HNHacker News
TopNewBestAskShowJobs

the_cyber_pass

126 karma · joined February 25, 2017

submissionscomments
the_cyber_pass··on An Anarchist Critique of Democracy (2005)
My argument was that you said police were invented largely as a force in the 19th century for "largely questionable purposes such as racism and anti-unionism." I brought up a pretty clear example of a police force existing in the time of Augustus which had no ties at all to the modern climate. I'm not arguing for or against anarchism. I am arguing for historical accuracy. You can define it as taking the authorities shit as much as you want, but I'm sure I could hear plenty of reasonable counter arguments from state loving people as well about how enforcement of the rule of law provides a stable framework for settling legal disputes and references to Hobbes.
the_cyber_pass··on An Anarchist Critique of Democracy (2005)
Just to comment on this. A common google search would have pointed out that your ideas about local police forces are largely incorrect. Police have been a thing for much longer. The big thing that happened in more recent history (Meaning 1700s) is separating them from the private market, the military or unregulated local mobs. You can trace the enforcers of civil law through force all the way back to ancient Babylon because civil unrest is bad for raising taxes. You could argue this were not police but rather various forms of 'authority,' but it's dishonest to say that they were not acting like police.

Easy example of this would be Cohortes Urbanae in ancient Rome which was specifically formed because the Praetorian Guard was too corrupt even by Roman standards at the time and mobs, gangs and 'random' violence were common.

the_cyber_pass··on Ask HN: How did you get started in Network Security/Penetration Testing?
Happens and I wont pass judgement. The IoT explosion has been the best thing to happen for me in years career wise and now I get to combine the best of both worlds.
the_cyber_pass··on Ask HN: How did you get started in Network Security/Penetration Testing?
Coming from someone who holds your company in high regard and loved your companies work in the CGC I really have to disagree. You can be neither a script kiddie or a non-technical manager and still have webdev shops view you with suspicion for much the same reason node shops might see someone who has a lot of Java on their resume as someone who may not be a good fit because of 'technical baggage.' We can say that someone just needs to 'git gud' but I do think it's important to acknowledge that many times their are biases that get placed which are not always 100% rational.

Edit: Also I do believe your claim about all 30 of your engineers being able to find work elsewhere. You have to admit the average employee you have probably isn't reflective of anywhere near the average of the industry or even the enthusiast community.

the_cyber_pass··on Ask HN: How did you get started in Network Security/Penetration Testing?
As someone who has tried a couple times to jump the other way I can attest to this. Completely stonewalled for full stack developer positions.

I have found exploits by knowing the quirks of all sorts of libraries and I have to be able to understand how things work on a deep level. But because a lot of the job is tracing other peoples work and finding gaps in their logic, you don't have as much 'dev' time in the traditional sense. Most of your coding turns into ways to prep your exploit. Your life gets wrapped up chasing obscure malloc bugs or strange chrome behavior rather than contributing in normal developer ways and companies don't recognize this as transferable. I'm only a little bit bitter about it, but I love my work. I just hope the pay stays solid and I don't end up in a dead end job later in life.

Also it's really hard to be good in this industry. It is almost entirely driven by the top 1% of people and as someone who is not in that demographic it feels like a constant struggle to keep up.

the_cyber_pass··on API to detect toxic comments
Although on a technical level I think it could prove an interesting challenge, I worry about it's implications on speech across the web. Besides potential fears about the creators bias training it, all I think this will do is create clever slang to get around the filter. There was a joke on 4chan a long time ago about starting to use the names of major companies as racial slurs because it would be harder to filter and I could easily see something like that happening here.
the_cyber_pass··on Richard Stallman Explains [video]
I see someone hasn't had GPL conflicts in their code base before. There is a reason companies specifically look for them and it's because the FSF and it's communities will make your life hell.
the_cyber_pass··on Google Fires Employee Behind Controversial Diversity Memo
I actually have constant fears about this, I always wonder because of programs like this if I am good enough or am I just a diversity hire.
the_cyber_pass··on Google Fires Employee Behind Controversial Diversity Memo
I appreciate that, but I don't think raising up some random guy on reddit is a valid way of drawing a conclusion.

