frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

I Spent 3 Months Researching Image-Based Attacks

https://zero-trust-web.vercel.app/
3•Raviteja_•2h ago

Comments

Raviteja_•2h ago
I Built a Security API Solo - Here's How I Turned 3 Months of Research Into a Product From security rabbit hole to live API: A solo dev's journey.

It started with a phone call at 2 AM. A friend's SaaS got hacked. The attack vector was embarrassingly simple: a user's profile picture. Somehow, a JPEG file managed to compromise their entire backend. After helping him triage the incident, I couldn't stop thinking about it. How did an image - something we all accept as harmless - become an attack vector? I went down a 3-month rabbit hole. And when I came out the other side, I had built something I think other developers actually need.

---

The Problem Nobody Talks About Every app that accepts user uploads has a hidden vulnerability. The industry "solution" is metadata stripping - running tools like ExifTool or ImageMagick to remove GPS coordinates, camera info, and timestamps. But here's what I learned: Threats don't live in metadata. They hide in: Polyglot files - A single file that's valid as both an image AND executable code Steganography - Hidden data encoded in pixel values (invisible to the human eye) Image bombs - A 50KB file that expands to 50GB when decoded (crashes your server)

None of these survive traditional "sanitization." I knew there had to be a better way.

---

Finding the Solution (That Enterprise Companies Charge $15k/Year For) After weeks of research, I stumbled onto a concept the military and enterprise use: Content Disarm and Reconstruction (CDR). The idea is simple but powerful: Don't try to detect threats. Instead, extract only the safe content (pixels) and rebuild the file from scratch. The output is a mathematically new image that can't possibly contain hidden threats - because it was just created from raw pixel data. The problem? Every CDR solution I found was either: Hidden behind "Contact Sales" forms Enterprise-priced ($10k-$50k/year) Built on risky dependencies (ImageMagick has a scary CVE history)

I saw an opportunity.

---

Building as a Solo Dev The Technical Bet: Rust + WebAssembly I needed to process hostile binary data without risking my server. JavaScript wouldn't cut it. Python was too slow. So I made a bet: Rust compiled to WebAssembly. Why? Memory safety - Rust prevents the buffer overflows that plague C/C++ image libraries WASM sandbox - Code runs in an isolated environment with strict memory limits Edge deployment - Cloudflare Workers run WASM at the edge, meaning sub-100ms latency globally

It was a steep learning curve (Rust is not for the faint of heart), but the result was exactly what I needed: a bulletproof image processor that could handle hostile inputs.

The Pricing Strategy I went with a generous free tier (100 requests/month) because: Trust is earned - Let developers test before paying Word of mouth - Free users become advocates Upgrade path is clear - When they hit limits, paid tiers are obvious

What I Learned 1. Niche Down Hard "Image sanitization" is a niche within a niche within a niche. That's the point. I'm not competing with general image APIs. I'm solving one specific problem for developers who actually understand the threat model. 2. Documentation Is Marketing My most effective "marketing" has been technical blog posts explaining the problem. Developers don't want to be sold to - they want to learn. Every article I write (like this one) is answering a question developers are already asking. 3. Build for the Long Term This isn't a growth hack or a quick flip. I'm building infrastructure that developers will depend on for years. That means: boring reliability > flashy features.

---

Try It The API is live: Zero Trust API on RapidAPI Send any image → get back a sterile PNG with zero metadata, zero hidden payloads. curl -X POST "https://zero-trust-api.p.rapidapi.com/sanitize" \ -H "X-RapidAPI-Key: YOUR_KEY" \ -H "Content-Type: image/jpeg" \ --data-binary "@image.jpg" \ --output clean.png

TorchStream: Upgrades PyTorch models to be streamable

https://github.com/CorentinJ/TorchStream
1•lucalp__•46s ago•0 comments

LynxEye – A fast code complexity analyzer built with Rust and Tree-sitter

https://github.com/yzzting/LynxEye
1•yzzTing•1m ago•1 comments

Show HN: Superapp – AI Full-Stack Engineer for iOS

https://www.superappp.com/
1•thekotik•4m ago•0 comments

The power of agentic loops – implementing Flexbox layout in 3 hours

https://blog.scottlogic.com/2025/12/22/power-of-agentic-loops.html
1•furkansahin•6m ago•0 comments

