Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kjok
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
Container Speed. VM-Level Security
(edera.dev)
8 points
by
kjok
4mo ago
|
2 comments
2.
▲
by
kjok
4mo ago
I should have been clearer and specific: state management is done on the backend, but collecting behavioral biometrics and device fingerprint is done using JavaScript, which can be manipulated.
3.
▲
by
kjok
4mo ago
Adversaries do not have to wait for LLM models to evolve to mimic human process, they can simply evade the detection JavaScript that evaluates similarity. JavaScript is visible, can easily be reverse-engineered.
4.
▲
by
kjok
4mo ago
Please also collect responses from people, you'd find a pattern: a new attack is launched, people make noise, and later go back to installing packages the same way. Enterprises already use private registries to combat such attacks, vul
5.
▲
by
kjok
4mo ago
> Compare this to Android where you can run malware and it cannot do anything except for annoying you with notifications. Are you sure it cannot do anything? Looking through various past malware/exploits, this doesn't seem to b
6.
▲
One Agent Sandbox Is Not Enough
(multikernel.io)
3 points
by
kjok
4mo ago
|
0 comments
7.
▲
by
kjok
4mo ago
Why should they be open source?
8.
▲
by
kjok
5mo ago
Cooldown sounds like a good idea ONLY IF these so called security companies can catch these malicious dependencies during the cooldown period. Are they doing this bit or individual researchers find a malware and these companies make headlin
9.
▲
by
kjok
5mo ago
How difficult is it to build a second startup on the side?
10.
▲
by
kjok
5mo ago
Are you a bot?
11.
▲
by
kjok
5mo ago
Building automated analysis tool that help identify the use of GPL-licensed SDKs in mobile apps, promoting license compliance and supporting sustainable open-source development.
12.
▲
Ask HN: Founders/investors, what AI bet you made in 2022 and how it is going?
6 points
by
kjok
5mo ago
|
1 comments
13.
▲
by
kjok
5mo ago
How do you know that they were LLM scrapers? The reason I ask is because user agents could easily be spoofed?
14.
▲
by
kjok
5mo ago
For those who have deployed Cloudflare in front, what are pros and cons? How's the user experience? Do they offer free bot protection?
15.
▲
by
kjok
5mo ago
How are you measuring this? Does your solution rely on user agent or device fingerprinting? Curious to know what tools are available today and how accurate they are.
16.
▲
by
kjok
5mo ago
Thanks for sharing your approach! > It is nothing special. We keep X number of machines in a warm pool. I'd love to better understand the unit economics here. Specifically, whether cost is a meaningful factor. The reason I ask is th
17.
▲
by
kjok
6mo ago
> The problem is that those underlying frameworks can very easily be misconfigured. Agreed. I'm sure a number of these sandboxing solutions are vibe-coded, which makes your concerns regarding misconfigurations even more relevant.
18.
▲
by
kjok
6mo ago
> There are dozens of projects like this emerging right now. They all share the same challenge: establishing credibility. Care to elaborate on the kind of "credibility" to be established here? All these bazillion sandboxing too
19.
▲
by
kjok
6mo ago
And this is exactly why we see noise on HN/Reddit when a supply-chain cyberattack breaks out, but no breach is ever reported. Enterprises are protected by internal mirroring.
20.
▲
by
kjok
6mo ago
I mean that agents can scan the code to find anything "suspicious". After all, security vendors that claim to "detect" malware in packages are relying on LLMs for detection.
21.
▲
by
kjok
6mo ago
Curious to know why are coding agents not detecting such risks before importing dependencies?
22.
▲
by
kjok
6mo ago
> I actually just published a paper... This gives me an impression that the paper has already been published and is available publicly for us to read.
23.
▲
by
kjok
8mo ago
Maybe humans can focus on cybersecurity and fraud? That’s not going away with AI
24.
▲
by
kjok
8mo ago
Block based on cookies (i.e., set a cookie on the browser and check on the server whether it exists).
25.
▲
by
kjok
8mo ago
I understand the need, but I don't understand why a VM or Docker is not enough. Why are people creating custom wrappers around VMs/containers?
26.
▲
by
kjok
8mo ago
Genuine question: why is everyone rolling out their own sandbox wrappers around VMs/Docker for agents?
27.
▲
At a major AI conference, Perplexity got voted most likely to flop
(businessinsider.com)
4 points
by
kjok
10mo ago
|
1 comments
28.
▲
by
kjok
10mo ago
> when they incorrectly fake devices And how often does this happen? Do you have any proof? Most YC companies building browser agents have built-in captcha solvers.
29.
▲
by
kjok
10mo ago
If not today, models will get better at solving captchas in the near future. IMHO, the real concern, however, is cheap captcha solving services.
30.
▲
A collection of links that existed about Anguilla as of 2003
(web.ai)
56 points
by
kjok
11mo ago
|
24 comments
More ›