Viewing profile — jerematasno
jerematasno
HN member- Joined
- Thu, Oct 23, 2014, 11:21 PM UTC
- HN karma
- 38
- Public activity
- 36 items
- HN profile
- View on Hacker News ↗
About jerematasno
http://chargen.matasano.com/
Recent public activity
-
comment
Comment #10020295
Compromised servers are detected and shutdown quickly? [ Citation needed ]
-
comment
Comment #9957530
If the server cannot be trusted, it will extract your encrypted data, since it serves up the code. The server, if compromised/subpoenaed, merely needs to serve you some JavaScript …
-
comment
Comment #9847734
Sorry, I really don't have any idea what our friends across the pond are doing with regards to hiring.
-
comment
Comment #9841522
(BTW, for those who miss him, Jeff is alive and well, but was super-busy with client work last week.)
-
comment
Comment #9605663
We are still working on new sets, though obviously the rate of new sets is pretty low. The mailing list is basically unmonitored at this point, but everything we've got is on the s…
-
comment
Comment #9512038
> Penetration tests, when done by a good firm like Matasano, are incredibly useful, but lose their value the next time you push code. I'd like to nicely but firmly push back on thi…
-
comment
Comment #9493467
Note that our work-sample tests are, not-insanely, done in the comfort of your own home, at your own pace, on your own schedule, and represent the work we actually do. As co-head o…
-
comment
Comment #9410165
Most of our candidates drop out before the work sample. On the other hand, almost none of our candidates are qualified to work for us when they initially apply. We make it really c…
-
comment
Comment #9290303
Sithu, Here are a couple of resources that I tend to hand out to startups that we do work for at Matasano. No charge :-) Not trying to be a salesperson, but I feel like most startu…
-
comment
Comment #9271889
> The problem with my suggestion I fail to see the problem...
-
comment
Comment #9257733
In general, my feeling is that the Matasano process (which I currently manage) works outstandingly well where there isn't a flood of qualified candidates. If you have a glut of fol…
-
comment
Comment #9181419
My policy (I'm co-in-charge of recruiting at Matasano/NCC, and a lot of folks report to me) is this: 1) Hire based on current ability, not potential. Hiring based on potential is a…
-
comment
Comment #9181376
We actually pre-pay on that. Candidates get an initial call with a very senior person to start. That call includes coaching on how to get through our interview process, and conclud…
-
comment
Comment #9181357
Getting an internship at Matasano is HARD . Unlike normal hiring, we are limited in the number of spots we can offer, and we also have a huge flood of candidates at once. I hate th…
-
comment
Comment #9181323
The way we do it now, the initial call person reads your resume, but we categorically do not reject based on the initial call (or the subsequent tech phone interview(s)). So, we ge…
-
comment
Comment #9181279
At Matasano (slash NCC), we get a lot of candidates. We look at resumes so that we have something to break the ice with when we talk to the candidates. We do triage interns using r…
-
comment
Comment #9180853
Hi, I've taken over from Tom for hiring at Matasano. There's a couple of things that you need for "diverse" recruiting (e.g. hiring women in tech): 1) A way of evaluating candidate…
-
comment
Comment #9180829
These days we mostly send The Web Application's Hacker's Handbook and a link to microcorruption. (We do somehow get candidates which haven't heard of microcorruption.) Generally, w…
-
comment
Comment #9095264
Speaking as one who stands to benefit from such a rule, I also think that requiring 3rd party validation is a bad idea. First off, it's always a race to the bottom, and secondly, t…
-
comment
Comment #8985370
Certainly not required! To get a job in application security (at Matasano/NCC or anywhere, really) you should be demonstrably okay at web application, and have interests beyond web…
-
comment
Comment #8985352
We are literally drowning in intern applications. Either we haven't gotten to yours yet (likely), or we accidentally dropped it on the floor (also, sadly, possible, given the numbe…
-
comment
Comment #8972943
As co-head of recruiting for Matasano/NCC US, I endorse this approach! Bear in mind that we are pretty heavily focused on appsec, but of course for us appsec includes kernel work, …
-
comment
Comment #8958112
We wrote a quick blog post on this. The main meaningful feature is a table of distros, versions, and whether they're not vulnerable, vulnerable but with a patch, or vulnerable with…
-
comment
Comment #8957603
Full blog post coming, but 14.04 was never vulnerable. glibc 2.17 was the last vulnerable version.
-
comment
Comment #8957488
It doesn't have to be internet accessible, AFAIK. If an attacker can get something to do arbitrary DNS lookups, I think it can be attacked. For instance, monitoring/log correlation…