Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jerematasno
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
jerematasno
11y ago
Compromised servers are detected and shutdown quickly? [ Citation needed ]
2.
▲
by
jerematasno
11y ago
If the server cannot be trusted, it will extract your encrypted data, since it serves up the code. The server, if compromised/subpoenaed, merely needs to serve you some JavaScript that sends home the encryption key, and your data is no
3.
▲
by
jerematasno
11y ago
Sorry, I really don't have any idea what our friends across the pond are doing with regards to hiring.
4.
▲
by
jerematasno
11y ago
(BTW, for those who miss him, Jeff is alive and well, but was super-busy with client work last week.)
5.
▲
by
jerematasno
11y ago
We are still working on new sets, though obviously the rate of new sets is pretty low. The mailing list is basically unmonitored at this point, but everything we've got is on the site. (This is a vast improvement on the previous state,
6.
▲
by
jerematasno
11y ago
> Penetration tests, when done by a good firm like Matasano, are incredibly useful, but lose their value the next time you push code. I'd like to nicely but firmly push back on this one, and have longitudinal analysis of clients
7.
▲
by
jerematasno
11y ago
Note that our work-sample tests are, not-insanely, done in the comfort of your own home, at your own pace, on your own schedule, and represent the work we actually do. As co-head of recruiting for NCC US (aka head of recruiting for Matasano
8.
▲
by
jerematasno
11y ago
Most of our candidates drop out before the work sample. On the other hand, almost none of our candidates are qualified to work for us when they initially apply. We make it really clear that there will be work samples before people even appl
9.
▲
by
jerematasno
11y ago
Sithu, Here are a couple of resources that I tend to hand out to startups that we do work for at Matasano. No charge :-) Not trying to be a salesperson, but I feel like most startups get more value out of sitting down with a security consul
10.
▲
by
jerematasno
11y ago
> The problem with my suggestion I fail to see the problem...
11.
▲
by
jerematasno
11y ago
In general, my feeling is that the Matasano process (which I currently manage) works outstandingly well where there isn't a flood of qualified candidates. If you have a glut of folks who are ready to start working, you can get away wit
12.
▲
by
jerematasno
12y ago
My policy (I'm co-in-charge of recruiting at Matasano/NCC, and a lot of folks report to me) is this: 1) Hire based on current ability, not potential. Hiring based on potential is a minefield that our whole process is designed to a
13.
▲
by
jerematasno
12y ago
We actually pre-pay on that. Candidates get an initial call with a very senior person to start. That call includes coaching on how to get through our interview process, and concludes with us sending free educational material (books, etc.).
14.
▲
by
jerematasno
12y ago
Getting an internship at Matasano is HARD . Unlike normal hiring, we are limited in the number of spots we can offer, and we also have a huge flood of candidates at once. I hate that it's so hard, and that we can't provide our us
15.
▲
by
jerematasno
12y ago
The way we do it now, the initial call person reads your resume, but we categorically do not reject based on the initial call (or the subsequent tech phone interview(s)). So, we get the advantage of being able to talk to someone about their
16.
▲
by
jerematasno
12y ago
At Matasano (slash NCC), we get a lot of candidates. We look at resumes so that we have something to break the ice with when we talk to the candidates. We do triage interns using resumes, because we get hundreds over the course of a few wee
17.
▲
by
jerematasno
12y ago
Hi, I've taken over from Tom for hiring at Matasano. There's a couple of things that you need for "diverse" recruiting (e.g. hiring women in tech): 1) A way of evaluating candidates that avoids mirrortocracy style instit
18.
▲
by
jerematasno
12y ago
These days we mostly send The Web Application's Hacker's Handbook and a link to microcorruption. (We do somehow get candidates which haven't heard of microcorruption.) Generally, we continue to endorse Tom's Amazon readi
19.
▲
by
jerematasno
12y ago
Speaking as one who stands to benefit from such a rule, I also think that requiring 3rd party validation is a bad idea. First off, it's always a race to the bottom, and secondly, there are not enough qualified people in the world to lo
20.
▲
by
jerematasno
12y ago
Certainly not required! To get a job in application security (at Matasano/NCC or anywhere, really) you should be demonstrably okay at web application, and have interests beyond webapps.
21.
▲
by
jerematasno
12y ago
We are literally drowning in intern applications. Either we haven't gotten to yours yet (likely), or we accidentally dropped it on the floor (also, sadly, possible, given the number of applications we've received this year). If th
22.
▲
by
jerematasno
12y ago
As co-head of recruiting for Matasano/NCC US, I endorse this approach! Bear in mind that we are pretty heavily focused on appsec, but of course for us appsec includes kernel work, sandboxes, firmware, etc, as well as web, mobile, custo
23.
▲
by
jerematasno
12y ago
We wrote a quick blog post on this. The main meaningful feature is a table of distros, versions, and whether they're not vulnerable, vulnerable but with a patch, or vulnerable with no patch yet. I am accepting requests for other distro
24.
▲
by
jerematasno
12y ago
Full blog post coming, but 14.04 was never vulnerable. glibc 2.17 was the last vulnerable version.
25.
▲
by
jerematasno
12y ago
It doesn't have to be internet accessible, AFAIK. If an attacker can get something to do arbitrary DNS lookups, I think it can be attacked. For instance, monitoring/log correlation software might be vulnerable.
26.
▲
by
jerematasno
12y ago
Blog post coming soon, but 12.04 is vulnerable, but has a patch available.
27.
▲
by
jerematasno
12y ago
I spent most of the day tracking down the status of various Linux distros. Blog post forthcoming, but the TL;DR is that you need to patch RedHat.
28.
▲
Phate: Investigations into Windows Phone 8
(chargen.matasano.com)
12 points
by
jerematasno
12y ago
|
0 comments
29.
▲
by
jerematasno
12y ago
That link is not wrong, but scrypt is probably significantly better than bcrypt, and PBKDF2 is not terrible, if you don't have a handy bcrypt/scrypt library.
30.
▲
by
jerematasno
12y ago
(Modifying the binary is much more fun to blog about, though.)
More ›