SYEF SID ALI BENKRIEF

SYEF SID ALI BENKRIEF

Co- founder and CEO of xseth.com

Badges

Tastemaker
Tastemaker
Gone streaking
Gone streaking
Gone streaking 5
Gone streaking 5

Maker History

  • Xseth
    XsethYour AI recon partner for offensive security
    Jun 2026
  • 🎉
    Joined Product HuntJune 19th, 2026

Forums

•

3d ago

Why we completely abandoned custom user roles for early accounts.

We spent three weeks writing granular permissions allowing team admins to assign custom read, write, and edit access for every single module. When we analyzed usage two months later, over 95% of workspaces were just using standard default roles.

Early-stage software needs sensible defaults, not complex configuration settings that slow down onboarding.

What do you check before putting a vibe-coded app in front of real users?

Genuine question for people shipping with Lovable, Bolt, v0 or Cursor. Building fast is the whole point, but the same few problems keep showing up on freshly shipped apps when you look at them from the outside: admin or debug routes left reachable, API endpoints that return another user's data if you change an ID in the URL, Supabase or Firebase tables readable without logging in, and API keys sitting in the frontend JavaScript. None of these need a hacker to find, just someone curious with a browser. So how do you handle it? Do you have a checklist before launch, rely on the platform's defaults, ask the AI to review its own code, or ship and fix later? And which of these has actually bitten you? Disclosure: I work on external recon at Xseth, so this is my day job, but I'd really like to hear what works for people here, with or without tools.

Looking for beta testers: external recon that only calls a bug "proven" when it can prove it

Hey PH, Syef here, co-founder of Xseth. Most scanners hand you a long list of "possible" issues and leave you to sort out what's real. Xseth runs external recon on a domain, narrows thousands of URLs down to the few worth testing, then checks each one. A finding is only marked PROVEN when a deterministic check confirms it; everything else is labeled refuted, inconclusive or not tested, so you know exactly where you stand. The GIF is an illustrative run on a demo target. We're looking for a small group of beta testers: bug bounty hunters, security folks, and anyone shipping fast with Lovable, Bolt, v0 or similar. It's external only, with no accounts, no code access and nothing to install. All we need is a domain you own or are authorized to test. In return we'd love a few minutes of your time or one honest email on what was right, what was missing and what you'd never use. Comment below or reach us at xseth.com.

View more