Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
bigmac
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
bigmac
11y ago
Keywhiz is a good solution. See here for some background info: https://square.github.io/keywhiz/ Disclaimer: I worked on it.
32.
▲
by
bigmac
11y ago
Docker | San Francisco, CA | Full Time | Onsite | Software Security Engineer Docker represents a big opportunity to significantly improve security for every infrastructure taking advantage of it. Docker’s security team has broad responsibil
33.
▲
by
bigmac
11y ago
There's an in-memory cache that keeps the secrets locally even when the server disappears either due to downtime or network issues.
34.
▲
Square Open-Sources Golang Crypto Package Based on JWE/JWS
(github.com)
73 points
by
bigmac
12y ago
|
14 comments
35.
▲
by
bigmac
13y ago
Hopefully the latest batches have per-device unique keys (based on some centrally-known KDF) so a compromise of one doesn't re-enable such an exploit. Yes, that's how it works.
36.
▲
Parliament: A Secret Sharing Service
(corner.squareup.com)
4 points
by
bigmac
13y ago
|
0 comments
37.
▲
by
bigmac
14y ago
San Francisco, CA Fulltime Security Engineer, Security Intern At Square (squareup.com) we're looking for security experts excited about securing the future of payments. Security at Square is involved in all aspects of the stack: hardware, f
38.
▲
by
bigmac
14y ago
San Francisco, CA Fulltime Security Engineer, Security Intern At Square (squareup.com) we're looking for security experts excited about securing the future of payments. Security at Square is involved in all aspects of the stack: hardware, f
39.
▲
by
bigmac
15y ago
Square San Francisco, CA FULLTIME Security Engineer We're looking for security experts excited about securing the future of payments. Security at Square is involved in all aspects of the stack: hardware, mobile, infrastructure, networks, cr
40.
▲
Why We Pair Interview
(corner.squareup.com)
3 points
by
bigmac
15y ago
|
1 comments
41.
▲
by
bigmac
15y ago
I've been expecting this for awhile. At the LLVM developer's conference in November, there were tons of compiler engineers working on the ARM backend, but I didn't meet anybody working on the x86 backend. Granted, iOS is important and runs
42.
▲
by
bigmac
15y ago
This is completely unsurprising. The licensing agreements with the studios mandate these kinds of measures. If Google didn't do it, they wouldn't be able to play the game.
43.
▲
by
bigmac
15y ago
“About a month ago I was chatting on skype to a colleague about a payload for one of our clients,” he wrote. “Completely by accident, my payload executed in my colleagues skype client. That means this thing is either BS or it is an egreg
44.
▲
by
bigmac
16y ago
Javascript is too hostile an environment for crypto. How do you know your js crypto code wasn't modified in transit? You use SSL. Now that you're using SSL why do you need encryption in the js at all?
45.
▲
by
bigmac
16y ago
Square doesn't store any data at all. Currently, the app requires internet access to process the payments.
46.
▲
by
bigmac
16y ago
Take a look at this short video: http://ecorner.stanford.edu/authorMaterialInfo.html?mid=2649 It looks like an API is on the way, as one of their roadmap items. It should be no surprise that they're going to do an API, given that their C
47.
▲
by
bigmac
16y ago
Leaving off the top cryptographers from a list of security researchers seems a bit disingenuous. However, including cryptographers might make Colin's argument trivially obvious, since so many of the top crypographers come from mathematics
48.
▲
by
bigmac
16y ago
Stuxnet didn't really do anything to actively thwart reverse engineering. See here: http://rdist.root.org/2011/01/17/stuxnet-is-embarrassing-not... Truly obfuscated code will just plain cause the Hex-Rays decompiler to crash, producing a
49.
▲
by
bigmac
16y ago
I've considered joining a Martial Arts gym, because I thoroughly enjoy the competition -- I wrestled all the way through High School. However, I've convinced myself that it may be detrimental to my long term cognitive abilities. Do any HN
50.
▲
by
bigmac
16y ago
Indeed - Virus Total can be useful for this task: http://www.virustotal.com/
51.
▲
Stuxnet is Embarassing, Not Amazing
(rdist.root.org)
2 points
by
bigmac
16y ago
|
0 comments
52.
▲
by
bigmac
16y ago
Subscription media services are impossible without DRM. Many, many consumers enjoy these services, myself included.
53.
▲
by
bigmac
16y ago
Congratz to Eric and the rest of the team. Sounds like Movity really put together a great team. Case in point, any Django users out there will know of Zain Memon's work: he designed the Django admin interface.
54.
▲
by
bigmac
16y ago
Their idea to checksum the global variables is really clever. Many benchmarks and testsuites simply rely on verifying program output. They're able to verify a greater surface area of the compiler by ensuring that all the intermediate glob
55.
▲
by
bigmac
16y ago
My understanding is Blizzard plans to keep the details of the math secret because they don't want the system to be gamed. Considering how seriously people take SC2 I can hardly blame them for this decision. This raises the question of what
56.
▲
by
bigmac
16y ago
So, predictions on how long until Google buys these guys? I'd guess within the next 7 days.
57.
▲
by
bigmac
16y ago
Very cool term, sadly its totally unacceptable to use in English. I will never be able to describe someone who is overly obsessed with minute details as a "fagidiot" in America. The associations built into that term are just too political
58.
▲
by
bigmac
16y ago
I grow tomatoes on my fire escape in downtown San Francisco. I had to self-pollinate them with an electric toothbrush. I'm pretty sure this is due to the natural lack of bees in San Francisco, not because of the bee die-off due to this ch
59.
▲
by
bigmac
16y ago
When it comes down to it, these cables were leaked most likely due to Bradley Manning handing them over to Wikileaks. Thus, it was fundamentally a failure of the security clearance screening process that made this leak possible; a bad appl
60.
▲
by
bigmac
16y ago
A coworker of mine is adamant that the only safe way to buy 2600 is with cash.
More ›