Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
joj123
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
Security tools inside coding agents get ignored unless we do things
(boringappsec.com)
2 points
by
joj123
3mo ago
|
0 comments
2.
▲
The SDLC is changing and so will AppSec (again)
(boringappsec.substack.com)
2 points
by
joj123
1y ago
|
0 comments
3.
▲
Security slows down Change Management and we have a chance to fix it
(boringappsec.substack.com)
1 points
by
joj123
1y ago
|
0 comments
4.
▲
by
joj123
2y ago
I am a founder of a company that generates LLM-generated output (the users know that). I am curious if folks would prefer we make it more "human-like", or do you prefer we just add more disclaimers of the text being LLM generated?
5.
▲
Why ADR v/s Shift-left is the wrong way to think about AppSec
(boringappsec.substack.com)
2 points
by
joj123
2y ago
|
0 comments
6.
▲
by
joj123
2y ago
Thanks. That's a good point, should have linked to the landing page instead :)
7.
▲
Show HN: Seezo SDR – Automated security design reviews
(app.seezo.io)
5 points
by
joj123
2y ago
|
2 comments
8.
▲
Managing LLM risk for companies using 3rd party LLMs
(boringappsec.substack.com)
1 points
by
joj123
3y ago
|
0 comments
9.
▲
by
joj123
3y ago
My cynical take is that HR teams don't know how to manage or engage remote teams. Instead of picking up that skill, they are forcing a return to office.
10.
▲
by
joj123
3y ago
I have no idea what they have built. Hope they talk about it though :)
11.
▲
by
joj123
3y ago
1. I agree with your point that Prompt Injection can still affect the consumer of a third party LLM 2. I prefer to categorize it as a supply chain security issue, since the vulnerability is with a software provider that you are consuming.
12.
▲
by
joj123
3y ago
Agree that the ownership of using a vulnerable 3rd party is on you. I would just categorize that as supply chain risk and not prompt injection.
13.
▲
by
joj123
3y ago
(Author of the newsletter here) It's early days, but the simplest use case has been to improve employee productivity (Github Copilot, ChatGPT etc.). The Stripe CEO just tweeted that over half of their employees are using an internal LL
14.
▲
Degrading UX to improve security hurts both UX and security
(boringappsec.substack.com)
2 points
by
joj123
3y ago
|
0 comments
15.
▲
Security's Prioritisation Problem
(boringappsec.substack.com)
1 points
by
joj123
3y ago
|
0 comments
16.
▲
Is CloudSec the new AppSec? tldr – not quite
(boringappsec.substack.com)
1 points
by
joj123
4y ago
|
0 comments
17.
▲
Building a static analysis program at Razorpay
(engineering.razorpay.com)
1 points
by
joj123
4y ago
|
0 comments
18.
▲
A simple framework on when WAFs work and when they may not
(boringappsec.substack.com)
1 points
by
joj123
5y ago
|
0 comments
19.
▲
Top AppSec metrics and why they are hard to measure
(boringappsec.substack.com)
2 points
by
joj123
5y ago
|
0 comments
20.
▲
Boring Appsec
(boringappsec.substack.com)
1 points
by
joj123
5y ago
|
0 comments
21.
▲
by
joj123
5y ago
Fair enough. Guess IDE plugins work even better for that
22.
▲
by
joj123
5y ago
The CI service is free, with some limitations on how long the findings stay on the dashboard, SSO integration and maybe a few others. The paid version was $40/usr/mo the last time I checked Once we figured it out, it takes us a f
23.
▲
by
joj123
5y ago
Out of curiosity, Is there value in doing this over (say) running a GitHub Action post commit and failing the build if it finds something nasty?
24.
▲
by
joj123
6y ago
I do the same with Whatsapp using a neat trick someone told me about. Create a group(call it "Share with self" or similar) with you and another person. Then, remove that person from the group.. that's it! Functionally it&#x
25.
▲
by
joj123
6y ago
+1 If any of you get a chance, try the "Najangud rasbaLe" variety often found in Mysore. It's my absolutely favorite kind of banana Edit 1: typos Edit 2: More details on what's ailing the rasbaLe and how fickle crops c
26.
▲
by
joj123
6y ago
I guess the idea is that TLS is sufficiently complicated that you can take tangents during the interview and establish if the candidate can understand and communicate complex concepts
27.
▲
by
joj123
6y ago
You make many of leaps of faiths to get to your conclusion. Let's for a second assume that's all accurate, are you in favour of government solving this problem by an executive decision? Note that the same State refuses to regulat
28.
▲
by
joj123
6y ago
One last point: Wipro has performed way better than expected during COVID ( https://www.livemint.com/companies/news/wipro-soars-as-june-... ) TCS has made an announcement that they will not have any layoffs during
29.
▲
by
joj123
6y ago
Wait, are you in good faith comparing H1B workers to slavery? I am not an expert on American history, but if you did, that escalated quickly :). The only rebuttal I have is, that no employee on Infosys is forced on a Lufthansa economy clas
30.
▲
by
joj123
6y ago
Wow. That's a mean acronym (whoever came up with it). FWIW - these companies add tremendous value to enterprises in the US and yes, they do that by paying lower wages to folks flying in from India (compared to American counterparts), b
More ›