Explosive GEMM: arbitrarily large FP error can be incurred in the GEMM operation

https://github.com/statusfailed/explosive-gemm
1•statusfailed•8m ago•0 comments

AI Data Center Gold Rush Driven by Newcomers

https://www.bloomberg.com/graphics/2025-ai-data-center-ownership/
1•tompark•9m ago•1 comments

Binance allowed suspicious accounts to operate even after 2023 US plea agreement

https://www.ft.com/content/5d8af345-d593-47b1-85ae-758ee60e9a89
1•thm•11m ago•0 comments

Streaming Uploads with LiveView

https://fly.io/phoenix-files/streaming-uploads-with-liveview/
1•m5r•12m ago•0 comments

Risks of Bottled Water

https://studyfinds.org/hidden-risks-bottled-water/
1•vixen99•12m ago•0 comments

The Price of Data

https://www.imf.org/en/publications/fandd/issues/2025/12/the-hidden-price-of-data-laura-veldkamp
1•rbanffy•13m ago•0 comments

MAGA's Manly Manufacturing Misfire

https://paulkrugman.substack.com/p/magas-manly-manufacturing-misfire
1•rbanffy•13m ago•1 comments

Go Scripting with Expr Lang

https://buildsoftwaresystems.com/post/go-scripting-expr-lang-gotchas/
1•ThierryBuilds•14m ago•0 comments

Show HN: Python Local Sandbox Code Execution (Podman and Uv)

https://github.com/portofcontext/pctx-py-sandbox
1•pmkelly4444•14m ago•0 comments

Free Santa themed micro clicker game

https://www.backai.dev/festive-santa
1•pollux01•14m ago•1 comments

Why Nvidia maintains its moat and Gemini won't kill OpenAI

https://siliconangle.com/2025/12/21/nvidia-maintains-moat-gemini-wont-kill-openai/
1•tompark•14m ago•0 comments

From Hyperinflation to the Euro

https://www.imf.org/en/publications/fandd/issues/series/analytical-series/from-hyperinflation-to-...
1•rbanffy•15m ago•1 comments

Clever Memory Tricks

https://xania.org/202512/22-memory-cunningness
1•hasheddan•15m ago•0 comments

Show HN: NICH – Browser-based tool to anonymize AI-conversations

https://www.nichtech.uk
1•akryshtal•21m ago•0 comments

The biggest CRT ever made: Sony's PVM-4300

https://dfarq.homeip.net/the-biggest-crt-ever-made-sonys-pvm-4300/
2•giuliomagnifico•22m ago•0 comments

Show HN: Context Agent" for LLMs coding libraries (lawyer turned dev project)

https://mymever7.streamlit.app/
1•glenpk•23m ago•1 comments

Beyond adoption: How to measure AI's real business impact

https://www.augmentcode.com/blog/beyond-adoption-how-to-measure-ai
1•mooreds•31m ago•0 comments

Why job boards are very important

https://taylordesseyn.substack.com/p/why-job-boards-are-v-important
1•mooreds•32m ago•0 comments

Tommy Flowers

https://en.wikipedia.org/wiki/Tommy_Flowers
1•tonyedgecombe•34m ago•0 comments

Ask HN: My mother was scammed out of all her savings. What should I do?

3•scapbi•36m ago•0 comments

What Is Good Product Management?

https://www.techfounderstack.com/p/what-is-good-product-management
1•makle•39m ago•0 comments

The State of Legal AI in 2025

https://theredline.versionstory.com/p/why-cant-43b-in-legal-ai-investment
1•jpbryan•39m ago•0 comments

Unofficial 37signals Coding Style Guide

https://github.com/marckohlbrugge/unofficial-37signals-coding-style-guide
1•mooreds•39m ago•0 comments

Is it overkill to build RPMs for yourself if there is no intention to distribute

https://old.reddit.com/r/Fedora/comments/1psm48n/is_it_overkill_to_build_rpms_for_yourself_if/
1•sipofwater•40m ago•0 comments

Laid Off After 25 Years in Tech: The Anxiety, Sacrifice, and Reality No One Talk

https://www.youtube.com/watch?v=VeMA9WGKxOg
1•aupra•42m ago•0 comments

The science of green hair care

https://knowablemagazine.org/content/article/food-environment/2025/science-of-green-hair-care
1•sohkamyung•44m ago•0 comments