HNHacker News
TopNewBestAskShowJobs

eskibars

378 karma · joined December 28, 2015

https://zeroquarry.com
submissionscomments
eskibars··on Ask HN: What are you working on? (September 2026)
https://zeroquarry.com/

It's an approach to defensive security for software products (especially smaller companies) by acting as the security team you don't have/can't afford. It does security recon/analysis, etc via AI.

I got tired of all of the LLM labs building firewalls of "oh, nobody is allowed to do security research/find+fix vulnerabilities in their software unless they apply for special registration."

Instead of saying "oh, anything that the model determines is security research is a vulnerability threat", it does reliably enforceable analysis like "look for a TXT record in DNS the same way a SSL provider would ensure you own the property". So it can do "live" penetration tests against your infrastructure if you provide authorization

It handles things like incoming "security researcher" e-mails to cut down on the noise of nonsense vulnerability reports by acting as your security team that defends against the reports

It provides provable/signed attestation that a pentester has checked your code/live infrastructure/APIs/etc and validated them, and/or has done a check after you've remediated whatever issues that were found. It helps all 3 sides of the "company needs pentester" and "pentester" and "auditor"/"customer" to come to agreements on what's important and what's been solved

eskibars··on What AI code review misses: SSRF and more
Author here. I built ZeroQuarry, and I was considering deploying an open source link shortener or using a SaaS one. I googled around and then found iShortn, so ran the iShortn scan with it.

I found a bunch of vulnerabilities, which I sent to the maintainer and have now been patched, but some of the most interesting ones I found were that many of these vulnerabilities were actually crafted by (or at least reviewed by) CodeRabbit.

I think there are a lot of reasons to use AI code review tools these days, and no problem with CodeRabbit, but one of the things I've found interesting is a discussion from investors and potential customers about "why would I use a security code reviewer when I have an AI code reviewer in place already". I thought some of the examples here may be interesting for others.

eskibars··on Ask HN: What Are You Working On? (July 2026)
Yeah, I think so. It's running on a pretty small VPS and I never implemented any caching. Should have thought about that before posting I guess. I see the CPU is currently pegged. I was able to get it to load at least 1 trip myself though, so maybe retry in a bit
eskibars··on Ask HN: What Are You Working On? (July 2026)
Also, a "just for fun" project: https://drifttrip.connelly.casa/ . I was always enthralled with the idea of taking a virtual road trip and then loading the local council's tourism promo videos at each "stop"
eskibars··on Ask HN: What Are You Working On? (July 2026)
Building http://zeroquarry.com

It's a way to augment small/overloaded security teams. It can pentest and then generate a pentester-style PDF report for auditors and procurement, triage incoming e-mails from security researchers by then checking whether the vulnerabilities they claim actually exist and are exploitable, hook into GitHub to scan for vulnerabilities and auto-propose fixes or file GitHub issues for you.

It's free for Open Source projects, if anyone here is maintaining one

eskibars··on I built a vulnerable app and spent $1,500 seeing if LLMs could hack it
What we've actually seen is a couple things that make this impractical "to just share a prompt". First, that nearly every major model still hallucinates a lot of vulnerabilities. Especially with temperature=0.7 as states in the original blog here, you get very inconsistent results regardless of the prompt, but that's almost kind of moot to the bigger picture. What you really need is to override the planning phase beyond asking a model "find the vulnerabilities" and you need to add another 1+ checking phases for "validate these vulnerabilities." Without that, even with the absolute best models with the highest levels of thinking enabled, you end up with garbage.

Setting the prompts and the flow with a coordinator agent directly gives a system much better capability to investigate security issues because it doesn't rely on 1-shotting things

eskibars··on I built a vulnerable app and spent $1,500 seeing if LLMs could hack it
I've been building a product (https://zeroquarry.com) that can use a variety of models for finding vulnerabilities. One of the things I've noticed is that the models will nearly always comply with some of this, but how you prompt it matters a ton. I've worked on a set of prompts and approaches which rarely get flagged
eskibars··on Obsidian plugins are (mostly) dangerous
I've been a long-timer Obsidian user with a number of plugins. Recently I launched ZeroQuarry (a product to scan code for security vulnerabilities) and pointed it at a number of Obsidian plugins. I was initially surprised to find out that so many of them had RCEs baked in: that if you open a malicious .md file, you could inadvertently run untrusted code.

I've reached out to a number of the Obsidian plugin maintainers for responsible disclosure to let them know about the issues and how to fix them, and what surprised me even more was that the most common response was roughly "yeah, we all know Obsidian plugins are basically unsafe when used against untrusted markdown content." I was surprised by this response as an Obsidian user with a number of plugins installed. It made me rethink how I think about plugins.

I like their new community program that attempts to identify some risks, but IMO it's just far too little. Obsidian really needs to have a sandboxed system. I've reached out to Obsidian as well to flag some of these risks and suggested a sandbox system as well, but haven't really had much progress in moving the needle, so I wanted to raise awareness here.

eskibars··on The US is winning the AI race where it matters most: commercialization
I just left a job for a German B2B software company which sold primarily to large automotive, defense, and aerospace companies. Several of our customers specifically banned anything with the word "DeepSeek" -- hosted or self-hosted.

There's still a lot of naivety on what the difference is between models and platforms, and its easier for a lot of these big companies to just make a blanket statement like "nothing DeepSeek" than for their procurement teams to try to understand and negotiate with each vendor. They don't see the potential benefit over the potential risk of somebody misinterpreting or getting it wrong, so they outright ban it.

Most people that approve or buy software simply also just don't understand how models are being trained or if it's possible/how far a model could go to "introduce backdoors." A backdoor could be, from a business perspective, a model which has been trained to give answers that could hurt western business in a "strict text mode" or produces payloads in a programmatic mode that are intentionally trained to introduce software vulnerabilities.

Anyone can make arguments against these for a variety of reasons (looking at the transparency of both sides and comparing, etc) but for many reasons today and for better or worse, many Chinese models are being banned on big software contracts, which gets back to the title of the article

eskibars··on Mythos Finds a Curl Vulnerability
I suspect so as well.

I've been running my own security scanning software (disclaimer: now starting a company @ zeroquarry.com) for this, and from what I've seen there's a huge value in prompts + adversarial LLM review. Without adversarial review, you get garbage (as this blog points out: 4/5 basically are nonsense) and with a good prompt, you can use almost any "near frontier" model from my experience as long as the prompt helps with the guardrails or the model doesn't protect in such a strict way

eskibars··on Maybe you shouldn't install new software for a bit
"If it ain't broke, don't fix it" is its own area of risk that people often ignore
eskibars··on Critical RCE found in Obsidian Tasks plugin
We found a critical RCE in the popular Obsidian Tasks plugin. It's now been fixed, but wanted to let others know to update ASAP. A malicious markdown file can trigger the RCE
eskibars··on How I made $350K from an open-source JavaScript library using dual licensing
Sure, but there's a case I'm particularly aware of where one of the major cloud infrastructure providers was about to host a significant AGPL-licensed project without modifications because their lawyers had reviewed it and determined it would have been OK. The particular VC-backed open-core company then got word of it and changed their license off of AGPL. IYKYK
eskibars··on How I made $350K from an open-source JavaScript library using dual licensing
Some things may be obvious to a lot of readers, but I want to spell things out explicitly because sometimes "OSS" etc have a lot of conflations.

A license in the software sense is effectively the legal terms and conditions for using the software in any way. A license can define anything your legal mind can dream up: "only usable when you wear a red shirt," "only usable on the third Tuesday of the month," etc. You can multi-license things: "License A is that you can only use this software when you wear a red shirt. License B is that you can only use it on the third Tuesday of the month. This software is dual licensed under A and B: you can choose which license you want to use, but you must use one of them if you want to use the software legally, because those are the legal conditions I've laid out in using the software." If you use the software on Wednesday wearing a blue shirt, you're operating it against the terms and effectively are in breach of the license. This is (part of) why putting source code out on the internet isn't the same as "open source" and why downloading and using source code you find without reviewing the actual license terms may end you up in hot water. It's why standardized licenses are so helpful to legal teams that review these sorts of things at corporations.

These are obviously facetious examples, but most for-profit entities might choose a dual licensing structure where "if you want to run it for free, you choose something in the realm of open source licenses and if you don't like the terms of those licenses, you pay us for a license that gives you something else." In cases like the blog author's here: you say "option A is AGPL" and "option B is you pay us for a license to remove AGPL and which gives you different rights." You hope enough companies are scared by AGPL to want to pay you for the non-AGPL version and the distribution/OSS-friendly nature of AGPL helps you build a user-base enough that by the time it gets to a legal team to approve/deny, that the legal team denies and is willing to pay to make the problem go away.

eskibars··on How I made $350K from an open-source JavaScript library using dual licensing
One thing I mention to folks that seem to think AGPL "protects you" against a major corporation incorporating your product into a SaaS product: it mostly doesn't.

