Live data from Hacker News

Viewing profile — ninegunpi

ninegunpi

HN member
Joined
Wed, Oct 04, 2017, 2:09 PM UTC
HN karma
97
Public activity
66 items

About ninegunpi

CTO at data security company. Opinions reflect my current state of mind and nothing else matters. I blog at http://www.ivychapel.ink about information security, risk and other things that amaze me.

Recent public activity

  1. comment
    Comment #31929871

    tl;dr: Balancing tradeoffs and benefits during disclosure is a hard job sometimes and if authors chosen to do it this way - they could have done it for a reason? You don't have to …

  2. comment
    Comment #29552917

    Infosec emotional climate always had a certain pessimistic, paranoid and panicky perception from the outside, but it is greatly exaggerated, I think. FUD, bullshit, lack of skilled…

  3. comment
    Comment #29514167

    Love cryptopals beyond my ability to articulate it well enough. This is monumental work many engineers owe their “cryptography 101-404” education to. For a long while company I wor…

  4. comment
    Comment #20745388

    To scale shipping static content, I'd rather look into CDN with proper caching, instead of maintaining ten layers of abstraction just to feel good about how modern my stack is.

  5. comment
    Comment #19169928

    Isn't RASP just slapping the WAF-like signature detection into your application data streams directly? How would RASP prevent: 1. Insiders having access to database front? 2. Same …

  6. comment
    Comment #19158167

    If your security strategy relies on one or two security controls, you're doomed most of the time. We've added SQL filtering as a defense-in-depth measure, having a convenient seat …

  7. story
  8. comment
    Comment #19113757

    I actually came to comment on this matter. Anecdotal evidence of several people I know is that playing FPS games with trackpad (pretty much of a torture) improves touchpad intuitiv…

  9. story
  10. story
  11. story
  12. comment
    Comment #18800143

    What you are describing is effectively two aspects of the first step of traditional buddhist meditation Shamatha - awareness on chosen object and awareness on present signals of th…

  13. comment
    Comment #18616404

    >We may never be able to build a machine that can recognize the full diversity of human emotional experience Even humans have a lot of problems recognizing full diversity of their …

  14. comment
    Comment #18545081

    You've made far better one than me below. Hats off.

  15. comment
    Comment #18545059

    1. A "quite a while" is less than a hundred years after Godel and in math? Compared to 2000+ years of Aristotlean logic dominance in hard sciences just because Romans inherited mos…

  16. comment
    Comment #18543810

    Indeed. Yet, it is still based on True/False pair, which does not reflect neither reality or human experience in most cases. Where it is applicable - it perfectly works. But the sc…

  17. story
  18. comment
    Comment #18541474

    Descendants of Aristotle still find limitations of the system amusing, that’s amusing itself. I hope to live to the day when philosophical advancements of 20th century (or re-disco…

  19. comment
    Comment #18532351

    1. The problem is that most population is terribly poor at defining and managing risk, by biological design and social selection - those who are good at it are usually not the best…

  20. comment
    Comment #18521530

    You are correct. I get a bit irritated when somebody claims to teach developers "all they need to know about cryptography" and goes on with explaining things they'd be happy to obs…

  21. comment
    Comment #18519944

    Opened the book, read first random page ( https://cryptobook.nakov.com/key-exchange/diffie-hellman-key... ), closed the book. If this is what "developers need to know", then explai…

  22. story
  23. comment
    Comment #18502327

    It would be terribly interesting to hear what some of the brighter minds here think about CS security model.

  24. story
  25. comment
    Comment #18502304

    In fact, due to browser execution model, it’s not impractical - it’s impossible - it can mutate any moment.