Live data from Hacker News

At Blind, a security lapse revealed private complaints from tech employees

techcrunch.com

131–140 of 141 posts

Re: At Blind, a security lapse revealed private complaints from tech employees

#131

Earlier quoted context omitted.

It's cool that you jumped on the opportunity to explain how password hashing works. However, the reporter actually cracked hashes, so we can bypass all of this discussion and plainly see the hashes were insecure. And for what it's worth: > To be secure the salt must be stored in a different location from the stored hashes and the salt value should not be statically visible in the source code provided a source code co…

You cannot crack a hash though. It is just a string of fixed length. Nobody says crack a string because it sounds ridiculous. > Your salt can be totally public if you're using a robust key derivation function. That is a deliberate strawman. If your salt is based on keys there is still information you aren't exposing even if you are exposing the salt itself.

Uh, what? You can obviously crack a hash digest, and this is standard nomenclature used in both industry and academia. It simply means you've broken preimage resistance or collision resistance in practice. What exactly do you find controversial about this?

And your second paragraph doesn't follow. What I said isn't a strawman attack, it's a basic observation. If you're not using a secure key derivation function, a private salt will not save you. If you are, the salt can be public and there is no meaningful degradation in security whatsoever - you could even prepend or append it to the digest if you'd like.

As a broader point, what you're saying about fixed-length strings is incorrect. Hash functions need not output strings of fixed length. The formal definition of a hash function also admits functions of the form:

    H: {0, 1}^* -> {0, 1}^*
not just functions of the form:

    H: {0, 1}^* -> {0, 1}^n.
Or in other words, the codomain need not be finite, and the range can be variable. Keccak (SHA-3) is an example of a hash function which provides variable-length output instead of fixed-length output (i.e. via the sponge construction).

Re: At Blind, a security lapse revealed private complaints from tech employees

#132
post #130

Using Blind with your company email on the company WiFi seems really dumb? Maybe I'm paranoid, but I act as though everything that goes through my company WiFi and on my company computer is being tracked and stored in some database forever under my name. And I assume the company email is used to send you a verification email, which means your employer is now tipped off to the fact that you're using a site to anonymou…

You can't use Blind without giving them your company email. But yeah, you can reasonably assume that your company can track who received Blind invites. The WiFi bit doesn't matter much assuming Blind uses SSL (though I've never checked). Your company could see that you've connected but not what you've posted or read.

Many companies terminate their internal/corporate TLS traffic on a reverse proxy they control. This typically lets them see employee internet activity in the clear.

Re: At Blind, a security lapse revealed private complaints from tech employees

#133
post #130

Earlier quoted context omitted.

You can't use Blind without giving them your company email. But yeah, you can reasonably assume that your company can track who received Blind invites. The WiFi bit doesn't matter much assuming Blind uses SSL (though I've never checked). Your company could see that you've connected but not what you've posted or read.

Many companies terminate their internal/corporate TLS traffic on a reverse proxy they control. This typically lets them see employee internet activity in the clear.

This works only if you're on a company-controlled device. If you're on a device they do not control, you won't have their root cert installed and this MITM attack is infeasible.

If you're using a company-controlled device, you should of course assume they can see all of your network activity. They could easily be capturing all of your activity on the device itself without any MITM attack.

Re: At Blind, a security lapse revealed private complaints from tech employees

#134
post #54

Earlier quoted context omitted.

I spent more time reading the threads than I should have, it's strangely addicting. I now feel naive for thinking that the people working at the big tech companies have a certain base level of "all-round" skills. In no way I expected so much cynicism, narcism and lack of empathy! Isn't this showing up in interviews? Or should it just be seen as online trolling and venting?

> Isn’t this showing up in intervires? That depends on the interview, isn’t it? In my on-site with one of the companies, I was asked hard algorithm questions in four out of five rounds, and then one system design round. I doubt anything related to personality would show up

You can read plenty of behavioral signal from how candidates interact with interviewers while solving hard technical challenges. But many companies don't really invest much into training interviewers how to effectively interview and gather useful signal or calibrating their evaluation to the goals and standards of the organization.

