HNHacker News
TopNewBestAskShowJobs

sprkyco

175 karma · joined August 21, 2014

[ my public key: https://keybase.io/sprkyco; my proof: https://keybase.io/sprkyco/sigs/zwa9gSfRYI4A3rEijOT-W-1RDs0CFh4-DP2vPV0ctAE ]
submissionscomments
sprkyco··on Ask HN: How do you continuously monitor web logs for hack attempts?
I work for: https://www.signalsciences.com/ and our tool is specifically designed for use cases like this. Let me know if you would like more info cody-at-signalsciences-dot-com
sprkyco··on Slack is down
http://moose-team.github.io/friends/
sprkyco··on Slack is down
Someone replied to our internal outage notification and replied to everyone@ with a gif. The chaos has begun.
sprkyco··on Reading privileged memory with a side-channel
https://cyber.wtf/2017/07/28/negative-result-reading-kernel-...

Failed attempt in July which is being attributed as earliest work via https://twitter.com/lavados/status/948700783259811847

sprkyco··on Ask HN: What you have automated with Python?
Common practice, but still illegal. Recommend watching https://en.wikipedia.org/wiki/The_Internet%27s_Own_Boy if you haven't. Similar use case here.
sprkyco··on Want a Job in Silicon Valley? Keep Away from Coding Schools
For anyone that thinks that programming bootcamps are still worth considering. Why not try a free one: https://www.freecodecamp.com/ Really great student curated content!
sprkyco··on The piracy paradox at Udemy (2015)
New TOS prompted a deletion of my account: https://twitter.com/sprkyco/status/770242306678988800
sprkyco··on ThinkPwn: System Management Mode arbitrary code execution
Typically physical control is deemed as the game ender. If this is proven to be OS executable it will be a major issue. Many of the Adobe, IE, and other high volume exploit vendors codebase zero-day root exploits would allow one to not only gain access at a root level on a machine, but now also at a much lower level. This level would negate the typical benefits of recovering from a root-level "hack" via HDD erasing or Malware Removal tools or any other method available to even tech-savvy people.
sprkyco··on Riot uses League of Legends chatlogs to weed out toxic employees
https://zedshaw.com/2016/06/10/riot-games-is-violating-calif...
sprkyco··on Instagram's Million Dollar Bug
Or... one could actually read the response article: "This bug has been fixed, the affected keys have been rotated, and we have no evidence that Wes or anybody else accessed any user data. "
sprkyco··on Canary in the Code Mine: Coal miners learning to code
Really mining is seen as this hardcore active lifestyle when in reality it is rather sedentary. Typically there are jobs for jr. level positions which are very physically demanding. Afer about 2 years experience most people get "promoted" to driving some sort of heavy machinery. Often these positions are union jobs where the workers can easily dictate the pace at which they work. Typically I could spend 8 hours or more in some sort of seat forklift/haul truck/loader or whatever. This may not be the case in Coal Mines in Kentucky, but as you can tell from the pictures many of the workers in mining are not in peak physical condition.

Even in the positions that were physically demanding your body "adjusts" to the workload and it becomes rather similar to sitting in front of a computer basically you go into periods of "auto-pilot" and then other times it was somewhat mentally demanding.

Most mining operations are heavily automated requiring at least some knowledge of I.ndustrial C.ontrol S.systems ICS/SCADA is somewhat of a programming work flow. If this valve is open turn on this other valve once this sensor is tripped turn off this motor and close this valve. From a very simplistic manner this is similar to binary logic.

At least from what I have experienced infosec is very mentally challenging, but it is not a constant demand there are definitely periods where I am in auto-pilot. The best solution for me having gone to a sedentary work life is to walk to work, drink lots of water at work (make you get up to pee alot) and to take walks at lunch.

sprkyco··on Canary in the Code Mine: Coal miners learning to code
Absolutely anecdotal. This article nor myself never stated that "the entire out-of-work blue collar worker population" can or even would want to make the jump. Many of these blue collar workers can move into other industries it just so happens that programming is becoming more of a trade skill than an engineering one. There is currently a demand for highly skilled CS engineers. However, the jobs that do not require CS skill sets per se, but rather require "coding" skills are becoming more abundant.

Really my "coding" skills have helped me in other areas opening my eyes in new ways to automating my skill set. One of the best testaments to this was talked about by Zed Shaw http://learncodethehardway.org/blog/MAY_15_2012.html Basically stating that programming is a supplement to other skill sets. The majority of these programming bootcamps/workshops are geared towards onramping rapidly to jobs that would not typically qualify as engineering positions. These jobs typically require whiteboard interviews, but once you actually get on the job your programming skill set is not nearly as utilized as it was during the interview. While I cannot quantify this supposition it would be really difficult to get a company to admit or supply data stating that they interview for rock stars, but have you do "janitorial" code work in reality.