It isn't written about often, but it's the reason many "open core" companies moved away from AGPL to protect their revenue from larger SaaS/IaaS/PaaS players from eating their lunch.

Some writings are:

- https://writing.kemitchell.com/2021/01/24/Reading-AGPL

- https://katedowninglaw.com/2019/09/08/the-great-open-source-...

- https://drewdevault.com/blog/Anti-AGPL-propaganda/

eskibars··on Securing a DoD contractor: Finding a multi-tenant authorization vulnerability
I know the space is starting to get crowded, but I've been building one and I'd love to get feedback if you have time
eskibars··on Ask HN: Who wants to be hired? (May 2026)
Location: Melbourne, AU

Remote: sure, or in person (preferred)

Technologies: Python, Lua, Docker, Java, pretty much all SQL/NoSQL. But I'm a bit unusual here in that my focus tends to be a bit more on the product side than the engineering.

CV: https://connelly.casa/Users/Public/Desktop/Shane%20Connelly%...

Email: me@sha.ne

About: I've worked in leadership positions at the border of product and engineering at several tech-heavy companies. I was head of product for Elasticsearch and Kong, CPO at SPREAD GmbH, and just moved from Germany to Australia earlier this year after having spent most of my career in San Francisco area. I'm currently very interested in product security areas especially and have been launching https://zeroquarry.com

eskibars··on Ask HN: Who wants to be hired? (March 2026)
Location: Melbourne, AU

Remote: Indifferent. I've worked partially remote from 2015-2025 and in-person before/after. I like both

Willing to relocate: no

Technologies: python, SQL and most major BI tools, javascript, elasticsearch, LLMs and surrounding tooling, various API gateways

CV: https://connelly.casa/?url=/Users/Public/Desktop/Shane%20Con...

LinkedIn: https://www.linkedin.com/in/shaneconnelly/

Email: in the CV

I'm a technologist turned product manager and into product leadership. Most of my career has been leading product teams in complex B2B applied ML/AI and "big data" products. I was product lead for Elasticsearch @ Elastic, Kong @ Kong, Vectara's head of product, and currently CPO @ SPREAD AI. We've recently relocated our family to Australia due to my wife changing positions, and realistically can't be at a company where everyone in the company is in/near Germany except me (the hours just don't work for a company that isn't committed to remote work).

eskibars··on What the hell have you built
Isn't the entire point of this post that many companies opt for flexible+future proof far too prematurely?
eskibars··on Solarpunk is happening in Africa
I agree in principal, but this whole post is lazy if it's AI-produced. There's certainly no original thought and as the comments mention here, most of the math is outright incorrect
eskibars··on Ask HN: Who is hiring? (November 2025)
SPREAD | https://www.spread.ai/ | Technical writer & support | Germany (Berlin, ideally) | Full-time

SPREAD builds B2B software for mechatronics customers like cars and defense systems. We help them design, build and diagnose problems with their systems faster. We do it with a combination of a well-designed ontology we've spent years working on as well as AI-based systems. Right now, we're looking for a technical writer and also someone to start our support organization.

Candidates must be in Germany already, though specific location within the country doesn't matter that much

eskibars··on PlanetScale Offering $5 Databases
So as some of my own feelings/thoughts on this: I've also sat on the "receiving side" of a "free forever" campaign now 2 times in my career. The first time driven by the CEO and the second time driven by the marketing team (and supported by the CEO). In both cases, I knew the truth (sitting on the product management side) that there was no sustainable way to have a "free forever" campaign: that there was finite end in both cases on the 2-5 year horizon before we needed to change plans. I advocated against adding the "forever" verbiage knowing this. The first time, I didn't push strongly: it was my mistake.

The second time, I pushed strongly and made sure the entire executive team knew that we would be misleading our users. I pointed to the horizon and talked about the problems with "forever" language. I had to push very strongly back on the marketing team to change verbiage and then they silently made updates anyway to add "forever" verbiage. They were eventually fired for this.

But what I find concerning here isn't that the "free" tier went away (it almost always must) but that there's denial and push-back in this set of threads about the verbiage. You made a mistake. Own it and apologize for the verbiage you put out there. Don't deny that it was ever there or argue over pedantic details about where/how that verbiage was placed.

eskibars··on PlanetScale Offering $5 Databases
https://web.archive.org/web/20240124013352/https://planetsca...

