Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
block_hacks
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
block_hacks
2mo ago
A VPN changes your IP address, but websites can still observe signals such as your timezone, language, screen resolution, user agent, canvas output, hardware details, and other browser properties. I built Spoof Me to let users control these
2.
▲
by
block_hacks
7mo ago
tanstack is worse
3.
▲
by
block_hacks
7mo ago
ok m8
4.
▲
Don't Use Next.js If You're Building for the Long Term
(audits.blockhacks.io)
7 points
by
block_hacks
7mo ago
|
5 comments
5.
▲
by
block_hacks
7mo ago
I’ve been using Next.js for a long time. Long enough to have shipped real products with it, migrated between major versions, rewritten parts that were “best practice” just a year earlier, and defended it in arguments like it was part of my
6.
▲
by
block_hacks
9mo ago
damn
7.
▲
Show HN: A free, no-signup invoice generator for one-off invoices
(the-invoice.app)
3 points
by
block_hacks
9mo ago
|
2 comments
8.
▲
by
block_hacks
9mo ago
That’s a fair question. Blockchain security work is rarely just cryptography in isolation. Web3 applications are still web applications. Wallets, dashboards, admin panels, and APIs are part of the system, and many of them are built with fra
9.
▲
by
block_hacks
9mo ago
Just to address the “AI-generated” point directly: This isn’t something you can realistically get out of an LLM by prompting it.... If you ask an AI to write about Next.js RCE, it will stay abstract, high-level, and defensive by default. It
10.
▲
by
block_hacks
9mo ago
To be clear, I’m not claiming this is some universal or inevitable failure mode, or that everyone running Next.js is compromised. Every system has strengths and weaknesses. This is just one area where the tradeoffs aren’t always modeled cor
11.
▲
by
block_hacks
9mo ago
what's up?
12.
▲
Next JavaScript app is hacked, you just don't know it yet
(audits.blockhacks.io)
10 points
by
block_hacks
9mo ago
|
8 comments
13.
▲
by
block_hacks
9mo ago
Modern Next.js apps execute attacker-controlled input earlier than most teams realize — during framework deserialization, hydration, and Server Action resolution, often before application logging, validation, or auth hooks run. In several r
14.
▲
by
block_hacks
10mo ago
good?
15.
▲
Hackers Use Npmscan.com to Hack Web Apps (Next.js, Nuxt.js, React, Bun)
(audits.blockhacks.io)
5 points
by
block_hacks
10mo ago
|
1 comments
16.
▲
by
block_hacks
10mo ago
peace