Viewing profile — jjarmoc
jjarmoc
HN member- Joined
- Wed, Nov 06, 2013, 10:04 PM UTC
- HN karma
- 275
- Public activity
- 66 items
- HN profile
- View on Hacker News ↗
About jjarmoc
No profile information was provided.
Recent public activity
-
comment
Comment #9904997
I don't know.. Google confirms they covered my area. I really don't look for house cleaning services, so maybe I just didn't get targeted for ads.
-
comment
Comment #9903943
When I hear about companies like this going under, I always think how odd it is that I've never previously heard about them. Then I realize, that may have been part of the problem.…
-
comment
Comment #9898582
He never 'got a lawsuit.' Instead, he got some comments from the contact to whom he reported it that criticized his approach. It's not even clear just who this person was. It seems…
-
comment
Comment #9897750
> So far as I know (this is sort of my profession), there's no federal "burglars tools" law regarding malware. To be fair, many "burglars tools" laws require possession of the tool…
-
comment
Comment #9727604
I feel like that's a reasonable timeframe from 'hmm, something is odd' to 'we're pretty sure we fully understand the impact, time to notify users.' There's a balance between early …
-
comment
Comment #9722313
In the comments, they indicate that they're in the process of sending out emails to users. Sending lots of emails takes some amount of time; hopefully those are arriving in inboxes…
-
comment
Comment #9722153
No, I don't think you did. I certainly haven't seen anything about the root cause. Let's hope it comes in time.
-
comment
Comment #9721967
This is one of the things that scares me. If an attacker had access to dump their credential digests, could they also have modified the site to silently log credentials upon entry?…
-
comment
Comment #9721948
> I just write down my passwords. People may laugh, but for many people that's a huge step up. I've tried explaining password managers to family members, and I've failed. The usabi…
-
comment
Comment #9721857
"Answer unclear, ask again later"
-
comment
Comment #9721604
I would also appreciate more detail, but that shouldn't be their first priority. They note that they discovered the breach on 'Friday' so I imagine they have an ongoing Incident Re…
-
comment
Comment #9721583
> Maybe there are people out there who will accept much more inconvenience in exchange for avoiding the risk associated with a cloud-based service. But, for me, the inconvenience i…
-
comment
Comment #9721419
While LastPass seems to be responding well, I find their entire service exceeds my tolerance for risk. If you don't use a password manager, you've got 99 problems, but a centralize…
-
comment
Comment #9641265
Thanks!
-
comment
Comment #9640629
~ -,._.,- ~'`^`'~ -,._.,- ~'`^`'~ -,._.,- ~'`^`'~ -,._.,- ~'`^`'~ -,._.,- ~ NCC Group Atlanta. Austin. Chicago. New York. San Francisco. Seattle. Sunnyvale. Application Security Co…
-
comment
Comment #9525829
> Any interview process that requires a substantial time investment by the candidate pre-interview is broken. I disagree, but accept that this depends largely on the desired outcom…
-
comment
Comment #9472163
~ -,._.,- ~'`^`'~ -,._.,- ~'`^`'~ -,._.,- ~'`^`'~ -,._.,- ~'`^`'~ -,._.,- ~ MATASANO SECURITY - Chicago. New York City. Sunnyvale. Application Security Consultant Full-Time, work v…
-
comment
Comment #9471816
Yes, it likely will. That's probably why the article mentions a deprecation of "Non-Secure HTTP" rather than prescribing a specific TLS version. It's the sort of language that will…
-
comment
Comment #9471446
The differences are significant when it comes to the security of the underlying protocol, and the downgrade is why it's important you refuse to support SSL entirely. SSL of any ver…
-
comment
Comment #9471051
Please, can we stop calling it SSL? SSL means something very specific; something that people should no longer be deploying. The article notably uses the term 'Non-secure HTTP' whic…
-
comment
Comment #9367823
> I can work either from home or from my office. My office is fine but I'm usually more productive in the comfort of my home because I'm less likely to be distracted. This is defin…
-
comment
Comment #9351004
> I’m curious exactly how many times a candidate gets to apply to Matasano. Undefined. Personally, I applied twice, ended up coming to work here the second time through. > Do I hav…
-
comment
Comment #9350639
He seems to see anything that doesn't include pitchforks and torches as apologetic.
-
comment
Comment #9350419
> There's no way to tell for sure if something like this is intentional or not. Right, so the simplest explanation is that it's an unintentional bug. The absence of evidence that i…
-
comment
Comment #9350321
So, it's my comment you quoted questioning whether this can be called a backdoor. I don't intend that to be apologetic for Apple. I called it a 'significant vulnerability' but at t…