Live data from Hacker News

Viewing profile — mkjones

mkjones

HN member
Joined
Sat, Dec 12, 2009, 1:23 AM UTC
HN karma
978
Public activity
185 items

About mkjones

i like making things do what they're not supposed to

http://mattkjones.com

Recent public activity

  1. comment
    Comment #10358341

    I had a similar but less-awful experience (fortunately as a renter rather than owner). Living in a similar slab house, I was surprised when my shower became slow to drain and drain…

  2. comment
    Comment #9084367

    I suspect flash is generally used to play sounds from chat messages - the https man-in-the-middle detection is heavily sampled, as referenced in https://www.linshunghuang.com/paper…

  3. story
  4. comment
    Comment #8891374

    OK, I can think of a few ways they might do this (DNS tricks and per-user IPv6 addresses, => user mapping). These all seem significantly more complex than HTTP header injection tho…

  5. comment
    Comment #8891300

    How would ISPs tag requests going over HTTPS as being from a particular subscriber?

  6. comment
    Comment #7533006

    Yep, "URLs shared primarily by not-sharey people" sounds similar to a lot of classifiers we have.

  7. comment
    Comment #7528895

    Yeah, we've played with that idea a bit. It doesn't help the sparseness problem (actually makes it worse), and if we took action as a direct result, it would give people the power …

  8. comment
    Comment #7528486

    So I can't speak for twitter, but I work on anti-spam at Facebook, and imagine the problems we face are relatively similar. It's worth noting that there's a constant barrage of peo…

  9. comment
    Comment #7528190

    hey I work on anti-spam at FB. Happy to talk sometime. facebook.com/mkjones or @fisherrider on twitter (lol). You can learn a little about how we think about securing login here: h…

  10. comment
    Comment #7484589

    I'm surprised more aren't mostly-white for the first 3/4, and then they split at the end. It seems like all the action in basketball always happens in the last 2 "minutes."

  11. story
  12. comment
    Comment #6686076

    We (I'm another eng at FB) definitely hire interns who are not juniors in college. You can be younger or older (or you could be a junior - I did my internship here after junior yea…

  13. comment
    Comment #6230910

    Hmm, wanna report at facebook.com/whitehat with more details? Please include repro instructions :).

  14. comment
    Comment #6230903

    I think there's a spectrum between letting whitehats do anything (including violating privacy, hurting real user accounts, etc) vs. suing everyone who changes a GET param somewhere…

  15. comment
    Comment #6230803

    OK - so I work on a security team at Facebook and sometimes help with reviewing Whitehat reports. To be clear, we fixed this bug on Thursday. The OP is correct that we should have …

  16. comment
    Comment #6230664

    Hey folks - I work on security at Facebook (though not specifically the Whitehat program) and just wanted to let you know we're looking into this right now.

  17. comment
    Comment #5297641

    Compromising an up-to-date machine is usually a bit harder than just pointing nmap at it and enumerating running services. Getting someone to visit a web site is relatively easy.

  18. comment
    Comment #5199794

    Yeah, the moment we realized what was going on, it was like one of those horror stories you tell as a kid: "...the call was coming from INSIDE THE HOUSE." The only way an attacker …

  19. comment
    Comment #5199757

    I was one of the people involved here (the guy quoted as saying "which means that whoever discovered this is looking at our code"). As the article noted, they started the whole dri…

  20. comment
    Comment #5185840

    I assume the 10.0.0.0/8 responses were from other hosts on their network?

  21. comment
    Comment #5114576

    Cow-orker of ldbrandy (and nbm!) here, and one of the clients of FXL. We definitely make use of machine-learned models to catch some kinds of spam. They're good at keeping old atta…

  22. comment
    Comment #5102488

    I think he's confusing the key-derivation function this article talks about for your "master key" with the MAC-in-JS this particular thread is discussing.

  23. comment
    Comment #5077000

    I suspect they care a lot more about the effect these additional upstream bytes have on response time than their own network ingress. Especially for a site that cares so much about…

  24. comment
    Comment #4733136

    https://www.facebook.com/whitehat/bounty/ describes our bug bounty program, linked to from the "bounty" tab on the left of https://www.facebook.com/whitehat/ .

  25. comment
    Comment #4733127

    We're working on improving this flow. However, if you tell us to trust a given computer when you log in, you shouldn't have to enter the code more than once.