Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ericalexander0
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
ericalexander0
1y ago
Security people will argue forever “defense in depth” this, “real world doesn’t match the study” that. Yawn. Here’s the hard truth: cybersecurity today is basically fashion. It’s not science, it’s herd behavior. The industry is still runnin
2.
▲
by
ericalexander0
1y ago
> Could a rogue agent theoretically run a destructive command? Sure. Have I seen it happen in weeks of usage? Never. I've been in cybersecurity over a decade, and this still blows my mind. It’s classic cognitive dissonance or just n
3.
▲
by
ericalexander0
1y ago
At the last job we deployed to thousands of nodes across AWS, Azure, and Aliyun. There was no unique needs across those environments, from a deploy perspective. There where some minor pain points from a config and monitor perspective. There
4.
▲
by
ericalexander0
1y ago
If you want alignment, set clear rules that everyone understands. At SpaceX, their spending policy was simple: If it helps us get to Mars faster, spend it. If not, don’t. That simple policy helped keep the whole company focused. Simpler rul
5.
▲
by
ericalexander0
1y ago
Most people and by extension, most businesses don’t think from first principles. They copy what others do because it’s easier. It reduces cognitive load. But that kind of thinking leads to cargo cults. People doing things that look right bu
6.
▲
by
ericalexander0
2y ago
I haven't seen anything useful in the agent space. I definitely haven't seen anything I would trust in a business process. At the same time, I'm constantly amazed at how accessible LLMs have made automating things with Python
7.
▲
by
ericalexander0
2y ago
Security is about real risk reduction, not chasing whatever’s trendy - but that's what most security teams do and then complain about the results. Most business functions are metric-driven. Security should be no different. The right ap
8.
▲
by
ericalexander0
2y ago
I look at this through the following perspectives: As a security engineer, this is pretty obvious - blindly handing over login credentials to AI agents? What could possibly go wrong? Feels like a ticking time bomb until courts start hashing
9.
▲
by
ericalexander0
2y ago
I see two possibilities here. Either Musk is a foreign agent attempting to cripple the US government or he's a student of Blitzscaling and Jim Collins' The Map. Incentives can help determine his motives. What could a foreign gover
10.
▲
by
ericalexander0
2y ago
I doubt they're no performers, they're likely selective performers. Issues like this can often be explained by Public Goods Game theory. If there's no economic incentive, then some participants will choose to not contribute o
11.
▲
by
ericalexander0
2y ago
The key is modularity with good interface design, then you have AI generate each component and play more of a QA role to validate each component is functional.
12.
▲
by
ericalexander0
2y ago
I code but my day job is closer to CISO. I've been working with react for years and one of the biggest pain points is the near immediate security debt you take on through the complex ecosystem that is node packages. That debt keeps gro
13.
▲
by
ericalexander0
2y ago
Cooling is a single DC factor with costs derived from electrical costs. In most DC build outs you're looking for favorable network peering (ie pipe size, latency, or both) and low electricity costs. If peering is the highest priority,
14.
▲
by
ericalexander0
2y ago
As a manager I'm always trying to figure out if my direct reports are vice or virtue motivated. With vice being money and title. Virtue being what you get to work and with who. In this context I'd say Grifters & Grinders are v
15.
▲
by
ericalexander0
2y ago
I've built security programs at 3 companies. This is how I would solve these problems. 1. SSO everywhere. Okta if budget is no concern and Keycloak if it is. 2. Password manager for the entire company. Even if it's possible to go
16.
▲
by
ericalexander0
2y ago
Having worked in adtech for 6 years I learned through many-many conversations with friends and family that 1) they don't care to understand how it all works and 2) they don't believe it influences them. Try to walk people through
17.
▲
by
ericalexander0
2y ago
The book Trillion Dollar Coach ( written by Eric Schmidt and other ex-Google leadership) has a first hand account of how they went from a philosophy of few managers to more. Surprisingly the debate was settled by impromptu interviews with I
18.
▲
by
ericalexander0
2y ago
Check out Beyond The Goal and Beyond The Phoenix Project for a deeper dive in this area. I work in cyber security and use many of the concepts often. The root cause of many poor outcomes are poor assumptions, prioritizing ideology over cust
19.
▲
by
ericalexander0
3y ago
So many questions. Why not reveal what sites/code this was tested on, so others can try to repeat? What was the false positive rate? Why didn't they compare results with commodity automated scanners like Burp or Zap?
20.
▲
by
ericalexander0
3y ago
This. I've established security programs at 3 companies over 10+ years. I've rarely encountered an engineer who didn't care. I've encountered many with competing priorities. What gets measured gets done. Establish the ri
21.
▲
by
ericalexander0
3y ago
My mind immediately goes to Bezos & "Resist Proxies". From a guy who has built security programs at 3 companies. https://www.aboutamazon.com/news/company-news/2016-letter-to...
22.
▲
by
ericalexander0
3y ago
Sometimes these events provoke regulators to take a closer look at the company. https://www.ftc.gov/news-events/news/press-releases/2023/11/...
23.
▲
by
ericalexander0
3y ago
Predictable based on a large body of knowledge. From Orson Scott Card's How Software Companies Die to David Packards HP Way. There's also Deming, Goldratt, and Jim Collins. https://medium.com/riow/how-software
24.
▲
by
ericalexander0
3y ago
This problem is not exclusive to Meta. It's the product of "big ball of mud" design. It relates to Dunbar's Number and the limitation of mental models.
25.
▲
by
ericalexander0
3y ago
https://docs.gitlab.com/ee/user/analytics/dora_metrics.html
26.
▲
by
ericalexander0
3y ago
When I read this it fascinates me how Plato's Allegory of the Cave continues to evolve in our modern digital world. Propaganda, visual witnessing, etc, etc - the theory stays the same, just the tools change.
27.
▲
by
ericalexander0
3y ago
Sounds like you want a government job.
28.
▲
by
ericalexander0
3y ago
https://archive.ph/2023.09.27-100255/https://www.nytimes.com...
29.
▲
by
ericalexander0
3y ago
Summary: A guy wrote a book about LLMs, prompt engineering, and how to write code to interface with LLM APIs. Oh, and you can use it to role play table top incident response exercises. IMHO the LLMs themselves are a better way to learn thi
30.
▲
by
ericalexander0
3y ago
https://archive.ph/2023.09.27-114901/https://www.wsj.com/tec...
More ›