German behavior and Anglo-American behavior to Americans/Brits I tell them the German language has no words for smalltalk, jaywalking, and date rape to set the tone for my explanation. :)

sp_··on Hack us, and we'll bomb you
I was kinda surprised when I heard about this. I always assumed this would have been US policy already. Russia, for example, has already stated in 1996 that it will consider nuclear retaliation for cyber attacks on their country.

Source: http://www.airpower.au.af.mil/airchronicles/apj/apj96/spec96...

sp_··on How to Beat High Airfares
Just tried it myself with SEA to MSP (hopping off on a SEA->MSP->DFW route) on July 15th. Direct flight is $230, hop-off route is $150 on exactly the same Delta plane.

Now the thing is, if I book SEA->MSP->DFW for Friday and MSP->SEA for Sunday I don't see how Delta could not notice this and block me from flying because of abusing this system.

Actually, I have done something like this before. When I moved from Europe to the US I booked a return ticket because it was 500 Euro cheaper than going one way, knowing fully well that I would never be on that return flight.

sp_··on Google plays ball with carriers to kill tethering apps
Tethering on T-Mobile is free. I don't have cable/DSL at home. Rather, I tether through my T-Mobile cell phone exclusively. Word on the street (T-Mobile forums) is that there is a 5 GB soft cap on data. Once you hit it, you are dropped to Edge speeds.

Last month I went over 5 GB for the first time (5.5 GB) but speeds were not dropped.

sp_··on Protip for salary seekers pt 2: Results from some mining of the H1-B database
The website in the OP is mine, so far all people who are interested in the uncropped lists, you can get it at http://www.the-interweb.com/bdump/misc/salaries.xlsx

The first sheet inside the Excel file is probably the most interesting one, showing software/computer/engineer salaries for nearly 3500 jobs.

sp_··on Protip for salary seekers pt 2: Results from some mining of the H1-B database
I created the lists in the OP and to determine whether an average salary value is legit I looked at the individual entries. For those I declared invalid there was something like four entries making $55000 and one entry making $550000, the latter one being an obvious typo in the database.
sp_··on Visualization of Home Price Reductions
The arithmetic average for home prices is not too useful either. I clicked on a random county in Wyoming that had an average of more than $600K. Turns out that it's like 20 cheap houses (most going for $150K to $200K) and one huge farm for $29.5 million.
sp_··on Protip for salary seekers: H1-B filings are public
This only applies if deportation is a threat to you. I am a H-1B employee and I have absolutely no problems going back to my home country in an instant.

I don't know if that is the reason but my salary is definitely not discounted compared to my American co-workers.

sp_··on Why T-shirts matter at tech companies
I wear collared shirts 365 days a year and as soon as it's warmer again I will trade my peacoat for a casual sports coat again. I went to work like this in startups and huge corporations even if it meant I was the only one not wearing a t-shirt at the office.

The good thing about being a hacker is that you can wear whatever you want. :)

sp_··on The audacity of charging from day one.
Good typo catch, yeah. :)

The product was BinNavi (http://www.zynamics.com/binnavi.html) which sold for (I believe) roughly 3000 Euro per license despite being really terrible for the first two years of its existence.

The only competition was IDA Pro (http://www.hex-rays.com/idapro/), the standard tool for binary code security researchers, but BinNavi aspired to be much more than IDA Pro and our customer was aware of our vision and bought many licenses to support us.

sp_··on The audacity of charging from day one.
I used to work at zynamics (http://www.crunchbase.com/company/zynamics) for a long time and while I was not part of the initial team, I still have a good idea of what went on in the early stages.

The company charged hundreds and thousands of dollars for software licenses from day 1 even though the first versions of the products were pretty bad. In fact, we even had customers who bought these early versions not because they wanted us to succeed. I remember at least one customer who bought licenses for many tens of thousands of Euro telling us 'we won't use your software yet because it is not good enough but we believe that you will deliver great software one day and by buying early version we will keep you alive'.

So yeah, charging right from the start worked out tremendously for us. Without it we would not have survived.

sp_··on Hiring Developers: You're Doing It Wrong
I worked for a German startup too and our main problem was not vetting interviewees but finding people who want to interview at all. In the five year history of the company I think only one single person was hired who was not already friends with someone at the company.

Other people just never applied. I remember manning the booth at one of those college campus events and it was very lonely. I probably talked to three students that day. Nobody followed up with us. I even had the distinct feeling that students avoided eye-contact with us and made beelines for the booths of the big established companies.

In the end, our hiring interview process for interns was 'do you want to work for us? yes? you're in' and for full-time applicants it was simply non-existent. I think in the last three years we did not interview a single person.

I often wondered why that is but I have never found a good answer. In the end it worked out for us. The company was acquired by Google.

Still, I would have liked to have some applicants and interviews once in a while because I keep reading so much about them and I wanted to practice being an interviewer to avoid pitfalls as described in the article.

sp_··on RSA hit by targeted attacks, SecurID 2-factor auth possibly compromised
I think a good start would be to read http://www.amazon.com/Art-Software-Security-Assessment-Vulne...
sp_··on RSA hit by targeted attacks, SecurID 2-factor auth possibly compromised
Operation Aurora was an Internet Explorer vulnerability, not an Adobe vulnerability.
sp_··on RSA hit by targeted attacks, SecurID 2-factor auth possibly compromised
Find vulnerability, develop exploit, sell to http://www.zerodayinitiative.com/ or http://labs.idefense.com/vcp/ if you are a "White Hat" or the Russian mafia if you want to make more money and don't care what your exploit is used for.

