HNHacker News
TopNewBestAskShowJobs

zinssmeister

756 karma · joined September 23, 2010

twitter.com/zinssmeister
submissionscomments
zinssmeister··on German economy contracts 0.2% in 2024 in second consecutive annual slowdown
Germany’s economy has been heavily dependent on specific sectors, particularly the automotive and machinery industries. These sectors are so vital that any decline in their performance could have significant ripple effects across the economy. However, the global market is increasingly shifting towards electric vehicles (EVs) with advanced software interfaces. Companies like Tesla and Chinese manufacturers have taken the lead in this space, while German carmakers have struggled to adapt to the EV and software revolution.

Germany also has been facing two big challenges that have seen limited action: rising energy costs and slowing exports to China, both of which have started around 2020. The decision to rely heavily on Russian energy to sustain its industrial economy has proven to be a bad idea. The influx of low- or unskilled labor into a social welfare system, coupled with the challenges of cultural integration (German culture isn't the sexiest of things), has also turned out to be a bad idea.

Bonus issue: Germany’s taxes are high, particularly for individuals and workers. Some of the highest in the world. This gives consumers less $ to consume with.

zinssmeister··on Nobody ever gets credit for fixing problems that never happened (2001) [pdf]
Great approach! For the past 2 years I keep experimenting with different ways to track day to day productivity. It has helped me tremendously in assessing how I should feel at the end of the day about my work day and the amount of time I put towards work. (I tend to overwork myself significantly). It is of course a lot harder to apply this approach to individual productivity tracking across my teams. But I do now believe, based on self experiments and within smaller teams, that there is generally a lack of visibility of knowledge worker productivity. Especially within larger companies. WFH and hybrid makes this more crucial to have for both management and self assessments on the IC level.
zinssmeister··on Security Architecture Anti-Patterns
Excellent and to the point. I see this apply to many technology SMB companies as well. We once compiled a few actionable recommendations for smaller companies that host on AWS and that post ended up being our most popular article https://www.templarbit.com/blog/2018/11/21/security-recommen...
zinssmeister··on Golden: Mapping human knowledge
this is a great idea. First URL I faved in the past 12 months. Good luck Jude!
zinssmeister··on In Japan, the Kit Kat Isn’t Just a Chocolate
Can second this. I travel to Tokyo often and have purchased Kit Kat to bring back home. Mostly tourists buy these, none of my local japanese friends do
zinssmeister··on Facebook Network Breach Impacts Up to 50M Users
No, but that sounds entertaining!
zinssmeister··on Facebook Network Breach Impacts Up to 50M Users
We compiled details on this breach here, including some insights on the attack vector https://breachroom.templarbit.com/facebook-is-breached-by-ha...
zinssmeister··on Google CA Root Inclusion Request
We just published the “SSL wars” story between Symantec and Google https://www.templarbit.com/blog/2018/09/07/the-story-of-why-...

This adds another layer of color to that story.

zinssmeister··on Ask HN: Who is hiring? (September 2018)
Templarbit (YC S17) | San Francisco, Irvine, Frankfurt, Tokyo | Onsite | https://www.templarbit.com

Companies of all sizes are incredibly vulnerable inside the application layer. Nearly half of all breaches originate on a website or web application and lead to devastating, often headline generating losses of customer data or other malicious activity. We at Templarbit are building the solution to this with the first intelligent security platform that integrates tightly with the application it is protecting, helping businesses defend themselves from breaches and provide them with real time insights into the state of their security posture. Our team has previously worked on increasing the application layer security of the pentagon and large fortune 5 enterprises.

Open roles:

- Senior Software Engineer (Fullstack)

- Senior Software Engineer (Frontend)

Tech Stack: Ruby on Rails, React, Go, Python, Node

Only apply if you like hard problems in high stake environments. Send an email with your resume as PDF and the subject line "Engineering @ Templarbit" to hello+hn@templarbit.com

zinssmeister··on Spyware Company Leaves ‘Terabytes’ of Selfies, Messages, Location Data Exposed
Incredibly difficult to even figure out who the company behind Spyfone is. Anyone know?
zinssmeister··on Podcast with Erik Berlin on Founding Breaker and Doing YC
This episode was fun to record. Thanks again Erik for making time to come chat with us and letting us peek inside the day to day at Breaker.
zinssmeister··on Evil Teacher: Code Injection in Moodle
This is one of the better write up formats I have seen. Good work Robin.
zinssmeister··on Highlights of Verizon 2018 Data Breach Investigations Report
Gabe, thanks for that. Just checked the Appendix E section you mentioned, instantly a fan of what I saw there. Glad you have filters in place rather than just taking any breach report into the data set.
zinssmeister··on Highlights of Verizon 2018 Data Breach Investigations Report
Thank you for sharing this, haven't seen this before. Pretty interesting.
zinssmeister··on Highlights of Verizon 2018 Data Breach Investigations Report
Ah, yes I see what you mean. You got an excellent point here. It's not just fortune 500 companies, because one of the data points highlights that among the victims the SMB sector has the highest allocation. My guess is that the analysts try to get data from as many breaches as possible every year. Probably partnering with incident response firms like Mandiant. It's not a sample set and at the same time it is because a lot of breaches go undetected.
zinssmeister··on Highlights of Verizon 2018 Data Breach Investigations Report
The percentages in this report are in relationship with the data points of 53,000 incidents and 2,216 confirmed data breaches that the team analyzed.
zinssmeister··on Highlights of Verizon 2018 Data Breach Investigations Report
Verizon released the 11th edition of their report yesterday and I took a quick look at it this morning and started compiling interesting highlights into this post.

