<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: andrei</title><link>https://news.ycombinator.com/user?id=andrei</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 16 Apr 2026 13:31:12 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=andrei" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by andrei in "Infinite Craft"]]></title><description><![CDATA[
<p>just link to the real thing :) [0]<p>[0]: <a href="https://twitter.com/nealagarwal/status/1747284257582506102" rel="nofollow">https://twitter.com/nealagarwal/status/1747284257582506102</a></p>
]]></description><pubDate>Wed, 31 Jan 2024 16:45:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=39205937</link><dc:creator>andrei</dc:creator><comments>https://news.ycombinator.com/item?id=39205937</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=39205937</guid></item><item><title><![CDATA[New comment by andrei in "Blank turns your TV screen black until you press any button on a remote"]]></title><description><![CDATA[
<p><i>facepalm</i> I read that paragraph, but my brain skipped that sentence for some reason. Thanks for clarifying</p>
]]></description><pubDate>Wed, 12 Apr 2023 18:13:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=35544202</link><dc:creator>andrei</dc:creator><comments>https://news.ycombinator.com/item?id=35544202</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=35544202</guid></item><item><title><![CDATA[New comment by andrei in "Blank turns your TV screen black until you press any button on a remote"]]></title><description><![CDATA[
<p>How is this different than just turning your TV off? I feel like I'm missing something</p>
]]></description><pubDate>Wed, 12 Apr 2023 18:09:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=35544126</link><dc:creator>andrei</dc:creator><comments>https://news.ycombinator.com/item?id=35544126</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=35544126</guid></item><item><title><![CDATA[New comment by andrei in "Why modern software is slow"]]></title><description><![CDATA[
<p>Somewhat relevant: <a href="https://tonsky.me/blog/disenchantment/" rel="nofollow">https://tonsky.me/blog/disenchantment/</a></p>
]]></description><pubDate>Fri, 30 Sep 2022 01:35:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=33029791</link><dc:creator>andrei</dc:creator><comments>https://news.ycombinator.com/item?id=33029791</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=33029791</guid></item><item><title><![CDATA[New comment by andrei in "Fuzzing Go APIs for SQL Injection"]]></title><description><![CDATA[
<p>As of go 1.18, fuzzing is built into the toolchain itself, and is what we're using in this post.<p>We go over the basics here [0], if you'd like to start at the beginning<p>[0]: <a href="https://blog.fuzzbuzz.io/go-fuzzing-basics/" rel="nofollow">https://blog.fuzzbuzz.io/go-fuzzing-basics/</a></p>
]]></description><pubDate>Wed, 31 Aug 2022 17:29:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=32665561</link><dc:creator>andrei</dc:creator><comments>https://news.ycombinator.com/item?id=32665561</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32665561</guid></item><item><title><![CDATA[New comment by andrei in "Fuzzing Go APIs for SQL Injection"]]></title><description><![CDATA[
<p>It's much more common than you may think - especially at larger organizations where engineers go "off-script" frequently.<p>That being said, we wanted to highlight an example of how fuzzing can be applied to a typical (albeit, toy) API to find logic bugs, and figured SQL Injection would be something that resonated with most (all?) developers.</p>
]]></description><pubDate>Wed, 31 Aug 2022 17:14:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=32665319</link><dc:creator>andrei</dc:creator><comments>https://news.ycombinator.com/item?id=32665319</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32665319</guid></item><item><title><![CDATA[New comment by andrei in "Fuzzing Go APIs for SQL Injection"]]></title><description><![CDATA[
<p>A lot of folks we talk to think fuzzing is only useful for finding memory leaks in C++ programs, so we wanted to show how adding a single fuzz test to your API can find SQL injection and other logic bugs.<p>Would love to hear others' experience with Go fuzzing now that it's been out for a few months.</p>
