Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
eskibars
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
eskibars
12d ago
https://zeroquarry.com/ It's an approach to defensive security for software products (especially smaller companies) by acting as the security team you don't have/can't afford. It does security recon
2.
▲
What AI code review misses: SSRF and more
(zeroquarry.com)
1 points
by
eskibars
26d ago
|
1 comments
3.
▲
by
eskibars
26d ago
Author here. I built ZeroQuarry, and I was considering deploying an open source link shortener or using a SaaS one. I googled around and then found iShortn, so ran the iShortn scan with it. I found a bunch of vulnerabilities, which I sent
4.
▲
Show HN: DriftTrip – A Virtual Road Trip
(drifttrip.connelly.casa)
3 points
by
eskibars
3mo ago
|
0 comments
5.
▲
by
eskibars
3mo ago
Yeah, I think so. It's running on a pretty small VPS and I never implemented any caching. Should have thought about that before posting I guess. I see the CPU is currently pegged. I was able to get it to load at least 1 trip myself
6.
▲
by
eskibars
3mo ago
Also, a "just for fun" project: https://drifttrip.connelly.casa/ . I was always enthralled with the idea of taking a virtual road trip and then loading the local council's tourism promo videos at each "
7.
▲
by
eskibars
3mo ago
Building http://zeroquarry.com It's a way to augment small/overloaded security teams. It can pentest and then generate a pentester-style PDF report for auditors and procurement, triage incoming e-mails from security r
8.
▲
Evaluating different LLMs for their security research capabilities
(zeroquarry.com)
2 points
by
eskibars
3mo ago
|
0 comments
9.
▲
by
eskibars
4mo ago
What we've actually seen is a couple things that make this impractical "to just share a prompt". First, that nearly every major model still hallucinates a lot of vulnerabilities. Especially with temperature=0.7 as states in
10.
▲
by
eskibars
4mo ago
I've been building a product ( https://zeroquarry.com ) that can use a variety of models for finding vulnerabilities. One of the things I've noticed is that the models will nearly always comply with some of this, but ho
11.
▲
Obsidian plugins are (mostly) dangerous
(zeroquarry.com)
5 points
by
eskibars
4mo ago
|
2 comments
12.
▲
by
eskibars
4mo ago
I've been a long-timer Obsidian user with a number of plugins. Recently I launched ZeroQuarry (a product to scan code for security vulnerabilities) and pointed it at a number of Obsidian plugins. I was initially surprised to find out
13.
▲
by
eskibars
5mo ago
I just left a job for a German B2B software company which sold primarily to large automotive, defense, and aerospace companies. Several of our customers specifically banned anything with the word "DeepSeek" -- hosted or self-host
14.
▲
by
eskibars
5mo ago
I suspect so as well. I've been running my own security scanning software (disclaimer: now starting a company @ zeroquarry.com) for this, and from what I've seen there's a huge value in prompts + adversarial LLM review. Wi
15.
▲
by
eskibars
5mo ago
"If it ain't broke, don't fix it" is its own area of risk that people often ignore
16.
▲
Critical RCE found in Obsidian Tasks plugin
(zeroquarry.com)
5 points
by
eskibars
5mo ago
|
1 comments
17.
▲
by
eskibars
5mo ago
We found a critical RCE in the popular Obsidian Tasks plugin. It's now been fixed, but wanted to let others know to update ASAP. A malicious markdown file can trigger the RCE
18.
▲
by
eskibars
5mo ago
Sure, but there's a case I'm particularly aware of where one of the major cloud infrastructure providers was about to host a significant AGPL-licensed project without modifications because their lawyers had reviewed it and determi
19.
▲
by
eskibars
5mo ago
Some things may be obvious to a lot of readers, but I want to spell things out explicitly because sometimes "OSS" etc have a lot of conflations. A license in the software sense is effectively the legal terms and conditions for usi
20.
▲
by
eskibars
5mo ago
One thing I mention to folks that seem to think AGPL "protects you" against a major corporation incorporating your product into a SaaS product: it mostly doesn't. It isn't written about often, but it's the reason ma
21.
▲
by
eskibars
5mo ago
I know the space is starting to get crowded, but I've been building one and I'd love to get feedback if you have time
22.
▲
Show HN: Free security scanning for OSS projects
2 points
by
eskibars
5mo ago
|
0 comments
23.
▲
by
eskibars
5mo ago
Location: Melbourne, AU Remote: sure, or in person (preferred) Technologies: Python, Lua, Docker, Java, pretty much all SQL/NoSQL. But I'm a bit unusual here in that my focus tends to be a bit more on the product side than the en
24.
▲
Show HN: Scan your OSS projects for vulnerabilities
(console.zeroquarry.com)
1 points
by
eskibars
5mo ago
|
0 comments
25.
▲
by
eskibars
7mo ago
Location: Melbourne, AU Remote: Indifferent. I've worked partially remote from 2015-2025 and in-person before/after. I like both Willing to relocate: no Technologies: python, SQL and most major BI tools, javascript, elasticsearc
26.
▲
by
eskibars
11mo ago
Isn't the entire point of this post that many companies opt for flexible+future proof far too prematurely?
27.
▲
by
eskibars
11mo ago
I agree in principal, but this whole post is lazy if it's AI-produced. There's certainly no original thought and as the comments mention here, most of the math is outright incorrect
28.
▲
by
eskibars
11mo ago
SPREAD | https://www.spread.ai/ | Technical writer & support | Germany (Berlin, ideally) | Full-time SPREAD builds B2B software for mechatronics customers like cars and defense systems. We help them design, build and di
29.
▲
by
eskibars
11mo ago
So as some of my own feelings/thoughts on this: I've also sat on the "receiving side" of a "free forever" campaign now 2 times in my career. The first time driven by the CEO and the second time driven by the m
30.
▲
by
eskibars
11mo ago
https://web.archive.org/web/20240124013352/https://planetsca... Says "free forever"
More ›