Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
guypod
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
guypod
2mo ago
(I'm the founder of Snyk and Tessl, apply what biases you wish) I think we're mixing three optimizations: higher success rate, higher consistency and higher efficiency. Success rate is about building confidence the agent can succe
2.
▲
Show HN: A package manager for agent skills with built-in evals
(tessl.io)
7 points
by
guypod
8mo ago
|
2 comments
3.
▲
by
guypod
4y ago
While Flox does improve the Nix UX, I don't think that's the most exciting thing about it. The real impact is in bringing the underlying power of Nix to people who would have never used it. Nix has all sorts of core portability,
4.
▲
GitHub Security Cheatsheet
(snyk.io)
3 points
by
guypod
8y ago
|
0 comments
5.
▲
by
guypod
9y ago
Fair point. I see the security concern, as far as availability goes, as something FaaS improves, but it's definitely up to you to decide whether downtime is better or worse than a big bill.
6.
▲
by
guypod
9y ago
The fact OS patching is done by people whose entire job and profession is to keep systems patched matters - they are patched more often and faster. In addition, the fact servers don't live long means it's easier to patch servers (
7.
▲
by
guypod
9y ago
- A sys admin will not be rolling out OS patches. The platform does itself. - Attackers typically use DoS to make a system unavailable, not just make it expensive to operate. I do note the cost concern, but if attackers are unsuccessful
8.
▲
by
guypod
9y ago
I have no doubt the operators of those networks do - on average - a far better job operating the systems. My concern is that FaaS developers would therefore consider FaaS naturally secure, and forget there are still quite a few security ris
9.
▲
by
guypod
9y ago
It's entirely doable to manage permissions granularly, but it's not the most natural thing to do. It's FAR easier to broaden permissions. The more functions you have and the more time they've had to morph, the more likel
10.
▲
by
guypod
9y ago
I think it's an absolute statement about the lack of awareness to this risk. Of course some of these site would not actually be vulnerable, but I would bet the vast majority of them don't even know they're using a library wit
11.
▲
by
guypod
9y ago
Scanning for vulnerable components is different. All the tool has to do is find out the site is using the specific library, the vulnerabilities themselves are manually validated.
12.
▲
State of Open Source Security Survey – Need Your Input
(snyk.io)
7 points
by
guypod
9y ago
|
0 comments
13.
▲
Equifax compromised via OSS library – who owns this, and how to defend yourself
(snyk.io)
12 points
by
guypod
9y ago
|
0 comments
14.
▲
by
guypod
9y ago
awkward typo there! Fixed now.
15.
▲
by
guypod
9y ago
This article was very much about the data we've collected and our analysis of it, as opposed to our opinions as to why - had to keep it to a reasonable length! So we kept that section short in the end. I do plan follow up posts that
16.
▲
by
guypod
9y ago
You're right, I tried to keep this section as brief as I could. DOM Based XSS could happen from any source, but the hardest-to-detect (and very common) variant is using the fragment (the part after the #) to inject the payload, which i
17.
▲
by
guypod
9y ago
Snyk's done some analysis on that aspect specifically too: https://snyk.io/blog/77-percent-of-sites-use-vulnerable-js-l...
18.
▲
by
guypod
10y ago
Rubysec is awesome but outdated, lacks many of the vulnerabilities in https://Snyk.io/ Also, Snyk covers JS issues, both Nodd and client side
19.
▲
Regular Expression Denial of Service and Catastrophic Backtracking
(snyk.io)
8 points
by
guypod
10y ago
|
1 comments
20.
▲
by
guypod
10y ago
It's worth noting this isn't unique to MongoDB. The "Marked" npm package, with it's 2 million downloads, doesn't sanitize input by default. "st", another popular package, allows directory listing by
21.
▲
Snyk's Style Guide: How we built it, and how we use it every day
(snyk.io)
5 points
by
guypod
10y ago
|
0 comments
22.
▲
The 5 dimensions of an npm dependency
(snyk.io)
8 points
by
guypod
10y ago
|
0 comments
23.
▲
How not to publish malicious npm packages
(snyk.io)
6 points
by
guypod
11y ago
|
0 comments
24.
▲
LinkNYC (NYC free Wifi) launched, but private wifi is limited to Apple devices
(link.nyc)
1 points
by
guypod
11y ago
|
0 comments
25.
▲
by
guypod
11y ago
Fair point, language is probably too broad (was just in the lawyers template...). Note it is "limited to the extent needed to provide the service", but can be reduced further, as we (Snyk) never had any intent to do anything more
26.
▲
by
guypod
11y ago
You've omitted the previous paragraph: We claim no intellectual property rights over the material you provide to the Service. Your profile and materials uploaded remain yours. However, to enable your use of the Platform, we do need to