Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
gbrindisi
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
gbrindisi
1mo ago
it kinda does unless he is straightforward about his financial incentives
2.
▲
by
gbrindisi
1mo ago
I used to accept only people I worked with/met in person, but the feed is crap anyway so why bother. I now accept pretty much everyone and prune the feed.
3.
▲
by
gbrindisi
1mo ago
I agree. They have quality data to build an effective AI pentest product that is good enough, and they already have a good offering to bundle that into and satisfy enterprise demand. Up and coming AI pentest companies need to have an except
4.
▲
by
gbrindisi
2mo ago
I also notice the growing trend to have EM carry individual contributor duties, I thought it was mostly a consequence of using coding agents but perhaps it's not: the EM figure as we know might just be a consequence of the golden zirp
5.
▲
by
gbrindisi
3mo ago
It's not just AI, these are the consequences of affiliate marketing. Just look at the crap that is YouTube nowadays.
6.
▲
by
gbrindisi
3mo ago
I like the pattern of making a dedicated cli/harness and just build a skill to teach coding agents to use it. At $work we built a thorough workflow to do security reviews, which is a pure skill to simplify adoption https://
7.
▲
Automating Code Security Reviews
(cloudberry.engineering)
2 points
by
gbrindisi
4mo ago
|
0 comments
8.
▲
by
gbrindisi
4mo ago
I protest the modern web by trying to consume all content via RSS. The feed reader shall be my main window to the world, and I am sorry that it's not obvious to content creators that I read them so I often send an email on the note of
9.
▲
by
gbrindisi
5mo ago
This is pretty much a spec driven workflow. I do similar, but my favorite step is the first: /rubberduck to discuss the problem with the agent, who is instructed by the command to help me frame and validate it. Hands down the most impa
10.
▲
by
gbrindisi
6mo ago
are agents/ still relevant after we got skills? I am genuinely confused on why I would need custom system prompts for specific agents, what should I use them for?
11.
▲
by
gbrindisi
6mo ago
thanks for raising the alarm and sharing this, very insightful (also beautifully presented!)
12.
▲
by
gbrindisi
6mo ago
1. I dont have hard metrics at hand but with the latest Sonnet I'd say we reach consensus around 80% of the time, with Opus is almost always but we are not using it due to cost 2. The difference I see in agent behavior when they don&#x
13.
▲
Scaling Vulnerability Management with AI: What Worked
(synthesia.io)
8 points
by
gbrindisi
6mo ago
|
3 comments
14.
▲
by
gbrindisi
6mo ago
I am doing something similar: I use openspec to create context and a sequential task list that I feed to ralph loops, so that i’m involved for the planning and the verification step but completely hands off the wheel during code generation.
15.
▲
by
gbrindisi
6mo ago
I like openspec, it lets you tune the workflow to your liking and doesn’t get in the way. I started with all the standard spec flow and as I got more confident and opinionated I simplified it to my liking. I think the point of any spec driv
16.
▲
Facing bankruptcy after unauthorized Gemini API usage of about $128k
(old.reddit.com)
5 points
by
gbrindisi
6mo ago
|
1 comments
17.
▲
Agentic Risks
(cloudberry.engineering)
1 points
by
gbrindisi
6mo ago
|
0 comments
18.
▲
Sandboxing Agents
(cloudberry.engineering)
1 points
by
gbrindisi
6mo ago
|
0 comments
19.
▲
by
gbrindisi
6mo ago
fifteen years ago I use to do mobile pentests for banks and when we could not find anything significant for the reports we could’ve always count on “lack of rooting detection” and pin the risk on some vague mobile banking malware threat pus
20.
▲
by
gbrindisi
6mo ago
ah I also did my own sandbox and at least twice the agent inside tried really hard to go around the firewall, so I ended up intercepting calls to `connect` to return a message that says "Connection refused by the sandbox, don't tr
21.
▲
by
gbrindisi
7mo ago
the most annoying thing with Google Workspace is that you need super admin privilege to properly audit the environment programmatically, I believe because of the cloud-identity api.
22.
▲
I Automated a Daily Intelligence Briefing with OpenClaw
(josecasanova.com)
1 points
by
gbrindisi
7mo ago
|
0 comments
23.
▲
by
gbrindisi
9mo ago
I noticed that too and it’s kinda scary. Soon we will have the opposite of canceling, where the target will be deepfaked to say everything and its opposite to nullify their signal to noise ratio.
24.
▲
by
gbrindisi
10mo ago
The crowdstrike incident taught us that no one is going to review any dependency whatsoever.
25.
▲
by
gbrindisi
1y ago
I wonder how far I could go with a barebone agent prompted to take advantage of this with Sonnet and the Bash tool only, so that it will always try to use the tool to only do `python -c …`
26.
▲
by
gbrindisi
1y ago
I can't use Google Meet on firefox/zen, I tried every setting combination I could find but the video call quality is still not comparable to chromium based browsers, so at work I reluctantly switched to Vivaldi. If you figure this
27.
▲
by
gbrindisi
1y ago
We’ve kinda solved the detection of issues. what we still lack is understanding what’s important. I think an underappreciated use case for LLMs is to contextualize security issues. Rather than asking Claude to detect problems, I think it’s
28.
▲
by
gbrindisi
1y ago
This must be the best technical article I read on HN in months!
29.
▲
by
gbrindisi
1y ago
meta: if you use AI to write articles, don’t have them written so that I’m forced to use AI to summarize them
30.
▲
by
gbrindisi
1y ago
not in Italy
More ›