Hacker Newsnew | past | comments | ask | show | jobs | submit | blanket_the_cat's commentslogin

This is awesome. I've been building almost the exact same project, along almost the same timeline (based on the commit history). Mostly an excuse to learn more advanced Bash, and Linux Internals/Features I've never had a good excuse to explore. Gonna release next week. Hope I get as warm a reception. Kudos on an awesome project!


As someone with an insatiable appetite for learning/being challenged, no kids, no serious relationship, and no equity in anything, I will walk almost immediately (with notice/finish the project/etc. of course) if I don't feel properly challenged. That said I don't feel like I'm a great person to give long term advice other than this..

I operate this way, because when I've stayed at places where my motivation began to wane, invariably, it then began swiftly descend, and then plummet incomprehensibly. The worst part was never going in to the office I had come to feel less than nothing about, it was bringing the lack of motivation home, because it inevitably followed me into my personal life, and stripped me of the desire to do the things I love.

That's where I draw the line.

Everyone is different of course. I'm sure you have good reasons for staying, and I sincerely wish you best figuring it out as someone who has been shackled very firmly with some golden-handcuffs to roles that ultimately offered me nothing more than big checks, and a sense of futility.


And we're surprised? Didn't we learn anything from the 90's? No amount of diligence sitting at a desk, carefully evaluating the implications of the placement/thoroughness of your user input sanitation, adjusting the settings in server configuration files, preventing your employees from using removable media and accessing outside sites... No threat model, seriously none.. ever.. will ever.. Stop a young Angelina Jolie on rollerblades from gaining access to your evil corporations's super computer and thwarting your carefully laid, super-villain plan.


There's so much sarcasm in your post that I'm not sure I understand your point. Can you clarify?


Let me rephrase that; Skipping reindexing punch cards: If your adversary can write some ASM to get the EIP to point to a malicious instruction, they can instruct your system to do something you don't necessarily want it to do. Then our homies at bell labs built C, as a layer of abstraction to ASM. With C, your adversary has several ways to accomplish getting the EIP to his malicious instruction. Then, over the years, many brilliant, incredible minds, (no sarcasm about that. None.) have built abstractions to simplify C, and then built abstractions on top of those abstractions, and then abstractions to simplify those abstractions. (I'm totally not even going to touch networking protocols) There is decades, of building systems with flaws, on top of systems with security flaws, (which admittedly wasn't as much of a concern to anyone, as providing the functionality to accomplish objectives, business and otherwise) ... literally, like over half a century of this. So then these middle-management suits, operating with "LEAN 6-Sigma" misconceptions about the nature of the world, expect a kid, with a degree in anthropology (not knocking the study) to run through a 12-week intensive program, and be able to write code for a production system, with perhaps 2 people on their dev team of 8-16, and 3 folks in devops/IT who understand security to be able to proof all of that code, and make sure that your Gibson is bulletproof? It's unrealistic. If she wants to hack your Gibson, she's going to hack your Gibson. We're all going to attempt to stop that, and after we've failed, we will spend days filling out reports, talking to feds, and mitigating the damage. But we're continuously building onto a flawed mechanism, with another flawed mechanism. I mean, do you know any civil engineers who would say, "Oh hey this foundation is cracked, let's build something that tries to patch those cracks, and when that's broken, we'll build another level on top of that, and let's just obfuscate what's really going on underneath everything so that nobody who uses the building realizes it's unstable, and just hope it doesn't get too windy, or that there is an earthquake." ? Ipso Facto: When you launch some ransomware, that threatens the software reading a gyroscope to tip over an oil tanker if you aren't paid $1,000,000, and try to blame it on some kids who's only crime was curiosity, they will find a way to subvert the carefully measured security mechanisms you have put in place, to not only clear their names, and prove beyond the shadow of doubt that it was in fact YOU, who hatched this terrible plot, but also save the environment.

Sorry, I should have said that to begin with.


> I mean, do you know any civil engineers who would say, "Oh hey this foundation is cracked, let's build something that tries to patch those cracks, and when that's broken, we'll build another level on top of that, and let's just obfuscate what's really going on underneath everything so that nobody who uses the building realizes it's unstable, and just hope it doesn't get too windy, or that there is an earthquake."

