Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
alexsmolen
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
alexsmolen
5mo ago
I've been using elhaz ( https://github.com/61418/elhaz ) to manage AWS creds locally, and also experimenting with sandboxed (e.g. dangerously-skip-permissions) agents using Docker. The nice thing is that you can use
2.
▲
AWS Credential Isolation for Local AI Agents
(engseclabs.com)
4 points
by
alexsmolen
5mo ago
|
1 comments
3.
▲
Show HN: TrailTool – open-source CLI for querying CloudTrail data with AI agents
(github.com)
2 points
by
alexsmolen
7mo ago
|
0 comments
4.
▲
by
alexsmolen
8mo ago
I'm working on TrailTool, which aggregates CloudTrail for analysis in both UI and AI contexts. I've always found it tough to tie together CloudTrail logs into meaningful narratives useful not only for security investigations but a
5.
▲
by
alexsmolen
8mo ago
In my research I haven’t come across the prior art you suggest exists. The trust centers you linked aren’t fungible with what I’m building with GraphGRC. The idea is to make all your security docs just a GitHub repo with structured markdown
6.
▲
by
alexsmolen
8mo ago
I love this idea despite the real world operational challenges - most people with governance responsibilities in organizations don't want to code, and code is often too precise to model messy social/organizational context without
7.
▲
What Should I Work on Next? A Framework for High-Impact Security Work
(engseclabs.com)
2 points
by
alexsmolen
11mo ago
|
0 comments
8.
▲
Backyard Apt: A Raccoon Story
(engseclabs.com)
3 points
by
alexsmolen
11mo ago
|
1 comments
9.
▲
Refocusing Vendor Security on Risk Reduction
(engseclabs.com)
3 points
by
alexsmolen
1y ago
|
1 comments
10.
▲
Small language model for secrets detection
(wiz.io)
3 points
by
alexsmolen
1y ago
|
0 comments
11.
▲
Securing GitHub Organizations
(alsmola.medium.com)
3 points
by
alexsmolen
5y ago
|
0 comments
12.
▲
by
alexsmolen
6y ago
This is a pretty good article about preventing SSRF including DNS rebinding-based attacks in Go https://www.agwa.name/blog/post/preventing_server_side_reque...
13.
▲
by
alexsmolen
6y ago
Kind of wild that there's no mention of SSRF. A quick search shows it's a pretty frequent security issue in Webhooks: https://www.google.com/search?q=ssrf+webhook
14.
▲
Use AWS Glue to Make CloudTrail Parquet Partitions
(medium.com)
1 points
by
alexsmolen
6y ago
|
0 comments
15.
▲
by
alexsmolen
7y ago
This is what https://tosback.org/ does, I believe.
16.
▲
Wag: A Go Web API Generator
(medium.com)
6 points
by
alexsmolen
9y ago
|
0 comments
17.
▲
Implementing the sudo access pattern for AWS IAM Users
(medium.com)
1 points
by
alexsmolen
9y ago
|
0 comments
18.
▲
Creating IAM resources and policies simply with terrafam
(medium.com)
6 points
by
alexsmolen
9y ago
|
0 comments
19.
▲
by
alexsmolen
10y ago
Yeah, I think it’s tricky to figure out how to place it somewhere that attackers would look but AWS tooling wouldn’t, by default, since otherwise they may be used in legitimate operation.
20.
▲
by
alexsmolen
10y ago
I recently helped build a secret store system for our infrastructure, and we decided to not use Vault. A big reason was that Vault’s AWS authentication backend is not based on AWS infrastructure like IAM/KMS, but uses a somewhat backha
21.
▲
by
alexsmolen
10y ago
The problem is that SMS provides better recovery rates than TOTP/HOTP + backup codes, because people can go to their carrier and get a new device at the same number. It's important to remember that availability is an important asp
22.
▲
18F caused a data breach using Slack
(nextgov.com)
18 points
by
alexsmolen
10y ago
|
0 comments
23.
▲
by
alexsmolen
12y ago
I built an open-source Rails engine for something like this: https://nopassword.alexsmolen.com .
24.
▲
by
alexsmolen
12y ago
Does anyone think JWT should replace cookies for session management in non-single page apps? I'm guessing you'd have to include an AJAX call to determine if you're logged in on each page, which seems kind of odd to me.
25.
▲
Twitter launches paid bug bounty program
(twitter.com)
2 points
by
alexsmolen
12y ago
|
0 comments
26.
▲
by
alexsmolen
12y ago
This is interesting and well-informed, but it's important to remember that fraud is an adversarial problem. The bad guys will change their behavior to evade detection. The habits described here may exist when there is no defense in pla
27.
▲
by
alexsmolen
12y ago
Shameless plug - I wrote a Rails engine for this type of authentication mechanism called NoPassword - see https://github.com/alsmola/nopassword
28.
▲
CSP Reporter - A Tool to Analyse CSP Logs
(oxdef.info)
1 points
by
alexsmolen
13y ago
|
0 comments
29.
▲
by
alexsmolen
13y ago
I built and open-sourced something like this a while ago: http://nopassword.alexsmolen.com HN thread here: https://news.ycombinator.com/item?id=4570600 It's a great concept, but like any new authentication
30.
▲
by
alexsmolen
13y ago
I built a Rails engine that does this, see https://github.com/alsmola/nopassword and https://nopassword.alexsmolen.com
More ›