HNHacker News
TopNewBestAskShowJobs

steakejjs

511 karma · joined September 8, 2014

e@ejj.io

[ my public key: https://keybase.io/ej; my proof: https://keybase.io/ej/sigs/C3HkPc4k5SISC7AK-sWYBiQ6q08dOW-MVrdoWl16x_4 ]

submissionscomments
steakejjs··on Keybase.io Vulnerability (2014)
Hey this is my blog post and that's not all it says. At the time, keybase used a font allowed me to perfectly copy (and make it look like twitter/github was verified) people's profiles.

Totally a lame vulnerability? Yes. Pretty effective? Also yes. If you go back in the github issue[1], it was even good enough to fool Chris, who founded the site, for 10 seconds.

[1] https://github.com/keybase/keybase-issues/issues/397

steakejjs··on My experience of interviewing for a job at Apple
EVERYONE does a horrible job recruiting. I think a very low number of companies are doing this correctly.

The thing about the process is one bad moment spoils the entire process for the candidate. Shallow/No responses, or horrible questions, or something unprofessional being said during the interview.

It's not just $AAPL it is everyone, but if you are an interviewer or a recruiter, please fight for the candidates to get good responses and good questions, especially if you fly someone across the globe to awkwardly sit in a room for 6 hours.

steakejjs··on Hacking Oklahoma State University's Student ID
Yes the school code was the same for everyone at the University. It differs from college to college, since this is a "solution" that the university purchases from a company.
steakejjs··on Hacking Oklahoma State University's Student ID
I went to a University in Virginia and ours, and other surrounding VA universities were equally insecure.

We each had a 9 digit code that looked like 10XXXXXXX. These numbers were incremented from one student or faculty to the next.

The only track that mattered was track 2. It had your 9 digit code, followed by a the school code (3 digits), followed by a "lost card digit" that was incremented each time a card was lost (obviously mod 10 here).

So if my ID was 100000001, I went to school 002, had lost my card two times, my current card's Track 2 would say: 1000000010022

Needless to say there are tons of things that can be done here. From getting access to rooms does not, to getting free lunches.

Pretty interesting things. I told my school and they didn't really care at all (as expected). The potential loss from this is so low that it they didn't bother since abusing these issues would get you arrested and expelled pretty quick.

In reality, it is probably pretty serious. This student id is used somewhat as a School social security number. You can take tests as other students or impersonate other students in a lot of different situations.

steakejjs··on Ask HN: What to do when all you have is talent?
IT security is ridiculously easy to break into, and I'm not kidding.

If you are able to demonstrate all that talent (github, outside projects, anything else) and you are able to hold a conversation with people, there are literally thousands of openings for you.

The certifications only really matter to Washington DC (or people making money off of DC).

Apply more places, make some things on the side that demonstrate you know what you're talking about, and look for positions at large, stable companies.

steakejjs··on OpenBSD Mail Server Intro
I wish the email stack was simpler.

While working on a project to learn go, I was using postfix to pipe email directly to a Go program, that then sent them as an SMS. I couldn't help but thinking how old and clunky the software I was using felt. The Go ended up being done in an hour and the postfix part took me 2 nights.

The same goes for all of the other email protocols and software. It's all big, bulky, and complicated. especially considering how much of a backbone email is to business today.

I know of the mailinabox project that was meant to package and abstract out a lot of the difficulties, but found that even that was too complicated.

Does anyone know of any projects meant to simplify the email stack?

steakejjs··on Popular images from Instagram everytime you open a new tab
Cool idea but will this actually be good in practice. When I go on Instagram a huge number of the popular images are NSFW with partial nudity or other things I wouldn't like to see every time I open a new tab
steakejjs··on Ask HN: Who wants to be hired? (February 2015)
pretty small world. I'm from Stafford and went to school in Harrisonburg too. Not a lot of VA folks on HN
steakejjs··on From Node.js to Go
I agree. Go was really nice to write code in since I do a huge variety of system level and Web things. It's my goto for practically everything now.

It will get better but for now I think writing a full web-app in Go, (presentation etc) is pretty annoying.

steakejjs··on From Node.js to Go
I wrote a Go Web Application with authentication and an API to learn Golang.

I must say, writing an API and some other services (SMTP pipe listener) was much nicer in Go than Authentication.

There is gorilla/sessions for sessions, but there's a lot to be desired here. A weak secret here means other people can decrypt the SessionStore Blob and possibly get secret information as a passive attacker or authenticate as another user. This sessionstore passphrase is the key to your entire webapp.

There's also nothing built in to Go for CSRF tokens, and HTMLTemplates are nice for preventing XSS but a pain in the butt for embedding, generating, and storing/regenerating (depending on how big you are) CSRF tokens.

Overall though....Writing Go has been pure joy for me. These are super knitpicky things to complain about.

steakejjs··on COMSEC: Beyond Encryption [pdf]
I don't know of any security conferences that preview slides. original research is presented regularly which means your hard work might leak by conference organizers who can't keep their mouths shut.

Alsp, many speakers are working on their slides and talk minutes before going on. These talks get finished notoriously late

steakejjs··on Front End Developer – Interview Questions
This looks like a giant list of trivia that has almost no bearing on the day-to-day effectiveness of the candidate.

For example, I don't have the slightest clue what the answer is to probably half of these and a lot of my job is to write javascript that gets run millions to billions of times a day. The "code questions", by contrast, were all ridiculously easy.

So, would it really matter if you are hiring someone who doesn't remember the difference between .call and .apply off the top of their head?

steakejjs··on Ask HN: How to get started with paying side projects?
In my opinion the best way to start a profitable side projects is to limit the scope of the project.

I fall into the category of starting too many things that I don't finish. I've recently realized that the size of the things I was working in was just way too big, especially since When working on a side project you are working around your life schedule.

After limiting the size of my projects I've found I am completing all of them

steakejjs··on Lab 1: Booting a PC
There are a lot of things here that stand out to me, as a recent grad of just a regular state school.

Things like "Using an API Key", and "Using git" cause students to HAVE to go above and beyond the assignment Because they will undoubtedly run into a problem with some of these extra steps along the way.

I think this type of learning can be more beneficial than the assignment itself. It's real problem solving using the computers.

That's just cool to see.

steakejjs··on Bitstamp problem and warm wallets
The API with a single call "createWithdrawl" is very good.

Having code like this to begin with changes how all your future code works. It also is easier to debug, simpler to explain, etc. You think twice about adding new API calls, which makes you think twice before you add new bugs. Having the ability to muck around with API calls you shouldn't be making will catch you eventually.

I've posted this before, but web-app security in most startups I look at is so bad. If it's written in PHP, I can normally find every bug in the book in under 5 minutes. What is worse on top of that is many companies don't respond (and don't fix) when you report bugs. I'm talking well known startups too.

I really think the OWASP Top 10 needs to be required reading for startup founders (or technical leads).

steakejjs··on Monster Sues Beats Electronics, Founders for Fraud
The answer to "Can you sue?" is always yes, yes, yes. You always can.
steakejjs··on Moonpig.com Vulnerability – Exposes customer data
I honestly don't think it is unfair. "Both technically violated the CFAA" is an important sentence.

The legal system is very complicated and sometimes small details make very big differences in cases. I'm not convinced others in the legal system would see this as different

steakejjs··on Moonpig.com Vulnerability – Exposes customer data
If this were the USA it would certainly be bad enough to warrant prosecution of the researcher. I am not familiar with laws in the UK, however. Keep in mind the similarities between this research and weev's research.

This type of blatant insecurity definitely should be punished and I wish more policy makers both cared, and made the effort to understand the terminology behind phrases like "No authentication", "Plaintext", Etc.

steakejjs··on CGI Using Node.js
This might be a good time to post the link to Facebook's XHP

https://www.facebook.com/notes/facebook-engineering/xhp-a-ne...

I've been using XHP at work and love the improvements it has made to the new code we are writing.

