Hacker Newsnew | past | comments | ask | show | jobs | submit | kitchenkarma's commentslogin

You are unable to tell whether any service uses E2E. It is best to assume we don't have E2E services and adjust own opsec accordingly.


Assume these services are being tapped. If you want ultimate privacy exchange keys with your contacts offline and you PGP over any messaging service.


But but Microsoft is goood! Look GitHub! Linux! Open Souwce! I only use Windows because software I need doesn't work on Linux.


Can someone explain to me what is so special in those photos? These look like snapped on the phone...


It's a bit naive thinking that employees would store their electronics in the lockers. Even if you have spot searches (including cavity search) it still doesn't exclude rogue employee just "forgetting" to store his or hers camera in the locker.


Nobody in that business was naïve. Employees did not "forget," if they were caught with their phone in the secure area, they were fired. I was told right up front that certain things were zero tolerance, and everybody knew what they were.

They took this very seriously.

Now when it comes to a deliberately bad actor, well, nothing is 100% perfect, but there were many other security things going on that I am not going to describe here, plus I know for a fact that there were security measures they did not disclose to me.

But let's face it: Somebody, somewhere, can train themselves to memorize a screen full of information. They could memorize something, go for a smoke break, and upload what they memorized. Lather, rinse, repeat.

The point I made, and am still making, is that some companies care enough to do everything reasonably possible to keep customer data secure, while other companies do not. The company I described here cares. I believe Apple cares too.

I suspect it will always be possible for someone to pull a small data heist, but extraordinarily difficult to set up a regular pipeline to exfiltrate data. The weak point is probably the digital systems. Most attackers would want everything, and the way to get everything is with a vulnerability.


Do they go through phased entry system. For example phase 1 metal detector arch and a 3d scanner like in the airport. Phase 2 strip naked for body and cavity search and then phase 3 - wear company uniform with attached camera and microphones? If not then I can't see how they couldn't take a pendrive in.


This is the future of electronic money. Companies will decide for you what you can or cannot buy.


It's their money, they can place whatever restrictions on it they like. You're under no obligation to use their service.


This is not money, it's a credit card. Banks have restricted what you can buy with the money you loan for ages.

You can always buy bitcoin with your debit card.


Shouldn't you also show intermediate page with a privacy warning and a cancel / continue buttons? Otherwise user can click it by mistake and compromise his data.


Move fast break things kind of doesn't work well with planes.

Also too big to fail (fall) doesn't apply here.


Au contraire, Boeing is most definitely too big too fail and will be bailed out somehow.


Typically CS degree means that you can finish something regardless if it makes sense or not. That skill is in demand in large corporations that require people to follow stupid processes and complete tasks that don't reflect on what are the actual needs. Of course there are good CS degrees, but these are not as common as one thinks. The purpose of universities was to gather knowledge and pass it on where it was not possible otherwise to do so. These days people have open access to all kind of knowledge and universities are not as much important as they were. If company lists CS degree as a job requirement, that for me is a good indication of a place I don't want to work in.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: