Live data from Hacker News

Viewing profile — collingreene

collingreene

HN member
Joined
Wed, Mar 13, 2013, 7:02 PM UTC
HN karma
131
Public activity
30 items

About collingreene

http://collingreene.com/

Recent public activity

  1. comment
    Comment #28004818

    Pysa - https://engineering.fb.com/2020/08/07/security/pysa/

  2. comment
    Comment #21013435

    Here is our experience building and using program analysis as part of our product security efforts at facebook: https://engineering.fb.com/security/zoncolan/ . Its run in both self…

  3. comment
    Comment #19569264

    https://www.facebook.com/data-abuse - as mentioned in the article this scenario (non-fb companies mishandling fb user data) is exactly the reason Facebooks data abuse bounty progra…

  4. comment
    Comment #17711326

    This exists, https://internetbugbounty.org/ Facebook, microsoft, github, etc all pay $$ and our time into a pool that is used to incentivize the finding, vetting and fixing of secu…

  5. comment
    Comment #16803697

    I work at Facebook and have personally seen no evidence of this. The article cites one designer who left (out of ~25,000+ total Facebook employees).

  6. comment
    Comment #16731110

    The two people interviewed were fired for cause from this same program, of course they will have a negative opinion. One even fired for the same thing this safety driver failed to …

  7. comment
    Comment #16688927

    > Why do you think the LIDAR did not work? The LIDAR might have worked just fine but what the system taking the output of the sensor did with the data is the question. Very true. I…

  8. comment
    Comment #16685445

    I remain interested in why the lidar didn't work in this case and I hope more details emerge so we can learn what happened. But it seems logical that Uber would disable the onboard…

  9. comment
    Comment #16676167

    Internal abuse is a big area of effort for Facebook and google but things still go wrong. Here was googles moment for that back in 2010: https://www.wired.com/2010/09/google-spy/

  10. comment
    Comment #16670317

    >I don’t understand ... why aren’t the default settings of an account more secure and private? They are (for the most relevant definition of your question). Specifically a Facebook…

  11. comment
    Comment #15967592

    This exists and companies purchase it, ex: https://www.thehartford.com/data-breach-insurance Risks (all kinds, not just technical) can be accepted, ignored, transferred and mitigat…

  12. comment
    Comment #15577638

    I don't think anyone in security would disagree with you. The problem is measuring something that is sort of definitionally unknowable (how many vulns are in this code, where, how …

  13. comment
    Comment #15577620

    If you like that book he wrote one about applying those ideas to this exact problem! https://www.amazon.com/How-Measure-Anything-Cybersecurity-Ri... I've never managed to make the …

  14. comment
    Comment #13202732

    +1 to starting a private program first which is recommended by all bounty programs. If helpful I wrote down my notes about starting a bounty program although my experiences were fo…

  15. comment
    Comment #9430750

    Nice, these look superior to the intel books (which intel graciously printed then mailed to me for free like 10 years ago, go intel!). Ill check them out.

  16. comment
    Comment #9425093

    Assembly Language step by step by Jeff Duntemann remains one of my favorite books overall (not just programming, not just computers). It was updated in the last few years and the 3…

  17. comment
    Comment #8184517

    Your acute mistaken conclusion> Simply throwing money at FOSS will not fix any security bugs. I can't think of anything closer to "throwing money at FOSS" than something like the i…

  18. comment
    Comment #8183721

    Maybe you just enjoy hyperbole but while part of what you say is correct (finding security vulns in software is unavoidably a bit of a crapshoot) your conclusions are wrong. Findin…

  19. comment
    Comment #7706198

    Cool article! A friend and I once did this but then recorded the commands attackers ran and replayed them on a big tv in our office. We called it hacker fishtank.

  20. comment
    Comment #7542812

    To echo this sentiment: In 2013 facebook received 14,763 submissions which lead to 687 paid issues, 1 : 21 signal to noise. Facebook errs on the side of paying out as often as poss…

  21. comment
    Comment #7193456

    We first learned of this claim a few hours ago. We've been in touch with MyPermissions directly and are waiting to receive more information from them. At this point, we haven't bee…

  22. comment
    Comment #7135072

    This is really great. I have found myself saying some of these same things when explaining things. Going to keep this in my pocket to use in the future. Thanks!

  23. comment
    Comment #7068217

    Replying as discussion originally seemed to be about first/last/profile picture privacy. The scenario is: you are not able to get into your rightful facebook account but you know s…

  24. comment
    Comment #7067819

    I work at facebook on the security team. This is an account recovery endpoint used if your account was hacked for example. Your name, profile picture and a few other things are con…

  25. comment
    Comment #6687062

    Google is on board. """ is sponsored by Microsoft and Facebook. It will be jointly controlled by researchers from those companies along with their counterparts at Google, """