Posting this might not seem relevant, but the examples of "replacing php with javascript" show one of the ugliest parts of PHP, and that is when presentation becomes super tangled with business logic.

XHP is really really nice for outputting the contents of an array into HTML (for example..it has many other really nice uses), and it would be very cool to see them do something like that.

steakejjs··on Show HN: Download and inline Google web fonts from the command-line
It's surprisingly not difficult.

I got the woff files, base64'd them, and then threw the output into several CSS files.

Words of warning, If you use Content Security policy, you must allow Unsafe Inline for the style-src directive.

steakejjs··on Show HN: Download and inline Google web fonts from the command-line
I got tired of using font CDNs, didn't like extra round trips for the woff files, and I also really liked open-sans, so I made an OpenSans.css which inlines all the OpenSans fonts.

It makes my life a little more convenient. https://github.com/steakejjs/OpenSans-CSS/blob/master/OpenSa...

steakejjs··on When security goes right
I think "Never unchecked the checked-by-default whois checkbox when purchasing the domain" is more accurate than actually saying it is a decision.

While a company should definitely have a whois page, most startups make it abundantly clear how to get ahold of someone at the company with large "Contact Us" buttons.

I've never contacted a startup to report a security issue, gotten a response (some don't respond), and had it not be from someone in a position to have the issue worked on immediately.

steakejjs··on Graceful server restart with Go
So I wrote a golang application and it runs behind nginx. My server "restart" when I want to push new code is,

Re run my program on a different port, point nginx at the new port, reload nginx, kill the old.

Curious what is so bad about this approach? I admit it's hacky, but it works. Is there just too many things to do?

steakejjs··on If goto statements are bad why does linux src have more than 10k of them?
"Goto is bad" is something that professors tell first year computer science students because as computer scientists, the students will find novel ways of abusing them.

Using goto for error cleanup is pretty standard, easily readable, and understandable.

It avoids ugly braces and depth.

So, are gotos bad? It depends.

steakejjs··on On Linux, 'less' can probably get you owned
This research lcamtuf has been doing with AFL is really important.

One thing that it is proving (exactly as a lot of people expected) is, we don't have any idea where security bugs (think the next heartbleed or shellshock) are going to show up, we have no idea how good the software out there is (meaning it is bad), and most of the time we don't even know what's running on our own boxes.

If these basic things we use hundreds of times a day (less, strings) have huge flaws, we have a lot of work ahead of us.

steakejjs··on Show HN: Picky Pint – Scan beer lists with a photo
Cool stuff. Really like the app.
steakejjs··on Show HN: Picky Pint – Scan beer lists with a photo
So this looked really great and I'm sure it will be. I realize that there are a lot of barcodes, but I happened to see this thread while at Costco. I downloaded the app while here and it only recognized 2 beers from the entire beer isle.

Some were tricky but some were things that you definitely should have (like Sam Adams Winter). This will be really great when it's more complete but there is still some work to do

steakejjs··on Introducing Snapcash
Seems like this might impose on Clinkle quite a bit? Who is going to download clinkle when they can do the same thing from snapchat?

Seems neat to me, and pretty unexpected. One scary thing is just how bad a lot of passwords are for mobile applications. I'm sure it is even easier to brute force passwords on mobile and send a snapcash to yourself

steakejjs··on Some REST best practices
One thing I've noticed that will become increasingly important in the future is for JavaScript APIs it would be really nice if you had a per user path, for example:

api.com/steakejjs/v1/

This way, user's of your API can implement Content-Security-Policy in a secure manner (where an attacker can't use your 3rd party API to exfiltrate data). It's not like there aren't other ways to exfiltrate data, but this will definitely help.

steakejjs··on Exercising but Gaining Weight
I think your comment shows part of the problem, which isn't mean as a dig.

carbs, sugar, low dairy, small portions? What does this leave you to eat? The average person will go crazy following these rules.

The problem is people aren't realistic about what they are eating and their activity level. It is okay to eat poptarts, icecream, whatever it is you like. But do so in moderation. It's not okay to develop a habit of gluttony while on the couch.

← PreviousPage 2 of 4Next →