Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
apimade
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
31.
▲
by
apimade
4mo ago
Such a list will never exist in an organisation of this size, with the amount of delegated management and operations required for these functions. In fact, it’s unlikely such a list is even _allowed_ to exist given the sensitive nature of s
32.
▲
by
apimade
5mo ago
Alpine is a great choice.. Provided you understand what’s included, and the ramifications it has on the stack you’re trying to work with. 99 times out of 100 it’s a terrible choice for an enterprise.
33.
▲
by
apimade
5mo ago
Agree, see the Delve fiasco. But that’s not their job. Their job is literally checkbox. However some audits are so poorly done, or have auditors with zero real world engineering or cyber experience, they’re actively harmful to a product or
34.
▲
by
apimade
5mo ago
Sometimes good change comes from compliance. More than once I’ve seen major product resource shift to address major cybersecurity gaps, in response to a compliance led audit. Compliance is not security, but engineers, especially solo ones t
35.
▲
by
apimade
5mo ago
iPhone.
36.
▲
by
apimade
5mo ago
No worries, it’s more about finding what the security and compliance teams care about — and making them comfortable. Compliance doesn’t equal security, I’ve onboarded startups with better security than the SOC2 certified, ISO27K Swiss chees
37.
▲
by
apimade
5mo ago
I’ll spend some more time replying to this next week, so circle back to this comment; I’m someone who regularly helps people get past these audits, meet the criteria customers are trying to assess with these certifications, and vet startups
38.
▲
by
apimade
5mo ago
"BrowserID failed in 2016, but WKID won't" "And the big providers (gmail.com, outlook.com, yahoo.com, icloud.com) will never be supported." You've changed the definition of "success" here. Why not jus
39.
▲
by
apimade
6mo ago
From my understanding is you’d probe the board during different operations, process the results and deduct what signals are useful and traffic transmitting across the board (I.E private keys, what protocols are used, debug interfaces, firmw
40.
▲
by
apimade
7mo ago
Total cost of ownership. I’d give my entire family these ahead of Windows laptops any day.
41.
▲
by
apimade
7mo ago
Likely aimed at classified/defence environments. In those spaces, hardware typically takes 18–36 months after commercial deployment before it’s approved—due to firmware vetting, side-channel analysis, crypto validation, and similar pro
42.
▲
by
apimade
8mo ago
Contract-first. API-first. Domain-driven. Platform driven. Microservice driven. Tech loves making something a top priority (and forgetting about it several years later); AI is the first one that is applicable to the masses. .. Well maybe no
43.
▲
by
apimade
8mo ago
Isn’t trivial? How is it not completely automated at this point?
44.
▲
by
apimade
8mo ago
Warning: in Enterprise (Grid) your account will likely be flagged as hijacked, and all of your sessions will be killed. Slack implemented session hijacking detection a while ago, and using LLM’s without throttling will very likely result in
45.
▲
by
apimade
9mo ago
I spent the better half of my first professional decade writing RESTful abstractions over SOAP services and XML RPC monstrosities. I’ve done it for probably upwards of 2 or 300 systems (not interfaces, systems). There’s one improvement XML
46.
▲
by
apimade
10mo ago
They are for large infrastructure projects, especially at large organisations. It takes companies 3-5 years for migration of these products, all of which are not CapEx funded and so get minimal resourcing without prioritisation by leadershi
47.
▲
by
apimade
10mo ago
I’ve got about 10 half way through write ups on projects I’ve done over the past few years. My whole “thing” is systemising exploitation. One day I’ll publish something..
48.
▲
by
apimade
10mo ago
The same way you write malware without it being detected by EDR/antivirus. Bit by bit. Over the past six weeks, I’ve been using AI to support penetration testing, vulnerability discovery, reverse engineering, and bug bounty research. W
49.
▲
by
apimade
10mo ago
https://addons.mozilla.org/en-US/firefox/addon/container-pro... You can default route domains through a VPN using a Firefox tab container, you don’t need a separate browser instance running!
50.
▲
by
apimade
11mo ago
I live in Merri-bek. 50%. 3km north of Melbourne CBD. I can drive to an ED within 3-5 minutes. This report doesn’t make me feel good.
51.
▲
by
apimade
11mo ago
The description you give inherently changes the structure of the data, and JavaScript would be the best way to post-process it. CSS is about styling the structure of HTML, not structural changes to it. Unless you have a good example, I thin
52.
▲
by
apimade
11mo ago
Why not just expose an HTML representation of the data? Why must it remain JSON, XML, CSV, Parquet, fixed length or tab delimited files, ProtoBuf, etc? API’s should provide content in the format asked of them. CSS should be used to style th
53.
▲
by
apimade
1y ago
This is like a guerrilla solar recipe from the anarchist’s cookbook. The author doesn’t explicitly dissuade people from plugging in another multipoint/powerstrip/plugstrip into the end of the extension cable you’ve run into the ot
54.
▲
by
apimade
1y ago
AgenticSeek, or you can get pretty far with local qwen and Playwright-Stealth or SeleniumBase integrated directly into your Chrome (running with Chrome DevTools Protocol enabled).
55.
▲
by
apimade
1y ago
It is strange to launch this type of functionality with not even a privacy policy in place. It makes me wonder if they’ve partnered with another of their VC’s peers who’s recently had a cash injection, and they’re being used as a design par
56.
▲
by
apimade
1y ago
An 8% increase y/o/y is quite substantial, however keep in mind globally we experienced the 2022 fuel shock. In Australia for example we saw energy prices double that year. Although wholesale electricity prices show double-digit a
57.
▲
by
apimade
1y ago
Accidentally installing a malicious package in your dev environment, the concern isn’t “what’s already installed”, it’s what’s potentially going to be installed in the future by you or your colleagues. So, you pin the version and update per
58.
▲
by
apimade
1y ago
Here’s a one-liner for node devs on MacOS, pin your versions and manually update your supply chain until your tooling supports supply chain vetting, or at least some level of protection against instantly-updated malicious upstream packages.
59.
▲
Show HN: Mermaid-animate, GSAP animations for Mermaid sequence and flow diagrams
(jameshealyio.github.io)
4 points
by
apimade
1y ago
|
0 comments
60.
▲
by
apimade
1y ago
I just realised for the first time in my life I’ve decided to delete my comment/reply because I’m concerned with how it’ll be used. I will say this; different countries wield different powers at their disposal. It’s unfair how China co
More ›