HNHacker News
TopNewBestAskShowJobs

zjs

149 karma · joined March 27, 2013

[ my public key: https://keybase.io/zjs; my proof: https://keybase.io/zjs/sigs/eeEb6XShsU64Ew-eIeSBr44Vh-d-eJ3UO7S3cMylkNE ]
submissionscomments
zjs··on A Humility Training Exercise for Technical Interviewers
I have a small set of interview questions I prefer to choose from, in part because I've given them quite a bit of thought.

I would be sad if I had to switch questions after 20 or 30 candidates because I find it necessary to invest substantial effort in calibrating a new question. Before I ask a candidate a new question, I try use it to mock interview at least 10 people I have worked closely with. Iteration is always required to tune the difficulty and complexity of a question, so the total time invested in a question can be quite high.

One way that I keep questions well-calibrated is that I use them to mock interview other members of the interview panel. This serves at least two purposes: one is to constantly remind myself what realistic answers sound like and another is the help the rest of the panel understand the areas my question will cover.

I find that — for me — this type of mock interviewing and the subsequent retrospective cultivate empathy for candidates. I think this avoids the sort of bias you're observing.

(NB: Some of this may be specific to the kinds of questions I ask; I care less about the initial answer a candidate gives than their ability to self-assess their answer or incorporate feedback to improve their solution.)

zjs··on I exploited TLS-SNI-01 issuing Let's Encrypt SSL-certs for any domain (2018)
PRs to add support for new DNS providers have been slow to merge, in part because the support story is complex[0].

However, plugins need not live in the main Certbot repository. Maintaining a plugin yourself may be the lowest-friction way to build one right now (or may have its own challenges; I haven't tried that approach).

Lexicon supports he.net[1] and Certbot provides a class for building Lexicon-based providers[2] with very little effort (although perhaps more effort and duplication than would be ideal[3][4]).

0: https://github.com/certbot/certbot/issues/6504

1: https://github.com/AnalogJ/lexicon/blob/master/lexicon/provi...

2: https://github.com/certbot/certbot/blob/master/certbot/plugi...

3: https://github.com/certbot/certbot/issues/6178

4: https://github.com/certbot/certbot/issues/6621

zjs··on Facebook has been paying people to install a “Research” VPN
People are opting into data collection in a way that creates a severe security vulnerability. Not only have you given up confidentiality (of everything, including passwords), you've also sacrificed integrity and availability. You can no longer trust anything you do on your phone.

A hypothetical experiment Facebook might be interested in conducting: Do people use Facebook more if Twitter is slow and/or unreliable?

zjs··on Facebook has been paying people to install a “Research” VPN
Imagine the malicious things someone could do with this level of access. And none of the usual mechanisms to, say, detect widespread compromise of a Certificate Authority would apply here.

They could drain your bank account, hiding the transactions and adjusting the balance whenever you viewed the mobile banking website or used your mobile banking app and adjusting any emailed statements.

They could send messages to your friends and family from your account asking them to send money to you in a certain way or donate money to a "charity", hiding the entire conversation from your view.

They could make some services you use slower or less reliable in subtle ways, to steer you towards the ones they want you to use— the ones that are easier for them to manipulate the traffic to/from.

They could make you think you're going insane, in any one of a variety of ways.

They could gather all of your private information, and then lock you out of your entire digital life all at once. Two-factor authentication wouldn't protect you; they could present you with a fake "re-confirm your settings" process to collect the information necessary to disable or replace the settings. (If you pay your rent using your phone, they could lock you out of your physical life too; they could prevent the payment from going through, show you a confirmation, and suppress notifications of unpaid rent and e-mails from your landlord.)

They could control which news you see, slowly shifting your views on things like privacy and security.

If you get suspicious about any of this, they could plant false information in your search results.

zjs··on Facebook has been paying people to install a “Research” VPN
Could you summarize what you believe you're giving up in exchange for $20/month?

(There's a thread about informed consent elsewhere in this discussion. I'd like to understand how informed you are about the risks associated with the app and certificate.)

zjs··on I exploited TLS-SNI-01 issuing Let's Encrypt SSL-certs for any domain (2018)
> TLS-SNI-01 and 02 were only disabled only a few weeks ago, and they haven't been officially removed from the ACME spec, ...

Based on the repository's history, TLS-SNI-01 and TLS-SNI-02 appear to have been removed from the spec approximately a year ago: https://github.com/ietf-wg-acme/acme/commit/cfe118734bab3f6b...

zjs··on I exploited TLS-SNI-01 issuing Let's Encrypt SSL-certs for any domain (2018)
Years ago, an HTTPS-01 challenge was proposed that would have operated like HTTP-01 except using port 443. However, concerns were raised about the safety of this challenge.

I can't find the relevant discussion thread at the moment, but I believe this was because the default configuration in some shared hosting environments would have allowed users to receive certificates to others' websites.

Edit: https://mailarchive.ietf.org/arch/msg/acme/B9vhPSMm9tcNoPrTE...

zjs··on Ask HN: How to shadow a CEO?
Do you consider yourself to be good at note taking?

> Consider finding a few episodes of Car Talk, My Favorite Murder, or another podcast with at least 2 people talking back and forth, putting it at 1.1x speed, and taking notes on that.

This is an interesting idea. I think I'll try it!

Do you recommend this as a way to get better at note taking or a way to assess your ability to take notes?

I find that the hardest part of taking useful notes is identifying and organizing the key ideas that will need to be referenced later; writing down everything that's said in the order it was said seems to be of less value in a lot of cases.

