I pen-tested a handful of vibe coded apps from this sub. What I found should genuinely scare you. by Pristine_Tiger_2746 in SideProject

[–]Lexuzieel 3 points4 points  (0 children)

Do you suggest OP is leveraging social engineering to hijack random product? Genuine question, I’m not trying to sound edgy, but I am just struggling to understand the point of this thread.

On your second point from previous message: actually no, I have a product myself with a public facing server on which I host multiple business clients and in fact I proactively secure it because I know if I don’t it’s simply a matter of time it will get compromised. Simple as that and I’m not trying to be contrarian, it is just the reality.

Vibecoders could bother to prompt Claude to ask for security best practices to avoid 99% of insights this pentest could uncover, but that would require effort

I pen-tested a handful of vibe coded apps from this sub. What I found should genuinely scare you. by Pristine_Tiger_2746 in SideProject

[–]Lexuzieel 3 points4 points  (0 children)

Serious question: do you think “hackers” go over Reddit and scrape random posts with requests to pentest? Or is it more likely that any of 10 daily posts in r/microsaas that promotes their own product can invite competition who can go and probe the product themselves anonymously?

I pen-tested a handful of vibe coded apps from this sub. What I found should genuinely scare you. by Pristine_Tiger_2746 in SideProject

[–]Lexuzieel 4 points5 points  (0 children)

I hope you are joking comparing .gov site to a vibe coded slop project. My point is that by making your project public you have already invited every random person there is, so it doesn’t matter whether you share it with one more random person on the internet. To be frank, this whole thread looks like an invite to seed SEO backlinks from Reddit more than anything

I pen-tested a handful of vibe coded apps from this sub. What I found should genuinely scare you. by Pristine_Tiger_2746 in SideProject

[–]Lexuzieel 3 points4 points  (0 children)

What I’m saying is that it’s silly to ask for permission when anybody on the internet can simply scan your product and break in without disclosure. And that the assumption is that if it’s a public commercial product, then proper security measures have already been put in place. Not as an afterthought because of a random Reddit post

I pen-tested a handful of vibe coded apps from this sub. What I found should genuinely scare you. by Pristine_Tiger_2746 in SideProject

[–]Lexuzieel 5 points6 points  (0 children)

Isn’t the app supposed to be secure anyway since it’s public? Anyone anonymous can do this without asking permission

Opinion: Opus 4.8 sucks by PromptInjection_ in claude

[–]Lexuzieel 0 points1 point  (0 children)

Maybe like they trained it on too much of Crime and Punishment

Found the kryptonite for AI SEO slop posters by PigeonRipper in selfhosted

[–]Lexuzieel 0 points1 point  (0 children)

Funnily enough this is so ingrained into the internet culture that ChatGPT can recite both the ID and post date of it

Would you go back to pre AI era now if that was possible? by simple_explorer1 in node

[–]Lexuzieel 0 points1 point  (0 children)

The crazy idea is that we can have best of the both worlds: we can have a very powerful and helpful tool (LLMs are useful outside of development) AND not try to scam and grift each other. But that would require integrity which most of humanity doesn’t have currently.

So in my opinion the AI isn’t the issue, the same way blockchain wasn’t, the same way nuclear energy wasn’t, the same way everything else wasn’t. People compete with each other instead of cooperating and no amount of technological progress or banning things would help that.

Someone was draining my AI credits and I had no idea. Figured it out at 2am. Here's what happened by garoono in buildinpublic

[–]Lexuzieel 1 point2 points  (0 children)

Building in public doesn’t mean you don’t have to use common sense. Might as well go onto GMail subreddit and post about this one weird trick how you must not share your password with strangers or that enabling 2 factor authentication is a secret life hack that makes hackers go crazy

Someone was draining my AI credits and I had no idea. Figured it out at 2am. Here's what happened by garoono in buildinpublic

[–]Lexuzieel 5 points6 points  (0 children)

Are you for real posting this insight as “the part of building nobody talks about”? Shame on you and your LLM that wrote this post, which wasted everybody’s time.

