san86's comments

san86 | 12 years ago | on: Salted Password Hashing – Doing it Right

IMO Hashing on the client side is a terrible idea. There is now no way for the application to check the complexity of the password on the server side. Relying on client side controls to do the same is almost useless.

san86 | 12 years ago | on: Evading Airport Security

"it's not terribly different from a random attack in the street or a shopping mall" You are right. However, the one difference is the reaction to an attack. It is fairly straightforward (these days) to get responders on the scene in a mall. A shooting or knife fight in an airplane is much harder to contain or react to.

Overall though, I agree with Schneier about the need for intelligence replacing TSA check points.

san86 | 12 years ago | on: This Google ad has moved people to tears across India and Pakistan

"This Google ad has moved people to tears across India and Pakistan"

Probably not all across India. I am from the south and neither me nor my ancestors have any personal experiences from the partition. Don't get me wrong.. this is a great ad and I understand the emotion behind it. but this is only as moving as a similar story on the Israel-Palestine border(ok maybe a little more because of my high school history books and representation in popular culture). Culturally, South India is more seperated from the North compared with North India (Punjab, Delhi, Kashmir) and Western regions of Pakistan.

To me this is a well produced ad which highlights the troubles of a particularly cruel time in India's history. Nothing personal about it.

san86 | 12 years ago | on: The Mission of Tesla

I did not see Elon complaining when a car launch got so much attention from the press. This just seems to be the other side of the same coin. This happens to every runaway success. Remember the "death grip" nonsense for iPhone4 and how it was blown out of proportion? Media loves the story of a man who worked against all adds to build/create something amazing. Unfortunately, they love "the fall of the guy" even more.

san86 | 12 years ago | on: Microsoft does away with stack ranking

I kinda like what my employer does. There is a 1-5 ranking, but the distribution/buckets for bonus is determined after the reviews are complete. Of course, the concern here is that management "can" slot the buckets in a way that suits them, but I trust them enough to not do that.. Due to this, no one knows "what needs to happen to get X bonus".. everyone is just trying to do their best to get to the highest score and the amount of cash you get depends on what bucket you fall under

san86 | 12 years ago | on: The way tech covers Apple is ridiculous

A good point to note is that none of the major reports on snowden leaks came from tech journalists. The best op-eds and reporting came from the Guardian, WaPo and other main stream outlets. This speaks volumes about the path taken by Tech Journalists. Having said that, I am not sure tech news sites (mashable, techcrunch, cnet etc) are capable of "newsie" stuff. A lot of the top "Reporters" who established the industry were techies first, journalists next. We need more traditional journalists understanding and writing about the tech industry (not in a naive way, which is what happens in traditional outlets these days) in a competent manner. This will probably lead to the kind of journalism the author hopes for

san86 | 12 years ago | on: Programming is a Terrible Job

I am not a programmer any more but working in the industry (InfoSec).. I remember a really smart guy who worked with us said he would be happy with 8-10 weeks of really exciting work each year. I agree with him.. if I have 8-12 weeks of really cool work that challenes me and the rest of the year is average, mundane work.. I will take it.

san86 | 12 years ago | on: Google timer

it's times like these where I wish they still had the "Beta" in their logo.. turns out "timer for 23 hours 99 minutes" breaks it too :P

more testing google.. more testing

san86 | 12 years ago | on: Google timer

I think the "tailoring to me" problem can be solved by logging out of google and doing the search (or search in incognito mode if you are a chrome user). However, I wish there was a way to turn off personalized search. That way, Google can remember what I searched (when I am signed in) for but not give me tailored results..

san86 | 12 years ago | on: Chaos Computer Club breaks Apple TouchID

The problem is not so much what CCC has done, but CCC has started. In the days/month ahead.. there is now a possibility of building a more practical attack. Remember the firefox plugin which allowed users to steal FB user sessions in a cafe with Free WiFi (or any WiFi hotspot)? That wasn't a new attack.. just made an existing attack easier (and hence caught a LOT of attention).

The threat is similar. Now there is an exploit.. now the collective security researcher (and hacktivist) will work to make the hack easier by building a tool.. THERE lies the real danger.

I still commend Apple for trying. The real issue will be if I can steal the "Hash" of the fingerprint and reverse it to know who it is... so far TouchId has done well. The way that happens, Apple users will need to rethink using TouchID

san86 | 12 years ago | on: If Amazon is the future of work, then be afraid

The contracting culture is indeed awful. It gives companies a way to fire workers without making the headlines. Also let's them not dirty their hands with benifits. But it's unfair to blame Amazon alone. Many organizations do this, including the US Federal Government. The DC metro area is filled with offices where the "employees" walk in and the "contractors" badge in. The tech contractors still make handsome cash, but the job scurity is not where it should be

san86 | 12 years ago | on: A Low-Tech Mosquito Deterrent

yeah.. but I'd expect a publication of such reputation to dig deeper than that. The ideas mentioned don't even scratch the surface. Hence the reference to "4 year olds".

san86 | 12 years ago | on: A Low-Tech Mosquito Deterrent

awesome stuff NY TImes. You just wrote an article about something every 4 year old in India (and every other tropical country) is well aware of

san86 | 13 years ago | on: Why Zuckerberg’s Lobby Is Collapsing Outside Of DC

My beef is with the lack of details FWD.us provided. If you want to look at how to grow a grassroot movement, look at Ron Paul. I certainly don't agree with Paul's policies, but he provided his opinions on things that matter to him in excrutiating detail. Instead of doing that, FWD.us provides vague descriptions of what they support. I would love to know what their stand on each of the major sections of the senate proposal is. Do they agree with all of it? If not, which parts do they not agree with? What's their proposed fix? Which ammendments do they support? Tehre are no answers to these questions. I am done seeing successful people talking about what an awful time they had succeding because of the issue. It was endearing at first, now it's boring (I am one of those immigrants who is currently suffering a little bit due to messed up policies, so I am sensitive to the sufferings.. but the videos are just annoying)
page 1