Says "free forever"

eskibars··on Ask HN: Who is hiring? (October 2025)
SPREAD | https://www.spread.ai/ | Technical writer | Germany (Berlin, ideally) | Full-time

SPREAD builds B2B software for mechatronics customers like cars and defense systems. We help them design, build and diagnose problems with their systems faster. We do it with a combination of a well-designed ontology we've spent years working on as well as AI-based systems. Right now, we're looking for a technical writer to join our team that's really forward thinking to own the writing, tooling, and also lead the company in ambitious technical writing.

You can reach me at shane at spread . ai with your resume

eskibars··on I want an iPhone Mini-sized Android phone (2022)
Man this hits home. I'm a reasonably sized human, but there are almost no devices on the market outside of iPhones where I can reach from bottom right to upper left with 1 hand without shifting the phone around in my hand. I hate it.

I'd be willing to take less battery life to get something like this, but nearly everything that's anywhere close either has no NFC (which means mobile payments are out the door) or doesn't have 5G or just has such an awful camera/processor as to be basically unusable for many every-day tasks.

eskibars··on Ask HN: Who is hiring? (July 2025)
SPREAD | https://www.spread.ai/ | On-site (Germany) | Product Manager | Full Time

SPREAD is a software company built to help electromechanical companies (automotive, aerospace, defense) build their products better and faster by bringing together the different data they have into a single system.

We have several of the largest automotive OEMs as customers already and are looking to expand our low-code platform.

https://spread-gmbh.jobs.personio.de/job/456964?language=en&... has job details and you're welcome to email [shane] at our domain as well

eskibars··on That Dropped Call with Customer Service? It Was on Purpose
Email me at shane@[my username].com or send me yours and I'll follow up with a ticket number
eskibars··on Airpass – Easily overcome WiFi time limits
This is just wrong. FWIW, I owned a bike, and this is wrong under both "bike" and "non-bike" conditions.

If you live directly next to the San Rafael central station, that'd be easiest/fastest. But San Rafael is much bigger than that. I'll get into that in a second. There are 2 basic options to do this trip:

Fastest option 1 was to go to San Rafael Station (I'll call it SR here on out) then bus to SF, then bike/walk to the Caltrain station, which was about a 25 minute walk. The buses from SR to SF ran often as rarely as once per hour, and occasionally they just don't show up at all. The ride took 30-60 minutes depending on traffic. There weren't always bike spaces on the bus, so sometimes you needed to lock your bike up in SR and you were going to be walking in SF to Caltrain. But because of the variability on traffic times, you have to leave incredibly early if you want to catch the fastest train to Palo Alto. And if you're going to California Avenue (which was where I was going to), the express option basically doesn't exist.

Here's how that plays out: 10 minute bike to SR station (or 30-40 minute walk, depending on your walk speed), you have hopefully timed things right to get on a bus leaving once every 30-60 minutes and that the bus is actually showing up: otherwise, you're waiting 30-60 minutes for the next one. Then a 30-60 minute ride into SF. Then a ~5 minute bike ride or 15-20 minute walk to Caltrain. Then a 45-60 minute ride to Palo Alto, but again the transfers aren't timed (they couldn't be, given the difference of where the bus dropoff is)

The second real alternative is replacing the first bus leg with a ferry leg by going to Larkspur Landing. There is the SMART train that goes there, but for some wild reason drops people off a 15 minute walk from the ferry and then has no timed transfer.

I did the journey dozens of times and never completed it in less than 2h 30m but more commonly was 4h and had more than 1 occasion where it took much longer than that.

eskibars··on That Dropped Call with Customer Service? It Was on Purpose
I already did this.

For transparency to others here, here's what happened:

I submitted a support request and separately a GDPR request for my information and removal. I let the legal team at Backblaze know what happened as well by e-mailing legal@.

- The support request auto-responded with "We will respond to your support request (<insert ticket number here>) within one day." That was 21 days ago. No response.

- The legal team stated that my information has never been sold to 3rd parties. Strange unless Backblaze is operating its own AI cold calling en masse and then refused to complete my GDPR request of telling me the data it had collected on me. They refused to acknowledge that I had gotten an AI cold call

So no. This is frankly a BS path forward. Nobody at Backblaze as far as I can tell is taking this seriously

eskibars··on That Dropped Call with Customer Service? It Was on Purpose
Even worse: I got a sales call from Backblaze a few weeks ago that was an AI voice agent. It seemed super suspicious the way it was talking, so I asked it directly if it was an AI, and it then said yes.

I asked it to talk to a real person: a manager, legal, or compliance employee and it hung up on me

Page 1 of 3Next →