Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
eskibars
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
What AI code review misses: SSRF and more
(zeroquarry.com)
1 points
by
eskibars
16d ago
|
1 comments
2.
▲
by
eskibars
16d ago
Author here. I built ZeroQuarry, and I was considering deploying an open source link shortener or using a SaaS one. I googled around and then found iShortn, so ran the iShortn scan with it. I found a bunch of vulnerabilities, which I sent
3.
▲
Show HN: DriftTrip – A Virtual Road Trip
(drifttrip.connelly.casa)
3 points
by
eskibars
2mo ago
|
0 comments
4.
▲
by
eskibars
2mo ago
Yeah, I think so. It's running on a pretty small VPS and I never implemented any caching. Should have thought about that before posting I guess. I see the CPU is currently pegged. I was able to get it to load at least 1 trip myself
5.
▲
by
eskibars
2mo ago
Also, a "just for fun" project: https://drifttrip.connelly.casa/ . I was always enthralled with the idea of taking a virtual road trip and then loading the local council's tourism promo videos at each "
6.
▲
by
eskibars
2mo ago
Building http://zeroquarry.com It's a way to augment small/overloaded security teams. It can pentest and then generate a pentester-style PDF report for auditors and procurement, triage incoming e-mails from security r
7.
▲
Evaluating different LLMs for their security research capabilities
(zeroquarry.com)
2 points
by
eskibars
3mo ago
|
0 comments
8.
▲
by
eskibars
4mo ago
What we've actually seen is a couple things that make this impractical "to just share a prompt". First, that nearly every major model still hallucinates a lot of vulnerabilities. Especially with temperature=0.7 as states in
9.
▲
by
eskibars
4mo ago
I've been building a product ( https://zeroquarry.com ) that can use a variety of models for finding vulnerabilities. One of the things I've noticed is that the models will nearly always comply with some of this, but ho
10.
▲
Obsidian plugins are (mostly) dangerous
(zeroquarry.com)
5 points
by
eskibars
4mo ago
|
2 comments
11.
▲
by
eskibars
4mo ago
I've been a long-timer Obsidian user with a number of plugins. Recently I launched ZeroQuarry (a product to scan code for security vulnerabilities) and pointed it at a number of Obsidian plugins. I was initially surprised to find out
12.
▲
by
eskibars
4mo ago
I just left a job for a German B2B software company which sold primarily to large automotive, defense, and aerospace companies. Several of our customers specifically banned anything with the word "DeepSeek" -- hosted or self-host
13.
▲
by
eskibars
4mo ago
I suspect so as well. I've been running my own security scanning software (disclaimer: now starting a company @ zeroquarry.com) for this, and from what I've seen there's a huge value in prompts + adversarial LLM review. Wi
14.
▲
by
eskibars
4mo ago
"If it ain't broke, don't fix it" is its own area of risk that people often ignore
15.
▲
Critical RCE found in Obsidian Tasks plugin
(zeroquarry.com)
5 points
by
eskibars
4mo ago
|
1 comments
16.
▲
by
eskibars
4mo ago
We found a critical RCE in the popular Obsidian Tasks plugin. It's now been fixed, but wanted to let others know to update ASAP. A malicious markdown file can trigger the RCE
17.
▲
by
eskibars
4mo ago
Sure, but there's a case I'm particularly aware of where one of the major cloud infrastructure providers was about to host a significant AGPL-licensed project without modifications because their lawyers had reviewed it and determi
18.
▲
by
eskibars
4mo ago
Some things may be obvious to a lot of readers, but I want to spell things out explicitly because sometimes "OSS" etc have a lot of conflations. A license in the software sense is effectively the legal terms and conditions for usi
19.
▲
by
eskibars
4mo ago
One thing I mention to folks that seem to think AGPL "protects you" against a major corporation incorporating your product into a SaaS product: it mostly doesn't. It isn't written about often, but it's the reason ma
20.
▲
by
eskibars
5mo ago
I know the space is starting to get crowded, but I've been building one and I'd love to get feedback if you have time
21.
▲
Show HN: Free security scanning for OSS projects
2 points
by
eskibars
5mo ago
|
0 comments
22.
▲
by
eskibars
5mo ago
Location: Melbourne, AU Remote: sure, or in person (preferred) Technologies: Python, Lua, Docker, Java, pretty much all SQL/NoSQL. But I'm a bit unusual here in that my focus tends to be a bit more on the product side than the en
23.
▲
Show HN: Scan your OSS projects for vulnerabilities
(console.zeroquarry.com)
1 points
by
eskibars
5mo ago
|
0 comments
24.
▲
by
eskibars
7mo ago
Location: Melbourne, AU Remote: Indifferent. I've worked partially remote from 2015-2025 and in-person before/after. I like both Willing to relocate: no Technologies: python, SQL and most major BI tools, javascript, elasticsearc
25.
▲
by
eskibars
11mo ago
Isn't the entire point of this post that many companies opt for flexible+future proof far too prematurely?
26.
▲
by
eskibars
11mo ago
I agree in principal, but this whole post is lazy if it's AI-produced. There's certainly no original thought and as the comments mention here, most of the math is outright incorrect
27.
▲
by
eskibars
11mo ago
SPREAD | https://www.spread.ai/ | Technical writer & support | Germany (Berlin, ideally) | Full-time SPREAD builds B2B software for mechatronics customers like cars and defense systems. We help them design, build and di
28.
▲
by
eskibars
11mo ago
So as some of my own feelings/thoughts on this: I've also sat on the "receiving side" of a "free forever" campaign now 2 times in my career. The first time driven by the CEO and the second time driven by the m
29.
▲
by
eskibars
11mo ago
https://web.archive.org/web/20240124013352/https://planetsca... Says "free forever"
30.
▲
by
eskibars
1y ago
SPREAD | https://www.spread.ai/ | Technical writer | Germany (Berlin, ideally) | Full-time SPREAD builds B2B software for mechatronics customers like cars and defense systems. We help them design, build and diagnose proble
More ›