How would you assess the quality of notes taken with this exercise?

zjs··on YubiKey 5 Series with New NFC and FIDO2 Passwordless Features
Off topic: I feel like a fireproof document safe is something that I should own, but every time I shop for one I find myself going down a rabbit hole of unfamiliar terminology and certifications. As with many things, it seems like the marketing for such safes doesn't always match the fine print.

(And sometime the fine print just seems impractical: I'm unlikely to actually air out my safe for 30 minutes each week, but could replace a desiccant a few times a year.)

Does anyone have a recommendation for a safe that can protect paper documents and digital media from both fire and water in realistic conditions?

zjs··on YubiKey 5 Series with New NFC and FIDO2 Passwordless Features
I configure a second YubiKey as a backup, and disabled SMS-based recovery where possible.

Many sites allow this explicitly, and will let you view details about the last time each key was used to log in.

Some sites that use TOTP only allow for one "authenticator" to be configured. In those cases, I scan the same QR code into each key.

This process requires you to retrieve your backup key from whatever safe place you store it in when configuring 2FA on new accounts, but that feels like a reasonable trade-off; I don't make new accounts very often, and when I do I can wait to configure 2FA until I have access to my backup key.

zjs··on Senator requests better https compliance at US Department of Defense [pdf]
Any CA can issue certificates for any domain, but they may not be permitted to do so.

Certification Authority Authorization (CAA) DNS records can be used to indicate which CA is authorized to issue certificates for a domain. The CA/Browser Forum requires all certificate authorities to check CAA records prior to issuance.

zjs··on Please Stop Using Adblock (But Not Why You Think)
From the article, Crystal also participates in eyeo's Acceptable Ads program.
zjs··on Hijack of Amazon’s domain service used to reroute web traffic for two hours
> There is a major chicken-and-egg/game-theoretical problem though: any browser that does that today will piss off/irritate its users, forcing them to use other browsers or older versions of the same browser, as DNSSEC is not widely deployed on the corporate side. And until most/all browsers do something major to make the current DNS security crisis obvious to large numbers of users, most companies won't care enough to deploy DNSSEC.

This seems analogous to the problem browsers faced with Flash. Perhaps they can leverage the same incremental approach here.

For example: 1) Validate DNSSEC. If present and valid, the HTTPS "green lock icon" gets a bonus glow. 2) 6 months later, not having a DNSSEC response gives a little red X badge on the "green lock icon". 3) 6 months later, not having a DNSSEC response graduates to a little ignorable info/warning box near the location bar. 4) 12 months later, you have to click through a big scary warning to access the site.

Essentially, start by providing a carrot and then introduce a progressively larger stick. Communicate the whole plan up front so that large organizations can get the ball rolling.

zjs··on Facebook Container for Firefox
> I already checked the box asking to always open foo.com in a specific container. Why is it asking again?

I have some sites that I almost always want to open in a specific container. Except when I don't.

I suspect this double-confirmation is for people like me: I can chose between "always open this site in this container" and "always suggest opening this site in this container".

zjs··on What Data Does Facebook Collect When I’m Not Using Facebook, and Why?
IANAL, but I think it depends on what data they collect.

Part of running any advertising business is accurately billing the advertisers. To do that, they need to measure enough information to track viewed impressions, click-through rate, etc.

If they collect only enough information to perform business functions like these, I believe that would constitute a legal basis for processing under the GDPR.

They may have a harder time using that justification for information that is only needed for ad targeting. In that case, consent may be an easier legal basis for them to establish, for which an account would be useful.

zjs··on Equifax CEO to Congress: Not Sure We Are Encrypting Data
More specifically:

"If a business collects and processes IP addresses, but has no legal means of linking those IP addresses to the identities of the relevant users, then those IP addresses are unlikely to be personal data. However, businesses should note that if they have sufficient information to link an IP address to a particular individual (e.g., through login details, cookies, or any other information or technology) then that IP address is personal data, and is subject to the full protections of EU data protection law."

https://www.whitecase.com/publications/alert/court-confirms-...

zjs··on French chef asks to be stripped of three Michelin stars
> “Maybe I will be less famous but I accept that,” he said, adding that he would continue to cook excellent local produce “without wondering whether my creations will appeal to Michelin’s inspectors”.

It sounds to me like he wants to be more adventurous.

zjs··on iPhone 8
> the fingerprint sensor being in the middle of the back on 6P is unquestionably a better choice

I've been very happy with the fingerprint reader positioning on the Sony Xperia Z5 Compact: as a part of the power button, along the edge of the device.

It's exactly where my right thumb naturally rests when holding my phone. (And lines up nicely with my left middle finger rests, if I'm holding it in my left hand.)

Side view: https://www.androidcentral.com/sites/androidcentral.com/file...

zjs··on Show HN: Kobble – Notes app that saves directly to GitHub
Ouch. It does seem as if anyone can view any users' content this way.
zjs··on Ask HN: Establishments that offer free Wi-Fi, how do you protect yourselves?
There's some information on this topic at https://openwireless.org.
zjs··on The DDoS that almost broke the Internet
Your calculation is assuming that all of the traffic from those 4 million London-based users is travelling through LINX. While LINX is the IX for London, not all traffic originating from London would have to travel through it; Tier 2 and Tier 3 networks would route some portion of the traffic as well.

This diagram from wikipedia shows some of the sorts of alternate routes that might be used: http://en.wikipedia.org/wiki/File:Internet_Connectivity_Dist...

As an aside: does anyone know of a good resource that gives an example of the rough percentage of traffic that would be handled in each of the various ways?

← PreviousPage 3 of 3