Viewing profile — guypod
guypod
HN member- Joined
- Wed, Jul 08, 2015, 1:18 PM UTC
- HN karma
- 24
- Public activity
- 26 items
- HN profile
- View on Hacker News ↗
About guypod
No profile information was provided.
Recent public activity
- story
-
story
Show HN: A package manager for agent skills with built-in evals
I'm Guy, the founder behind Snyk — now building Tessl, a package manager for agent skills. We’ve recently witnessed that most teams still treat skills as static artifacts: markdown…
-
comment
Comment #34695655
While Flox does improve the Nix UX, I don't think that's the most exciting thing about it. The real impact is in bringing the underlying power of Nix to people who would have never…
- story
-
comment
Comment #16466380
Fair point. I see the security concern, as far as availability goes, as something FaaS improves, but it's definitely up to you to decide whether downtime is better or worse than a …
-
comment
Comment #16466367
The fact OS patching is done by people whose entire job and profession is to keep systems patched matters - they are patched more often and faster. In addition, the fact servers do…
-
comment
Comment #16466349
- A sys admin will not be rolling out OS patches. The platform does itself. - Attackers typically use DoS to make a system unavailable, not just make it expensive to operate. I do …
-
comment
Comment #16466324
I have no doubt the operators of those networks do - on average - a far better job operating the systems. My concern is that FaaS developers would therefore consider FaaS naturally…
-
comment
Comment #16465102
It's entirely doable to manage permissions granularly, but it's not the most natural thing to do. It's FAR easier to broaden permissions. The more functions you have and the more t…
-
comment
Comment #15760506
I think it's an absolute statement about the lack of awareness to this risk. Of course some of these site would not actually be vulnerable, but I would bet the vast majority of the…
-
comment
Comment #15760485
Scanning for vulnerable components is different. All the tool has to do is find out the site is using the specific library, the vulnerabilities themselves are manually validated.
- story
- story
-
comment
Comment #14517808
awkward typo there! Fixed now.
-
comment
Comment #14517802
This article was very much about the data we've collected and our analysis of it, as opposed to our opinions as to why - had to keep it to a reasonable length! So we kept that sect…
-
comment
Comment #14517784
You're right, I tried to keep this section as brief as I could. DOM Based XSS could happen from any source, but the hardest-to-detect (and very common) variant is using the fragmen…
-
comment
Comment #14515760
Snyk's done some analysis on that aspect specifically too: https://snyk.io/blog/77-percent-of-sites-use-vulnerable-js-l...
-
comment
Comment #13832836
Rubysec is awesome but outdated, lacks many of the vulnerabilities in https://Snyk.io/ Also, Snyk covers JS issues, both Nodd and client side
- story
-
comment
Comment #13375939
It's worth noting this isn't unique to MongoDB. The "Marked" npm package, with it's 2 million downloads, doesn't sanitize input by default. "st", another popular package, allows di…
- story
- story
- story
- story
-
comment
Comment #10803647
Fair point, language is probably too broad (was just in the lawyers template...). Note it is "limited to the extent needed to provide the service", but can be reduced further, as w…