<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: dweinstein</title><link>https://news.ycombinator.com/user?id=dweinstein</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 11 Oct 2026 09:09:55 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=dweinstein" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[Show HN: Tiny filesystem honeypot for macOS with zero dependencies in Go]]></title><description><![CDATA[
<p>When malware, a rogue script, npm module, or an attacker with shell access starts scanning your home directory for credentials, the canary trips and fires an alert. Developer's computers are increasingly being targeted with attacks, for example the LiteLLM attacks demonstrate the recent risks and complex supply chain attacks.<p>I made this tool for macOS systems that helps detect when a package accesses something it shouldn't. It's a tiny go binary (less than 2k LOC) with no dependencies that will mount a webdav filesystem (no root) or NFS (root required) with fake secrets and send you a notification when anything accesses it. Very stupid simple. I've always really liked the canary/honeypot approach and this at least may give some folks a chance to detect (similar to like LittleSnitch) when something strange is going on!<p>When to use which mode? Use WebDAV for low-friction canaries you can spin up anywhere. Use NFS for canaries that need to survive an attacker who has your user shell and is looking around.</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47548938">https://news.ycombinator.com/item?id=47548938</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Fri, 27 Mar 2026 22:03:18 +0000</pubDate><link>https://github.com/dweinstein/canary</link><dc:creator>dweinstein</dc:creator><comments>https://news.ycombinator.com/item?id=47548938</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47548938</guid></item><item><title><![CDATA[New comment by dweinstein in "Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised"]]></title><description><![CDATA[
<p>cool - <a href="https://github.com/dweinstein/canary/blob/main/LICENSE" rel="nofollow">https://github.com/dweinstein/canary/blob/main/LICENSE</a></p>
]]></description><pubDate>Thu, 26 Mar 2026 20:38:30 +0000</pubDate><link>https://news.ycombinator.com/item?id=47535410</link><dc:creator>dweinstein</dc:creator><comments>https://news.ycombinator.com/item?id=47535410</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47535410</guid></item><item><title><![CDATA[New comment by dweinstein in "Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised"]]></title><description><![CDATA[
<p>thanks for your feedback!<p>that's a really good point and could be an interesting thing to play with as an extension. Since we potentially know which process is doing the "read" we could ask the user if it's ok to kill it. obviously the big issue is that we don't know how much has already been shipped off the system at that point but at least we have some alert to make some tough decisions.</p>
]]></description><pubDate>Wed, 25 Mar 2026 15:32:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=47518765</link><dc:creator>dweinstein</dc:creator><comments>https://news.ycombinator.com/item?id=47518765</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47518765</guid></item><item><title><![CDATA[New comment by dweinstein in "Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised"]]></title><description><![CDATA[
<p>hi, glad you like it and that it encourages you to try some things you've always wanted to do :-)<p>I was thinking for the license I'd do GPLv3. Would that work for you?</p>
]]></description><pubDate>Wed, 25 Mar 2026 15:31:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=47518743</link><dc:creator>dweinstein</dc:creator><comments>https://news.ycombinator.com/item?id=47518743</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47518743</guid></item><item><title><![CDATA[New comment by dweinstein in "Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised"]]></title><description><![CDATA[
<p><a href="https://github.com/dweinstein/canary" rel="nofollow">https://github.com/dweinstein/canary</a><p>I made this tool for macos systems that helps detect when a package accesses something it shouldn't. it's a tiny go binary (less than 2k LOC) with no dependencies that will mount a webdav filesystem (no root) or NFS (root required) with fake secrets and send you a notification when anything accesses it. Very stupid simple. I've always really liked the canary/honeypot approach and this at least may give some folks a chance to detect (similar to like LittleSnitch) when something strange is going on!<p>Next time the attack may not have an obvious performance issue!</p>
]]></description><pubDate>Tue, 24 Mar 2026 21:18:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=47509479</link><dc:creator>dweinstein</dc:creator><comments>https://news.ycombinator.com/item?id=47509479</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47509479</guid></item><item><title><![CDATA[New comment by dweinstein in "Decoding Apple Privacy Manifests for iOS Developers"]]></title><description><![CDATA[
<p>Apple announced at the Worldwide Developers Conference (WWDC) 2023 in June new initiatives to increase transparency about mobile app privacy. All mobile app developers will be required to submit a privacy manifest that details data collection practices and usages when they add or update an iOS app in App Store Connect, the platform used for publishing and tracking performance in the App Store.<p>Apple will offer a grace period for developers to become familiar with the forthcoming privacy requirements.<p>Beginning in fall 2023, Apple will email developers via when an app uses a privacy-impacting SDK without providing a privacy manifest or taps a required reason API without specifying a valid explanation in the privacy manifest. Starting in spring 2024, the privacy manifest will become mandatory and Apple will begin enforcing that requirement as part of the app review process.</p>
]]></description><pubDate>Wed, 15 Nov 2023 16:50:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=38278866</link><dc:creator>dweinstein</dc:creator><comments>https://news.ycombinator.com/item?id=38278866</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38278866</guid></item><item><title><![CDATA[Decoding Apple Privacy Manifests for iOS Developers]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.nowsecure.com/blog/2023/11/15/decoding-apple-privacy-manifests-for-ios-developers/">https://www.nowsecure.com/blog/2023/11/15/decoding-apple-privacy-manifests-for-ios-developers/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=38278865">https://news.ycombinator.com/item?id=38278865</a></p>
<p>Points: 1</p>
<p># Comments: 1</p>
]]></description><pubDate>Wed, 15 Nov 2023 16:50:08 +0000</pubDate><link>https://www.nowsecure.com/blog/2023/11/15/decoding-apple-privacy-manifests-for-ios-developers/</link><dc:creator>dweinstein</dc:creator><comments>https://news.ycombinator.com/item?id=38278865</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38278865</guid></item><item><title><![CDATA[Show HN: NowSecure Observer helps iOS devs with Privacy Manifests, app security]]></title><description><![CDATA[
<p>Apple announced at the Worldwide Developers Conference (WWDC) 2023 in June new initiatives to increase transparency about mobile app privacy. All mobile app developers will be required to submit a privacy manifest that details data collection practices and usages when they add or update an iOS app in App Store Connect, the platform used for publishing and tracking performance in the App Store.<p>Currently available in beta, the NowSecure Observer developer tool simplifies mobile privacy and security during the coding stage. It provides real-time visibility into how sensitive data is being used, stored and transmitted by first- and third-party code. It also enables developers to quickly resolve security and privacy issues and avoid App Store surprises and rejections.<p>Once developers add it to their iOS project, the NowSecure Observer SDK collects telemetry as the developer codes and at runtime during pre-prod testing. The SDK feeds information to the NowSecure Observer web app so you can see data flows, observe dependencies that have been introduced over time and generate Apple privacy manifests and mobile Software Bill of Materials (SBOM) reports. In addition, line of code-level detail and backtrace context ease remediation so developers understand what issues are critical to address and how. Developers can also receive guidance through the app store submission process in the form of a customized publication checklist to avoid rejections, and secure code training from NowSecure Academy.</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=38278778">https://news.ycombinator.com/item?id=38278778</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 15 Nov 2023 16:45:06 +0000</pubDate><link>https://www.nowsecure.com/nowsecure-observer/</link><dc:creator>dweinstein</dc:creator><comments>https://news.ycombinator.com/item?id=38278778</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38278778</guid></item></channel></rss>