No, but civil engineers say stuff like "What's the likelihood that a 9.5 earthquake will his this area? What about a 5?" and model their designs on that. That's the point behind threat modelling - if a nation state actor decides they want to 'hack your Gibson' that's one thing, but if you're a bank than it may be that your most likely threat is employees or contractors stealing customer data. So you put your effort into protecting against those threats as well.


I completely agree. It's strange to me that people are so scared of 'all of the hackers'. It's not like everyone with a black belt in karate runs around beating up everyone they see. Personally, everyone I know who has a deeper understanding of computer security, is so caught up in their curiosity, and getting 'that next trick' (more like skateboarders) that they don't even have a trace of the inclination, the time, or the threshold for the risk of prison time as it would interfere with their research, to plot and execute the type of stuff that people are so worried about.


You might like this talk on historical computer viruses and the shift from hobby to business in the 2000's. [0]

[0] https://www.youtube.com/watch?v=yswPIwDFYDY


It's true that there are lots of white-hat hackers, but there are also lots of black-hat ones, many of them, I gather, associated with criminal organizations -- and as Retric points out, the Internet allows attacks to come from anywhere on the planet. I don't think it's responsible to suggest that people are unnecessarily worried about the problem.

(Full disclosure: I work in the computer security industry.)


Yes. This isn't even a question. The answer is yes. The ubiquitous 'clean, modern, "Tech is neat! :D Business and advertising! :D Everything is safe! :D" aesthetic' is wrong. It's a monolithic lie, and we all know it.

The biggest contributing factor to the decline of the cyberpunk aesthetic in the 80's-90's was how quickly it became realism. If you read a William Gibson novel now, it would be like reading William Faulkner in the 1800's.

(I know Faulkner didn't publish in the 1800's. don't go there, this is my reply and that means I decide how time works here.)

The implications of the use of the advanced tools we build on the individual, and the species as a whole, is rarely considered with the gravity it deserves, at least by the vast majority of end users, I believe, in large part, because capitalism is predatory, and subsequently the tools it uses to accomplish it's end must be uniformly masked, behind a layer of safe aesthetics. A revival of the cyberpunk aesthetic in general, which paints technology as dangerous, empowering, and hints that the deeper into the technical details you get, the more empowered you become, would be a welcome return to realism from the magazine glossy, UI/UX of modern services. I mean seriously, this "Mumblecore" jargon and friendly faces on services which, let's be frank here, are simply the injections of profit and information siphoning mechanisms (the successful ones anyway) into monetary transactions for goods and services, and exchanges of information, between people, which already existed, in exchange for a razor-thin layer of convenience, and a gross distortion to their psychological faculties for perceiving value, to the end of contributing to the centralization of money, thus access to resources, and data, thus the ability to derive information, into the hands of a few, and creating (I'm trying my best to tone down the hyperbole here) impermeable veil of branding, that obfuscates as completely as possible, what anything actually is, or does.

(Don't go there. It's my reply, that means I can nest as many clauses in a statement as I want.)

If your blog even piques someone's curiosity, or contributes peripherally to a compulsion to dig deeper into how the layers of complex systems underlying the mechanisms we use to interact with the world now work, it was worth every minute you spent on it up to that point. Seriously, do it.

Speaking from personal experience, if you had shown me an ad for a "coding bootcamp" when I was 10, I would have chosen.. literally anything else to get into. Fortunately, I got my hands on a copies "Hell: A Cyberpunk Thriller", and "Shadowrun" instead. The sentiment of that art, the feeling of those ideas, with regards to technology, has kept my interest alive through day after day of questioning whether or not this specific impending bout of 'meeting business requirements' in which I am about to engage means I am a terrible person.

Just do it dude. You know you want to.


What this data definitively effectively demonstrates is that only about 1/5 of developers/engineers are taking a lunch. Way to go! Keep up the hard work guys!


Cool, now you can help develop clever mechanisms to exfiltrate information and wealth from end users and consolidate capital into the hands of those who already possess more than they need, from the picturesque, rolling green hills of sunny New Zealand... Wake me up when the tech scene in Monrovia is booming out of control.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: