Viewing profile — ericalexander3
ericalexander3
HN member- Joined
- Fri, Dec 28, 2018, 12:12 AM UTC
- HN karma
- 29
- Public activity
- 18 items
- HN profile
- View on Hacker News ↗
About ericalexander3
No profile information was provided.
Recent public activity
- story
-
comment
Comment #24123254
Peter Senge has a great definition in The Fifth Discipline > Mental models are deeply ingrained assumptions, generalizations, or even pictures of images that influence how we under…
-
comment
Comment #23404333
Isn't open source proof that you don't need buts in seats in the same office? If open source projects can do it, why can't most businesses? What's the limiting factor in business? …
- story
-
comment
Comment #22266475
Interested in data on real world impact from these attack vectors? Hackerone has public data on how often they reward each type: https://www.hackerone.com/blog/hackerone-top-10-mos…
-
comment
Comment #22247957
>The great ones are a treasure: and they are rare. And in order to stay great, they regularly need to go back to the well to refresh their own hands-on technical abilities. Similar…
-
comment
Comment #22247794
Keeping up with security news is important for situational awareness, but it can be time consuming. This is a tool I wrote for my own benefit to reduce signal to noise. It runs ent…
- story
-
comment
Comment #22246643
Technology can bring benefits if, and only if, it diminishes a limitation. -Dr. Eliyahu M. Goldratt Goldratt was critical of ERP systems, not because they couldn't bring benefit; r…
-
comment
Comment #21894810
SSRF to metadata service to S3 access was the entry point. There's a lot of focus on the SSRF and metadata service components but the S3/IAM component is possibly more intriguing. …
-
comment
Comment #21893314
U2F > TOTP > Any MFA > no MFA Why? About 23% of the classified breaches in this data set are due to compromised valid accounts and any MFA would probably have prevented the breach.…
-
comment
Comment #21885003
Articles like this inspired this project: https://github.com/ericalexanderorg/SecurityBreach It's sensational to make a claim that's based on the opinion of a few people in the wor…
-
comment
Comment #21878631
FUD article focusing on DDOS/Stresser/Booter incidents but doesn't share any data to show an upward trend on Christmas. Using this data on breaches we can see there's more incident…
-
comment
Comment #21790725
That's not the Toyota way. From a Westrum "Three Cultures Model" perspective Toyota would fall into the Generative classification, not Pathological or Bureaucratic. Based on the di…
- story
-
comment
Comment #19338535
https://en.wikipedia.org/wiki/List_of_autodidacts
-
comment
Comment #19337814
Coding test early in the recruitment pipeline. I've seen plenty of CS degrees on resumes that can't pass basic coding exercises/tests; at the same time, I've been impressed with th…
- story