Live data from Hacker News

Viewing profile — eskibars

eskibars

HN member
Joined
Mon, Dec 28, 2015, 4:50 PM UTC
HN karma
377
Public activity
108 items

About eskibars

https://zeroquarry.com

Recent public activity

  1. story
    Show HN: DriftTrip – A Virtual Road Trip

    I've always loved the idea of taking a "virtual road trip" between 2 cities. You get to experience the tourism ads or other short-form videos at each "stop" along the way. I hope o…

  2. comment
    Comment #48897993

    Yeah, I think so. It's running on a pretty small VPS and I never implemented any caching. Should have thought about that before posting I guess. I see the CPU is currently pegged. …

  3. comment
    Comment #48897759

    Also, a "just for fun" project: https://drifttrip.connelly.casa/ . I was always enthralled with the idea of taking a virtual road trip and then loading the local council's tourism …

  4. comment
    Comment #48897661

    Building http://zeroquarry.com It's a way to augment small/overloaded security teams. It can pentest and then generate a pentester-style PDF report for auditors and procurement, tr…

  5. story
  6. comment
    Comment #48396327

    What we've actually seen is a couple things that make this impractical "to just share a prompt". First, that nearly every major model still hallucinates a lot of vulnerabilities. E…

  7. comment
    Comment #48396106

    I've been building a product ( https://zeroquarry.com ) that can use a variety of models for finding vulnerabilities. One of the things I've noticed is that the models will nearly …

  8. comment
    Comment #48218093

    I've been a long-timer Obsidian user with a number of plugins. Recently I launched ZeroQuarry (a product to scan code for security vulnerabilities) and pointed it at a number of Ob…

  9. story
  10. comment
    Comment #48126959

    I just left a job for a German B2B software company which sold primarily to large automotive, defense, and aerospace companies. Several of our customers specifically banned anythin…

  11. comment
    Comment #48094000

    I suspect so as well. I've been running my own security scanning software (disclaimer: now starting a company @ zeroquarry.com) for this, and from what I've seen there's a huge val…

  12. comment
    Comment #48059512

    "If it ain't broke, don't fix it" is its own area of risk that people often ignore

  13. comment
    Comment #48057961

    We found a critical RCE in the popular Obsidian Tasks plugin. It's now been fixed, but wanted to let others know to update ASAP. A malicious markdown file can trigger the RCE

  14. story
  15. comment
    Comment #48045444

    Sure, but there's a case I'm particularly aware of where one of the major cloud infrastructure providers was about to host a significant AGPL-licensed project without modifications…

  16. comment
    Comment #48044434

    Some things may be obvious to a lot of readers, but I want to spell things out explicitly because sometimes "OSS" etc have a lot of conflations. A license in the software sense is …

  17. comment
    Comment #48044288

    One thing I mention to folks that seem to think AGPL "protects you" against a major corporation incorporating your product into a SaaS product: it mostly doesn't. It isn't written …

  18. comment
    Comment #48017773

    I know the space is starting to get crowded, but I've been building one and I'd love to get feedback if you have time

  19. story
    Show HN: Free security scanning for OSS projects

    Hi HN, I've spent a lot of my career working in open source and I want to give back. Recently, I launched https://zeroquarry.com , which is a tool that helps you find 0-days in you…

  20. comment
    Comment #47982737

    Location: Melbourne, AU Remote: sure, or in person (preferred) Technologies: Python, Lua, Docker, Java, pretty much all SQL/NoSQL. But I'm a bit unusual here in that my focus tends…

  21. story
    Show HN: Scan your OSS projects for vulnerabilities

    Hi all, I've had a feeling for a while that there was going to be a war on software based on LLMs controlled by "bad actors." LLMs have gotten really good at finding security vulne…

  22. comment
    Comment #47229643

    Location: Melbourne, AU Remote: Indifferent. I've worked partially remote from 2015-2025 and in-person before/after. I like both Willing to relocate: no Technologies: python, SQL a…

  23. comment
    Comment #45833568

    Isn't the entire point of this post that many companies opt for flexible+future proof far too prematurely?

  24. comment
    Comment #45832784

    I agree in principal, but this whole post is lazy if it's AI-produced. There's certainly no original thought and as the comments mention here, most of the math is outright incorrec…

  25. comment
    Comment #45807768

    SPREAD | https://www.spread.ai/ | Technical writer & support | Germany (Berlin, ideally) | Full-time SPREAD builds B2B software for mechatronics customers like cars and defense sys…