Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
alp1n3_eth
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
alp1n3_eth
1y ago
What are you using on the backend to actually scan it? Is it just ZAP / Burp Scanner? Or are you scanning the code itself, and just using a Semgrep / Snyk approach? The landing page being free-tier Framer is a little sketch, the m
2.
▲
by
alp1n3_eth
1y ago
A lot of people don't self-host it, even though it is open core. This is due to their docs being garbage and tons of differences between the offerings, so you can't even rely on the main docs if you're self-hosting. It's
3.
▲
by
alp1n3_eth
1y ago
Yep! I was sad to see Skiff shutting down, as I loved their UI and there isn't a lot of tough competition that can match ProtonMail. I had already left Notion as the app kept getting slower / bogged down and they added tons of use
4.
▲
Mitre support for the CVE program is due to expire tomorrow
(twitter.com)
8 points
by
alp1n3_eth
1y ago
|
0 comments
5.
▲
by
alp1n3_eth
1y ago
I'd say it doesn't exactly meet the minimum standard for a CVE, as it's more of a technique vs. an actual vulnerability in an application/library. If there was a repo that had a vulnerable component that was currently in
6.
▲
by
alp1n3_eth
1y ago
"Have fun suffering and hopefully you don't die as we go through 8 medications that will most likely fail, but there's a slim chance they'll work!"
7.
▲
by
alp1n3_eth
1y ago
Is there a good example repository to see how it's done?
8.
▲
by
alp1n3_eth
1y ago
You're a frontend web developer, so I'm assuming you're going to want to work in the areas of either: 1) application security engineering 2) application penetration testing 3) devsecops 4) vulnerability management It really i
9.
▲
React Router and the Remix'ed path: CVE-2025-31137
(zhero-web-sec.github.io)
3 points
by
alp1n3_eth
2y ago
|
0 comments
10.
▲
by
alp1n3_eth
2y ago
Externally / Blackbox options would be Nessus, Nuclei, OWASP ZAP (as you mentioned), and Burp Suite. The two latter only work well when used in combination with manual methods though, as they won't pick up business logic, auth byp
11.
▲
by
alp1n3_eth
2y ago
A lot of aggregators will also not allow your blog to be posted if it's on a newsletter site like Substack, Patreon, etc. I use GitHub Pages for hosting, Porkbun for the domain, and Astro for the blog itself. EZPZ to manage and very st
12.
▲
by
alp1n3_eth
2y ago
You'd be surprised how much the government would potentially hurt itself in its own confusion. Not all parts of it are aligned to the same beliefs / mission, and there are certainly parts that believe in the saying "Why are y
13.
▲
Don't Overthink the Easy Choices
(alp1n3.dev)
1 points
by
alp1n3_eth
2y ago
|
0 comments
14.
▲
by
alp1n3_eth
2y ago
I appreciate Caido because of the ability to save projects in the free tier, which I use for (personal use) different projects and tinkering. Burp Pro is my daily driver at work, and I think Caido could certainly use some improvement to the
15.
▲
by
alp1n3_eth
2y ago
If you want a super bad audio-related journey, try fixing external speakers connected to a Linux box. It's abysmal, and 99% of it can only be done via the CLI. Nothing wrong with that... but for something so normal I expected more ease
16.
▲
by
alp1n3_eth
2y ago
Weirdly enough... not always. When it comes to random companies running their own VDP vs. hiring it out, it can be less than standard despite there being lots of resources on setting it up. I've seen ones that only include a phone numb
17.
▲
Do What I Mean (DWIM)
(alp1n3.dev)
1 points
by
alp1n3_eth
2y ago
|
0 comments
18.
▲
Don't Pre-Optimize with Go
(alp1n3.dev)
1 points
by
alp1n3_eth
2y ago
|
0 comments
19.
▲
Next.js Middleware Exploit: Deep Dive into CVE-2025-29927 Authorization Bypass
(zeropath.com)
3 points
by
alp1n3_eth
2y ago
|
0 comments
20.
▲
by
alp1n3_eth
2y ago
Surprisingly, Go is great for CLI tooling. It may not have the insane speed that carefully planned and written Rust does, but it's very easy to write and be performant without even needing to go to great lengths to optimize it. I gener
21.
▲
by
alp1n3_eth
2y ago
Before needing an LLM for it, they might want to ensure their doc system is using a search system that actually works. There's too many doc-focused templates / apps that have the worst search possible.
22.
▲
by
alp1n3_eth
2y ago
This is one area where I'll actively discourage fragmentation of the existing ecosystem. Currently in the U.S. it's: 1) PawBoost 2) Facebook Groups (which PawBoost usually posts to as well) 3) NextDoor Past that, the animal needs
23.
▲
by
alp1n3_eth
2y ago
I think there's a difference between Microsoft refusing to support completely operational hardware for their new OS, and Apple not adding extra features / support into a pre-existing product just because the underlying tech is now
24.
▲
by
alp1n3_eth
2y ago
I don't know how it works overseas, but it sounds like this is a plus for US companies hiring US employees. According to the laws the company is required to fully ID you before hiring, which means either: 1) Hopping on a video call and
25.
▲
by
alp1n3_eth
2y ago
They could build an optional "risk score" that open-source community-oriented projects could turn on. It could include requirements like having something dependabot-esque along with CodeQL enabled. Rules could be created for CodeQ
26.
▲
by
alp1n3_eth
2y ago
War between the EU and US, however unlikely, probably wouldn't mean all your devices stop working right away. At absolute worst, patches would stop rolling out to EU-owned and operated devices, so you'd still have your hardware, t
27.
▲
by
alp1n3_eth
2y ago
Would it be useful or easier to plug in if these were rules developed for platforms such as Semgrep? It looks like they already have an existing nginx ruleset: https://semgrep.dev/p/nginx . They can always use some extr
28.
▲
by
alp1n3_eth
2y ago
As @ianpurton stated: Defense-in-Depth works. The instructor is teaching a class with some people who may be bad programmers, some that may be good, and some that may be great. The safest general advice is to rely on well audited and commun
29.
▲
by
alp1n3_eth
2y ago
Tooling for asciidoc (last time I used it) was super sparse and next to unusable. There was primarily one underlying engine everyone relied on to do cross-filetype generations, and the available editors was pretty bad as well. Of the few fr
30.
▲
by
alp1n3_eth
2y ago
There's probably going to be a flood of lawsuits, complaints, etc. following this. Cleaning up inefficient gov processes and waste would be good, but this is the completely wrong way to go about it. A single team, made up of extremel
More ›