Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How did you find all these product market fits?

Have you made more than a typical SWE?



It was actually a wandering hyperactive/ADHD mind that often said "why isn't there one" and follows through doggedly to the very end.

It is one of those traits where a mind clicks and said "this is it and how" and surprisingly gets into the most illusive hyperfocus/high-energy mode (without using any drug).

Slow-path network processing (arguably me) was commercially made in Ascom Timeplex in 1982 and someone else leaked it to Cisco (or ripping AT's patent off). I got that from observing how different river bends (re)connect year-after-year while doing trout fishing trips.

Money-wise, I am disabled, got abled, disabled again in different way, re-enabled, now just coasting with my own ideas: JavaScript Host-Based Intrusion Detection/Protection System, being one of them. And an portable AirPod detector (for home/auto/travel) is another idea. And DNSSEC for within private enterprise is almost done.

Money is not my thing but it does help greatly in the pursuit of my ideals (so many hardwares, so many test equips).


How did you get disabled?


A bacterial infection. Differently twice.


Wear a rubber next time.


Kinda hard to do, I do sorta have to breath, ya know.


Just not sure it would have helped much. Think Civil War battlefield infection.


can you please explain what is JavaScript Host-Based Intrusion Detection/Protection System?


It is simple. Too many malicious and privacy-violating JavaScript abounds, especially after being boiled down to seemingly-indecipherable WebAssembly bytecode.

And a typical enterprise NIDS would not be able to see beyond those encrypted packet containing JS over 2-way-signed TLS/SSL, or HTTPv3 (QUIC) (or a few other E2E protocols).

Since JavaScript won't be banned (unlike Adobe Flash/ActionScript, BTW Adobe's JavaScript is still being used within PDF files) anytime soon, this is another example of seeing a void and rushing to fill its need for the betterment of Internet citizens.

Just yesterday, another "this is it and how" moment came to me: this Python PDF guy (and a few PDF experts) got me thinking "this is how to remove or make inert the JavaScript inside PDF": https://news.ycombinator.com/item?id=33646951


My understanding is that JS/WASM is sandboxed within the browser environment. It does have some access (say Camera) but only if you allow it.

Care to develop more on the potential attacks here?



Quick and dirty cleanup - convert to, then from postscript.


I absolutely love your thinking. What you propose does is defang the programmability aspect into an inert (but safer) "text-based" form.

But which side should assume the responsibility of this JS-defanging effort into text-based? Client or server? Postal said "be liberal in what you receive and conservative in what you send". So, being conservative (in this respect), server has to be minimalistic (including denial of programmability).

Real problem remains, too much accessibility of programming is being made available to let client-side take it in ... in a gullible way.

And no amount of Sideshow Barker (not a dig on HN's Sideshow Barker) can fix this, until one of the MAANG decides "enough".

Meanwhile, the wild Wild West shall continue.


[flagged]


I do enjoy sharing the fruit of my labor; but I share what money I have as well.

But, I "share" my money with those who provided me and others with things, like farmers, truckers, construction workers, plumbers, electricians, architects, textile workers, drafters, crafts-folks, artists, custodial, medical specialists, government workers, educational specialists, sanitation folks, engineers, engineers, engineers. Did I repeat that? Yes, more engineers.

I'm quite sure you do share your money too (and probably may not know the true extent of your reach).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: