Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Eh. I've spent almost a cumulative six years of my career writing code signing code. Both times I had only a couple of coworkers who understood everything, so most growth was self started. The larger project involved counter signing (signatures over signatures) and HSMs and was mostly my code, and I ran into a lot of people who knew words but didn't know what the hell they were talking about. I had to get very good at telling people "No, but..." because they always wanted to make decisions based on unverified data.

At the end I knew a lot about a narrow slice of security. I did not feel like an expert although I do feel like I got the job done (which in this field is very hard to say with a straight face).

I haven't touched that kind of code in 5 years and I'm not confident how much of it I could regurgitate under duress. But I'd like to think I'd know how to produce a signed document that's verifiable. If the key were stored someplace exotic (I don't recall how Bitcoin stores it's keys) that might be harder.

I would not be surprised if the real Slim Shady had trouble with it too, but it would cause me to wonder about exploits in the code.



Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: