Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ericalexander3
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
Rethinking how I share mental models in a pandemic
(ericalexander.org)
1 points
by
ericalexander3
6y ago
|
0 comments
2.
▲
by
ericalexander3
6y ago
Peter Senge has a great definition in The Fifth Discipline > Mental models are deeply ingrained assumptions, generalizations, or even pictures of images that influence how we understand the world and how we take action.
3.
▲
by
ericalexander3
6y ago
Isn't open source proof that you don't need buts in seats in the same office? If open source projects can do it, why can't most businesses? What's the limiting factor in business? Is it communication? Is it antiquated ma
4.
▲
2019 Breach Trends – Based on Open Source Data
(ericalexander.org)
1 points
by
ericalexander3
7y ago
|
0 comments
5.
▲
by
ericalexander3
7y ago
Interested in data on real world impact from these attack vectors? Hackerone has public data on how often they reward each type: https://www.hackerone.com/blog/hackerone-top-10-most-impactf... . You can also browse thr
6.
▲
by
ericalexander3
7y ago
>The great ones are a treasure: and they are rare. And in order to stay great, they regularly need to go back to the well to refresh their own hands-on technical abilities. Similar to principle 9 from the Toyota Way. >Grow leaders w
7.
▲
by
ericalexander3
7y ago
Keeping up with security news is important for situational awareness, but it can be time consuming. This is a tool I wrote for my own benefit to reduce signal to noise. It runs entirely on Github using pages and actions. Source: https:
8.
▲
Show HN: InfoSec News Aggregator
(ericalexander.org)
2 points
by
ericalexander3
7y ago
|
1 comments
9.
▲
by
ericalexander3
7y ago
Technology can bring benefits if, and only if, it diminishes a limitation. -Dr. Eliyahu M. Goldratt Goldratt was critical of ERP systems, not because they couldn't bring benefit; rather, because many businesses adopted through a cargo
10.
▲
by
ericalexander3
7y ago
SSRF to metadata service to S3 access was the entry point. There's a lot of focus on the SSRF and metadata service components but the S3/IAM component is possibly more intriguing. Did the role/account follow the principle of
11.
▲
by
ericalexander3
7y ago
U2F > TOTP > Any MFA > no MFA Why? About 23% of the classified breaches in this data set are due to compromised valid accounts and any MFA would probably have prevented the breach. Often security isn't about out running the be
12.
▲
by
ericalexander3
7y ago
Articles like this inspired this project: https://github.com/ericalexanderorg/SecurityBreach It's sensational to make a claim that's based on the opinion of a few people in the world, some who are motivated t
13.
▲
by
ericalexander3
7y ago
FUD article focusing on DDOS/Stresser/Booter incidents but doesn't share any data to show an upward trend on Christmas. Using this data on breaches we can see there's more incident/breach activity in October than an
14.
▲
by
ericalexander3
7y ago
That's not the Toyota way. From a Westrum "Three Cultures Model" perspective Toyota would fall into the Generative classification, not Pathological or Bureaucratic. Based on the discussion in the article I think Toyota is say
15.
▲
Show HN: Crowd sourced security breach data
(github.com)
2 points
by
ericalexander3
7y ago
|
0 comments
16.
▲
by
ericalexander3
8y ago
https://en.wikipedia.org/wiki/List_of_autodidacts
17.
▲
by
ericalexander3
8y ago
Coding test early in the recruitment pipeline. I've seen plenty of CS degrees on resumes that can't pass basic coding exercises/tests; at the same time, I've been impressed with the capabilities of new grads. I'm lo