Home

Conversation

$$3220
https://lemmy.dbzer0.com/u/pjusk posted on Feb 23, 2026 18:42
In reply to: https://slrpnk.net/post/34491367

This is wild and a rather unfortunate situation… Ty for sharing.

https://lemmy.dbzer0.com/comment/24584872
Reply
$$3223
https://lemmy.world/u/irmadlad posted on Feb 23, 2026 18:46
In reply to: https://slrpnk.net/post/34491367

As I commented in another thread, I don’t run ‘arr anything, but I’m thankful that there are competent people who can make sense of all the code involved to do a proper audit.

https://lemmy.world/comment/22305162
Reply
$$3228
https://slrpnk.net/u/Sunny posted on Feb 23, 2026 18:57
In reply to: https://lemmy.world/comment/22305162

Absolutely, in an optimal world it would be easier to audit software ourselves through tooling, but we’re not there yet. Personally looking to build a pipeline to run apps i wan to host through tools such as:, semgrep, grype and trivy, to at least get somewhat of an overview.

https://slrpnk.net/comment/20895841
Reply
$$3230
https://lemmy.world/u/era posted on Feb 23, 2026 19:05
In reply to: https://slrpnk.net/post/34491367

I don’t personally run Huntarr but thank you so much for your amazing work!

https://lemmy.world/comment/22305546
Reply
$$3240
https://lemmy.ca/u/avidamoeba posted on Feb 23, 2026 19:23
In reply to: https://slrpnk.net/comment/20895841

Secuarr?

https://lemmy.ca/comment/21861949
Reply
$$3262
https://slrpnk.net/u/Sunny posted on Feb 23, 2026 20:02
In reply to: https://lemmy.world/comment/22305546

Want to stress that it was not me personally who did this deep dive, its a repost from reddit. So all kudos goes to them!

https://slrpnk.net/comment/20897070
Reply
$$3301
https://lemmy.world/u/basic_user posted on Feb 23, 2026 21:35
In reply to: https://slrpnk.net/post/34491367

Thanks you for your thorough analysis and report. Very interesting read. Just doing the basics, as you say, is more than a layman like me can do!

https://lemmy.world/comment/22308467
Reply
$$3314
https://lemmy.world/u/homesweethomeMrL posted on Feb 23, 2026 21:51
In reply to: https://slrpnk.net/post/34491367

The maintainer says they have “a series of steering documents I generated that does cybersecurity checks and provides additional hardening” and “Note I also work in cybersecurity.”

Yeah, that’s a big no. No one ‘generates’ ‘steering documents’. No one I would take seriously, anyway.

One more thing - the project’s README has a “Support - Building My Daughter’s Future” section soliciting donations.

Yuck.

https://lemmy.world/comment/22308768
Reply
$$3320
https://slrpnk.net/u/Sunny posted on Feb 23, 2026 21:55
In reply to: https://lemmy.world/comment/22308467

Want to stress that it was not me personally who did this deep dive, its a repost from reddit. So all kudos goes to them!

https://slrpnk.net/comment/20899173
Reply
$$3323
https://lemmy.dbzer0.com/u/defaultusername posted on Feb 23, 2026 21:56
In reply to: https://slrpnk.net/post/34491367

My password is huntarr2

https://lemmy.dbzer0.com/comment/24588453
Reply
$$3337
https://lemmy.ml/u/Ferrous posted on Feb 23, 2026 22:16
In reply to: https://slrpnk.net/post/34491367

Thanks for this.

I’m starting to get worried about how much AI slop is being pushed on top of the venerable arr stack. A few months ago I was evaluating a music solution, and came across a promising solution called Soulsync, only to learn it was vibe coded. Since that fiasco, it looks like there is a new one called Aurral 2.0 with the same issue.

Its a shame since the arr developers are real deal.

https://lemmy.ml/comment/24143444
Reply
$$3343
https://lemmy.world/u/SubUrbanIT posted on Feb 23, 2026 22:24
In reply to: https://lemmy.dbzer0.com/comment/24588453

Huntarr123?

https://lemmy.world/comment/22309406
Reply
$$3354
https://lemmy.world/u/peacefulpixel posted on Feb 23, 2026 22:53
In reply to: https://slrpnk.net/post/34491367

i know this will hurt feelings but this is just gonna keep happening as long as y’all use GenAI. this is quite literally what it was made for

https://lemmy.world/comment/22309819
Reply
$$3371
https://lemmy.world/u/mlg posted on Feb 23, 2026 23:28
In reply to: https://slrpnk.net/post/34491367

Gamefreak used an additional hardcoded RSA public key auth in Pokémon Black/White because for some reason they didn’t trust OpenSSL to not fail for their HTTPS API connections, and yet here we are in 2025 with unahtenticated API endpoints.