Person A thinks X.

Person B who belongs a group the blue tribe hates also thinks X.

Therefore person A is a bad person because they agree with person B about X.

We have failed to prove that the group person B belongs to is actually bad and not just an exercise in signaling and we are also trying to smear person A by saying they agree with some other completely unrelated person who may belong to a distasteful group. Additionally X can still be correct and both people can be distasteful, but it wont change the fact that X is correct.

Sorry if I am not being clear, it's been a long day.

the_cyber_pass··on Google Fires Employee Behind Controversial Diversity Memo
Is that our guy? He is talking about him in the 3rd person later on down the line. How is one reddit comment even relevant to this right now?
the_cyber_pass··on Google Fires Employee Behind Controversial Diversity Memo
Will do.
the_cyber_pass··on Google Fires Employee Behind Controversial Diversity Memo
Link me the part where he said anything like that.
the_cyber_pass··on Google Fires Employee Behind Controversial Diversity Memo
I think you skipped about 2 Reichs there.
the_cyber_pass··on Google Fires Employee Behind Controversial Diversity Memo
None of what he said were men's rights dog whistles. If you think this you clearly don't have an ear for them. The closest you could say is he was maybe inspired by Peterson and Slatestarcodex.
the_cyber_pass··on Google Fires Employee Behind Controversial Diversity Memo
Completely disagree and I think the reaction to the post proved his point. Unfortunately this is now easily going to blow up into another donglegate.
the_cyber_pass··on There is no such thing as EQ (2016)
Go home /pol/ your drunk.
the_cyber_pass··on There is no such thing as EQ (2016)
I think pop media needed a phrase to describe someone who was obviously smart but had a lot of trouble interacting with others. I am sure we all have run into Bob or Alice the cave troll who for lack of a better word can't pick up on any of the needs of other people no matter how hard they try. Pop media isn't going to go for words with academic rigor. They just know IQ = Smart and Bob is obviously smart, but Bob is also an idiot when it comes to reading social situations so Bob is also an idiot. People realize that Bob can't both be smart and an idiot at the same time so society created a way of differentiating that Bob is both an idiot and genius at different things aspects of life.
the_cyber_pass··on Kids Pass Just Reminded Us How Hard Responsible Disclosure Is
You forgot another possibility which is that the organization might have a bad office culture and the person is just instinctively protecting their turf.
the_cyber_pass··on The Full 10-Page Anti-Diversity Screed Circulating Internally at Google
If you are talking about IQ the data would support you, the problem comes when you look at standard deviation and we see men have a slightly higher standard deviation which leads to the extremes on both sides being overwhelmingly male. It's not something we need to worry about much in day to day interactions because you wont notice it but in hyper selective environments it might become an something people notice.
the_cyber_pass··on The Full 10-Page Anti-Diversity Screed Circulating Internally at Google
It's a product of the left/right divide in modern American politics. It's mostly a dog whistle so the other side knows he is ok to unperson.
the_cyber_pass··on The Full 10-Page Anti-Diversity Screed Circulating Internally at Google
Aren't blacklists supposed to be illegal in the US?
the_cyber_pass··on What Is the Highest Salary Can a Programmer Make?
Nice is relative. People who make a lot of money want things relative to their interests. Areas become more expensive due to poor planning from civil servants more than Google salaries. NYC, DC, Boston, Atlanta, Austin, London, Brussels and Berlin are all cities which are also working on "solving hard problems" but they don't have nearly the cost of living problems that SF has.
the_cyber_pass··on What Is the Highest Salary Can a Programmer Make?
I believe it, but this is more of an argument between the exceptional vs the broader industry. Me and the other person (I think) are looking at the industry in a much broader sense because there are various reasons someone would even make it into Facebook or Google in the first place which are not entirely dependent on ability. Even the majority of people at Google and Facebook are not at a senior level which is roughly what I think E5 is if I recall correctly.
the_cyber_pass··on What Is the Highest Salary Can a Programmer Make?
Ok so first off, rent in Tulsa is 12k at most for a full house.

