<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: jrozner</title><link>https://news.ycombinator.com/user?id=jrozner</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Mon, 14 Sep 2026 20:17:10 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=jrozner" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by jrozner in "What Happened to HackerOne?"]]></title><description><![CDATA[
<p>I know Joel well and think a lot here is both accurate and well written. I led the Yahoo bug bounty program from 2023-2024 and was involved in it from about 2021. A major event that this glosses over is Covid which also happened right around this time as well. Covid killed travel (and budget) which in turn made it impossible to do the live events. A lot of companies ended up shifting to virtual live events which just never delivered on the same value, scale, or impact.<p>When COVID restrictions were lifted, travel and t&e budgets just never returned. Layoffs started happening and what were lavish, expensive events just couldn’t happen anymore. Hackerone charged for and likely made a lot of money on these events. I think a lot of what is talked about in the article is true but I think Covid is a big part of the why that led to it.</p>
]]></description><pubDate>Mon, 10 Aug 2026 07:44:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=49240584</link><dc:creator>jrozner</dc:creator><comments>https://news.ycombinator.com/item?id=49240584</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49240584</guid></item><item><title><![CDATA[New comment by jrozner in "Are we offloading too much of our thinking to AI?"]]></title><description><![CDATA[
<p>Most people only do the simplest of math on a day to day basis. I’d bet that if you asked most adults to do something even remotely non-trivial (addition, subtraction, multiplication) a lot would have trouble without a calculator and/or make a large number of mistakes. That’s probably fine because it’s unlikely most adults are all of a sudden going to have to do non-trivial math without a calculator. That probably isn’t the case for people who are having agents do effectively everything for them in their lives</p>
]]></description><pubDate>Tue, 14 Jul 2026 17:37:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=48910344</link><dc:creator>jrozner</dc:creator><comments>https://news.ycombinator.com/item?id=48910344</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48910344</guid></item><item><title><![CDATA[New comment by jrozner in "NLAB: The worlds smallest electronics lab"]]></title><description><![CDATA[
<p>This seems really cool with very underwhelming specs. They maybe enough for people just getting started, especially at that price point. I think if there are lots of ready to go projects and easily purchasable kits for parts this could be a really great intro for cheap</p>
]]></description><pubDate>Wed, 03 Jun 2026 07:38:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=48381063</link><dc:creator>jrozner</dc:creator><comments>https://news.ycombinator.com/item?id=48381063</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48381063</guid></item><item><title><![CDATA[New comment by jrozner in "Epic Games to cut more than 1k jobs as Fortnite usage falls"]]></title><description><![CDATA[
<p>People hated steam when it launched but you needed it to play CS 1.6. It made installing mods easier. Then HL2 released, orange box, and they were able to get a critical mass as they provided platforms support for other games. Steam got better. It’s still not great but they have so much market share that basically any PC gamer already has it. Epic wants some of that money. The problem is nobody wants to install another store and they aren’t doing anything to improve gamer’s experience other than giving away games and having some exclusives. They’ll never hit the critical mass needed that way.</p>
]]></description><pubDate>Tue, 24 Mar 2026 21:48:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=47509904</link><dc:creator>jrozner</dc:creator><comments>https://news.ycombinator.com/item?id=47509904</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47509904</guid></item><item><title><![CDATA[New comment by jrozner in "JetBrains cancels Fleet"]]></title><description><![CDATA[
<p>Fleet was a terrible product. I’m a long time jetbrains user and still use goland, rust rover, and clion. I was really excited when it got announced because I had had a lot of issues with vs code, extensions, and lsp at the time. I was hoping jetbrains was going to build something competitive but it never materialized. Rather than building something lightweight and fast on a native ui toolkit with faster analysis engines they basically built on top of a lot of the tech that was the bad parts of their existing IDEs. important features and the ability for community extensions to fill them never came to fleet which meant it never could replace other tools for real work and jetbrains seemed to focus on building LLM features to capture the hype rather than fixing the issues people have with their existing products. Instead they have mediocre ai features that are essentially commoditized and IDEs that are under invested in that are sluggish. In terms of full batteries included IDEs they’re still probably the best, but they’re losing a lot of the market.</p>
]]></description><pubDate>Sat, 13 Dec 2025 18:41:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=46256849</link><dc:creator>jrozner</dc:creator><comments>https://news.ycombinator.com/item?id=46256849</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46256849</guid></item><item><title><![CDATA[New comment by jrozner in "There is a huge pool of exceptional junior engineers"]]></title><description><![CDATA[
<p>Up or out generally stops once someone reaches engineer or sr engineer. Most of the time a jr engineer is going to need substantial mentoring and support. Them never moving beyond that point likely results in a net negative gain if you need another person always available to provide that for their entire time there if it goes beyond 1-2 years.</p>
]]></description><pubDate>Tue, 30 Sep 2025 06:43:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=45422617</link><dc:creator>jrozner</dc:creator><comments>https://news.ycombinator.com/item?id=45422617</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45422617</guid></item><item><title><![CDATA[New comment by jrozner in "SedonaDB: A new geospatial DataFrame library written in Rust"]]></title><description><![CDATA[
<p>Whats the point of this over polars?</p>
]]></description><pubDate>Wed, 24 Sep 2025 16:50:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=45362953</link><dc:creator>jrozner</dc:creator><comments>https://news.ycombinator.com/item?id=45362953</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45362953</guid></item><item><title><![CDATA[New comment by jrozner in "Ask HN: Would you get a CS degree today?"]]></title><description><![CDATA[
<p>Unless he’s getting into a truly top tier school, have him go to a state university for much less. Community college and transferring is also an option but the social experience of going to a 4 year university is unique and fun. If you have something local where he can live at home or work enough while in school to cover part of the expenses, great. Spend $30-40k instead. I went to a fine state school in California and have talked to a lot of CS grads. I’ve rarely seen significant value add for paying more for a mid tier school than whatever the cheaper average option is.</p>
]]></description><pubDate>Mon, 11 Aug 2025 03:19:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=44860513</link><dc:creator>jrozner</dc:creator><comments>https://news.ycombinator.com/item?id=44860513</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44860513</guid></item><item><title><![CDATA[New comment by jrozner in "Ask HN: Why are dating apps so bad? Why hasn't anyone made a good one?"]]></title><description><![CDATA[
<p>For the most part, everything in your last point is something you can’t solve with an app. Virtually all of that would be problematic meeting someone in any other way and for the most part is all within your control to change. Sure, there are limits to what you can do about conventional attractiveness but there is a lot within your control for most people. Most of those issues you brought up are things that the vast majority of people don’t want in a partner no matter how you meet them. If you like those attributes about yourself you might eventually find someone compatible but if you don’t, most/all of those are things you can address by going to therapy and working on it.</p>
]]></description><pubDate>Mon, 02 Jun 2025 00:16:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=44154814</link><dc:creator>jrozner</dc:creator><comments>https://news.ycombinator.com/item?id=44154814</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44154814</guid></item><item><title><![CDATA[New comment by jrozner in "Ask HN: What are you working on? (March 2025)"]]></title><description><![CDATA[
<p>We’re leveraging ssh certificates which are backed by keys stored in a variety of hardware. For yubikeys we’re leveraging piv and the standard ssh tooling. We’re determining whether we’ll be able to use a pkcs11 implementation for TPMs and Secure Enclave or whether we’ll need to build a custom agent.</p>
]]></description><pubDate>Sun, 30 Mar 2025 22:45:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=43528486</link><dc:creator>jrozner</dc:creator><comments>https://news.ycombinator.com/item?id=43528486</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43528486</guid></item><item><title><![CDATA[New comment by jrozner in "Ask HN: What are you working on? (March 2025)"]]></title><description><![CDATA[
<p>Building Based Security (<a href="https://www.basedsec.io" rel="nofollow">https://www.basedsec.io</a>), a startup in the zero trust/identity space creating immovable, attestable, hardware backed identities that can be used for strong and continuous authentication but not moved from the device. We can guarantee the user and the device are known, the user is assigned the device they are using, and characteristics of the identity matches the defined policy. The initial product offering is tied to GitHub/GitLab, offering secure authentication for git over ssh operations with plans to expand to general ssh access and additional systems with pluggable access control.</p>