Hope this will be of value to some of you. Particularly to people that don't want to spend time reading the entire PDF report.

zinssmeister··on Ask HN: Who is hiring? (April 2018)
Templarbit (YC S17) | San Francisco, Irvine, Frankfurt, Tokyo | Onsite | https://www.templarbit.com

Companies of all sizes are incredibly vulnerable inside the application layer. Nearly half of all breaches originate on a website or web application and lead to devastating, often headline generating losses of customer data or other malicious activity. We at Templarbit are building the solution to this with the first intelligent security platform that integrates tightly with the application it is protecting, helping businesses defend themselves from breaches and provide them with real time insights into the state of their security posture. Our team has previously worked on increasing the application layer security of the pentagon and large fortune 5 enterprises.

Open roles:

- Senior Software Engineer (Fullstack)

- Senior Software Engineer (Frontend)

Tech Stack: Ruby on Rails, React, Go, Python, Node

Only apply if you like hard problems in high stake environments. Send an email with your resume as PDF and the subject line "Engineering @ Templarbit" to hello+hn@templarbit.com

zinssmeister··on Tracking Users with CSS
Direct link to the code https://github.com/jbtronics/CrookedStyleSheets
zinssmeister··on Ask HN: How good is the job market for .NET stack?
.Net is only a great stack if your focus is to contract or work for Corporations in America (mostly in the midwest and south). Europe is heavily set on PHP, some Rails and Python. The coasts in the U.S. incl. the valley are usually Rails, Django and Go.

I personally would not invest in a .Net focused education.

zinssmeister··on Self-Control Relies on Glucose as a Limited Energy Source (2007)
I do it a month at a time and yeah I eventually get over it but never fully into the same calm state as with carbs
zinssmeister··on Self-Control Relies on Glucose as a Limited Energy Source (2007)
I do both of these things and especially when I am on a low-carb diet I have a very short fuse. Politeness goes out the window and compromising as well.
zinssmeister··on Launch HN: Templarbit (YC S17) – Protect Your Web Apps from XSS Attacks
There is a lot more signal than noise, especially they way we aggregate the security reports. CSP can be deployed in report only mode, which provides a great way to detect how your policy has to come together.
zinssmeister··on Launch HN: Templarbit (YC S17) – Protect Your Web Apps from XSS Attacks
Yes we are looking at this. We will release a more integrated solution for PHP soon + docs.
zinssmeister··on Launch HN: Templarbit (YC S17) – Protect Your Web Apps from XSS Attacks
Noise is a problem and we are in this fight to improve exactly that.
zinssmeister··on Launch HN: Templarbit (YC S17) – Protect Your Web Apps from XSS Attacks
I actually have never heard/seen Tcell.io so I can't speak to them and what they do. Will check it out though!
zinssmeister··on Launch HN: Templarbit (YC S17) – Protect Your Web Apps from XSS Attacks
Setting a CSP header can be simple but managing changes to it can get difficult. Especially as team members add or remove services from the app (Intercom, Google Analytics, etc.)

We also provide a reporting endpoint that captures all violations. Do you currently use a CSP header with a report-uri setting?

zinssmeister··on Launch HN: Templarbit (YC S17) – Protect Your Web Apps from XSS Attacks
That is great feedback! Some of this was on our "immediately post-launch" todo list. Expect us to implement everything you just mentioned over the coming days.
zinssmeister··on Launch HN: Templarbit (YC S17) – Protect Your Web Apps from XSS Attacks
Thank you!

Google Webmaster tools has made an effort to help fight XSS vulnerabilities by providing some educational tools to devs (among other things). It's not a solution in the same realm as ours, for example they don't collect any violations and show you detailed reports on where something bad happened.

I don't see Google as a threat to us at all. We actually sat down with them at their SF office last week to work closely together on how they can quickly provide a better Content Security Policy feature set to their cloud customers.

zinssmeister··on Launch HN: Templarbit (YC S17) – Protect Your Web Apps from XSS Attacks
Yep. I do the same :)
Page 1 of 9Next →