Was ChatGPT unable to generate swagger docs they could have lazily plugged into an API scanner bruh

Or better yet notice the big fat “unathenticated” label when you look at the endpoint list.

https://lemmy.world/comment/22310295
Reply
$$3374
https://lemmy.decronym.xyz/u/Decronym posted on Feb 23, 2026 23:30
In reply to: https://slrpnk.net/post/34491367

Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:

Fewer Letters More Letters
HTTP Hypertext Transfer Protocol, the Web
HTTPS HTTP over SSL
SSL Secure Sockets Layer, for transparent encryption

[Thread #112 for this comm, first seen 23rd Feb 2026, 23:30] [FAQ] [Full list] [Contact] [Source code]

https://lemmy.decronym.xyz/comment/13269
Reply
$$3381
https://lemmy.makearmy.io/u/makearmy posted on Feb 23, 2026 23:46
In reply to: https://slrpnk.net/post/34491367

OP is a GOD

https://lemmy.makearmy.io/comment/1977356
Reply
$$3384
https://sh.itjust.works/u/usernameusername posted on Feb 23, 2026 23:49
In reply to: https://lemmy.dbzer0.com/comment/24588453

All I see is ********

https://sh.itjust.works/comment/23940945
Reply
$$3395
https://lemmy.zip/u/fta posted on Feb 24, 2026 00:20
In reply to: https://slrpnk.net/post/34491367

Thanks for forwarding.

Looks like the repo was deleted: https://github.com/plexguide/Huntarr.io

https://lemmy.zip/comment/24839709
Reply
$$3412
https://sh.itjust.works/u/ohshit604 posted on Feb 24, 2026 00:54
In reply to: https://sh.itjust.works/comment/23940945

Huh, swear I’ve seen this somewhereX

https://sh.itjust.works/comment/23941896
Reply
$$3459
https://lemmy.world/u/Dultas posted on Feb 24, 2026 02:05
In reply to: https://lemmy.zip/comment/24839709

The dev also shutdown their subreddit.

https://lemmy.world/comment/22312479
Reply
$$3478
https://sh.itjust.works/u/CocaineShrimp posted on Feb 24, 2026 03:18
In reply to: https://lemmy.zip/comment/24839709

Good

https://sh.itjust.works/comment/23943535
Reply
$$3480
https://sh.itjust.works/u/CocaineShrimp posted on Feb 24, 2026 03:32
In reply to: https://slrpnk.net/post/34491367

Thank you for this. I have seen a few *arr combination projects I wanted to look into; so I may have had come across this one.

It’s unfortunate that the “developer” chose to nope out, instead of fixing it or at least seeking help from the community. This is one of the good aspects of OSS - that we can and should audit ourselves. But if it was all vibe coded, maybe they didn’t know that an audit is good and should be welcomed; instead of rejected and shutdown.

https://sh.itjust.works/comment/23943675
Reply
$$3587
https://lemmy.world/u/myplacedk posted on Feb 24, 2026 09:27
In reply to: https://sh.itjust.works/comment/23941896

I’ll give you a hint: Originally it was *******.

Wait, let me try again - hunter2

https://lemmy.world/comment/22316960
Reply
$$3590
https://lemmy.world/u/myplacedk posted on Feb 24, 2026 09:28
In reply to: https://lemmy.world/comment/22309819

…as long as y’all use GenAI incorrectly.

It has it’s uses i programming. Doing all the coding for you is not one of them.

https://lemmy.world/comment/22316979
Reply
$$3598
https://lemmy.zip/u/punkibas posted on Feb 24, 2026 09:53
In reply to: https://slrpnk.net/post/34491367

Hoy shit! What a trainwreck of an app

https://lemmy.zip/comment/24846778
Reply
$$3621
https://lemmy.world/u/x00z posted on Feb 24, 2026 11:51
In reply to: https://slrpnk.net/post/34491367

I already had a feeling from navigating the interface.

Thanks for your work.

https://lemmy.world/comment/22318313
Reply
$$3637
https://lemmy.world/u/Fmstrat posted on Feb 24, 2026 12:30
In reply to: https://slrpnk.net/post/34491367

If you are willing, I would love to see a blog post, video, or repo of exactly how you conducted this audit. Great read, and would like to learn more of your specific process (beyond the readmes and man pages).

https://lemmy.world/comment/22318792
Reply
$$3659
https://lemmy.world/u/SlurpingPus posted on Feb 24, 2026 13:10
In reply to: https://lemmy.world/comment/22305162

Once again I’m glad that I just search trackers with the browser and download torrents with a torrents client, like a peasant.

https://lemmy.world/comment/22319458
Reply
$$3664
https://lemmy.world/u/irmadlad posted on Feb 24, 2026 13:20
In reply to: https://lemmy.world/comment/22319458

I’ll be honest, if ‘arr were my modus operandi, I would most likely take your approach because the alternative would keep me up at night worrying.

https://lemmy.world/comment/22319642
Reply
$$3666
https://lemmy.world/u/Bazoogle posted on Feb 24, 2026 13:22
In reply to: https://lemmy.world/comment/22316979

Doing all the coding for you is not one of them.

yet. If AI can do anything well, I think it should be writing code, given the formulaic nature of code. We are NOT there yet. But it will one day, no doubt.

https://lemmy.world/comment/22319684
Reply
$$4930
https://mander.xyz/u/NastyNative posted on Feb 27, 2026 12:57
In reply to: https://slrpnk.net/post/34491367

This is great thank you for this since the next step on my journey is the ARR stack!

https://mander.xyz/comment/25527420
Reply
$$5059
https://slrpnk.net/u/Sunny posted on Feb 27, 2026 18:36
In reply to: https://mander.xyz/comment/25527420

Best lf luck, hit me up if you have any questions regarding it 😊

https://slrpnk.net/comment/20970811
Reply