Re: At Blind, a security lapse revealed private complaints from tech employees

#135

Earlier quoted context omitted.

My first look at Blind rated cities to work in by how hot/available women were there (e.g. comments like "SF sucks, you have to settle on dating uglies" or "NYC women are so much hotter than SV women, no contest where to live"). The question asked to the Blind community was just "where would it be better to live long term" or something completely not to do with dating or women, but the majority of responses were abou…

> outright racism against Indians in particular. Racism is not illegal and should not be suppressed. It does should also not be encouraged, however. At the end of he day, people do not have the right to feel good. > My first look at Blind rated cities to work in by how hot/available women were there (e.g. comments like "SF sucks, you have to settle on dating uglies" or "NYC women are so much hotter than SV women, no…

Vouched. If we're going to talk about Blind of all things (and the kinds of sentiments it reveals, incites, or amplifies) we can't bury those perspectives.

Sure I'd rather keep most of HN clean of vitriol, but a thread about it? We need to challenge, understand, and dissect these perspectives, not disregard them.

Re: At Blind, a security lapse revealed private complaints from tech employees

#136

Earlier quoted context omitted.

It's pathetic, you see some of the most depraved, narcissistic members of the tech society there. The quality of the discourse you can guess is shockingly bad, and most people are from the Bay area. Is this an accurate representation of people in the Bay? Or is it just a platform for toxic folk to hang out?

Having been on blind for nearly a year, I find it interesting how weak the rumor mill on Blind is. The real rumor mill at most large companies basically knows everything that is going on; blind is mostly junior programmers flaunting often made-up compensation and scrambling to gain a low-tier grade level. Blind could have been an opportunity for them to get direct and honest insight into how the sausage is made but i…

Exactly my thoughts!

Re: At Blind, a security lapse revealed private complaints from tech employees

#137
post #55

Earlier quoted context omitted.

There's so much misinformation on it I find it hard to trust. I prefer to go with H1B salary databases.

H1B databases tend to underestimate. My entry in the database lists my starting salary from a few years ago, with no bonuses, options/rsus, or promotion/raises.

Though you have a very solid lower bound number from the database. It is just important to understand what that number is.

Re: At Blind, a security lapse revealed private complaints from tech employees

#138
post #54

Earlier quoted context omitted.

It's pathetic, you see some of the most depraved, narcissistic members of the tech society there. The quality of the discourse you can guess is shockingly bad, and most people are from the Bay area. Is this an accurate representation of people in the Bay? Or is it just a platform for toxic folk to hang out?

I spent more time reading the threads than I should have, it's strangely addicting. I now feel naive for thinking that the people working at the big tech companies have a certain base level of "all-round" skills. In no way I expected so much cynicism, narcism and lack of empathy! Isn't this showing up in interviews? Or should it just be seen as online trolling and venting?

Am surprised as well, its so easy to spot for those traits in an interview - apply some pressure or ask some pointed questions. I've weeded out those folk as an interviewer.My feeling is that the Bay Area has a huge tech engineer shortage and companies throwing absurd amounts of money/benefits has bred a culture of entitlement.

Re: At Blind, a security lapse revealed private complaints from tech employees

#139

Earlier quoted context omitted.

Correct, it's very easy to find out who in the company is on Blind -- most corporations use Exchange. Easy as this: http://ivan.dretvic.com/2011/05/remove-specific-email-from-a... The article says "remove" but before you remove, you need to list all employees that have that email - if you just make a test account or look for the domain then you can pipe the results to a text file and that's your list of company insid…

Posted above but someone at my org sent an invite to everyone. Having a list of everyone that received an invite does not mean they signed up...

No, but people who did have an email confirmation. You can search not only from domain sent, but from subject and body.

Re: At Blind, a security lapse revealed private complaints from tech employees

#140

Earlier quoted context omitted.

Posted above but someone at my org sent an invite to everyone. Having a list of everyone that received an invite does not mean they signed up...

No, but people who did have an email confirmation. You can search not only from domain sent, but from subject and body.

What? The invite email from blind is the email confirmation from blind...
Post reply on HN