Where the Bloomberg article most failed is stating that they "cannot" learn to code. Pretending that becoming a developer/engineer/coder requires some minimal level of IQ, even the IQ standard is hotly debated, is ridiculous. Just as any other skill set it just requires dedication and commitment.

sprkyco··on Canary in the Code Mine: Coal miners learning to code
After eight years in mining I made the jump to coding. However, my coding quickly changed to infosec. So definitely miners can make this jump. This is highly biased, but I would say that many blue collar workers bring a very different work ethic as compared to other workers in the software industry. Miners especially have a comradery that I have not heard of in other industries. In addition to this 80+ hour work weeks were definitely the norm in many mining industries. This type of work ethic has somewhat set me apart from many of my peers.
sprkyco··on Latest Android phones hijacked with one-shot Chrome exploit
Can you cite "all Android devices affected"? Cannot find this particular quote in this or any other article. Also what bug report? I found this article and other articles cited, but no bug report from Google or the researcher as of yet.

The article does state "The vuln being in recent version of Chrome should work on all Android phones;" which is factually correct.

This is a "Chrome" bug in so much as the Chrome browser uses the V8 Javascript engine. However, this particular bug could have other consequences as it is stated in this article and others that the bug in fact occurs in the V8 Javascript Engine which is used in Nodejs, Mongo and others.

So, no, none of your comments sound reasonable.

sprkyco··on Latest Android phones hijacked with one-shot Chrome exploit
What is the logic to responding to security disclosures like this? In the reddit world this is called shit posting. Security bug A affects product B (or c-f) someone always responds at least I use g or h on z! Thus, I am immune from this particular security issue! Genuinely interested in why anyone bothers posting this non-sense.
sprkyco··on The best cities to get ahead are often the most expensive places to live (2014)
Can you suggest a better term that would enable a speaker to convey a generally identifiable demographic?
sprkyco··on A vulnerability in WebLogic, WebSphere, JBoss, Jenkins, OpenNMS and others
One thing I really liked about the write-up is the thoroughness that everything was explained. Nothing was assumed. The author explains what burp is why it was used. Broke down the basics in a high level and the touched on the simple things. Showed exploits in multiple frameworks. Really a well done article just from a write-up perspective let alone the impact of the issue.
sprkyco··on Elsevier, that just freaked me out
Most likely due to the fact that a publishing company was utilizing this "hack".
sprkyco··on Free Tutorials to Learn Python: PDFs, eBooks, Online
This seems like trolling, but this line of thought seems very extreme. Not sure where the perceived obsession comes from. People communicate in different ways and assuming that there should be a single refined dump of information is not taking into the account the fact that the people reading the documentation come from completely different backgrounds and technical levels of understanding.

"Submit a pull request before.." The unofficial documentation and related tutorials are exactly that, unofficial, they are not meant a replacements by any stretch of the imagination for the official documentation. Rather, these forks exist to speak to many different audiences and in some cases, speaking from personal experience, attempting to document and teach others is a very useful tool for personal edification regardless if it is a distraction from the "blessed" documentation.

sprkyco··on In China, Women Hired to Motivate Computer Programmers
Would agree with above, but given the evidence of chauvinism in the workplace I would say regardless of the facts this will be seen as sexism. Personally, I think it would be cool to have either a male or a female that was genuinely interested in some of my programming projects.

Motivational employees would help to significantly ease some of the social anxiety of programmers such as my self. Male or female the interaction of genuine interest is at the core of what seems to be lacking here. Typically any "collaborative" or "interest" showed by coworkers or superiors falls into two buckets.

- coworker: "oh that's cool reminds me of the time that I did x" with subtle connotations of why x is better than what you are doing.

- superior: "hmm really interesting, make sure you get this other stuff done before next week" with less subtle connotations of I have no idea what or why you are doing nor do I care as long as you get all your work done.

sprkyco··on Mr. Robot Episode Titles Are Brilliant
Out of curiosity what would be a better theme to follow that is "hacker-y" if 1337speak is not currently trendy. It is something that is deeply ingrained in the culture and was never really a trend to infosec people. It's fun. Would something be more to date if the titles were emojis?

