<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: gavingmiller</title><link>https://news.ycombinator.com/user?id=gavingmiller</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 13 Jun 2026 10:25:24 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=gavingmiller" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by gavingmiller in "1 bug, $50k in bounties, a Zendesk backdoor"]]></title><description><![CDATA[
<p>It’s a good callout, shouldn’t have editorialized like that.</p>
]]></description><pubDate>Sat, 12 Oct 2024 21:27:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=41822799</link><dc:creator>gavingmiller</dc:creator><comments>https://news.ycombinator.com/item?id=41822799</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41822799</guid></item><item><title><![CDATA[New comment by gavingmiller in "1 bug, $50k in bounties, a Zendesk backdoor"]]></title><description><![CDATA[
<p>Not even close to the point I was making: If you want to get taken seriously, write to audience.</p>
]]></description><pubDate>Sat, 12 Oct 2024 17:36:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=41820881</link><dc:creator>gavingmiller</dc:creator><comments>https://news.ycombinator.com/item?id=41820881</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41820881</guid></item><item><title><![CDATA[New comment by gavingmiller in "1 bug, $50k in bounties, a Zendesk backdoor"]]></title><description><![CDATA[
<p>The piece the author is missing, and why zendesk likely ignored this is impact, and it's something I continually see submissions lacking. As a researcher, if you can't demonstrate impact of your vulnerability, then it looks like just another bug. A public program like zendesk is going to be swamped with reports, and they're using hackerone triagers to augment that volume. The triage system reads through a lot of reports - without clear impact, lots of vulnerabilities look like "just another bug". Notice that Zendesk took notice once mondev was able to escalate to an ATO[1]. That's impact, and that gets noticed!<p>[1] <a href="https://gist.github.com/hackermondev/68ec8ed145fcee49d2f5e2b9d2cf2e52#aftermath" rel="nofollow">https://gist.github.com/hackermondev/68ec8ed145fcee49d2f5e2b...</a></p>
]]></description><pubDate>Sat, 12 Oct 2024 14:25:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=41819293</link><dc:creator>gavingmiller</dc:creator><comments>https://news.ycombinator.com/item?id=41819293</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41819293</guid></item><item><title><![CDATA[New comment by gavingmiller in "1 bug, $50k in bounties, a Zendesk backdoor"]]></title><description><![CDATA[
<p>zendesk is 6k employees, they have general council on staff</p>
]]></description><pubDate>Sat, 12 Oct 2024 14:20:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=41819263</link><dc:creator>gavingmiller</dc:creator><comments>https://news.ycombinator.com/item?id=41819263</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41819263</guid></item><item><title><![CDATA[New comment by gavingmiller in "Include diagrams in your Markdown files with Mermaid"]]></title><description><![CDATA[
<p>3 is hardly a sea shanty of vulnerabilities for a 7 year old library. I think you're conflating releases with vulns.</p>
]]></description><pubDate>Mon, 14 Feb 2022 21:17:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=30338469</link><dc:creator>gavingmiller</dc:creator><comments>https://news.ycombinator.com/item?id=30338469</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=30338469</guid></item><item><title><![CDATA[New comment by gavingmiller in "SolarWinds CEO blames intern for password leak"]]></title><description><![CDATA[
<p>In no way is this an interns fault. If your entire infrastructure relies on the secure password of ...<p><i>checks notes</i><p>... a single intern! then you're doing it wrong.</p>
]]></description><pubDate>Sat, 27 Feb 2021 15:09:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=26285281</link><dc:creator>gavingmiller</dc:creator><comments>https://news.ycombinator.com/item?id=26285281</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=26285281</guid></item><item><title><![CDATA[New comment by gavingmiller in "Slack account takeovers using HTTP Request Smuggling"]]></title><description><![CDATA[
<p>Anyone know if the `smuggler` tool used is available online? Can't find any reference to it in github or elsewhere, and I'm not familiar with it.<p>Edit: Found it here: <a href="https://github.com/gwen001/pentest-tools/blob/master/smuggler.py" rel="nofollow">https://github.com/gwen001/pentest-tools/blob/master/smuggle...</a></p>
]]></description><pubDate>Fri, 13 Mar 2020 16:43:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=22568735</link><dc:creator>gavingmiller</dc:creator><comments>https://news.ycombinator.com/item?id=22568735</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=22568735</guid></item><item><title><![CDATA[Clarifying ProtonMail and Huawei]]></title><description><![CDATA[
