<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: brene</title><link>https://news.ycombinator.com/user?id=brene</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 16 Apr 2026 04:18:42 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=brene" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by brene in "ElectricSQL database takeover vulnerability found by AI"]]></title><description><![CDATA[
<p>Rene from Casco here. While our agents were performing a security test, they discovered a database takeover vulnerability. It's a good example of how SQL injection is still a test path that needs to be explicitly be validated. Really want to give props to the ElectricSQL team from issue reported to issue fixed and deployed, it took ~2 hours.</p>
]]></description><pubDate>Tue, 14 Apr 2026 15:16:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=47766758</link><dc:creator>brene</dc:creator><comments>https://news.ycombinator.com/item?id=47766758</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47766758</guid></item><item><title><![CDATA[ElectricSQL database takeover vulnerability found by AI]]></title><description><![CDATA[
<p>Article URL: <a href="https://casco.com/blog/electricsql-order-by-sql-injection">https://casco.com/blog/electricsql-order-by-sql-injection</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47766757">https://news.ycombinator.com/item?id=47766757</a></p>
<p>Points: 5</p>
<p># Comments: 2</p>
]]></description><pubDate>Tue, 14 Apr 2026 15:16:23 +0000</pubDate><link>https://casco.com/blog/electricsql-order-by-sql-injection</link><dc:creator>brene</dc:creator><comments>https://news.ycombinator.com/item?id=47766757</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47766757</guid></item><item><title><![CDATA[New comment by brene in "The Blueprint of a North Korean Attack on Open-Source"]]></title><description><![CDATA[
<p>Just debugging the issue :-)</p>
]]></description><pubDate>Tue, 07 Apr 2026 22:00:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=47681880</link><dc:creator>brene</dc:creator><comments>https://news.ycombinator.com/item?id=47681880</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47681880</guid></item><item><title><![CDATA[New comment by brene in "The Blueprint of a North Korean Attack on Open-Source"]]></title><description><![CDATA[
<p>are you using Safari's Lockdown Mode?</p>
]]></description><pubDate>Tue, 07 Apr 2026 20:40:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=47681074</link><dc:creator>brene</dc:creator><comments>https://news.ycombinator.com/item?id=47681074</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47681074</guid></item><item><title><![CDATA[New comment by brene in "The Blueprint of a North Korean Attack on Open-Source"]]></title><description><![CDATA[
<p>Author here. We were analyzing a compromised contributor account targeting better-auth when we noticed something interesting about the attack vector. Most coverage of supply chain attacks focuses on the "what happened" but I wanted to document the "how it actually works" with the deobfuscated code.<p>Wwo things stood out: 
1. hiding the payload in next.config.mjs is clever because GitHub's UI truncates long lines so the malicious string is literally invisible when scrolling through the file. second, storing the c2 payload on binance smart chain means theres no server to take down. The axios attack was mitigated by removing the GitHub-hosted payload. This one can't be.<p>2. found 30+ repos with the same signature string. Pretty sure there's way more we didn't catch with basic string matching.<p>happy to answer questions about the deobfuscation process or the c2 protocol analysis.</p>
]]></description><pubDate>Tue, 07 Apr 2026 16:37:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=47677953</link><dc:creator>brene</dc:creator><comments>https://news.ycombinator.com/item?id=47677953</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47677953</guid></item><item><title><![CDATA[The Blueprint of a North Korean Attack on Open-Source]]></title><description><![CDATA[
<p>Article URL: <a href="https://casco.com/blog/the-blueprint-of-a-north-korean-attack-on-open-source">https://casco.com/blog/the-blueprint-of-a-north-korean-attack-on-open-source</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47677952">https://news.ycombinator.com/item?id=47677952</a></p>
<p>Points: 32</p>
<p># Comments: 12</p>
]]></description><pubDate>Tue, 07 Apr 2026 16:37:50 +0000</pubDate><link>https://casco.com/blog/the-blueprint-of-a-north-korean-attack-on-open-source</link><dc:creator>brene</dc:creator><comments>https://news.ycombinator.com/item?id=47677952</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47677952</guid></item><item><title><![CDATA[New comment by brene in "So, you want to chunk really fast?"]]></title><description><![CDATA[
