Live data from Hacker News

Viewing profile — ianmf

ianmf

HN member
Joined
Sun, Aug 05, 2018, 12:38 AM UTC
HN karma
99
Public activity
47 items

About ianmf

A security engineer. https://ianm.tech

Recent public activity

  1. comment
    Comment #48886751

    Thanks for taking one for the team. I was about to do the same.

  2. comment
    Comment #42545566

    I owned several versions of Little Snitch too. It started to be annoying when you had to approve each request, especially when running command-line scripts. Then I moved to run in …

  3. comment
    Comment #40964489

    I used their software when I was a Windows user. Simple GUI, and functional. This is similar but for Mac. https://objective-see.org/tools.html

  4. comment
    Comment #40964480

    It's the same company that keeps getting breached over and over. Do this really surprises you?

  5. comment
    Comment #38158067

    I share the same feeling with smitty1e. But I have to admit, my military experience, GI Bill, and security clearance opened many doors for me. As you put it, it gave me a major leg…

  6. comment
    Comment #33963484

    You could print them and store them in a safe, or in your parents' collections of old embarrassing photos of you. Just an idea.

  7. comment
    Comment #32334888

    These devices are funded by government/school systems. When you receive them, you have to sign a TOS or User agreement, where highly likely contains a verbage similar to "This devi…

  8. comment
    Comment #31112435

    They probably cut market research funding to obtain that $300M.

  9. comment
    Comment #30381270

    IIRC from my military time, the first generations of the patriot missiles (PAC-1, PAC-2) were designed to explode when in vicinity of the target. The PAC-3 missile was the first to…

  10. comment
    Comment #30282226

    It depends on how you define top-tier hackers. State sponsored attackers (hackers with ties to governments, regime, etc.) have a lot more capital at their disposal. Sometimes they …

  11. comment
    Comment #30012653

    I have not received an email from Google about the changes. It lead me to think that it is for accounts that have more than 1 active user. I have a G Suite Legacy with 1 account on…

  12. comment
    Comment #29973353

    I don't miss the physical media. I am happy purchasing digital content. It makes management and organization very easy. What I do miss is owning the content. If you purchased a Mus…

  13. comment
    Comment #29962062

    If the attacker opens the document on a computer connected to the internet, it will. IIRC, the way it works: the document contains external resources with a unique identifier attac…

  14. comment
    Comment #29961840

    You could use a Canary / beacon. I have used this before to detect/confirm insider threats in organizations. You could create a PDF with instruction on how to view the data inside …

  15. comment
    Comment #29910938

    > I was once looking for a solution to some technical problem, clicked on a promising web result, and found myself at my blog. I had posted a solution several years earlier but had…

  16. comment
    Comment #29910237

    > I don't have anything interesting to say I don't agree with this part. I use my blog to keep a journal on technical issues that were hard to fix, or was hard to find web sources …

  17. comment
    Comment #29910069

    I got hired via LinkedIn, but it wasn't necessary to have an account to get the job. The position I got hired for had a job announcement on the corporate website. LinkedIn was just…

  18. comment
    Comment #29505617

    When Google Chrome came out, it was fast, reliable, secure, and it was not Internet Explorer. Chrome was what everyone needed back then. The competition was Firefox, which performa…

  19. comment
    Comment #29247756

    As long as it is work related, it is not unethical to educate yourself in something new. For example, a new tech stack, similar discipline, or business administration. Employers an…

  20. comment
    Comment #29231335

    Hopefully, this fixes the pay cap on the current positions. Government contractors would receive compensation of 25%-50% more than federal employees for the same work. It is hard t…

  21. comment
    Comment #29231243

    Almost all government agencies use USAJOBS for job postings. For DHS/CISA: https://www.usajobs.gov/Search/Results?a=HSCA NSA, FBI, and CIA have their own internal job application w…

  22. comment
    Comment #28666646

    I am tired of dealing with cellphone services providers. I treat them as such, a service company. I buy my phones from directly from apple, never from ATT. I simply pay my monthly …

  23. comment
    Comment #28666596

    If you are interested in shodan.io, every year the hold a one-day offer for a lifetime subscription for cheap.

  24. comment
    Comment #27626023

    These devices typically callback to the server and stay connected. Since the client is initiating the connection, there is no incoming NAT necessary.

  25. comment
    Comment #25750286

    > 3. These banners are required on all government IT systems. The sole purpose of these banners is to prevent criminals from saying they were not aware of what they were doing, mis…