<p>Article URL: <a href="https://protonmail.com/blog/clarifying-protonmail-and-huawei/">https://protonmail.com/blog/clarifying-protonmail-and-huawei/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=20914585">https://news.ycombinator.com/item?id=20914585</a></p>
<p>Points: 210</p>
<p># Comments: 64</p>
]]></description><pubDate>Mon, 09 Sep 2019 01:50:49 +0000</pubDate><link>https://protonmail.com/blog/clarifying-protonmail-and-huawei/</link><dc:creator>gavingmiller</dc:creator><comments>https://news.ycombinator.com/item?id=20914585</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=20914585</guid></item><item><title><![CDATA[New comment by gavingmiller in "Thank u, next"]]></title><description><![CDATA[
<p>> Why’d he quit? ... he told me this: at each stage of a company’s growth, they have different needs. Those needs generally require different skills. What he enjoyed, and what he had the skills to do, was to take a tiny company and make it medium sized. Once a company was at that stage of growth, he was less interested and less good at taking them from there.<p>This is an aspect that gets overlooked in many businesses & careers. I've heard it phrased that companies go through 3 stages: Startup, Scale Up, Optimize. The above quote is a sub-stage of Scale Up. Some people are built for just a single stage and knowing how and where your skillset fits in is crucial to career happiness. As well as knowing when to encourage employees to move on.<p>Great post and I wish @steveklabnik continued success in his career!</p>
]]></description><pubDate>Mon, 07 Jan 2019 15:59:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=18846204</link><dc:creator>gavingmiller</dc:creator><comments>https://news.ycombinator.com/item?id=18846204</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=18846204</guid></item><item><title><![CDATA[New comment by gavingmiller in "The Devil's Hair Dryer: Hell is other people, with leaf blowers (2016)"]]></title><description><![CDATA[
<p>> TVs blaring in waiting rooms when you'd prefer to just sit in silence.<p>When I can, I turn the TVs off. No one has complained yet.</p>
]]></description><pubDate>Sun, 25 Nov 2018 04:15:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=18525441</link><dc:creator>gavingmiller</dc:creator><comments>https://news.ycombinator.com/item?id=18525441</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=18525441</guid></item><item><title><![CDATA[New comment by gavingmiller in "Losing 100 pounds in 276 days"]]></title><description><![CDATA[
<p>> Getting motivated to lift 2x a week is another issue...<p>Was in the same boat until I started doing group classes. Used that to build accountability, motivation, and a "vocabulary" of how the gym works. Now I could spend hours at the gym by myself and love it. Find what works for you, cuz lifting is a blast!</p>
]]></description><pubDate>Mon, 25 Jun 2018 14:43:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=17392776</link><dc:creator>gavingmiller</dc:creator><comments>https://news.ycombinator.com/item?id=17392776</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=17392776</guid></item><item><title><![CDATA[New comment by gavingmiller in "Ask HN: What mistakes in your experience does management keep making?"]]></title><description><![CDATA[
<p>Not training managers on how to manage.<p>When devs are promoted into management or team lead positions they are not given adequate training on what it means to manage / lead. Thus devs don't learn what good management is, and the stereotype of the bad manager perpetuates.</p>
]]></description><pubDate>Thu, 17 Aug 2017 15:14:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=15037472</link><dc:creator>gavingmiller</dc:creator><comments>https://news.ycombinator.com/item?id=15037472</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=15037472</guid></item><item><title><![CDATA[New comment by gavingmiller in "Cisco's Talos team analysis of WannaCry worm"]]></title><description><![CDATA[
<p>Password protected zip. And/or wrap in another zip is usually enough to thwart Gmail</p>
]]></description><pubDate>Sat, 13 May 2017 14:07:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=14331036</link><dc:creator>gavingmiller</dc:creator><comments>https://news.ycombinator.com/item?id=14331036</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=14331036</guid></item><item><title><![CDATA[New comment by gavingmiller in "List of Sites Affected by Cloudflare's HTTPS Traffic Leak"]]></title><description><![CDATA[
<p>As a happy customer of 1Password, it would be great to see you connect with Have I been pwned?[1] for watchtower notifications.<p>[1] <a href="https://haveibeenpwned.com/" rel="nofollow">https://haveibeenpwned.com/</a></p>
