需求数据最后更新:6/22/2026, 2:02:48 PM
需求列表
554 个已验证需求,来自 53 条原始帖。数据来源:hackernews + indiehackers + reddit + twitter + v2ex。
554
已验证需求
180
分类
26.0
平均评分
1398
证据帖数
显示 554 个需求中的 5 个
#1极高Security
多租户SaaS→水平权限漏洞检测
SaaS开发者在构建多租户应用时,难以发现和验证水平权限漏洞(IDOR)。由于测试时仅使用单一账户,此类漏洞在开发阶段极难察觉,可能导致严重数据泄露。
“the part that gets me is it looks totally fine when you test it yourself, because you're only ever looking at your own account. it only breaks when a second person pokes at a first person's data, which you just never do while building.”
100/1001 帖19 参与
reddit#2早期Security
AI Agent 生产环境安全与鉴权
AI Agent 在访问真实生产环境时,现有网关和沙箱无法提供针对底层协议和复杂网络拓扑的安全控制。同时,Agent 调用第三方服务时缺乏通用的短期令牌生成机制,存在长期令牌泄露风险。
“There are a few projects that sit as a proxy in front of agents to do secret injection or apply various guardrails, but none met our needs... particularly the need to handle low-level protocols, or handle complex real world situations like tunneling postgres through k8s.”
24/1002 帖123 参与
hackernews#3早期Security
macOS隐私→原生级特定应用锁定
用户在不锁定整台Mac的情况下需要保护特定个人应用的隐私,但现有的macOS应用锁工具大多过时、收费、被放弃或不够原生。
“If you hand your laptop to someone for a few minutes, they can still open Messages, Photos, Notes, Mail, WhatsApp, browsers, password managers, and other personal apps.”
6.5/1001 帖6 参与
reddit#4早期Security
SaaS销售→企业合规问卷自动化
面向企业销售时缺乏标准化流程处理安全问卷与合规审查,拖慢销售周期并增加沟通成本。
“Founders selling to enterprise: how are you handling the security-questionnaire + subprocessor asks?”
5/1001 帖9 参与
indiehackers#5早期Security
独立开发资产→域名防劫持与UI侵权监控
独立开发者的域名被恶意劫持且UI设计被直接抄袭,缺乏有效的预防和侵权监控机制。
“Somehow, someone had taken control of the domain or redirected it, and now [astrae.design](http://astrae.design) leads to what looks like a shadcn style template store.”
5/1001 帖28 参与
reddit