Viewing profile — collingreene
collingreene
HN member- Joined
- Wed, Mar 13, 2013, 7:02 PM UTC
- HN karma
- 131
- Public activity
- 30 items
- HN profile
- View on Hacker News ↗
About collingreene
Recent public activity
-
comment
Comment #28004818
Pysa - https://engineering.fb.com/2020/08/07/security/pysa/
-
comment
Comment #21013435
Here is our experience building and using program analysis as part of our product security efforts at facebook: https://engineering.fb.com/security/zoncolan/ . Its run in both self…
-
comment
Comment #19569264
https://www.facebook.com/data-abuse - as mentioned in the article this scenario (non-fb companies mishandling fb user data) is exactly the reason Facebooks data abuse bounty progra…
-
comment
Comment #17711326
This exists, https://internetbugbounty.org/ Facebook, microsoft, github, etc all pay $$ and our time into a pool that is used to incentivize the finding, vetting and fixing of secu…
-
comment
Comment #16803697
I work at Facebook and have personally seen no evidence of this. The article cites one designer who left (out of ~25,000+ total Facebook employees).
-
comment
Comment #16731110
The two people interviewed were fired for cause from this same program, of course they will have a negative opinion. One even fired for the same thing this safety driver failed to …
-
comment
Comment #16688927
> Why do you think the LIDAR did not work? The LIDAR might have worked just fine but what the system taking the output of the sensor did with the data is the question. Very true. I…
-
comment
Comment #16685445
I remain interested in why the lidar didn't work in this case and I hope more details emerge so we can learn what happened. But it seems logical that Uber would disable the onboard…
-
comment
Comment #16676167
Internal abuse is a big area of effort for Facebook and google but things still go wrong. Here was googles moment for that back in 2010: https://www.wired.com/2010/09/google-spy/
-
comment
Comment #16670317
>I don’t understand ... why aren’t the default settings of an account more secure and private? They are (for the most relevant definition of your question). Specifically a Facebook…
-
comment
Comment #15967592
This exists and companies purchase it, ex: https://www.thehartford.com/data-breach-insurance Risks (all kinds, not just technical) can be accepted, ignored, transferred and mitigat…
-
comment
Comment #15577638
I don't think anyone in security would disagree with you. The problem is measuring something that is sort of definitionally unknowable (how many vulns are in this code, where, how …
-
comment
Comment #15577620
If you like that book he wrote one about applying those ideas to this exact problem! https://www.amazon.com/How-Measure-Anything-Cybersecurity-Ri... I've never managed to make the …
-
comment
Comment #13202732
+1 to starting a private program first which is recommended by all bounty programs. If helpful I wrote down my notes about starting a bounty program although my experiences were fo…
-
comment
Comment #9430750
Nice, these look superior to the intel books (which intel graciously printed then mailed to me for free like 10 years ago, go intel!). Ill check them out.
-
comment
Comment #9425093
Assembly Language step by step by Jeff Duntemann remains one of my favorite books overall (not just programming, not just computers). It was updated in the last few years and the 3…
-
comment
Comment #8184517
Your acute mistaken conclusion> Simply throwing money at FOSS will not fix any security bugs. I can't think of anything closer to "throwing money at FOSS" than something like the i…
-
comment
Comment #8183721
Maybe you just enjoy hyperbole but while part of what you say is correct (finding security vulns in software is unavoidably a bit of a crapshoot) your conclusions are wrong. Findin…
-
comment
Comment #7706198
Cool article! A friend and I once did this but then recorded the commands attackers ran and replayed them on a big tv in our office. We called it hacker fishtank.
-
comment
Comment #7542812
To echo this sentiment: In 2013 facebook received 14,763 submissions which lead to 687 paid issues, 1 : 21 signal to noise. Facebook errs on the side of paying out as often as poss…
-
comment
Comment #7193456
We first learned of this claim a few hours ago. We've been in touch with MyPermissions directly and are waiting to receive more information from them. At this point, we haven't bee…
-
comment
Comment #7135072
This is really great. I have found myself saying some of these same things when explaining things. Going to keep this in my pocket to use in the future. Thanks!
-
comment
Comment #7068217
Replying as discussion originally seemed to be about first/last/profile picture privacy. The scenario is: you are not able to get into your rightful facebook account but you know s…
-
comment
Comment #7067819
I work at facebook on the security team. This is an account recovery endpoint used if your account was hacked for example. Your name, profile picture and a few other things are con…
-
comment
Comment #6687062
Google is on board. """ is sponsored by Microsoft and Facebook. It will be jointly controlled by researchers from those companies along with their counterparts at Google, """