Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
AlwaysNewb23
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
Should You Use Comment Prefixes for Code Reviews?
(doppler.com)
1 points
by
AlwaysNewb23
2y ago
|
0 comments
32.
▲
by
AlwaysNewb23
3y ago
At least they didn't blame 'supply chain' issues.
33.
▲
by
AlwaysNewb23
3y ago
I like the design of Heinz's 404 page. Mostly because of the clever use of ketchup in the design. https://www.heinz.com/404
34.
▲
by
AlwaysNewb23
3y ago
Did anyone else need to read the pricing a few times to understand it?
35.
▲
by
AlwaysNewb23
3y ago
You should know what they are doing and keep an eye on them, but I think it's important to be careful not to copy them and solve problems in your own way.
36.
▲
Using Narrative Commits for Better Code Reviews
(doppler.com)
1 points
by
AlwaysNewb23
3y ago
|
1 comments
37.
▲
by
AlwaysNewb23
3y ago
We've been using commit messages to tell a story using our git history and it's improved our code review process. By doing this, we've created a commit history that clearly details all the steps leading up to each change. By
38.
▲
by
AlwaysNewb23
3y ago
This is really impressive. Do you plan to use it for anything or another project?
39.
▲
by
AlwaysNewb23
3y ago
The biggest impact seems to be on team culture. I would love to know if anyone has tired something similar.
40.
▲
Improving Code Reviews with Storytelling
(doppler.com)
2 points
by
AlwaysNewb23
3y ago
|
0 comments
41.
▲
Ask HN: What would make you trust a cloud solution over on-prem?
2 points
by
AlwaysNewb23
3y ago
|
3 comments
42.
▲
by
AlwaysNewb23
3y ago
Thanks for clarifying this.
43.
▲
by
AlwaysNewb23
3y ago
Thanks for taking the time to write this up. You shared some interesting opinions to consider. "I absolutely refuse to use a security service that's hosted on the cloud." - I run into this a lot.
44.
▲
by
AlwaysNewb23
3y ago
"Every cloud service will be hacked" - I totally get this. It's the reason it's hard to build trust for a cloud service.
45.
▲
by
AlwaysNewb23
3y ago
I've always liked this model for my own projects. However, I'm not sure it really builds trust, especially from a security standpoint. Open sourcing could mean more eyes on the code, potentially leading to better security through
46.
▲
Parasitic Engineers Among Us
(readfromdisk.substack.com)
1 points
by
AlwaysNewb23
3y ago
|
0 comments
47.
▲
Ask HN: How do you get developers to trust your product?
2 points
by
AlwaysNewb23
3y ago
|
6 comments
48.
▲
by
AlwaysNewb23
3y ago
Tracking for you and your team. So if a developer on your team goes rogue, you know when and what happened, just like how you can see who committed when and what on GitHub. Your backend is as secure as you make it. The critical point is tha
49.
▲
Mobile Devs – Stop leaking your API keys: There's a better way
(doppler.com)
4 points
by
AlwaysNewb23
3y ago
|
2 comments
50.
▲
by
AlwaysNewb23
3y ago
Doppler is exploring adding the ISO 27001 certification in the near future.
51.
▲
by
AlwaysNewb23
3y ago
Doppler ( https://doppler.com ) is my preferred tool for storing API keys. It centralizes where you manage all of your environmental variables and makes it so you never risk exposing your API keys in a code repo. There's a CL
52.
▲
by
AlwaysNewb23
3y ago
Audit logs for secret managers are an underrated feature. It really helps to encourage best practices as well as track changes.
53.
▲
by
AlwaysNewb23
3y ago
For personal projects, it's probably fine to just use environmental variables and .env files the traditional way. The security risk really increases when you start to scale and work with other team members.
54.
▲
by
AlwaysNewb23
3y ago
Are you familiar with the recent Mercedes-Benz Source Code Exposure [1]? It's a good example of why you should consider a secrets manager for any serious project. Environment variables come with a lot of risks and are difficult to mana
55.
▲
by
AlwaysNewb23
3y ago
A secrets management service would be most convenient. Documentation makes them easy to set up without having to build anything extra yourself. A secrets manager like Doppler ( https://Doppler.com ) or AWS Secrets Manager ( https:
56.
▲
Ask HN: What will be the next big thing in software engineering?
3 points
by
AlwaysNewb23
3y ago
|
7 comments
57.
▲
by
AlwaysNewb23
3y ago
You are very correct but it’s also not on the dev product teams to decide the best practices for secrets at large companies. It’s the responsibility of the security and devops team to implement best practices.
58.
▲
What's the difference between a password manager and a secret manager?
(secureframe.com)
1 points
by
AlwaysNewb23
3y ago
|
0 comments
59.
▲
by
AlwaysNewb23
3y ago
Yes- More people need to know secrets managers exist and the types of problems they solve. I'm passionate about helping people discover and understand what secrets managers do. Using any secrets manager would be better than none at all
60.
▲
by
AlwaysNewb23
3y ago
Yes I am. More people need to know secrets managers exist. Doesn't have to be Doppler - but they should be used more often.
More ›