Hacker Newsnew | past | comments | ask | show | jobs | submit | jiva's commentslogin


Sorry but I am skeptical. Unless you’ve managed to reverse engineer “almost any IP camera”, I’ll believe this when I see it.


No comment in 3 days. I refreshed everyday to see if he replied.


I was ghosted by Tenable after spending about 48 hours completing their CTF challenges, so I just posted the interview questions/challenges and my solutions to my GitHub.

https://github.com/jiva/tenable_zero_day_assessment


It looks like you made the best of a frustrating situation and, at the very least, have an excellent piece for your portfolio.

With the rise in number of new security engineers all competing for few "security research" jobs (security research/hacking is the "I want to be a game developer" of security), you start getting into these convoluted hiring processes. Unlike standard software engineering, there aren't even remotely enough positions to accommodate everyone, so the bar can get absurdly high.

Honestly, if the team is asking CTF questions, they clearly want hires with previous CTF experience and should just do targeted hiring from the top teams at different conferences.

At least send people a free t-shirt if they complete the challenge.


> With the rise in number of new security engineers every year all competing for few "security research" jobs (security research/hacking is the "I want to be a game developer" of security)

I’ll believe it, curious what other options there are for all those other new “security engineers”. Compliance work?


If you're new, it's the same advice as any other field. Find a way to stand out. Build a portfolio, have great grades, come from a good university program, ping contacts from your alumni network, do bug bounties, find and fix issues in open-source, etc.


Did you happen to have these thoughts when the CEOs were white males?


I’m not hopeful they’ll release anytime soon considering how long the project has been in alpha.


I use gdb dashboard

https://github.com/cyrus-and/gdb-dashboard

It makes for a very pleasant debugging experience

https://i.imgur.com/iw21sbU.jpg


This is the best option I've tried so far. Thanks :)


Off topic but can you share your .tmux.conf? Thats hot af.



Thanks a lot @jiva <3


Generating virtual credit card numbers is kind of a big sell for me. I double any other credit card companies will have anything comparable to Apple's UI/UX of it either.


you can do this with citi and capital one, but yes the UI is terrible. citi requires flash player or an absolutely terrible java desktop app. capital one requires a browser extension


Bank of America's ShopSafe is similarly garbage - it's a flash app that halfway works.


I've never gotten it to work. At all.


what’s a better way to do it than a browser extension?


Why does it need a browser extension instead of just being a page on the bank's website?


My phone preferably.


If your SSH session gets locked, you can kill the session without killing the terminal window by pressing Enter, ~, . (period)


"there will be no updates, not even source-only security patches" from the man himself: https://mail.python.org/pipermail/python-dev/2018-March/1523...


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: