Live data from Hacker News

Viewing profile — jjarmoc

jjarmoc

HN member
Joined
Wed, Nov 06, 2013, 10:04 PM UTC
HN karma
275
Public activity
66 items

About jjarmoc

No profile information was provided.

Recent public activity

  1. comment
    Comment #9904997

    I don't know.. Google confirms they covered my area. I really don't look for house cleaning services, so maybe I just didn't get targeted for ads.

  2. comment
    Comment #9903943

    When I hear about companies like this going under, I always think how odd it is that I've never previously heard about them. Then I realize, that may have been part of the problem.…

  3. comment
    Comment #9898582

    He never 'got a lawsuit.' Instead, he got some comments from the contact to whom he reported it that criticized his approach. It's not even clear just who this person was. It seems…

  4. comment
    Comment #9897750

    > So far as I know (this is sort of my profession), there's no federal "burglars tools" law regarding malware. To be fair, many "burglars tools" laws require possession of the tool…

  5. comment
    Comment #9727604

    I feel like that's a reasonable timeframe from 'hmm, something is odd' to 'we're pretty sure we fully understand the impact, time to notify users.' There's a balance between early …

  6. comment
    Comment #9722313

    In the comments, they indicate that they're in the process of sending out emails to users. Sending lots of emails takes some amount of time; hopefully those are arriving in inboxes…

  7. comment
    Comment #9722153

    No, I don't think you did. I certainly haven't seen anything about the root cause. Let's hope it comes in time.

  8. comment
    Comment #9721967

    This is one of the things that scares me. If an attacker had access to dump their credential digests, could they also have modified the site to silently log credentials upon entry?…

  9. comment
    Comment #9721948

    > I just write down my passwords. People may laugh, but for many people that's a huge step up. I've tried explaining password managers to family members, and I've failed. The usabi…

  10. comment
    Comment #9721857

    "Answer unclear, ask again later"

  11. comment
    Comment #9721604

    I would also appreciate more detail, but that shouldn't be their first priority. They note that they discovered the breach on 'Friday' so I imagine they have an ongoing Incident Re…

  12. comment
    Comment #9721583

    > Maybe there are people out there who will accept much more inconvenience in exchange for avoiding the risk associated with a cloud-based service. But, for me, the inconvenience i…

  13. comment
    Comment #9721419

    While LastPass seems to be responding well, I find their entire service exceeds my tolerance for risk. If you don't use a password manager, you've got 99 problems, but a centralize…

  14. comment
  15. comment
    Comment #9640629

    ~ -,._.,- ~'`^`'~ -,._.,- ~'`^`'~ -,._.,- ~'`^`'~ -,._.,- ~'`^`'~ -,._.,- ~ NCC Group Atlanta. Austin. Chicago. New York. San Francisco. Seattle. Sunnyvale. Application Security Co…

  16. comment
    Comment #9525829

    > Any interview process that requires a substantial time investment by the candidate pre-interview is broken. I disagree, but accept that this depends largely on the desired outcom…

  17. comment
    Comment #9472163

    ~ -,._.,- ~'`^`'~ -,._.,- ~'`^`'~ -,._.,- ~'`^`'~ -,._.,- ~'`^`'~ -,._.,- ~ MATASANO SECURITY - Chicago. New York City. Sunnyvale. Application Security Consultant Full-Time, work v…

  18. comment
    Comment #9471816

    Yes, it likely will. That's probably why the article mentions a deprecation of "Non-Secure HTTP" rather than prescribing a specific TLS version. It's the sort of language that will…

  19. comment
    Comment #9471446

    The differences are significant when it comes to the security of the underlying protocol, and the downgrade is why it's important you refuse to support SSL entirely. SSL of any ver…

  20. comment
    Comment #9471051

    Please, can we stop calling it SSL? SSL means something very specific; something that people should no longer be deploying. The article notably uses the term 'Non-secure HTTP' whic…

  21. comment
    Comment #9367823

    > I can work either from home or from my office. My office is fine but I'm usually more productive in the comfort of my home because I'm less likely to be distracted. This is defin…

  22. comment
    Comment #9351004

    > I’m curious exactly how many times a candidate gets to apply to Matasano. Undefined. Personally, I applied twice, ended up coming to work here the second time through. > Do I hav…

  23. comment
    Comment #9350639

    He seems to see anything that doesn't include pitchforks and torches as apologetic.

  24. comment
    Comment #9350419

    > There's no way to tell for sure if something like this is intentional or not. Right, so the simplest explanation is that it's an unintentional bug. The absence of evidence that i…

  25. comment
    Comment #9350321

    So, it's my comment you quoted questioning whether this can be called a backdoor. I don't intend that to be apologetic for Apple. I called it a 'significant vulnerability' but at t…