<p>Do you see this project merge with the Chonkie at some point? Or do you intend to keep it separate?</p>
]]></description><pubDate>Mon, 05 Jan 2026 17:54:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=46502149</link><dc:creator>brene</dc:creator><comments>https://news.ycombinator.com/item?id=46502149</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46502149</guid></item><item><title><![CDATA[New comment by brene in "Show HN: Sim – Apache-2.0 n8n alternative"]]></title><description><![CDATA[
<p>How does it deal with loops? I’ve often see workflow builders struggle at that?</p>
]]></description><pubDate>Thu, 11 Dec 2025 19:37:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=46236104</link><dc:creator>brene</dc:creator><comments>https://news.ycombinator.com/item?id=46236104</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46236104</guid></item><item><title><![CDATA[New comment by brene in "Show HN: Tracking AI Code with Git AI"]]></title><description><![CDATA[
<p>I actually wonder is there a way to feed back some consistently reedited code into the context window of your coding agent tools, so that future edits require less tokens?</p>
]]></description><pubDate>Mon, 10 Nov 2025 17:46:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=45878523</link><dc:creator>brene</dc:creator><comments>https://news.ycombinator.com/item?id=45878523</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45878523</guid></item><item><title><![CDATA[New comment by brene in "Show HN: Prism – Let browser agents access any app"]]></title><description><![CDATA[
<p>Hi Rene from Casco here. I think the post just referenced us as a customer because we use it for pentesting. For us, Prism solves the "browser agents can reliably auth into any website" problem.</p>
]]></description><pubDate>Thu, 25 Sep 2025 19:42:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=45377942</link><dc:creator>brene</dc:creator><comments>https://news.ycombinator.com/item?id=45377942</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45377942</guid></item><item><title><![CDATA[New comment by brene in "Show HN: Prism – Let browser agents access any app"]]></title><description><![CDATA[
<p>Hi - Rene from Casco here. Thought to share a bit about our journey of dealing with auth for browser agents before Prism. We have a diverse set of customers whose login experience differ dramatically. Sometimes it's directly accessible on request, other times, you have to click through into a "login menu", other times we'd be dealing with Google sign-in and OTP.<p>We initially tried manually uploading session cookies to our browser agent after we authenticate locally. But soon realized how unscalable that is. We needed a general purpose API that allows our agents to auth into any application reliably. We needed something like Prism because making an agent reliable for our vertical is hard enough and I don't want us to maintain infrastructure just for the purposes of managing test user credentials and session management. If you're using browser agents and they've "hit the auth wall", then you know what I'm talking about.<p>Thanks for building Prism for us and letting us be a pilot customer. The API is straightforward and a pleasure to use. Can't wait for user sign-up and GitHub auth support to come soon.</p>
]]></description><pubDate>Thu, 25 Sep 2025 19:40:20 +0000</pubDate><link>https://news.ycombinator.com/item?id=45377922</link><dc:creator>brene</dc:creator><comments>https://news.ycombinator.com/item?id=45377922</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45377922</guid></item><item><title><![CDATA[New comment by brene in "AWS launches Kiro, its Cursor clone"]]></title><description><![CDATA[
<p>wait, it's completely free during the preview period? That's a better deal than Cursor, Windsurf, or Claude Code. Gotta check it out</p>
]]></description><pubDate>Mon, 14 Jul 2025 15:37:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=44561427</link><dc:creator>brene</dc:creator><comments>https://news.ycombinator.com/item?id=44561427</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44561427</guid></item><item><title><![CDATA[New comment by brene in "Show HN: HelixDB – Open-source vector-graph database for AI applications (Rust)"]]></title><description><![CDATA[
<p>How does this scale horizontally across multiple regions. Is this something on your roadmap?</p>
