Readit News logoReadit News
vvram commented on Launch HN: Dedalus Labs (YC S25) – Vercel for Agents    · Posted by u/windsor
muratsu · 4 months ago
Oh interesting. I've previously looked into implementing it myself but seemed like it would require a lot of effort. I would love to connect and learn more about your implementation. What's the best way to reach out to you? My email is available on my profile.
vvram · 4 months ago
Interesting, what do you use if not Openrouter?
vvram commented on ScreenCoder: An intelligent UI-to-code generation system   github.com/leigest519/Scr... · Posted by u/Dowwie
alooPotato · 5 months ago
Ohh nice can you say more? Do you somehow map your Figma components to React components?
vvram · 5 months ago
Nice! What kind of rules do you recommend? Are any of the rules in OSS?
vvram commented on Show HN: Jibril – Runtime security monitoring and enforcement for modern infra   garnet.ai/platform/jibril... · Posted by u/garnet
pwny700 · 9 months ago
eBPF is hard to do right. We couldn’t use Falco in production on our kubernetes infrastructure because of that.

I long for a production-ready runtime monitoring tool that can ACTUALLY be used in a blocking mode. Otherwise we’re always too late, and I’ve been burned more than once when dealing with an incident. Damned hackers always seem to come around weekends and holidays.

vvram · 9 months ago
If you can, please elaborate on what specifically were limitations with Falco?
vvram commented on Google to buy Wiz for $32B   reuters.com/technology/cy... · Posted by u/uncertainrhymes
Sohcahtoa82 · 9 months ago
> Wiz is very cohesive with a much nicer API and great UX

I actually don't care for Wiz's UX.

If you're a manager and just want to get an idea of what your security posture looks like, it's great. They have a million dashboards for you.

But if you're an AppSec Engineer that just wants to see which EC2 instances have which CVEs, it's kind of a pain in the pass and takes way too many clicks.

vvram · 9 months ago
How would you like to consume that information?
vvram commented on Show HN: Globstar – Open-source static analysis toolkit    · Posted by u/sanketsaurav
sanketsaurav · 10 months ago
Thanks!

> I'd love to hear how this project differs from Bearer, which is also written in Go and based on tree-sitter? https://github.com/Bearer/bearer

The primary difference is that we're optimizing for users to write their custom rules easily. We do plan to ship built-in checkers [1] so we cover at least OWASP Top 10 across all major programming languages. We're also truly open-source using the MIT license.

> Regardless, considering there is a large existing open-source collection of Semgrep rules, is there a way they can be adapted or transpiled to tree-sitter S-expressions so that they may be reused with Globstar?

I'm pretty sure there should be a way to make that work. We believe writing checkers (and having a long list of built-in checkers) will be a commodity in a world where AI can generate S-expressions (or tree-sitter node queries in Go) for any language with very high accuracy (which is where we have an advantage as compared to tools that use a custom DSL). To that extent, we're focused on improving the runtime itself so we can support complex use cases from our YAML and Go interfaces. If the community can help us port rules from other sources to our built-in checkers, we'd love that!

[1] https://github.com/DeepSourceCorp/globstar/pulls

vvram · 10 months ago
Great release! What is the delta to achieve that porting using a trained approach?
vvram commented on Leveraging AI for efficient incident response   engineering.fb.com/2024/0... · Posted by u/Amaresh
LASR · a year ago
We've shifted our oncall incident response over to mostly AI at this point. And it works quite well.

One of the main reasons why this works well is because we feed the models our incident playbooks and response knowledge bases.

These playbooks are very carefully written and maintained by people. The current generation of models are pretty much post-human in following them, performing reasoning and suggesting mitigations.

We tried indexing just a bunch of incident slack channels and result was not great. But with explicit documentation, it works well.

Kind of proves what we already know, garbage in, garbage out. But also, other functions, eg: PM, Design have tried automating their own workflows, but doesn't work as well.

vvram · a year ago
That's great to hear. What is your current tool chain in the effort? Do you have a structure for Playbooks and KBs you would recommend
vvram commented on Show HN: Telescope – Hassle-free company research   scope.quantichq.com/... · Posted by u/GRVYDEV
vvram · 2 years ago
Interesting problem, but it's hard to say what you offer compares to others. You should probably have some examples for visitors to understand the value prop without signup.
vvram commented on A bacterial culprit for rheumatoid arthritis?   the-scientist.com/news-op... · Posted by u/pseudolus
michalu · 3 years ago
Which brand of fish oil did you use?
vvram · 3 years ago
+1 Would be great if you can share the brand
vvram commented on Markdoc: Stripe's Markdown-based authoring framework   markdoc.io... · Posted by u/colinclerk
nkohari · 4 years ago
Right now we're only using it in our narrative docs (http://stripe.com/docs) but we have plans to use it in the reference docs as well.
vvram · 4 years ago
What powers the API docs ?
vvram commented on IBM’s Watson Health is sold off in parts   statnews.com/2022/01/21/i... · Posted by u/alexmorley
tekstar · 4 years ago
I worked for a large e-commerce company. I wanted to investigate putting all our support data into Watson and see what sort of recommendations it could provide, maybe a sort of auto-suggestion to help our customers. Three really funny points stand out from the experience:

1) To apply for Watson access you needed to show C-level approval, so our CEO put his name and phone number on the application (trying Watson was somewhat his idea). A few months later, an IBM marketing team called HIS CELL and asked for ME. Imagine how it felt to have the CEO walk up to me, deadpan hand me his personal iphone and say "It's for you."..

2) They told me they'd help me with the support data idea, and every meeting we set up they tried to pitch "what if we put Watson on all of your customer's storefronts, we could add a 'powered by watson' banner on every page, and you give us a cut of GMV?". I pivoted them to our plugin framework and told them to build it themselves.

3) To demo the technology, the first step was to buy a $250k server from IBM. To demo it.

Big LOLs all around, never trust big blue.

vvram · 4 years ago
This is not an IBM thing only, this is fate of most companies that did not transition from sales led

u/vvram

KarmaCake day19August 31, 2016View Original