HNHacker News
TopNewBestAskShowJobs

weeks

223 karma · joined April 30, 2016

submissionscomments
weeks··on We have a year to fix security everywhere
https://jamstack.org

You're describing the Jamstack or headless CMS concept verbatim.

weeks··on Apple set to stave off daily fines, EU to accept App Store changes, sources say
They're referring to the EU not being able to compete.
weeks··on I was part of a human subject research study without my consent
“Buy, receive, or sell the personal information of 50,000 or more California residents”

If a business engages this type of activity, they need to have a scalable process for providing California residents with their data.

Describing a California law passed by a majority of voters as “idiotic hoops” is a miss.

weeks··on Google's infamous internal 2010 “I just want to serve 5TB” video now public
Is. :D
weeks··on Google and Facebook mandate vaccines for employees at U.S. offices
Do I have a choice not to work with you?
weeks··on AWS announces forks of Elasticsearch and Kibana
Apache Spark and Apache Kafka? It doesn't seem likely that the Apache Software Foundation would consider implementing the SSPL instead of the Apache License.
weeks··on Guy Who Reverse-Engineered TikTok Reveals the Scary Things He Learned
The technical claims don't seem very far fetched. They're basically describing every banking "anti-fraud SDK" I've ever reversed.
weeks··on How the CIA used Crypto AG encryption devices to spy on countries for decades
https://googleprojectzero.blogspot.com/2017/10/over-air-vol-...

Even Apple's IOMMU has had vulnerabilities allowing for full memory access from the WiFi modem.

weeks··on Apple leaves Facebook offices in disarray after revoking app permissions
Apple's policy is one certificate per company. So it being a single point of failure is unavoidable.
weeks··on Did Uber steal Google’s intellectual property?
Code review, trusted build environments and code signing could entirely prevent a single engineer from modifying the code running on the car.
weeks··on Hardening macOS
"I recommend rolling your own email server"

This is actively harmful advice. Do not roll your own email. Use a well-known provider with a solid security track record.

weeks··on VLC is blacklisting recent Huawei devices to combat negative app reviews
https://developer.android.com/distribute/best-practices/deve...

That hasn't actually happened yet.

weeks··on 23andMe Anne Wojcicki Berates Stanford and Valley Med on Behalf of Sick Friend
You think the CEO of 23andMe and ex-wife of Sergey Brin can't afford the best nursing home for her grandmother?
weeks··on Meltdown and Spectre
Thanks for pointing that out. I've escalated internally to have the video restored.

Edit: the video has been restored.

weeks··on There are over a billion outdated Android devices in use
https://developer.android.com/guide/topics/ui/layout/recycle...

https://developer.android.com/guide/topics/media/exoplayer.h...

RecyclerViews are only implemented in the support libraries, even for newer versions of Android. I haven't used Exoplayer personally but by reputation it does all of the hard media stuff for you.

weeks··on Se­cu­rity Keys
While I absolutely agree with you, it seems far more likely that native implementations by Apple, Google and Microsoft will dominate the market. Windows Hello is a great early example of this.
weeks··on How to use BeyondCorp to ditch VPN, improve security and go to the cloud
Android supports U2F via NFC and Bluetooth now, which is used for user authentication on Android devices. We've also released an (experimental?) iOS app to support U2F over Bluetooth.

https://itunes.apple.com/us/app/google-smart-lock/id11520663...

weeks··on Advanced CIA firmware has been infecting Wi-Fi routers for years
https://www.ubnt.com/edgemax/edgerouter/

Ubiquiti's EdgeRouter gets my vote if you're willing to muck around on the CLI to get to advanced features.

weeks··on The Holder Report on Uber
My former employer reimbursed our lunch as taxable income for this reason.
weeks··on ARKit
From what I've gathered this totally depends on your market. Creating a paid app or an app targeting US University students? iOS first. Creating an ad supported app or targeting an international market? Android first or use a framework that supports compiling to both platforms.
weeks··on iOS 11 Location Privacy: "Only While Using" is now always an option for users
Android 1.0 had this via ACCESS_COARSE_LOCATION, unfortunately Android only recently got runtime permissions.
weeks··on The Judy Malware: Possibly the largest malware campaign found on Google Play
If the user isn't informed the app they installed is clicking on ads, it absolutely is malware.
weeks··on Windows 10 Enterprise ignores various privacy settings
Playing whack-a-mole with memory corruption vulnerabilities isn't how you create a secure operating systems.
weeks··on Wikimedia Foundation spending
Where I feel a lot of the animosity from the Wikipedia community stems from is that the people who have "cultivated expertise in governing" are actually Wikipedia volunteers, not WMF employees.
weeks··on Wikimedia Foundation spending
As a Wikipedia administrator (mostly inactive), this sentiment makes complete sense to me. The WMF seemingly spends the majority of its money on non-critical functions such as community outreach, local chapters, yearly conferences and other non-critical costs. Including a parade of highly paid, not very effective executives. One thing to keep in mind is the WMF != the Wikipedia community, it is very possible to truly support the Wikipedia mission without also supporting how the WMF is ran.
weeks··on Uber CEO Plays with Fire
While you're right that a lot of FinTech applications do use fingerprinting, it is absolutely against the rules. It's rather annoying from a mobile security perspective but given the rampant abuse of persistent device identifiers on Android, I understand and appreciate Apple's stance here.
weeks··on Google Identity-Aware Proxy
The purpose of ascertaining device identity is to prevent someone who can't obtain legitimate Google issued hardware from using stolen user credentials. If you're already a Google employee you can just ask for more trusted hardware, so there would be little point in breaking that part of the security model.
weeks··on Basic Security Precautions for Non-Profits and Journalists
For one, without Google Play Services you have no Play Store. Unless you're going to prevent users from installing apps entirely, there isn't really another safe way to obtain apps. Additionally Verify Apps, SafetyNet, Safe Browsing, etc. are all part of Google Play Services. You _really_ want Verify Apps.
weeks··on Basic Security Precautions for Non-Profits and Journalists
https://source.android.com/security/verifiedboot/verified-bo...

How do you propose a custom rom can establish hardware root of trust without being signed by the device manufacturer?

weeks··on Basic Security Precautions for Non-Profits and Journalists
Disabling Verified Boot and not having Google Play Services would dramatically reduce the security posture of an Android device.

Disclaimer: I work at Google.

Page 1 of 2Next →