Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
trustfixsec
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
trustfixsec
6mo ago
been using claude code heavily for a while now and yeah the memory files are just plaintext sittng in your home directory. no encryption, no access controls. if you're running it on a shared machine or a dev server that's a real e
2.
▲
by
trustfixsec
6mo ago
AI generated an IAM trust policy for me that looked perfect — correct syntax, right structure, passed review. except the OIDC sub condition was scoped to the entire org instead of the specific repo. any workflow in the org could assume the
3.
▲
by
trustfixsec
6mo ago
i run claude code pretty heavily for overnight sessions and yeah the inconsistency b/w runs is noticeable. same prompt, same codebase, wildly different quality depending on the day. the frustrating part is when it half-finishes somethi
4.
▲
by
trustfixsec
6mo ago
honest take from someone who spends most of their time looking at how orgs actually get breached — the scariest thing isnt what a frontier model can do, but what orgs have already left wide open. i've been auditing CI/CD setups fo
5.
▲
by
trustfixsec
6mo ago
The part that worries me most isnt AI-generated malware- its AI agents getting their own cloud creds. we're already seeing OIDC trust policies being setup for bedrock and copilot agents with the same 'make it work and move on'
6.
▲
by
trustfixsec
6mo ago
Lived this many times. the worst part about these freezes is what happens right before the freeze - everyone will rush to push their changes prior to cutoff, which is exactly when you get the sloppiest commits. and then after the freeze lif
7.
▲
by
trustfixsec
6mo ago
great find, irony of a security scanner being the attack vector is brutal. For those who havent read it: attackers poisoned Trivy(widely used vulnerability scanner), which gave them a static AWS API Key from the EC's CI pipeline, leadi
8.
▲
by
trustfixsec
6mo ago
Nice approach. Confidence scoring on what's the safe one to delete is smart, and that's the hardest part of any cleanup tool. How are you handling false positives? I've been thinking about similar confidence scoring in a diff