]]></description><pubDate>Sun, 26 Feb 2017 16:02:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=13737821</link><dc:creator>gavingmiller</dc:creator><comments>https://news.ycombinator.com/item?id=13737821</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=13737821</guid></item><item><title><![CDATA[New comment by gavingmiller in "DHH answers: What makes Rails a framework worth learning in 2017?"]]></title><description><![CDATA[
<p>corrected - thanks</p>
]]></description><pubDate>Tue, 24 Jan 2017 21:52:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=13475945</link><dc:creator>gavingmiller</dc:creator><comments>https://news.ycombinator.com/item?id=13475945</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=13475945</guid></item><item><title><![CDATA[DHH answers: What makes Rails a framework worth learning in 2017?]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.quora.com/What-makes-Rails-a-framework-worth-learning-in-2017/answer/David-Heinemeier-Hansson?srid=tfS&amp;share=1">https://www.quora.com/What-makes-Rails-a-framework-worth-learning-in-2017/answer/David-Heinemeier-Hansson?srid=tfS&amp;share=1</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=13475215">https://news.ycombinator.com/item?id=13475215</a></p>
<p>Points: 200</p>
<p># Comments: 130</p>
]]></description><pubDate>Tue, 24 Jan 2017 20:35:20 +0000</pubDate><link>https://www.quora.com/What-makes-Rails-a-framework-worth-learning-in-2017/answer/David-Heinemeier-Hansson?srid=tfS&amp;amp;share=1</link><dc:creator>gavingmiller</dc:creator><comments>https://news.ycombinator.com/item?id=13475215</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=13475215</guid></item><item><title><![CDATA[New comment by gavingmiller in "Rails 5.0.1 has been released"]]></title><description><![CDATA[
<p>I'd love to DM you with some questions about Toronto. Can you ping me via my profile info?</p>
]]></description><pubDate>Wed, 21 Dec 2016 14:41:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=13229423</link><dc:creator>gavingmiller</dc:creator><comments>https://news.ycombinator.com/item?id=13229423</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=13229423</guid></item><item><title><![CDATA[New comment by gavingmiller in "An insider's look at what he gave up to create a classic game"]]></title><description><![CDATA[
<p>> 'progressive' practices such as unlimited vacation<p>Unlimited vacation is not progressive and it is also unhealthy.<p>It causes feelings of guilt while on vacation. Often there's an unspoken obligated to check-in (email & chat) when on vacation. And leads to taking fewer vacation days not more. When leaving a company, they have no obligation to pay out accrued vacation days since there is none defined (this may be a Canadian thing). Additionally, it can also come with the unspoken culture of overtime, since it can easily be made up with "more time off".<p>Having worked with unlimited vacation, if I am ever offered it again, I will decline and negotiate defined vacation into my employment agreement.</p>
]]></description><pubDate>Thu, 02 Jun 2016 01:42:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=11819778</link><dc:creator>gavingmiller</dc:creator><comments>https://news.ycombinator.com/item?id=11819778</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=11819778</guid></item><item><title><![CDATA[New comment by gavingmiller in "A Tale of Security Gone Wrong"]]></title><description><![CDATA[
<p>Your solution of mapping to a grading system A,B,C,D; or terrible, crap, better, best was mentioned in another thread about this article. It's a common thought, however it's incorrect because you're still leaking substantial information about passwords. By storing entropy of any kind: whole number, graded, > threshold, etc you are weakening your password hash. This is completely unnecessary where better solutions exist: TFA</p>
]]></description><pubDate>Thu, 07 Apr 2016 22:56:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=11451362</link><dc:creator>gavingmiller</dc:creator><comments>https://news.ycombinator.com/item?id=11451362</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=11451362</guid></item><item><title><![CDATA[New comment by gavingmiller in "A Tale of Security Gone Wrong"]]></title><description><![CDATA[
<p>It's an assumption on my part, and anecdotally a correct one. Having included this entropy example in a number of talks and asking the audience what's wrong, the majority of the technical audience did not know, nor did they have an appropriate guess.</p>
]]></description><pubDate>Thu, 07 Apr 2016 22:49:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=11451320</link><dc:creator>gavingmiller</dc:creator><comments>https://news.ycombinator.com/item?id=11451320</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=11451320</guid></item></channel></rss>