]]></description><pubDate>Sun, 30 Mar 2025 21:56:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=43528044</link><dc:creator>jrozner</dc:creator><comments>https://news.ycombinator.com/item?id=43528044</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43528044</guid></item><item><title><![CDATA[New comment by jrozner in "Open-sourcing OpenPubkey SSH (OPKSSH): integrating single sign-on with SSH"]]></title><description><![CDATA[
<p>I can understand the concern about having a second trusted party but think that the value of utilizing the standard ssh ca auth flow is worth the potential risk. If you require keys in attested hardware and verify that before issuing certs, the actual attack becomes very difficult. You need to compromise the actual hardware or compromise the CA in a pretty substantial way to issue certs to untrusted private keys. The certificate alone doesn't actually do anything without the key. In addition to just being supported out of the box, we can also issue hardware bound host keys, which allow us to offer bi-directional verification. We gain the benefit of all the standard PKI tooling (eg. revocation lists, ACME, etc.) and can use the same PKI for other scenarios (eg. mTLS, piv, etc.) by issuing x509 certificates instead. That's our long term plan is moving past ssh auth and having it be an attestable, immovable, hardware backed identity that can be usable for continuous authentication in other areas.<p>I have looked into OpenPubKey briefly in the past but haven't spent a ton of time with it. We were going in a very different direction and it didn't seem particularly useful based on our goals or what we wanted to achieve.<p>edit:
Looking at the documentation <a href="https://docs.bastionzero.com/openpubkey-ssh/openpubkey-ssh/installation-and-deployment" rel="nofollow">https://docs.bastionzero.com/openpubkey-ssh/openpubkey-ssh/i...</a> It seems like to use OpenPubKey you also need a fairly modern version of OpenSSH.   It also requires that the user authenticating have sudo access on the machine, which doesn't sound great. It's not clear to me whether it's possible for the existing authorized_keys file to co-exist or whether that's just to stop access using existing keys but using the standard ssh certs will co-exist allowing for a non-binary rollout if there are use cases that need to be worked around.</p>
]]></description><pubDate>Tue, 25 Mar 2025 22:03:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=43476511</link><dc:creator>jrozner</dc:creator><comments>https://news.ycombinator.com/item?id=43476511</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43476511</guid></item><item><title><![CDATA[New comment by jrozner in "Open-sourcing OpenPubkey SSH (OPKSSH): integrating single sign-on with SSH"]]></title><description><![CDATA[
<p>I think it's interesting they're choosing to use certificates this way. If they're already using certs, why not just leverage sshca auth? Also, at the end of the day, it's still effectively a bearer token. I founded a company called Based Security last year in this space. We're looking for design partners currently. We host a CA for you (or you can host yourself if you want) and use ssh certificates and bind the user identity (oidc to the IdP) to a physical device (yubikey, secure enclave, tpm, etc.) This ensures that the user is both in possession of the physical device and that the credential can't be stolen without stealing the device, unlike the bearer token examples here. Currently we're offering support for GitHub and GitLab authentication but it works out of the box with standard ssh tooling as well. It just currently requires manually handling user provisioning for standard ssh access.</p>
]]></description><pubDate>Tue, 25 Mar 2025 20:47:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=43475787</link><dc:creator>jrozner</dc:creator><comments>https://news.ycombinator.com/item?id=43475787</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43475787</guid></item><item><title><![CDATA[Paranoids' Vulnerability Research: NetIQ iManager Security Alerts]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.yahooinc.com/paranoids/paranoids-vulnerability-research-netiq-imanager-security-alerts">https://www.yahooinc.com/paranoids/paranoids-vulnerability-research-netiq-imanager-security-alerts</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=41999206">https://news.ycombinator.com/item?id=41999206</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 30 Oct 2024 19:29:37 +0000</pubDate><link>https://www.yahooinc.com/paranoids/paranoids-vulnerability-research-netiq-imanager-security-alerts</link><dc:creator>jrozner</dc:creator><comments>https://news.ycombinator.com/item?id=41999206</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41999206</guid></item><item><title><![CDATA[New comment by jrozner in "Ruby-SAML pwned by XML signature wrapping attacks"]]></title><description><![CDATA[
