<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: kyuradar</title><link>https://news.ycombinator.com/user?id=kyuradar</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 23 Apr 2026 07:29:08 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=kyuradar" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by kyuradar in "Trappsec – Deception as a Developer Tool"]]></title><description><![CDATA[
<p>A video explainer - <a href="https://www.youtube.com/watch?v=Tke40NKbYxk" rel="nofollow">https://www.youtube.com/watch?v=Tke40NKbYxk</a><p>trappsec is an open-source framework that helps developers detect attackers who probe API business logic. By embedding realistic decoy routes and honey fields that are difficult to distinguish from real API constructs, attackers are nudged to authenticate converting reconnaissance into actionable security telemetry. I'm looking for early adopters to help with feedback and refining the direction and form of this framework.</p>
]]></description><pubDate>Sat, 18 Apr 2026 19:13:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=47818651</link><dc:creator>kyuradar</dc:creator><comments>https://news.ycombinator.com/item?id=47818651</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47818651</guid></item><item><title><![CDATA[Trappsec – Deception as a Developer Tool]]></title><description><![CDATA[
<p>Article URL: <a href="https://trappsec.dev">https://trappsec.dev</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47818650">https://news.ycombinator.com/item?id=47818650</a></p>
<p>Points: 3</p>
<p># Comments: 1</p>
]]></description><pubDate>Sat, 18 Apr 2026 19:13:54 +0000</pubDate><link>https://trappsec.dev</link><dc:creator>kyuradar</dc:creator><comments>https://news.ycombinator.com/item?id=47818650</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47818650</guid></item><item><title><![CDATA[Show HN: Trappsec – Active Defense via Business Logic Deception]]></title><description><![CDATA[
<p>Article URL: <a href="https://trappsec.dev">https://trappsec.dev</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47661913">https://news.ycombinator.com/item?id=47661913</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 06 Apr 2026 15:07:19 +0000</pubDate><link>https://trappsec.dev</link><dc:creator>kyuradar</dc:creator><comments>https://news.ycombinator.com/item?id=47661913</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47661913</guid></item><item><title><![CDATA[New comment by kyuradar in "Ask HN: What are you working on? (February 2026)"]]></title><description><![CDATA[
<p>I'm working on trappsec - an experimental open source framework that helps developers detect attackers who probe API business logic.<p>By embedding realistic decoy routes and honey fields that are difficult to distinguish from real API constructs, attackers are nudged to authenticate — converting reconnaissance into actionable security telemetry.<p>github: <a href="https://github.com/trappsec-dev/trappsec" rel="nofollow">https://github.com/trappsec-dev/trappsec</a><p>docs: <a href="https://trappsec.dev" rel="nofollow">https://trappsec.dev</a></p>
]]></description><pubDate>Wed, 11 Feb 2026 11:58:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=46973868</link><dc:creator>kyuradar</dc:creator><comments>https://news.ycombinator.com/item?id=46973868</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46973868</guid></item><item><title><![CDATA[Show HN: Trappsec – detect attackers probing API business logic]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/trappsec-dev/trappsec">https://github.com/trappsec-dev/trappsec</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46882024">https://news.ycombinator.com/item?id=46882024</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 04 Feb 2026 06:03:12 +0000</pubDate><link>https://github.com/trappsec-dev/trappsec</link><dc:creator>kyuradar</dc:creator><comments>https://news.ycombinator.com/item?id=46882024</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46882024</guid></item><item><title><![CDATA[Show HN: Trappsec – open-source library to catch attackers probing your API]]></title><description><![CDATA[
<p>WAFs and most traditional detection tools are blind to business logic abuses. They can catch a SQL injection pattern, but they can't tell if a legitimate user is probing for privilege escalation, IDOR or mapping out your internal API structure. I built trappsec to cover this gap - with decoys that are difficult to distinguish from real API resources. By treating your API surface as a defensive asset, you generate high-confidence alerts that contain intent and identity attribution.<p>I am currently looking to collect as much feedback as possible on the core concepts and API design.<p>I currently support Flask, FastAPI and ExpressJS. Post feedback, will then proceed with porting this to the top 2-3 web frameworks in other relevant languages (Go, Ruby, Java etc.)</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46872263">https://news.ycombinator.com/item?id=46872263</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Tue, 03 Feb 2026 15:33:33 +0000</pubDate><link>https://trappsec.dev/</link><dc:creator>kyuradar</dc:creator><comments>https://news.ycombinator.com/item?id=46872263</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46872263</guid></item></channel></rss>