Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ashishb
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
31.
▲
by
ashishb
4mo ago
I have been targeted with this attack in the wild where '.vscode/tasks.json' had the auto-run code. I smelled something fishy and never ran it though. https://news.ycombinator.com/item?id=48127469
32.
▲
by
ashishb
4mo ago
> For dependabot it's as simple as > cooldown.default-days: 1 Most people stick to default of 0. In fact, I am realizing over time that it is best to make it 7-14 days.
33.
▲
by
ashishb
4mo ago
Hypothesis: a big accelerant of these rapid repository compromise (from Red hat to GitHub to Amazon to small startups) might be GitHub+dependabot automatic dependency updates. So, just like COVID-19 used air travel, modern malware attacks a
34.
▲
by
ashishb
4mo ago
And why didn't they chose self-hosted for git then?
35.
▲
by
ashishb
4mo ago
Simpler answer: TINA (there is no better alternative)
36.
▲
by
ashishb
4mo ago
> I'm thinking like "you had 200 GitHub stars before coming to us so we start you with 200 stars" as a migration process. maybe they wouldn't be as reputable but everyone knows it's gamed anyway, so why not? And
37.
▲
by
ashishb
4mo ago
> What stops a new platform from just mirroring GitHub stars on import or something, actually? So, the source is still GitHub, right? Which means I have to keep my FOSS project on GitHub to accumulate stars.
38.
▲
by
ashishb
4mo ago
Nginx was compelled to move to GitHub [1]. The fact that companies request you to star them on GitHub and the stars can be bought tells you that there is a value in these stars. [2] Now, some astute reader, who thinks the $1 trillion global
39.
▲
by
ashishb
5mo ago
Alpine is a bad idea for a non-trivial application written in Python, Node.js, or any other interpreted language. Too many weird edge cases to deal with, especially related to Alpine using musl libc instead of glibc. At best, your builds ar
40.
▲
by
ashishb
5mo ago
Afaik, they eventually cleaned it up. And it was each team owning multiple internal repos of their own deployments/libraries, and not, primarily, clones of public repos.
41.
▲
by
ashishb
5mo ago
Uber had 8000 repos at one point with 2000 engineers - https://highscalability.com/lessons-learned-from-scaling-ube...
42.
▲
by
ashishb
5mo ago
Yeah. Real profile names. Unlikely that those guys were real. And I did reach out to them for explanation. Only to be blocked by both!
43.
▲
by
ashishb
5mo ago
This is just a negative filter to see as a warning sign. It is like walking into a dark alley at night. Nothing might happen but you should be on the alert.
44.
▲
by
ashishb
5mo ago
Those were real companies. The conversation started online and immediately moved in-person. I was never asked to install anything. I was not even given code access (without NDA) and I did get paid with equity/money in cases there was
45.
▲
by
ashishb
5mo ago
Not for someone who get 10-20 such requests a year. None till date were such scams.
46.
▲
I was asked to install malware during a fake interview
(ashishb.net)
54 points
by
ashishb
5mo ago
|
10 comments
47.
▲
by
ashishb
5mo ago
> Also, Docker is a huge binary, run as root, with lot of APIs and wide attack surface. You can run it without root. And that's what you should do. > No Wayland, DBus, Pipewire, proc, sys filtering. Yeah, I don't need Wayla
48.
▲
by
ashishb
5mo ago
Then try https://github.com/ashishb/amazing-sandbox I use it every day for CLI tools > How would you sandbox an Electron app I haven't figured that out yet
49.
▲
by
ashishb
5mo ago
Always run third-party code (especially npm packages) inside a sandbox, take your pick: ai-jail, bubblewrap, seatbelt, or amazing-sandbox (the last one, I wrote for myself after trying all others).
50.
▲
by
ashishb
5mo ago
> Ive used python at scale and its fine if you have reasonably good code hygiene. True but that's the problem. Once you have a big enough team, it becomes an uphill battle to maintain that.
51.
▲
by
ashishb
5mo ago
Indeed. Python is faster to write and harder to maintain over the long run. The "faster to write" advantage becomes less relevant if most code is going to be auto-generated. The "harder to maintain" might still remain mo
52.
▲
by
ashishb
5mo ago
Python is amazing for scripting. Python is terrible for writing big systems. Projects whose V1 is written in Go/Rust/C++ don't normally go out and re-write V2 in Python. The reverse is really common. Even many famous Python p
53.
▲
by
ashishb
5mo ago
I didn't qualify. And the reason was that majority of backend engineers have never worked on frontend. At almost all big companies, the team working on the frontend problem is relatively small +and that's how it should be). > I
54.
▲
by
ashishb
5mo ago
Software engineers drastically underestimates GUI - Web layouts, mobile app layouts, and even PDF layouts are non-trivial pieces of work to get right in all circumstances.
55.
▲
by
ashishb
5mo ago
Always run third party code inside a sandbox
56.
▲
by
ashishb
5mo ago
> At least 80% of what you’re describing would be satisfied by trains and buses. It’s wild that Americans are so obsessed with self-driving cars while ignoring public transit that solves most of the problems. It’s reliable, more efficien
57.
▲
by
ashishb
6mo ago
This has nothing to do with Apple/Firebase notification service. It has to do with the fact that any notification displayed on your device goes via a separate system service which was caching them. It is amusing to see how often people
58.
▲
by
ashishb
6mo ago
WordPress was great because of the plugins. WordPress is now a dangerous ecosystem because of the plugins and their current security model. I moved to Hugo and encourage others to do so - https://ashishb.net/tech/wordpr
59.
▲
by
ashishb
6mo ago
And what are good options that you use and that work on Linux as well as Mac OS?
60.
▲
by
ashishb
6mo ago
What makes you think that? Your can see the commit history <10% of code is written by agents. Rest was all written by me. Unlike other criticisms of the project, this one feels personal as it is objectively incorrect.
More ›