Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jrozner
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
1.
▲
by
jrozner
1mo ago
I know Joel well and think a lot here is both accurate and well written. I led the Yahoo bug bounty program from 2023-2024 and was involved in it from about 2021. A major event that this glosses over is Covid which also happened right aroun
2.
▲
by
jrozner
2mo ago
Most people only do the simplest of math on a day to day basis. I’d bet that if you asked most adults to do something even remotely non-trivial (addition, subtraction, multiplication) a lot would have trouble without a calculator and/o
3.
▲
by
jrozner
4mo ago
This seems really cool with very underwhelming specs. They maybe enough for people just getting started, especially at that price point. I think if there are lots of ready to go projects and easily purchasable kits for parts this could be a
4.
▲
by
jrozner
6mo ago
People hated steam when it launched but you needed it to play CS 1.6. It made installing mods easier. Then HL2 released, orange box, and they were able to get a critical mass as they provided platforms support for other games. Steam got bet
5.
▲
by
jrozner
9mo ago
Fleet was a terrible product. I’m a long time jetbrains user and still use goland, rust rover, and clion. I was really excited when it got announced because I had had a lot of issues with vs code, extensions, and lsp at the time. I was hopi
6.
▲
by
jrozner
1y ago
Up or out generally stops once someone reaches engineer or sr engineer. Most of the time a jr engineer is going to need substantial mentoring and support. Them never moving beyond that point likely results in a net negative gain if you need
7.
▲
by
jrozner
1y ago
Whats the point of this over polars?
8.
▲
by
jrozner
1y ago
Unless he’s getting into a truly top tier school, have him go to a state university for much less. Community college and transferring is also an option but the social experience of going to a 4 year university is unique and fun. If you have
9.
▲
by
jrozner
1y ago
For the most part, everything in your last point is something you can’t solve with an app. Virtually all of that would be problematic meeting someone in any other way and for the most part is all within your control to change. Sure, there a
10.
▲
by
jrozner
1y ago
We’re leveraging ssh certificates which are backed by keys stored in a variety of hardware. For yubikeys we’re leveraging piv and the standard ssh tooling. We’re determining whether we’ll be able to use a pkcs11 implementation for TPMs and
11.
▲
by
jrozner
1y ago
Building Based Security ( https://www.basedsec.io ), a startup in the zero trust/identity space creating immovable, attestable, hardware backed identities that can be used for strong and continuous authentication but not move
12.
▲
by
jrozner
1y ago
I can understand the concern about having a second trusted party but think that the value of utilizing the standard ssh ca auth flow is worth the potential risk. If you require keys in attested hardware and verify that before issuing certs,
13.
▲
by
jrozner
1y ago
I think it's interesting they're choosing to use certificates this way. If they're already using certs, why not just leverage sshca auth? Also, at the end of the day, it's still effectively a bearer token. I founded a co
14.
▲
Paranoids' Vulnerability Research: NetIQ iManager Security Alerts
(yahooinc.com)
3 points
by
jrozner
2y ago
|
0 comments
15.
▲
by
jrozner
2y ago
Also an alum from WAY back (pre-A). One of the first things I did when I started was look at a different wrapping vuln.
16.
▲
Scaling Variant Analysis
(goingbeyondgrep.com)
3 points
by
jrozner
2y ago
|
0 comments
17.
▲
by
jrozner
2y ago
Why focus on SAML rather than OIDC2?
18.
▲
by
jrozner
2y ago
I agree that personal responsibility is important and both things can be true. I also think anyone who believes our taxes are going to go down if we don’t bail students out is delusional. With that belief, I’d rather my taxes directly impro
19.
▲
by
jrozner
3y ago
After reading the policy when the blog post came out, I think one negative thing about it is that it can self select for people generally later in their career or with a much bigger safety net. When you have a 10-20+ tech career and the mon
20.
▲
by
jrozner
3y ago
I applied almost two years ago. I am excited about what Oxide is doing and it felt like a fun opportunity. While I respect what they do around comp, for where I was in my life and goals I had set, it was going to be rough. I applied anyway
21.
▲
New Vulnerabilities in Ivanti EPM
(yahooinc.com)
1 points
by
jrozner
3y ago
|
0 comments
22.
▲
by
jrozner
3y ago
When using a resident/discoverable credential the authenticator is supposed to authenticate the user (using a pin, biometrics, etc.) This fulfills the multi-factor requirement. All passkeys/webauthn credentials are something you h
23.
▲
by
jrozner
4y ago
I have a similar experience (effectively failed out of CS and ended up with an BA in philosophy + minor in CS). For me it was the math courses more than anything else, I wasn’t interested, and preferred to spend my time snowboarding and par
24.
▲
Paranoids’ Vulnerability Research: PrinterLogic Issues Security Alert
(yahooinc.com)
3 points
by
jrozner
5y ago
|
0 comments
25.
▲
Adversary Simulators High-Fidelity Intelligence and Reporting Toolkit (Ashirt)
(github.com)
1 points
by
jrozner
6y ago
|
0 comments
26.
▲
by
jrozner
8y ago
My original option grant was for 0.00225%. I optimized for salary when I was hired, due to the stock at my previous two startups being worthless, and didn’t fight for more. Between series A and B we were going through some rough times as a
27.
▲
by
jrozner
8y ago
No. New company’s comp package was underwhelming but they didn’t want to negotiate. I consider it a blessing in disguise to not have handcuffs.
28.
▲
by
jrozner
8y ago
The current company I’m at just sold about a month ago for $140mil. I was one of the first engineers (the three of us originals all started at the same time) and started a few months after initial funding was raised. Between my purchased op
29.
▲
Lessons Learned Deploying a Generic CSRF Solution
(medium.com)
1 points
by
jrozner
8y ago
|
0 comments
30.
▲
by
jrozner
8y ago
Prevoty | Software Engineer | Los Angeles/San Francisco | Fulltime Prevoty is a Runtime Application Self Protection company founded in 2013 that builds language plugins to provide mitigation to security vulnerabilities without the need
More ›