Live data from Hacker News

Viewing profile — alp1n3_eth

alp1n3_eth

HN member
Joined
Sun, Nov 24, 2024, 2:44 PM UTC
HN karma
156
Public activity
74 items

About alp1n3_eth

No profile information was provided.

Recent public activity

  1. comment
    Comment #43808956

    What are you using on the backend to actually scan it? Is it just ZAP / Burp Scanner? Or are you scanning the code itself, and just using a Semgrep / Snyk approach? The landing pag…

  2. comment
    Comment #43772120

    A lot of people don't self-host it, even though it is open core. This is due to their docs being garbage and tons of differences between the offerings, so you can't even rely on th…

  3. comment
    Comment #43716984

    Yep! I was sad to see Skiff shutting down, as I loved their UI and there isn't a lot of tough competition that can match ProtonMail. I had already left Notion as the app kept getti…

  4. story
  5. comment
    Comment #43687225

    I'd say it doesn't exactly meet the minimum standard for a CVE, as it's more of a technique vs. an actual vulnerability in an application/library. If there was a repo that had a vu…

  6. comment
    Comment #43667105

    "Have fun suffering and hopefully you don't die as we go through 8 medications that will most likely fail, but there's a slim chance they'll work!"

  7. comment
    Comment #43656694

    Is there a good example repository to see how it's done?

  8. comment
    Comment #43611565

    You're a frontend web developer, so I'm assuming you're going to want to work in the areas of either: 1) application security engineering 2) application penetration testing 3) devs…

  9. story
  10. comment
    Comment #43563103

    Externally / Blackbox options would be Nessus, Nuclei, OWASP ZAP (as you mentioned), and Burp Suite. The two latter only work well when used in combination with manual methods thou…

  11. comment
    Comment #43563006

    A lot of aggregators will also not allow your blog to be posted if it's on a newsletter site like Substack, Patreon, etc. I use GitHub Pages for hosting, Porkbun for the domain, an…

  12. comment
    Comment #43561254

    You'd be surprised how much the government would potentially hurt itself in its own confusion. Not all parts of it are aligned to the same beliefs / mission, and there are certainl…

  13. story
  14. comment
    Comment #43525546

    I appreciate Caido because of the ability to save projects in the free tier, which I use for (personal use) different projects and tinkering. Burp Pro is my daily driver at work, a…

  15. comment
    Comment #43508499

    If you want a super bad audio-related journey, try fixing external speakers connected to a Linux box. It's abysmal, and 99% of it can only be done via the CLI. Nothing wrong with t…

  16. comment
    Comment #43499830

    Weirdly enough... not always. When it comes to random companies running their own VDP vs. hiring it out, it can be less than standard despite there being lots of resources on setti…

  17. story
  18. story
  19. story
  20. comment
    Comment #43413778

    Surprisingly, Go is great for CLI tooling. It may not have the insane speed that carefully planned and written Rust does, but it's very easy to write and be performant without even…

  21. comment
    Comment #43406823

    Before needing an LLM for it, they might want to ensure their doc system is using a search system that actually works. There's too many doc-focused templates / apps that have the w…

  22. comment
    Comment #43398573

    This is one area where I'll actively discourage fragmentation of the existing ecosystem. Currently in the U.S. it's: 1) PawBoost 2) Facebook Groups (which PawBoost usually posts to…

  23. comment
    Comment #43342876

    I think there's a difference between Microsoft refusing to support completely operational hardware for their new OS, and Apple not adding extra features / support into a pre-existi…

  24. comment
    Comment #43342692

    I don't know how it works overseas, but it sounds like this is a plus for US companies hiring US employees. According to the laws the company is required to fully ID you before hir…

  25. comment
    Comment #43245209

    They could build an optional "risk score" that open-source community-oriented projects could turn on. It could include requirements like having something dependabot-esque along wit…