Side-note: Attended a BlackHat training and one of the people who works on the show (didn't catch their title) was attending one of the classes. Even saw them interracting with the offenisve security[1] cr3w. This small gesture adds an air of legitimacy in the infosec crowd.

https://www.offensive-security.com/

sprkyco··on Banksy Dismaland Show Revealed at Weston's Tropicana
Really wish he would pull something like this stateside at Lake Dolores: https://en.wikipedia.org/wiki/Lake_Dolores_Waterpark
sprkyco··on Windows 10 phones home when you search your start menu, even with Bing disabled
List of Android SSL MITM vulnerable apps: https://samsclass.info/128/proj/popular-ssl.htm

Highly recommend any material on the main site as well. One of the few legit infosec professors I have ever interacted with.

sprkyco··on Infosec's inability to quantify risk
"because there is virtually no quantifications of risks in anything I've read on the results of security research"

Nearly all results of security research are given at least some metric for risk quantification. https://cve.mitre.org is a single example of an attempt to quantify risk. I'm assuming at least at some point you have run across these numbers so the statement is patently false or a complete exaggeration.

sprkyco··on Infosec's inability to quantify risk
It is quite ironic that the article completely fails at risk analysis even from a perspective where an abundant amount of data is available. After some brief googling through top causes of accidents [1] most attributed deaths to speeding, drunk driving, or distracted driving.

It would be a fair attribution to say that the behavior of the vehicle as viewed from another drivers perspective was none of these situations as the driver was to at least some extent still in control of the car. While I do not know the exact model of the Jeep I'm assuming that there is a mechanical emergency brake still present.

Stopping in the middle of traffic is probably very low on the metric of causes of accidents or death. Although I did not accumulate enough data to give a metric on how much risk the researchers incurred through this experiment it may be beneficial for the author to at least do some due diligence in acquiring data before labeling an industry (one the author is well known in for that matter) as having an inability to quantify risk and then immediately fail to quantify risk.

[1] Pretty ironic that the author fails in his own analysis while talking about 'proper "risk analysis"'.

sprkyco··on Infosec's inability to quantify risk
An inability to quantify risk is attributing a skill set to an industry which is probably not responsible for quantifying risk. Infosec researchers should only be beholden to identifying and detailing risks. There are infosec subsets that require better skills to identify risks, but those subsets are the one's more responsible for quantifying risk in an appropriate manner not the ENTIRE industry.

Quantifying risk is a very difficult endeavor to do properly so any measure of it is done from the security researchers biased perspective. Yes infosec researchers seem to want attention for their work this is often because there is not near enough attention paid to their work. Actuarial science is an entire professional field specifically tasked with quantifying risk, at least from an insurance perspective.

The inferred statement, at least in the title, is that not only do infosec researchers now have to stay up on crypto, assembly, js[buzzword] framework and on and on, but now they must also become actuarial scientists. As a neophyte in the industry I'm having trouble getting caught up to a static point let alone that the static point is a moving and rapidly accelerating target and not in my favor. Adding to this unachievable standard I now must study and become at least somewhat proficient in actuarial sciences is maddening!

sprkyco··on Universal asks Google to take down 127.0.0.1 for piracy
Also it wasn't Universal per se, but Trident Media Group on behalf of Universal. However, in link provided by @waldirbj https://www.chillingeffects.org/notices/search?utf8=%E2%9C%9... there have been instances of Universal doing such a thing.
sprkyco··on Homejoy says goodbye
Looks like Google may have picked up some of the team: https://news.ycombinator.com/item?id=9904483

So not ALL that bad.

sprkyco··on California Is on the Verge of Water Abundance
Agreed linkbait, but I would have to say that people do care enough to act. To pretend that a huge population doesn't give a shit about water usage is a gross misrepresentation of the facts. I agree that California is not the model of water preservation considering the climate and water available to the geography. When statistics point to the fact that only a fraction of the water used in California occurs from lifestyle behavior, stating that the issue is lifestyle changes is failing to take into account any other information than pure speculation. The numbers regarding agricultural usage vary, but in most cases the amount used by things other than directly attributable to people is far less when compared to agriculture or any other source of usage[1].

The lifestyle changes that would need to occur to stem California's water usage are far more extensive and could easily qualify as a scientific dilemma. Basically non-california citizens are the "problem". When you're talking about drastically altering the diet of the entire U.S. (most likely other nations as well) due to the water being consumed by Agriculture it is absolutely a scientific dilemma.

[1]http://www.scpr.org/news/2015/04/15/50941/10-things-to-know-...

sprkyco··on I taught myself Python on the Internet and so can you
In that case I would recommend: http://www.pentesteracademy.com/course?id=1

,but that is because I am an unabashed infosec enthusiast that attempts to force feed everyone infosec information.

Page 1 of 3Next →