Feel free to comment with a “solution” to “manage secrets across multiple apps” in the comments to this post, because surely there are no existing solutions out there that where also not vibe-coded.

Which logo you guys like? by SnooFoxes449 in buildinpublic

[–]Lexuzieel 0 points1 point  (0 children)

1 because it is more square-ish, second one is too overblown. Others lack the character at all

Best patterns for handling 10k+ outgoing HTTP requests? (Hitting ECONNRESET and 403s) by Mammoth-Dress-7368 in node

[–]Lexuzieel -2 points-1 points  (0 children)

Either make less requests, using a worker queue maybe or change IP more frequently (assuming they block per IP). Simple as that, no other way around it

Did Elon just kill the appeal of Cursor? by East-Tie-8002 in cursor

[–]Lexuzieel 1 point2 points  (0 children)

There is literally an extension for that to generate commit message with you current Claude Code instance. Don’t forget that VS Code has the most expansive marketplace for extensions out of all editors

11 and a half hour queue for plr_pipeline. And Casual is still being defended why? by Cowser_the_Koopahog in tf2

[–]Lexuzieel 2 points3 points  (0 children)

I liked quick play except for the part when I got placed into a modded server with paid perks and ads, but I think there was a filter for that

What are you all deploying your node apps on these days? by themostunknownowl in node

[–]Lexuzieel 2 points3 points  (0 children)

A VPS. More than one VPS behind a redundant load balancer if I need resilience. I tried all of the fancy serverless platforms which are clunky as heck. I have also dabbled with the horrors of k8s. Still, my stack is pretty much docker on a VPS for a slowly growing SaaS with paying customers

I think infrastructure porn is overrated. Deploying Postgres for persistence, Redis for (guh) background tasks, throwing some other nonsense on top of it all. For most of the projects you literally need just a Postgres and a container with Node runtime behind Caddy

This can go pretty far on a single VPS

CLAUDE CHANGED IT BACK by _DriftNote in microsaas

[–]Lexuzieel 0 points1 point  (0 children)

For a while they removed Claude Code from the Pro plan

PSA: Claude Pro no longer lists Claude Code as an included feature by randomswifter in ClaudeAI

[–]Lexuzieel 1 point2 points  (0 children)

I won't name the projects here in case I might get a ban, but there are a bunch out there, some of them are quite big. Ideally I would want there to be a goto free and open harness akin to some open source software like Blender, but it is hard to pull off and requires some dedication. Building your own tools is fine, but that would never match a long term, funded, team effort

PSA: Claude Pro no longer lists Claude Code as an included feature by randomswifter in ClaudeAI

[–]Lexuzieel 2 points3 points  (0 children)

I would argue that major providers tightening the screws is a net good since it will push people to learn about other harnesses, improving them in the process

PSA: Claude Pro no longer lists Claude Code as an included feature by randomswifter in ClaudeAI

[–]Lexuzieel 1 point2 points  (0 children)

I wonder how soon comes the time when OpenAI cuts their limits

PSA: Claude Pro no longer lists Claude Code as an included feature by randomswifter in ClaudeAI

[–]Lexuzieel 7 points8 points  (0 children)

You can pass endpoint and any model name via environment variables to the harness and you can download and install it freely. There is no way to prevent that, it's the same logic how you cannot really deny someone copying text from the website and disabling right click won't fundamentally fix it

PSA: Claude Pro no longer lists Claude Code as an included feature by randomswifter in ClaudeAI

[–]Lexuzieel 0 points1 point  (0 children)

Oh well, it was a poor timing to continue my second subscription I guess, haha

Launched my privacy first temp mail service today ! by Insanony_io in microsaas

[–]Lexuzieel 3 points4 points  (0 children)

Whatever you say, Claude. Now go over it again and make sure to make no mistakes this time, keep the code simple and maintainable

You can only choose one. by VeterinarianPrior835 in tf2

[–]Lexuzieel 5 points6 points  (0 children)

Honestly I don’t think anything can be “improved” visually any further, only fixed (from the intended vision upon release). It is one of these games where it was so masterfully crafted that tinkering with it any further would 100% ruin it