u/SweetHunter2744

Are AI Trading Tools actually helping traders or just hype?

been trading on and off for a couple months, mostly messing with stocks and some futures on a small account. saw all these ai trading tools popping up everywhere, promising signals and edges and all that. figured why not test one out with paper money first.

set it up last monday, fed it my usual watchlist, let it spit out entries and exits. first couple days it nailed a few scalps on nq, made like 2 percent on the demo which felt great. but then thursday it chased a fakeout on gold, told me to long right into resistance and wiped half the gains. yesterday same thing, signal came late and i watched it reverse.

not sure if its helping or just adding noise to my own reads. the ai stuff feels slick but half the time im second guessing it anyway. anyone else tried ai trading tools lately do they actually improve your edge or just more hype?

reddit.com
u/SweetHunter2744 — 20 hours ago

Anyone else's pipelines pulling durabletask? versions 1.4.1–1.4.3 are backdoored

caught this today and wanted to flag it here before it gets buried.

TeamPCP compromised a GitHub account, found a PyPI publish token sitting in the repo secrets, and used it to push malicious versions of Microsoft's durabletask package. 1.4.1, 1.4.2 and 1.4.3 are all malicious.

payload runs the moment you import it. no errors, nothing that looks off, just silently stealing credentials in the background, cloud provider keys, SSH keys, Docker creds, 1Password and Bitwarden vaults, HashiCorp Vault secrets, shell history. On AWS it propagates to other EC2 instances via SSM. Kubernetes environments get it through kubectl exec.

417k downloads a month on this package. GitHub is also investigating a separate claimed breach of ~4,000 of their internal repos from the same group, apparently stemming from the same initial access.

The entry point was a token with too much access sitting in a repo secret. That's it.

If your pipelines pulled durabletask recently, treat those machines as fully compromised. Rotate everything, don't just remove the package.

Has anyone already run into this? how wide the impact is.

u/SweetHunter2744 — 2 days ago

Best body scrub for strawberry legs

i have been struggling with keratosis pilaris, and it seems like the bumps are just getting worse lately. i am srsly at a loss for why it’s flaring up so much so if anyone has found a specific scrub or a routine that actually helps smooth out these bumps, i’d love to hear your recommendations. it’s reached the point where it’s really starting to affect my confidence.

forgot to add i have steered clear of shaving and have been trying epilating instead to see if it helps and applying a heavy urea based cream every night.  despite being super diligent with this for the last month the bumps still aren't looking good.

reddit.com
u/SweetHunter2744 — 3 days ago

Is agentic IAM even a real category yet, or are we all just duct-taping service accounts and hoping for the best?

We've been running Okta for a few years, pretty mature setup with SCIM provisioning, RBAC, regular access reviews. Then we started deploying internal AI agents earlier this year and the whole model falls apart.

Agents don't have HR records. They don't get onboarded through a ticket. They get spun up by a dev team, inherit a service account that was already there, and just... run. Nobody reviews what they have access to because there's no process for it. The access review cycle we run every quarter has no concept of an agent as a distinct identity type.

The first one we caught was running under a senior engineer's service account. That account had broad access across three environments because the engineer needed it. The agent didn't need any of that, it had one job, but it ran with everything attached to the account because nobody thought to scope it down.

We started calling it agentic IAM because nothing in our tooling had a name for it. Our tooling has no concept of an agent as something you provision, scope, and eventually deprovision separately from a human. It's all mapped to users.

Has anyone built actual lifecycle controls for AI agents inside an existing IAM setup, or is everyone just doing this by hand?

reddit.com
u/SweetHunter2744 — 5 days ago

How to exfoliate KP bumps on sensitive skin without making it worse?

Looking for skin hydration cleansers that don't dry out KP skin or thick moisturiser to calm it after. My arms and legs have these KP bumps that wont go away and my skin is super sensitive so everything irritates it. I have tried a few gentle scrubs but they just make redness worse and sometimes bring out acne too.

What works for sensitive skin care with KP?

reddit.com
u/SweetHunter2744 — 7 days ago
▲ 2 r/skin

Gentle ways people are managing keratosis pilaris.

As a skincare brand, we see a lot of people struggling with keratosis pilaris because it’s hard to find products that help with the bumps without making the skin feel irritated or overly dry afterward. A lot of people end up over-exfoliating or using really harsh scrubs, which can sometimes make the redness and texture look even worse.

From what we’ve seen, keeping the routine simple usually works best gentle exfoliation a couple times a week combined with consistent hydration. Ingredients like lactic acid, glycolic acid, and urea tend to help with rough, bumpy skin while still supporting the skin barrier when used properly.

Products like AmLactin and First Aid Beauty’s KP Bump Eraser get mentioned a lot by people looking for something effective that still feels gentle on sensitive skin and also focusing on science backed skincare solutions that are effective, but still comfortable for everyday use, and a lot of the feedback we hear is that consistency makes the biggest difference over time.

reddit.com
u/SweetHunter2744 — 7 days ago

How to treat skin that feels like sandpaper after a day outdoor?

so i went out without reapplying sunscreen like an idiot and now my face is paying the price. i have always had sensitive skin, but this is worse than usual. its not even red or burned looking, just incredibly tight and dry and uncomfortable. i have tried my usual moisturizer, but its just sitting on top of my skin and not actually helping at all.

i would appreciate any suggestions because my skin feels like its about to crack off my face and its genuinely uncomfortable.

reddit.com
u/SweetHunter2744 — 8 days ago

how do you optimize AI threat intelligence integration?

we put an LLM app into production recently thinking guardrails were in good shape. prompt filters, output checks, rate limits. everything looked solid in testing.

then real usage started.