]]></description><pubDate>Wed, 14 May 2025 18:20:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=43987628</link><dc:creator>brene</dc:creator><comments>https://news.ycombinator.com/item?id=43987628</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43987628</guid></item><item><title><![CDATA[New comment by brene in "Show HN: Airweave – Let agents search any app"]]></title><description><![CDATA[
<p>Pretty cool stuff. How does it deal with self-hosted data sources? can it run inside a VPC and talk to my RDS instances directly?</p>
]]></description><pubDate>Mon, 12 May 2025 17:18:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=43965355</link><dc:creator>brene</dc:creator><comments>https://news.ycombinator.com/item?id=43965355</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43965355</guid></item><item><title><![CDATA[New comment by brene in "Show HN: Sim Studio – Open-Source Agent Workflow GUI"]]></title><description><![CDATA[
<p>I checked it out and it’s quite polished for a workflow builder. But I struggled for it to handle lists of content well. But I saw that’s already an ongoing feature request.</p>
]]></description><pubDate>Mon, 28 Apr 2025 21:24:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=43826279</link><dc:creator>brene</dc:creator><comments>https://news.ycombinator.com/item?id=43826279</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43826279</guid></item><item><title><![CDATA[New comment by brene in "Launch HN: Cua (YC X25) – Open-Source Docker Container for Computer-Use Agents"]]></title><description><![CDATA[
<p>will this also be available as a hosted service? Or do you have instructions on how to manage a fleet of these manually while you're building the orchestration workflows?</p>
]]></description><pubDate>Wed, 23 Apr 2025 16:58:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=43774154</link><dc:creator>brene</dc:creator><comments>https://news.ycombinator.com/item?id=43774154</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43774154</guid></item><item><title><![CDATA[New comment by brene in "Interviews on Skype"]]></title><description><![CDATA[
<p>Feedback noted! Will evaluate this with the team. Thanks for the feedback</p>
]]></description><pubDate>Fri, 25 Aug 2017 19:58:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=15101685</link><dc:creator>brene</dc:creator><comments>https://news.ycombinator.com/item?id=15101685</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=15101685</guid></item><item><title><![CDATA[New comment by brene in "Interviews on Skype"]]></title><description><![CDATA[
<p>Test candidates using a real-time code editor over Skype. Give instructions, interview candidates and provide feedback via the in-browser Skype call. The in-browser code editor allows candidates to run their code and check their results. Help candidates avoid syntactic mistakes with real-time syntax highlighting for 7 popular programming languages.</p>
]]></description><pubDate>Fri, 25 Aug 2017 17:11:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=15100250</link><dc:creator>brene</dc:creator><comments>https://news.ycombinator.com/item?id=15100250</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=15100250</guid></item><item><title><![CDATA[Interviews on Skype]]></title><description><![CDATA[
<p>Article URL: <a href="https://skype.com/interviews">https://skype.com/interviews</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=15100235">https://news.ycombinator.com/item?id=15100235</a></p>
<p>Points: 24</p>
<p># Comments: 6</p>
]]></description><pubDate>Fri, 25 Aug 2017 17:10:42 +0000</pubDate><link>https://skype.com/interviews</link><dc:creator>brene</dc:creator><comments>https://news.ycombinator.com/item?id=15100235</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=15100235</guid></item><item><title><![CDATA[New comment by brene in "Learn Apollo: Build GraphQL Apps with React, React Native or Exponent"]]></title><description><![CDATA[
<p>I tried using Scaphold but the main issue is that their entire service is just so buggy. They try to do everything and then nothing works "really" well. 
It's actually because I got so disappointed, I was looking for other solutions and Graph.cool was the best that I could find. 
The best is their support. They are so highly responsive on their Slack channel, I rarely see that.</p>
]]></description><pubDate>Fri, 16 Dec 2016 15:31:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=13193898</link><dc:creator>brene</dc:creator><comments>https://news.ycombinator.com/item?id=13193898</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=13193898</guid></item></channel></rss>