Live data from Hacker News

Viewing profile — jrozner

jrozner

HN member
Joined
Thu, Feb 02, 2012, 2:27 AM UTC
HN karma
71
Public activity
44 items

About jrozner

CEO and Founder of Based Security (https://www.basedsec.io)

GitHub https://www.github.com/jrozner Twitter @jrozner

Recent public activity

  1. comment
    Comment #49240584

    I know Joel well and think a lot here is both accurate and well written. I led the Yahoo bug bounty program from 2023-2024 and was involved in it from about 2021. A major event tha…

  2. comment
    Comment #48910344

    Most people only do the simplest of math on a day to day basis. I’d bet that if you asked most adults to do something even remotely non-trivial (addition, subtraction, multiplicati…

  3. comment
    Comment #48381063

    This seems really cool with very underwhelming specs. They maybe enough for people just getting started, especially at that price point. I think if there are lots of ready to go pr…

  4. comment
    Comment #47509904

    People hated steam when it launched but you needed it to play CS 1.6. It made installing mods easier. Then HL2 released, orange box, and they were able to get a critical mass as th…

  5. comment
    Comment #46256849

    Fleet was a terrible product. I’m a long time jetbrains user and still use goland, rust rover, and clion. I was really excited when it got announced because I had had a lot of issu…

  6. comment
    Comment #45422617

    Up or out generally stops once someone reaches engineer or sr engineer. Most of the time a jr engineer is going to need substantial mentoring and support. Them never moving beyond …

  7. comment
    Comment #45362953

    Whats the point of this over polars?

  8. comment
    Comment #44860513

    Unless he’s getting into a truly top tier school, have him go to a state university for much less. Community college and transferring is also an option but the social experience of…

  9. comment
    Comment #44154814

    For the most part, everything in your last point is something you can’t solve with an app. Virtually all of that would be problematic meeting someone in any other way and for the m…

  10. comment
    Comment #43528486

    We’re leveraging ssh certificates which are backed by keys stored in a variety of hardware. For yubikeys we’re leveraging piv and the standard ssh tooling. We’re determining whethe…

  11. comment
    Comment #43528044

    Building Based Security ( https://www.basedsec.io ), a startup in the zero trust/identity space creating immovable, attestable, hardware backed identities that can be used for stro…

  12. comment
  13. comment
    Comment #43476511

    I can understand the concern about having a second trusted party but think that the value of utilizing the standard ssh ca auth flow is worth the potential risk. If you require key…

  14. comment
    Comment #43475787

    I think it's interesting they're choosing to use certificates this way. If they're already using certs, why not just leverage sshca auth? Also, at the end of the day, it's still ef…

  15. story
  16. comment
    Comment #41587580

    Also an alum from WAY back (pre-A). One of the first things I did when I started was look at a different wrapping vuln.

  17. story
  18. comment
    Comment #41112186

    Why focus on SAML rather than OIDC2?

  19. comment
    Comment #40068882

    I agree that personal responsibility is important and both things can be true. I also think anyone who believes our taxes are going to go down if we don’t bail students out is delu…

  20. comment
    Comment #38134773

    After reading the policy when the blog post came out, I think one negative thing about it is that it can self select for people generally later in their career or with a much bigge…

  21. comment
    Comment #38134589

    I applied almost two years ago. I am excited about what Oxide is doing and it felt like a fun opportunity. While I respect what they do around comp, for where I was in my life and …

  22. story
  23. comment
    Comment #36715851

    When using a resident/discoverable credential the authenticator is supposed to authenticate the user (using a pin, biometrics, etc.) This fulfills the multi-factor requirement. All…

  24. comment
    Comment #34669878

    I have a similar experience (effectively failed out of CS and ended up with an BA in philosophy + minor in CS). For me it was the math courses more than anything else, I wasn’t int…

  25. story