People are gonna learn real quick the ramifications of connecting all their apps and credentials to startups with zero security & data compliance posture.
I keep saying the strength is in the harness, not the model - because it's true. Not much use without a harness, though.
Here's VISA's open-source cybersecurity harness. Just add model; use hosted closed models, use hosted open models, run on-prem, whatever. Very cool of them to share this tech and lift the defensive cybersec poverty line.
@levelsio Problem will always be budget, right? A good pentest will cost $$$ (more if you want code review, architecture review, etc) and indie hacking usually have a tight budget
@jasonfried Have you consider making the code or docker available? It would be a nice way to enable deployments in coolify and other platforms (when not wanting to have a vps just for this)
Buscamos: talentos emergentes en aprendizaje automático de América Latina. Esta es tu oportunidad de ampliar las fronteras de la investigación en aprendizaje automático y generar un impacto. 🌎
@alejandrozepe Te recomiendo que le hagas una llamada a tu abogado / contador. No vayas a manejarlo mal y tener problemas graves (a veces, según wording y scope, tendrías que ser prácticamente una fintech... Cuida para que no)
My heart is so full. I’ll tell you why:
Over the past 10 years I’ve run into some incredible people just starting their way into security and bug hunting. Some I mentored, some I just offered a safe place to talk and ask questions.
This year, they are all winning CTFs, finding 0day, giving talks, and are supremely gainfully employed.
Im so proud of you all!
🫶you know who you are!
@alejandrozepe Si es un senior (poco o nada de guidance), entiende bien el código y trabaja bien (limpio, claro, comunica bien), AI hace pre review (o es otro review) y tu solo eres el segundo review será menos trabajo (ahora... No sé si haga sentido a nivel negocio...)