early on, users found ways to chain prompts that bypassed filters. nothing obviously malicious on its own, but combined it slipped through. a few days later we saw drift issues where outputs started including things that shouldn’t be there, tied back to how we were handling updates and evaluation data.

under load, some of the controls didn’t behave the same way. limits that worked in testing didn’t hold consistently once traffic increased, especially with async processing. we tried layering in additional controls, but each one seems to hold until usage patterns change or scale increases.

where have yours failed in production. what actually held up once usage and scale increased?

reddit.com
u/SweetHunter2744 — 9 days ago

Gentle ways people are managing keratosis pilaris

As a skincare brand, we see a lot of people struggling with keratosis pilaris because it’s hard to find products that help with the bumps without making the skin feel irritated or overly dry afterward. A lot of people end up over exfoliating or using really harsh scrubs, which can sometimes make the redness and texture look even worse.

From what we have seen, keeping the routine simple usually works best gentle exfoliation a couple times a week combined with consistent hydration. Ingredients like lactic acid, glycolic acid, and urea tend to help with rough, bumpy skin while still supporting the skin barrier when used properly.

Products like AmLactin and First Aid Beauty’s KP Bump Eraser get mentioned a lot by people looking for something effective that still feels gentle on sensitive skin and also focusing on science backed skincare solutions that are effective but still comfortable for everyday use, and a lot of the feedback we hear is that consistency makes the biggest difference over time.

reddit.com
u/SweetHunter2744 — 10 days ago

 Hey everyone,

Running a small DTC skincare brand out of my garage for 2 years now. Sales were ok at 20k a month but delivery complaints are burying us. Customers rage about late packages, no tracking updates, and that one time a box showed up crushed after 5 days. Switched carriers twice, costs up 30% and still getting 1 star reviews on trustpilot saying we suck at shipping.

Heard about these last mile platforms like next day delivery services and flexible scheduling but which ones drop shipped on time without jacking prices? One guy in comments last week mentioned a fulfillment network that cut delays, anyone else try that? Or is it all hype?

Tried outsourcing to a local courier but they ghosted on weekends. Need real talk from founders who fixed their delivery mess without going broke. What worked, what bombed?

reddit.com
u/SweetHunter2744 — 15 days ago
▲ 11 r/sre

CVE Spike after EKS node upgrade? How to separate host-level from image-level vulnerabilities in Trivy

did everything right on the image side. distroless bases with Grype scanning and pinned digests  the whole standard playbook, rebuilt on vuln alerts. CVE counts were clean for months.

platform team pushed a node OS upgrade last week. Amazon Linux 2023 bump on our EKS nodes. CVE counts jumped roughly 40% in the next scan cycle. nothing in our images changed.

turned out our scanner (Trivy in cluster mode) was pulling host-level package data from the node OS alongside the image layer scan and attributing findings to our workloads. the node upgrade added packages to the host that weren't there before  our images are the same but the scanner is now reporting host-level exposure alongside image-layer results.

tried isolating image-only scan results to separate the two surfaces. harder than it sounds when your scanner mixes host and image findings in the same report. the platform team owns the node OS, we can patch images all day and the host-level count won't move.

anyone dealt with cleanly separating node-level from image-level CVE reporting? not sure if this is a scanner config problem or if we need a different tool for host vs image scanning. 

reddit.com
u/SweetHunter2744 — 15 days ago

Data engineer running a dbt stack here.. source issues are killing us, freshness drops, volumes tank, models break downstream, and by the time we notice, stakeholders have already seen garbage. then it’s hours of tracing logs and upstream tables to find the root cause. Heard about automated source monitors that flag freshness or volume issues without manual thresholds, ideally catching problems before dbt even runs. Sounds great, but every time we add more tests or monitoring slack floods with false positives, eventually people just ignore alerts.

for those using source monitors, do they actually catch issues early and help pinpoint root causes? lineage end-to-end? or is it mostly hype and you still end up playing detective manually? how does it scale without eating up engineering time?

reddit.com
u/SweetHunter2744 — 16 days ago

hey you all,

i am having trouble with my skin, it's constantly red and irritated, and it just wont calm down. its been like this for weeks now. i have got pretty sensitive skin, so i am trying to be careful with what i use. i have tried a few moisturizers for babies, but none of them seem to help much. i think it might be from using a new product or maybe just the change in weather, but i am not sure.

the redness is mostly on my cheeks and nose, and its not like an acne breakout, just like an irritation. i am wondering if anyone here has gone through something similar and found a product that helped with their skin.

does anyone know any products that help with this issue?

reddit.com
u/SweetHunter2744 — 17 days ago

Grandma is 84, lives alone, budget is tight as hell with everything going up. Keeps falling in her apartment, last one she hit her head and was out cold for who knows how long before neighbour's heard. Need a watch or whatever that detects falls for real, calls help automatically, works all day every day no gaps. Not some gimmick that beeps wrong or needs perfect gps. Tried reading reviews but half say battery craps out overnight, other half false alarms wake everyone. She wont do a full medical alert necklace, too bulky. Apple watch too pricey monthly. What actually saved someone here?

reddit.com
u/SweetHunter2744 — 23 days ago
▲ 8 r/grc

Found a case where a sales rep pasted a large customer dataset into Notion AI to summarize it. Around 50k records with contact details. There's no record of the interaction anywhere. Logs show traffic to an approved domain. DLP didn't trigger because nothing moved as a file. Logging didn't capture the prompt. Nothing stands out in monitoring.

We had been reporting low risk based on usage and activity, but this didn't show up at all.

has anyone been able to reconstruct what went into a session after the fact or are you just patching forward here

reddit.com
u/SweetHunter2744 — 24 days ago