Viewing profile — eskibars
eskibars
HN member- Joined
- Mon, Dec 28, 2015, 4:50 PM UTC
- HN karma
- 377
- Public activity
- 108 items
- HN profile
- View on Hacker News ↗
About eskibars
Recent public activity
-
story
Show HN: DriftTrip – A Virtual Road Trip
I've always loved the idea of taking a "virtual road trip" between 2 cities. You get to experience the tourism ads or other short-form videos at each "stop" along the way. I hope o…
-
comment
Comment #48897993
Yeah, I think so. It's running on a pretty small VPS and I never implemented any caching. Should have thought about that before posting I guess. I see the CPU is currently pegged. …
-
comment
Comment #48897759
Also, a "just for fun" project: https://drifttrip.connelly.casa/ . I was always enthralled with the idea of taking a virtual road trip and then loading the local council's tourism …
-
comment
Comment #48897661
Building http://zeroquarry.com It's a way to augment small/overloaded security teams. It can pentest and then generate a pentester-style PDF report for auditors and procurement, tr…
- story
-
comment
Comment #48396327
What we've actually seen is a couple things that make this impractical "to just share a prompt". First, that nearly every major model still hallucinates a lot of vulnerabilities. E…
-
comment
Comment #48396106
I've been building a product ( https://zeroquarry.com ) that can use a variety of models for finding vulnerabilities. One of the things I've noticed is that the models will nearly …
-
comment
Comment #48218093
I've been a long-timer Obsidian user with a number of plugins. Recently I launched ZeroQuarry (a product to scan code for security vulnerabilities) and pointed it at a number of Ob…
- story
-
comment
Comment #48126959
I just left a job for a German B2B software company which sold primarily to large automotive, defense, and aerospace companies. Several of our customers specifically banned anythin…
-
comment
Comment #48094000
I suspect so as well. I've been running my own security scanning software (disclaimer: now starting a company @ zeroquarry.com) for this, and from what I've seen there's a huge val…
-
comment
Comment #48059512
"If it ain't broke, don't fix it" is its own area of risk that people often ignore
-
comment
Comment #48057961
We found a critical RCE in the popular Obsidian Tasks plugin. It's now been fixed, but wanted to let others know to update ASAP. A malicious markdown file can trigger the RCE
- story
-
comment
Comment #48045444
Sure, but there's a case I'm particularly aware of where one of the major cloud infrastructure providers was about to host a significant AGPL-licensed project without modifications…
-
comment
Comment #48044434
Some things may be obvious to a lot of readers, but I want to spell things out explicitly because sometimes "OSS" etc have a lot of conflations. A license in the software sense is …
-
comment
Comment #48044288
One thing I mention to folks that seem to think AGPL "protects you" against a major corporation incorporating your product into a SaaS product: it mostly doesn't. It isn't written …
-
comment
Comment #48017773
I know the space is starting to get crowded, but I've been building one and I'd love to get feedback if you have time
-
story
Show HN: Free security scanning for OSS projects
Hi HN, I've spent a lot of my career working in open source and I want to give back. Recently, I launched https://zeroquarry.com , which is a tool that helps you find 0-days in you…
-
comment
Comment #47982737
Location: Melbourne, AU Remote: sure, or in person (preferred) Technologies: Python, Lua, Docker, Java, pretty much all SQL/NoSQL. But I'm a bit unusual here in that my focus tends…
-
story
Show HN: Scan your OSS projects for vulnerabilities
Hi all, I've had a feeling for a while that there was going to be a war on software based on LLMs controlled by "bad actors." LLMs have gotten really good at finding security vulne…
-
comment
Comment #47229643
Location: Melbourne, AU Remote: Indifferent. I've worked partially remote from 2015-2025 and in-person before/after. I like both Willing to relocate: no Technologies: python, SQL a…
-
comment
Comment #45833568
Isn't the entire point of this post that many companies opt for flexible+future proof far too prematurely?
-
comment
Comment #45832784
I agree in principal, but this whole post is lazy if it's AI-produced. There's certainly no original thought and as the comments mention here, most of the math is outright incorrec…
-
comment
Comment #45807768
SPREAD | https://www.spread.ai/ | Technical writer & support | Germany (Berlin, ideally) | Full-time SPREAD builds B2B software for mechatronics customers like cars and defense sys…