frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

The Final Step to Secure File Uploads

https://newsletter.ferranverdes.net/p/the-final-step-to-secure-file-uploads
2•ferranverdes•2h ago

Comments

ferranverdes•2h ago
Thinking about security in terms of vulnerabilities is an outdated mindset.

"Are we vulnerable?" is a wrong question. The one that leads to real protection is "Are we exploitable?".

Risk isn't about how many CVEs you have. It's about what attackers can leverage to cause damage.

In the cloud era, attackers can harm a company without taking advantage of a single CVE.

They can simply drain your cloud budget by abusing storage, bandwidth, or compute resources, for instance.

Take file uploads as a good illustration of this. When there are no resource limits, the feature itself becomes a risk.

Scalability is great. But unlimited is not.

Many times, a few clear boundaries make all the difference, and every developer should be aware of them.

Let's dive into the technical side of this post. Just make sure they read it carefully.

AWS outage exposes Achilles heel: central control plane

https://www.theregister.com/2025/10/20/aws_outage_chaos/
3•beardyw•2m ago•0 comments

YC deal size inflation calculator. Including "unicorn" adjustment

https://www.danielfalbo.com/yc-inflation-calculator
1•danielfalbo•2m ago•0 comments

Colin Jost, Pete Davidson and the Staten Island Ferry Fiasco

https://www.nytimes.com/2025/10/20/style/colin-jost-pete-davidson-staten-island-ferry.html
1•axiomdata316•6m ago•0 comments

Brain Entrain (40hz mode inspired by MIT Research)

https://brainentrain.web.app/
1•MichealCodes•6m ago•1 comments

Research results are cultural artifacts, not public goods

https://lemire.me/blog/2025/10/17/research-results-are-cultural-artifacts-not-public-goods/
1•vinhnx•7m ago•0 comments

Funny Domain

https://thisdomain.sucks/domain/penisland-net
1•nachoag7•9m ago•0 comments

Why I'm not a fan of zero-copy Apache Kafka-Apache Iceberg

https://jack-vanlightly.com/blog/2025/10/15/why-im-not-a-fan-of-zero-copy-apache-kafka-apache-ice...
1•vinhnx•9m ago•0 comments

Japan Unleashes Capitalism by Letting 'Zombie' Companies Die

https://www.bloomberg.com/features/2025-japan-zombie-companies-debt
1•pr337h4m•11m ago•0 comments

Show HN: Restring – a fast, smart web toolbox for JSON, JWT, Base64, and more

https://restring.dev
1•kang_li•13m ago•0 comments

Elegy for AWS us-east-1 (on guitar) [video]

https://www.youtube.com/shorts/gMolfiaUrPI
1•jszafran•13m ago•0 comments

The Human Only Public License

https://frederic.vanderessen.com/posts/hopl/
2•freediver•14m ago•0 comments

Show HN: Wyapy – Capture customer feedback and uncover what to improve

https://www.wyapy.com
1•tony31•15m ago•0 comments

Claude for Life Sciences

https://www.anthropic.com/news/claude-for-life-sciences
1•meetpateltech•15m ago•0 comments

Ask HN: Better Brain Entrainment?

1•MichealCodes•16m ago•0 comments

Show HN: Excalidraw for Sticky Notes

https://stickyflo.app/
1•abhishekbasu•16m ago•0 comments

AI and the Art of Persuasion

https://fleetingswallow.com/winning-small-claims-with-ai/
1•pcoz•16m ago•1 comments

Measuring Engineering Productivity

https://justoffbyone.com/posts/measuring-engineering-productivity/
1•cancan•17m ago•0 comments

DaoFlow: Not an AWS Wrapper, your bare metal / VM wrapper

https://github.com/DaoFlow-dev/DaoFlow
1•imWildCat•19m ago•1 comments

AWS us-east-1 outage on 2025-10-20: 7% of teams were paged

https://heyoncall.com/blog/aws-outage-2025-10-20-percent-paged
1•compumike•20m ago•1 comments

AI will never be your friend

https://www.msn.com/en-us/entertainment/news/ai-will-never-be-your-friend/ar-AA1OObbs
7•RickJWagner•20m ago•0 comments

Kohler launches smart toilet camera

https://techcrunch.com/2025/10/19/kohler-unveils-a-camera-for-your-toilet/
7•alangibson•24m ago•1 comments

Windows Shell Previews

https://textslashplain.com/2025/10/20/windows-shell-previews/
1•speckx•25m ago•0 comments

Trump Lists Top Demands on China Before Trade Talks Resume

https://www.bloomberg.com/news/articles/2025-10-20/trump-says-us-will-be-fine-with-china-as-trade...
3•zerosizedweasle•26m ago•3 comments

Show HN: Copilot AI Agent

https://copilotaiagent.com
1•Fra_sol•26m ago•1 comments

Xyne: Open-source LLM-driven search engine for Google Workspace

https://github.com/xynehq/xyne
1•ignoramous•27m ago•0 comments

Show HN: Visual autocomplete for drawings (real-time Human-AI interaction)

https://github.com/olwal/AiDrawing
2•olwal•28m ago•0 comments

What I Self Host

https://fredrikmeyer.net/2025/10/18/what-i-self-host.html
9•FredrikMeyer•29m ago•1 comments

Spin-orbit torque switching of epitaxial ferrimagnetic insulator

https://www.nature.com/articles/s44306-025-00105-z
1•PaulHoule•29m ago•0 comments

Building a lightweight ImGui profiler in ~500 lines of C++

https://vittorioromeo.com/index/blog/sfex_profiler.html
1•ibobev•30m ago•0 comments

China is well positioned for a trade showdown with Trump

https://www.ft.com/content/c2fd550d-cbca-4e39-a9a5-29a1e9d902c4
5•zerosizedweasle•30m ago•0 comments