Live data from Hacker News

Viewing profile — guypod

guypod

HN member
Joined
Wed, Jul 08, 2015, 1:18 PM UTC
HN karma
24
Public activity
26 items

About guypod

No profile information was provided.

Recent public activity

  1. story
  2. story
    Show HN: A package manager for agent skills with built-in evals

    I'm Guy, the founder behind Snyk — now building Tessl, a package manager for agent skills. We’ve recently witnessed that most teams still treat skills as static artifacts: markdown…

  3. comment
    Comment #34695655

    While Flox does improve the Nix UX, I don't think that's the most exciting thing about it. The real impact is in bringing the underlying power of Nix to people who would have never…

  4. story
  5. comment
    Comment #16466380

    Fair point. I see the security concern, as far as availability goes, as something FaaS improves, but it's definitely up to you to decide whether downtime is better or worse than a …

  6. comment
    Comment #16466367

    The fact OS patching is done by people whose entire job and profession is to keep systems patched matters - they are patched more often and faster. In addition, the fact servers do…

  7. comment
    Comment #16466349

    - A sys admin will not be rolling out OS patches. The platform does itself. - Attackers typically use DoS to make a system unavailable, not just make it expensive to operate. I do …

  8. comment
    Comment #16466324

    I have no doubt the operators of those networks do - on average - a far better job operating the systems. My concern is that FaaS developers would therefore consider FaaS naturally…

  9. comment
    Comment #16465102

    It's entirely doable to manage permissions granularly, but it's not the most natural thing to do. It's FAR easier to broaden permissions. The more functions you have and the more t…

  10. comment
    Comment #15760506

    I think it's an absolute statement about the lack of awareness to this risk. Of course some of these site would not actually be vulnerable, but I would bet the vast majority of the…

  11. comment
    Comment #15760485

    Scanning for vulnerable components is different. All the tool has to do is find out the site is using the specific library, the vulnerabilities themselves are manually validated.

  12. story
  13. story
  14. comment
    Comment #14517808

    awkward typo there! Fixed now.

  15. comment
    Comment #14517802

    This article was very much about the data we've collected and our analysis of it, as opposed to our opinions as to why - had to keep it to a reasonable length! So we kept that sect…

  16. comment
    Comment #14517784

    You're right, I tried to keep this section as brief as I could. DOM Based XSS could happen from any source, but the hardest-to-detect (and very common) variant is using the fragmen…

  17. comment
    Comment #14515760

    Snyk's done some analysis on that aspect specifically too: https://snyk.io/blog/77-percent-of-sites-use-vulnerable-js-l...

  18. comment
    Comment #13832836

    Rubysec is awesome but outdated, lacks many of the vulnerabilities in https://Snyk.io/ Also, Snyk covers JS issues, both Nodd and client side

  19. story
  20. comment
    Comment #13375939

    It's worth noting this isn't unique to MongoDB. The "Marked" npm package, with it's 2 million downloads, doesn't sanitize input by default. "st", another popular package, allows di…

  21. story
  22. story
  23. story
  24. story
  25. comment
    Comment #10803647

    Fair point, language is probably too broad (was just in the lawyers template...). Note it is "limited to the extent needed to provide the service", but can be reduced further, as w…