Once upon a time http://www.wslabi.com/ tried to create some kind of eBay for vulnerabilities too but it did not seem to go well.

sp_··on Why 'Secret Questions' Suck as a Security Measure
I fully agree with the article and I am also one of the people that give bogus (but consistent) answers to these questions. So for example for 'what is your first pet' I fill in something like 'the last unicorn' or another phrase that has never left my brain.

The article also reminds me of another anecdote.Many years ago in the last millennium I checked out this German teenage forum (bravo.de) because well, I was a German teenager. Anyway, on that forum you could not only give the answer to the security question. They even allowed you to specify the question you want.

That feature amused me a lot and I checked out other people's self-made security questions. Being a teenager forum in the later 90s this is what happened. A very substantial number of forum users had the security question 'what is my favorite Backstreet boy' or a variation thereof. And, well, pretty much everybody loved Nick Carter. Nobody liked the others. In just one our I was able to log on to many, many accounts just with the phrase 'Nick'.

sp_··on Google acquires Zynamics
Congrats to my former company! I was lead devevloper of three of our products (BinNavi, BinCrowd, PDF Dissector) until 5 months ago when I was tired of the stuff we worked on and bailed out.

Curiously, we always saw HBGary as one of our main competitors. However, we were focused on tech, not shady deals. :)

sp_··on Google acquires Zynamics
I am very sure this does not happen because the products (especially BinNavi) are entangled in commercial licenses for 3rd party components.
sp_··on Zynamics acquired by Google
My former boss (I left the company in October 2010) just announced that zynamics was acquired by Google. zynamics is a boostrapped German startup that never took any VC capital. We specialized in building reverse engineering tools that help security researchers find vulnerabilities in software.

Curiously, we always saw HBGary as one of our main competitors. However, we were focused on tech, not shady deals. :)

sp_··on Natalie Portman - Scientist
Or how about this fellow who has an undergraduate degree in Chemistry, a PhD in law, and was an Olympic swimmer but is best known for his movies where he gets into fights with other guys (pretty much everybody in my age bracket in Germany and some other European countries knows him).

http://en.wikipedia.org/wiki/Bud_Spencer

Edit: He is also a jet pilot, helicopter pilot, holder of multiple patents, and a startup founder with a successful exit as Wikipedia shows! :)

sp_··on HBGary Federal CEO Aaron Barr Steps Down
The name comes from the three co-founders. The H is for Hoglund (Greg). The B is for Bracken (Shawn). The Gary is for Jon Gary who left the company shortly after it was founded.
sp_··on Why does Adobe Reader need so many updates?
Without wanting to go into more details, I work a job that makes me see and analyze more Adobe vulnerabilities than anybody else outside of Adobe.

Having said that, I run both Flash and Adobe Reader (and Foxit for dubious stuff) on my normal machine. The number of 0-days exploited in the wild is not actually that big (I'd like to see stats here but I am not aware of any) and the odds of being hit by an 0-day exploit is really low. When people get owned through Adobe exploits, it is because they are not updating regularly.

sp_··on Kayak Explore - see where you can go for how much
My use case is "When is it the cheapest to get me out of here?". I can take vacation days at pretty much every date so I do not really care when I go on vacation. The destination does no really matter to me either.

Unfortunately, I found Kayak Explorer does not work for this as it does not allow me to see flights at a day for day granularity. http://www.adioso.com does a much better job. I can just search for stuff like "SEA to anywhere" and it will show me what I want.

sp_··on Redditors earning $100k+ a year, what are your secrets to your success?
I just want to quickly point out that making $100K puts you into the top 6% with $150K putting you into the top 2%. The 15% figure is for household income, not personal income.

The income distribution tables from the last US census can be found at http://www.census.gov/hhes/www/cpstables/032010/perinc/new11...

sp_··on Kevin McDonagh on: How to attend a conference
The advice is really good for someone who wants to sell stuff. I kind of do comparable things without wanting to sell anything. I just like to hear what people are working on and what there plans are so I can stay in the loop of new developments. My goal for a conference is 20 business cards, not 200 to 400.

The talking to new people thing is pretty important. I am terrible at this. When I attended my first conference in 2008 a continent away I stood there in a room of 400 people literally not knowing anybody. That moment it dawned me that my boss just paid thousands of dollars to get me here so I better use this opportunity. Three years later, one of the first five people I talked to at that conference got me an H1-B visa and a six figures job.

There are related mistakes to make. I've been to so many conferences by now that I know a lot of people I want to hang out with at any given conference. It's easy to just keep talking to these people because that means I do not have to leave my comfort zone again. This is obviously bad because I will not meet new people that way. The same happens when you go to a conference with other people of your company and just stick together the whole time. Do not do this.

About this demoing thing. I used to demo our software a lot at conferences. However, our software was so popular in our niche market that people always asked me to see it. I don't think I ever pushed it on anybody. Demoing works perfectly fine if you just leave the main room and sit somewhere around the corner. Most of the conferences I attend are in hotels, so they have plenty of chairs everywhere.

What is not mentioned in the article is that you should try to be a speaker at conferences. It is not very hard to become a speaker and it puts you into the spotlight. This makes it much easier to make new contacts. Additionally, many conferences pay travel and hotel costs of their speakers which is awesome.

← PreviousPage 2 of 3Next →