Second off a lot of the high cost of living has nothing to do with solving hard problems, if it did the civil engineers would have solved the hard problem of fixing the housing market in SF. What you are essentially arguing is Tom Cruise 2.0 makes 6 million a film after a few years in the industry so therefor everyone else sucks which you can tell because they don't make 6 million. Being generous I would claim it's a survivorship bias.

the_cyber_pass··on What Is the Highest Salary Can a Programmer Make?
The average developer is average, not awful. You can make more if you are better than average and know the right people and speak the right language. I know people who are making $350k, but they are very much an exception and we both know and understand this. Much of how much you get paid is based around who you know, your location and your cultural fit. Most people do not live in the bay area for various reasons and salaries like that are extremely uncommon outside of there and the upper echelons of the NY finance market.

I was exaggerating, but if you save your money while making 250k you can easily live off 30k and pocket the rest. It's not hard to become a millionaire off of that salary in a very short amount of time.

the_cyber_pass··on What Is the Highest Salary Can a Programmer Make?
Are you really willing to tell me that that the average engineer in 3-6 years can pull in $250k? Your own source says the median is $100,690. How long do you think those people have been working in the industry? Are they all just fresh out of college? So if these people all just work 3-6 years should I expect a bunch of multimillionaires? Can the industry support $250k salaries for a wider amount of the population?
the_cyber_pass··on What Is the Highest Salary Can a Programmer Make?
Look at /r/programming, do you think these people are pulling $250k. They are closer to the average. If you think $250k is normal you're in an exceptional bubble.
the_cyber_pass··on Notepad++ V 7.3.3 – Fix CIA Hacking Notepad++ Issue
The problem doing DLL injections is you are dropping things directly to the disk which is a great way to get AVs attention. Heuristics based detection can be a pain in the ass here and you want your rootkit to be able to be 'unique' for every installation if possible.

Also rootkits are way overrated. What you do when you compromise an organization is you open a connection to your C&C on a few machines to keep your foothold if any reboot. If you need to get in you just connect to one of those boxes and just continue on. You never have to drop anything on the hard disk which makes it much stealthier.

the_cyber_pass··on Notepad++ V 7.3.3 – Fix CIA Hacking Notepad++ Issue
There is a case to be made that you only need to be good enough to get in. I myself am not nearly at the level where I could write a hypervisor exploit even though I have been in the industry for a while. However I feel pretty confident in my ability to break into almost any company if I set my mind to it. Fancy exploits are just things that take time to create and if your super great payload gets flagged by fireeye down the line you might have just wasted a ton of time for no other reason than showing off if powershell would suffice. So I guess I am torn on this because I don't want to flame the sysadmin's turned security people for not being a top speaker at blackhat or CCC because I myself come from that background, but on the other hand I think I should expect more quality work out of the CIA than what comes out of infosecinstitute. If this is the average of the CIA I really think NCC group might have more capability than the intelligence agency of the US government which is kind of crazy to think about. I am sure they have some really great zero days that they save for very important projects, but I doubt we will get to see the same level of capability that we saw out of the NSA leaks.
the_cyber_pass··on Notepad++ V 7.3.3 – Fix CIA Hacking Notepad++ Issue
I don't think they wanted to flex muscle over Apple, I think they were trying to build case law for situations like this. Also breaking into a phone with an exploit like this is expensive and if they have an exploit, they might not want to publish that they have it in the future so having the backdoor provides deniability even if it's fundamentally dumb.

/puts on tinfoil hat

There is also the other option which is that trust in American tech companies has been sketchy at best following the NSA leaks and this was a chance for the Obama administration to allow companies to reestablish some legitimacy when it came to security by making the US government look evil but having the corporations 'prove' that they are not backdoored by the NSA. They can still break in the covert way, but it makes it look tech companies are not as compromised as the NSA leaks would suggest.

Page 1 of 2Next →