<p>Also an alum from WAY back (pre-A). One of the first things I did when I started was look at a different wrapping vuln.</p>
]]></description><pubDate>Thu, 19 Sep 2024 01:32:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=41587580</link><dc:creator>jrozner</dc:creator><comments>https://news.ycombinator.com/item?id=41587580</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41587580</guid></item><item><title><![CDATA[Scaling Variant Analysis]]></title><description><![CDATA[
<p>Article URL: <a href="https://goingbeyondgrep.com/posts/scaling-variant-analysis/">https://goingbeyondgrep.com/posts/scaling-variant-analysis/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=41162671">https://news.ycombinator.com/item?id=41162671</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 05 Aug 2024 16:14:45 +0000</pubDate><link>https://goingbeyondgrep.com/posts/scaling-variant-analysis/</link><dc:creator>jrozner</dc:creator><comments>https://news.ycombinator.com/item?id=41162671</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41162671</guid></item><item><title><![CDATA[New comment by jrozner in "Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source"]]></title><description><![CDATA[
<p>Why focus on SAML rather than OIDC2?</p>
]]></description><pubDate>Tue, 30 Jul 2024 17:58:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=41112186</link><dc:creator>jrozner</dc:creator><comments>https://news.ycombinator.com/item?id=41112186</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41112186</guid></item><item><title><![CDATA[New comment by jrozner in "Student debt is haunting Americans from graduation to retirement"]]></title><description><![CDATA[
<p>I agree that personal responsibility is important and both things can be true. I also think anyone who believes our taxes are going to go down if we don’t bail students out is delusional. With that belief, I’d rather my taxes directly improve the lives of tens of thousands of people than funnel more money into defense contractors, poorly run construction companies that can’t build infrastructure, and other already wealthy people’s pockets who aren’t actually returning what I think is enough value to the country for what we’re paying.</p>
]]></description><pubDate>Wed, 17 Apr 2024 19:09:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=40068882</link><dc:creator>jrozner</dc:creator><comments>https://news.ycombinator.com/item?id=40068882</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40068882</guid></item><item><title><![CDATA[New comment by jrozner in "Oxide Hiring Process"]]></title><description><![CDATA[
<p>After reading the policy when the blog post came out, I think one negative thing about it is that it can self select for people generally later in their career or with a much bigger safety net. When you have a 10-20+ tech career and the money saved up, like the founders and many of the early employees, it can be much easier to say that’s enough to cover expenses. I have nothing against it as a policy and I think there are definitely benefits to it. I just think that the biases aren’t clearly talked about either.</p>
]]></description><pubDate>Fri, 03 Nov 2023 20:45:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=38134773</link><dc:creator>jrozner</dc:creator><comments>https://news.ycombinator.com/item?id=38134773</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38134773</guid></item><item><title><![CDATA[New comment by jrozner in "Oxide Hiring Process"]]></title><description><![CDATA[
<p>I applied almost two years ago. I am excited about what Oxide is doing and it felt like a fun opportunity. While I respect what they do around comp, for where I was in my life and goals I had set, it was going to be rough. I applied anyway at the encouragement of a friend who worked there. I think the packet process is awful. So much unnecessary work and frankly by the end I just sort of phoned it in because I lost interest. It took about two months to hear back (I applied in December 2021 and heard back February 2022) and get rejected and got nothing more than a generic form rejection letter after all the time spent on preparing the packet.<p>———<p>We are so humbled by your application to join Oxide Computer Company. At this
stage of the company we are hyper-focused on certain areas of the stack and
when we need specific domain space experience such as yours, please engage
with us. Our roles will be updated as we need them.<p>We are grateful you took the time to apply and put so much thought into the
candidate materials, we loved reading them. We would absolutely love to work
with you in the future and cannot wait for that stage of the company!<p>All the best,
The Oxide Team</p>
]]></description><pubDate>Fri, 03 Nov 2023 20:31:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=38134589</link><dc:creator>jrozner</dc:creator><comments>https://news.ycombinator.com/item?id=38134589</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38134589</guid></item></channel></rss>