Live data from Hacker News

Viewing profile — sarciszewski

sarciszewski

HN member
Joined
Wed, Jun 11, 2014, 2:48 PM UTC
HN karma
2,268
Public activity
1,771 items

About sarciszewski

No profile information was provided.

Recent public activity

  1. story
  2. story
  3. story
  4. story
    Ask HN: How does your company handle application security?

    How does your company ensure the code you produce (or consume) is secure? Do you have in-house security controls? Third-party penetration tests? Independent code audits? Bug bounty…

  5. story
  6. story
  7. comment
    Comment #11290510

    (Switching back to my old account because rate limits.) I wouldn't ever use something like FizzBuzz to assess a candidate. It would be more of "here's a mostly finished sample appl…

  8. comment
    Comment #11290088

    > All true but my observation is that the companies that put candidates through multi-day-out-of-town interview processes can afford to miss out on the candidates that can't do it.…

  9. story
  10. comment
    Comment #11166698

    > RSA security depends mostly on how you build your private keys and ECC security depends on what parameters and what curve was chosen. No. RSA security depends on getting your par…

  11. comment
    Comment #11164063

    I really appreciate the level-headed discussion in this thread so far, especially the comment I'm replying to. It's a stark contrast to the CFRG mailing list. (At least, so far, no…

  12. comment
    Comment #11159638

    http://pastebin.com/AYW682BJ https://archive.is/exvT2

  13. comment
    Comment #11151528

    Person: "I'm starving and barely able to get by working for Yelp in SF." Yelp: "You're fired." (Good luck paying rent without a job.) Yelp CEO: "The cost of living is too high here…

  14. comment
    Comment #11143520

    How would transforming it before sending it over the wire help here?

  15. comment
    Comment #11143500

    No, it's one-way cryptography, but it's not a form of encryption. https://paragonie.com/blog/2015/08/you-wouldnt-base64-a-pass...

  16. comment
    Comment #11137412

    Cryptocat was not secure. No argument there! Decryptocat was the proof in the pudding. If a secure product could be as user-friendly as Cryptocat was while still being secure, then…

  17. comment
    Comment #11136632

    See: "but the execution was flawed." > Security at the expense of usability comes at the expense of security. It got the usability part down, it just wasn't secure. And I wasn't cl…

  18. comment
    Comment #11135924

    Cryptocat was a good concept (i.e. it was USABLE!), but the execution was flawed. It grew a lot of criticism and Nadim made mistakes in handling some of his critics, creating a sch…

  19. comment
  20. comment
    Comment #11133815

    Warning: Autoplay video.

  21. comment
    Comment #11131773

    "shoulder surf protection"?

  22. comment
    Comment #11130346

    No, you're saying "which of this limited set of companies are you going to authenticate with" instead. If you don't want to be guilty of taking users' agency away from their own tr…

  23. story
  24. comment
    Comment #11127590

    > I don't understand why they would trust over a dedicated authentication storage place but that's their choice. What if happens to be a security engineer, and happens to be Silk R…

  25. comment