Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
_slih
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
61.
▲
by
_slih
7mo ago
the article treats agency like it's new but founders have always been delusional risk takers. the difference is VCs used to demand a working prototype before writing the check
62.
▲
by
_slih
7mo ago
the gist author being new and the writing looking polished doesn't change that the log files are right there on disk for anyone to verify. ls the directory and read the output yourself.
63.
▲
by
_slih
7mo ago
the article assumes monster codebases because we can build them. but cheaper code also means cheaper rewrites. maybe the future is disposable software, not carefully reviewed software.
64.
▲
by
_slih
7mo ago
the subscription already has usage caps. if the caps are the caps, why does the client matter. if the caps aren't actually the caps, that's a different conversation.
65.
▲
by
_slih
7mo ago
36 to 53 percent score discrepancy just from switching the policy language. imagine that kind of variance in a compliance tool where the output determines what gets flagged.
66.
▲
by
_slih
7mo ago
most of these companies deployed microsoft copilot, watched it hallucinate meeting summaries for six months, and called that an AI strategy. source: current situation
67.
▲
by
_slih
7mo ago
the non-apology is worse than staying quiet. 'if this experiment personally harmed you', like dude it wasn't an experiment for the guy whose name got dragged through an AI-generated hit piece
68.
▲
by
_slih
7mo ago
calling it a bug is generous. the whole point of these tools is to read everything you have access to. the 'bug' is that it worked exactly as designed but on the wrong emails
69.
▲
by
_slih
7mo ago
We built accountability systems that assume bad actors are humans with reputations to protect. none of that works when the attacker is disposable.
70.
▲
by
_slih
7mo ago
turns out convenience loses when you start asking for face scans.
71.
▲
by
_slih
7mo ago
400 attempts and zero wins says more about the attack surface than the model. email is a pretty narrow channel for injection when you can't iterate on responses.
72.
▲
by
_slih
7mo ago
so the government's fix for a data breach is to delete the entire database instead of fixing the access controls. classic.
73.
▲
by
_slih
7mo ago
funny how the FAQ disclaimer about Persona already vanished from the site. not a great look when your transparency lasts shorter than the data retention.
74.
▲
by
_slih
7mo ago
ran something similar on a home network once and was surprised how many of my neighbors' devices showed up with full manufacturer names and model numbers. you don't even need to try hard.
75.
▲
by
_slih
7mo ago
Insurance is already moving that direction for cyber policies. Some underwriters now require screenshots or PDF exports of third-party vendor security attestations as part of the application process, not just URLs. The carriers learned the
76.
▲
by
_slih
7mo ago
The 'I'll use something else' threat is my favorite. In my space the threat is usually 'I'll just use the AWS native tools.' And my honest answer is: if that works for you, do it. Most of them come back three m
77.
▲
by
_slih
7mo ago
Exactly this. The sticker price of open source is zero but the total cost of ownership is your team's time. I've talked to CTOs who spent more engineering hours configuring and maintaining free tools than they would have spent on
78.
▲
by
_slih
7mo ago
The compliance form thing is wild but predictable. I'm on the other side of that equation now. Companies will pay me to handle their compliance mapping but balk at paying an open source maintainer to fill out a security questionnaire f
79.
▲
by
_slih
7mo ago
There's a compliance angle to this that nobody's talking about. Regulatory frameworks like SOC 2 and HIPAA require audit trails and evidence retention. A lot of that evidence lives at URLs. When a vendor's security documentat
80.
▲
by
_slih
8mo ago
Same thing happens with infrastructure config. Ask an AI to fix a security group issue and it'll add a new rule instead of fixing the existing one. You end up with 40 rules where 12 would do and nobody knows which ones are actually nee
81.
▲
by
_slih
8mo ago
It means code review, except now you're reviewing code you didn't write, for a system you didn't design, generated by a model that can't explain its reasoning. That's a harder job than writing it yourself, not an ea
82.
▲
by
_slih
8mo ago
The Klarna reversal is the most honest thing on this list. Went all in, quality dropped, hired humans back. Every other memo on here is still in the 'we declared victory' phase. Be interesting to check back in a year and see how m
83.
▲
by
_slih
8mo ago
Companies spend a fortune on endpoint security and then let employees install random Chrome extensions with full page access. I've seen AWS console sessions running in browsers with a dozen extensions nobody's ever audited. The ex
84.
▲
by
_slih
8mo ago
The creepy part isn't the tech itself, it's that BFI data is unencrypted by default. So it's not even that someone has to hack your router. Any device in range can just passively read it.
85.
▲
by
_slih
8mo ago
Always fun when the status page goes down with the thing it's supposed to be reporting on. This is why your monitoring stack can't live on the same infrastructure it's watching. If your alerting depends on CloudFront and Clou
86.
▲
by
_slih
8mo ago
The alignment framework is something I wish I'd thought about earlier. I spent months chasing outreach channels that felt like a grind because I was copying what other people said worked instead of figuring out what fit my own strength
87.
▲
by
_slih
8mo ago
Yep. I built a security posture monitoring tool that goes up against AWS Security Hub and Config rules. The trick is you're not really competing with AWS. You're competing with the decision to do nothing. Most SMBs I talk to aren&
88.
▲
by
_slih
8mo ago
Building AWSight ( https://www.awsight.com ), continuous AWS security posture monitoring with compliance mapping to SOC 2, NIST, and CIS. Flat rate starting at $249/mo. Built it because I kept seeing SMBs get stuck between tw
89.
▲
by
_slih
8mo ago
This campaign worked because the operator knew exactly what most detection stacks look for: execution, lateral movement, data exfil. They did none of that. They dropped a loader, confirmed it worked, and left. No behavioral triggers, no ale
90.
▲
by
_slih
8mo ago
What’s playing out between AT&T/Verizon and Congress is something I see all the time at a smaller scale across the industry, that is, rganizations routinely avoid getting real visibility into their security posture because the mome
More ›