]]></description><pubDate>Wed, 31 Aug 2022 16:36:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=32664719</link><dc:creator>andrei</dc:creator><comments>https://news.ycombinator.com/item?id=32664719</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32664719</guid></item><item><title><![CDATA[Fuzzing Go APIs for SQL Injection]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.fuzzbuzz.io/fuzzing-go-apis-for-sql-injection/">https://blog.fuzzbuzz.io/fuzzing-go-apis-for-sql-injection/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=32664270">https://news.ycombinator.com/item?id=32664270</a></p>
<p>Points: 64</p>
<p># Comments: 22</p>
]]></description><pubDate>Wed, 31 Aug 2022 16:11:19 +0000</pubDate><link>https://blog.fuzzbuzz.io/fuzzing-go-apis-for-sql-injection/</link><dc:creator>andrei</dc:creator><comments>https://news.ycombinator.com/item?id=32664270</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32664270</guid></item><item><title><![CDATA[New comment by andrei in "Oven: The Company Behind Bun"]]></title><description><![CDATA[
<p>> 2. What measures is Oven taking to proactively detect and mitigate vulnerabilities? (e.g.: fuzzing, audits, bug bounties)<p>We're huge fans of bun at Fuzzbuzz (waiting for it to get a bit more production-ready). If Jarred's interested, we'd be happy to donate some compute to support fuzzing Bun.<p><hn username> @ fuzzbuzz.io</p>
]]></description><pubDate>Wed, 24 Aug 2022 04:18:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=32574933</link><dc:creator>andrei</dc:creator><comments>https://news.ycombinator.com/item?id=32574933</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32574933</guid></item><item><title><![CDATA[House passes bill that DoD software can’t have any CVEs]]></title><description><![CDATA[
<p>Article URL: <a href="https://twitter.com/JGamblin/status/1560016175265972224">https://twitter.com/JGamblin/status/1560016175265972224</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=32504225">https://news.ycombinator.com/item?id=32504225</a></p>
<p>Points: 19</p>
<p># Comments: 9</p>
]]></description><pubDate>Thu, 18 Aug 2022 01:47:11 +0000</pubDate><link>https://twitter.com/JGamblin/status/1560016175265972224</link><dc:creator>andrei</dc:creator><comments>https://news.ycombinator.com/item?id=32504225</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=32504225</guid></item><item><title><![CDATA[Advanced Go Fuzzing Techniques]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.fuzzbuzz.io/writing-effective-go-fuzz-tests/">https://blog.fuzzbuzz.io/writing-effective-go-fuzz-tests/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=31769065">https://news.ycombinator.com/item?id=31769065</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Thu, 16 Jun 2022 18:00:43 +0000</pubDate><link>https://blog.fuzzbuzz.io/writing-effective-go-fuzz-tests/</link><dc:creator>andrei</dc:creator><comments>https://news.ycombinator.com/item?id=31769065</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=31769065</guid></item><item><title><![CDATA[New comment by andrei in "Gitlab New Logo: DevOps Is at the Center of Gitlab"]]></title><description><![CDATA[
<p>I've heard this talked about before, and I believe there's a phrase for it, but I don't remember. Do you happen to know?</p>
]]></description><pubDate>Wed, 27 Apr 2022 18:16:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=31183717</link><dc:creator>andrei</dc:creator><comments>https://news.ycombinator.com/item?id=31183717</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=31183717</guid></item><item><title><![CDATA[New comment by andrei in "Go Fuzz Testing"]]></title><description><![CDATA[
<p>Good catch :) fixed!</p>
]]></description><pubDate>Tue, 29 Mar 2022 22:22:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=30849119</link><dc:creator>andrei</dc:creator><comments>https://news.ycombinator.com/item?id=30849119</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=30849119</guid></item><item><title><![CDATA[New comment by andrei in "Go Fuzz Testing"]]></title><description><![CDATA[
<p>It does! Fuzzing actually started off as a tool built by security researchers to find vulnerabilities in parsers, and other complex codebases, usually written in C/C++ (looking for memory bugs). So anything that deals with untrusted binary data is a prime candidate for fuzz testing.<p>Go’s fuzzing framework supports `[]byte` arguments as well as all of the standard Go primitives, so you should be able to test netcode this way.<p>If you're looking for a C/C++ solution, my recommendation is libfuzzer [0]. We've also built our own C/C++ fuzzing engine at Fuzzbuzz [1].<p>[0] <a href="https://llvm.org/docs/LibFuzzer.html" rel="nofollow">https://llvm.org/docs/LibFuzzer.html</a><p>[1] <a href="https://docs.fuzzbuzz.io/docs/getting-started-in-c-or-c++" rel="nofollow">https://docs.fuzzbuzz.io/docs/getting-started-in-c-or-c++</a></p>
