Live data from Hacker News

Viewing profile — ericalexander3

ericalexander3

HN member
Joined
Fri, Dec 28, 2018, 12:12 AM UTC
HN karma
29
Public activity
18 items

About ericalexander3

No profile information was provided.

Recent public activity

  1. story
  2. comment
    Comment #24123254

    Peter Senge has a great definition in The Fifth Discipline > Mental models are deeply ingrained assumptions, generalizations, or even pictures of images that influence how we under…

  3. comment
    Comment #23404333

    Isn't open source proof that you don't need buts in seats in the same office? If open source projects can do it, why can't most businesses? What's the limiting factor in business? …

  4. story
  5. comment
    Comment #22266475

    Interested in data on real world impact from these attack vectors? Hackerone has public data on how often they reward each type: https://www.hackerone.com/blog/hackerone-top-10-mos…

  6. comment
    Comment #22247957

    >The great ones are a treasure: and they are rare. And in order to stay great, they regularly need to go back to the well to refresh their own hands-on technical abilities. Similar…

  7. comment
    Comment #22247794

    Keeping up with security news is important for situational awareness, but it can be time consuming. This is a tool I wrote for my own benefit to reduce signal to noise. It runs ent…

  8. story
  9. comment
    Comment #22246643

    Technology can bring benefits if, and only if, it diminishes a limitation. -Dr. Eliyahu M. Goldratt Goldratt was critical of ERP systems, not because they couldn't bring benefit; r…

  10. comment
    Comment #21894810

    SSRF to metadata service to S3 access was the entry point. There's a lot of focus on the SSRF and metadata service components but the S3/IAM component is possibly more intriguing. …

  11. comment
    Comment #21893314

    U2F > TOTP > Any MFA > no MFA Why? About 23% of the classified breaches in this data set are due to compromised valid accounts and any MFA would probably have prevented the breach.…

  12. comment
    Comment #21885003

    Articles like this inspired this project: https://github.com/ericalexanderorg/SecurityBreach It's sensational to make a claim that's based on the opinion of a few people in the wor…

  13. comment
    Comment #21878631

    FUD article focusing on DDOS/Stresser/Booter incidents but doesn't share any data to show an upward trend on Christmas. Using this data on breaches we can see there's more incident…

  14. comment
    Comment #21790725

    That's not the Toyota way. From a Westrum "Three Cultures Model" perspective Toyota would fall into the Generative classification, not Pathological or Bureaucratic. Based on the di…

  15. story
  16. comment
    Comment #19338535

    https://en.wikipedia.org/wiki/List_of_autodidacts

  17. comment
    Comment #19337814

    Coding test early in the recruitment pipeline. I've seen plenty of CS degrees on resumes that can't pass basic coding exercises/tests; at the same time, I've been impressed with th…

  18. story