]]></description><pubDate>Tue, 29 Mar 2022 19:24:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=30847184</link><dc:creator>andrei</dc:creator><comments>https://news.ycombinator.com/item?id=30847184</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=30847184</guid></item><item><title><![CDATA[Go Fuzz Testing]]></title><description><![CDATA[
<p>Article URL: <a href="https://blog.fuzzbuzz.io/go-fuzzing-basics/">https://blog.fuzzbuzz.io/go-fuzzing-basics/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=30843814">https://news.ycombinator.com/item?id=30843814</a></p>
<p>Points: 114</p>
<p># Comments: 22</p>
]]></description><pubDate>Tue, 29 Mar 2022 15:23:47 +0000</pubDate><link>https://blog.fuzzbuzz.io/go-fuzzing-basics/</link><dc:creator>andrei</dc:creator><comments>https://news.ycombinator.com/item?id=30843814</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=30843814</guid></item><item><title><![CDATA[New comment by andrei in "Apple removes Python 2.7 in macOS 12.3 beta"]]></title><description><![CDATA[
<p>This was a big reason for why our entire eng team moved to linux</p>
]]></description><pubDate>Fri, 28 Jan 2022 17:36:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=30117797</link><dc:creator>andrei</dc:creator><comments>https://news.ycombinator.com/item?id=30117797</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=30117797</guid></item><item><title><![CDATA[New comment by andrei in "Use Pixar's story formula to win over investors"]]></title><description><![CDATA[
<p>I think this downplays things quite a bit. I grew up as a middle class immigrant in Canada. My parents have office jobs, but basically 0 connections (certainly not the ones you're implying you need to raise).<p>In university (which I paid for myself through internships + loans), my cofounder and I just started coding on an idea, which got us into YC, which helped us get in front of a bunch of VCs, which allowed us to raise $3m in seed funding. No connections, just lots of googling and talking/pitching to anyone that would pay attention to us.<p>It could've been the 5% luck you're talking about, but certainly don't think that coming from a well-connected family is the only way to fundraise in 2021.</p>
]]></description><pubDate>Sat, 14 Aug 2021 22:57:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=28184660</link><dc:creator>andrei</dc:creator><comments>https://news.ycombinator.com/item?id=28184660</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=28184660</guid></item><item><title><![CDATA[New comment by andrei in "Fuzzing Grub, part 2: Going Faster"]]></title><description><![CDATA[
<p>Part 1 here: <a href="https://sthbrx.github.io/blog/2021/03/04/fuzzing-grub-part-1/" rel="nofollow">https://sthbrx.github.io/blog/2021/03/04/fuzzing-grub-part-1...</a></p>
]]></description><pubDate>Thu, 15 Jul 2021 03:43:58 +0000</pubDate><link>https://news.ycombinator.com/item?id=27841183</link><dc:creator>andrei</dc:creator><comments>https://news.ycombinator.com/item?id=27841183</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=27841183</guid></item><item><title><![CDATA[Fuzzing Grub, part 2: Going Faster]]></title><description><![CDATA[
<p>Article URL: <a href="https://sthbrx.github.io/blog/2021/06/14/fuzzing-grub-part-2-going-faster/">https://sthbrx.github.io/blog/2021/06/14/fuzzing-grub-part-2-going-faster/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=27841177">https://news.ycombinator.com/item?id=27841177</a></p>
<p>Points: 1</p>
<p># Comments: 1</p>
]]></description><pubDate>Thu, 15 Jul 2021 03:43:33 +0000</pubDate><link>https://sthbrx.github.io/blog/2021/06/14/fuzzing-grub-part-2-going-faster/</link><dc:creator>andrei</dc:creator><comments>https://news.ycombinator.com/item?id=27841177</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=27841177</guid></item><item><title><![CDATA[New comment by andrei in "Let's stop building APIs around a network hack (2017)"]]></title><description><![CDATA[
<p>Should add the date to the title: (2017)</p>
]]></description><pubDate>Sun, 25 Apr 2021 05:52:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=26930584</link><dc:creator>andrei</dc:creator><comments>https://news.ycombinator.com/item?id=26930584</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=26930584</guid></item></channel></rss>