Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ashishb
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
12 ms
·
181.
▲
by
ashishb
11mo ago
I'll do soft local workflow restriction right away. The secure process change might take anywhere from a day to months.
182.
▲
by
ashishb
1y ago
My host is Mac OS. My container platform is Linux. Can you share an example where this approach will cause a failure?
183.
▲
by
ashishb
1y ago
Yeah but those deps won't access your browser cookies and tour secret keys that are outside the current directory.
184.
▲
by
ashishb
1y ago
Can you show an example of how can a malicious package break out of docker?
185.
▲
by
ashishb
1y ago
Your machine has more projects, data, and credentials than your CI machine, as you normally don't log into Gmail on your CI. So, just protecting your machine is great. Further, you are welcome to use this alias on your CI as well to en
186.
▲
by
ashishb
1y ago
> The above simple alias may work for node/npm, but it doesn't generalize for many other programs that are available on the local system, with resources that would somehow have to get mounted into the container ... Thanks. You
187.
▲
by
ashishb
1y ago
> A compromised neovim or vscode gives you plenty of user permissions, a full scripting language, ability to do http calls, system calls, etc. Most LSPs are installed globally, doesn't matter if you downloaded it via a docker comman
188.
▲
by
ashishb
1y ago
No. Most valuable data on your system for a malware author is login cookies and saved auth tokens of various services.
189.
▲
by
ashishb
1y ago
I run linters like eslint on my machine inside a container. This reduces attack surface. How does this throw hygiene over the fence?
190.
▲
by
ashishb
1y ago
> Also I can recommend pnpm, it has stopped executing lifecycle scripts by default so you can whitelist which ones to run. Imagine you are in a 50-person team that maintains 10 JavaScript projects, which one is easier? - Switch all p
191.
▲
by
ashishb
1y ago
> That seems a bit excessive to sandbox a command that really just downloads arbitrary code you are going to execute immediately afterwards anyways? I won't execute that code directly on my machine. I will always execute it inside t
192.
▲
by
ashishb
1y ago
Here's my `npm` command these days. It reduces the attack surface drastically. alias npm='docker run --rm -it -v ${PWD}:${PWD} --net=host --workdir=${PWD} node:25-bookworm-slim npm' - No access to my env vars - No ac
193.
▲
by
ashishb
1y ago
I'll be down voted by JavaScript lobby for saying this but I'll still say this. Never use JavaScript on the server side. The amount of bugs that can happen is insane. JavaScript is just a specification with varying implementations
194.
▲
Best practices for using Python and uv inside Docker
(ashishb.net)
7 points
by
ashishb
1y ago
|
0 comments
195.
▲
by
ashishb
1y ago
What you are asking for is to write tests along the axis of least change https://ashishb.net/programming/bad-and-good-ways-to-write-a...
196.
▲
by
ashishb
1y ago
I run all npm based tools inside Docker with no access beyond the current directory. https://ashishb.net/programming/run-tools-inside-docker/ It does reduce the attach surface drastically.
197.
▲
by
ashishb
1y ago
Sikkim is one of the most beautiful states in India. And surprisingly a fairly prosperous one[1]. Thankfully, the mistake of Tibet where India helped Chinese army was not repeated.[2] 1 - https://ashishb.net/travel/gork
198.
▲
Family Ties in Your DNA: Some relatives are closer than others
(ashishb.net)
2 points
by
ashishb
1y ago
|
0 comments
199.
▲
by
ashishb
1y ago
Docker can be used on Mac, Linux, BSD [and probably even Windows]. Switching to Qubes OS requires a much bigger shift.
200.
▲
by
ashishb
1y ago
Third-party CLI tools. It is doable, but hard to run a browser inside Docker. Further, the browser itself has a layer of safety against executing malicious code.
201.
▲
by
ashishb
1y ago
That's true. However, you are reducing your attack surface by running some of those tools inside Docker.
202.
▲
To keep your machine secure, run third-party tools inside Docker
(ashishb.net)
13 points
by
ashishb
1y ago
|
9 comments
203.
▲
by
ashishb
1y ago
> 100% guaranteed when VCs are involved that something nasty will happen to the project. I presume you don't use any VC-backed projects like Google, Apple, Amazon, Facebook, etc.
204.
▲
by
ashishb
1y ago
> The first 2 projects are most likely to be VC backed and do a rug pull in the next 5 years. The first two are more likely to get VC backing. Rug pull is a false assumption.
205.
▲
by
ashishb
1y ago
> Ah yes because reading the code and deciding if it's any good is difficult. No one has infinite time in the universe to read the code of all alternatives before deciding which one is best for their use case. GitHub stars are a fil
206.
▲
by
ashishb
1y ago
What's unique to GitHub is not code hosting, UI or CI. Rather it is GitHub stars. People trust a project with 5K stars on GitHub.com more than a self-hosted project. VCs fund startups based on the star history. Big companies decide whi
207.
▲
by
ashishb
1y ago
Sorry I meant think and not then.
208.
▲
by
ashishb
1y ago
> My personal theory is that this is because you can make every sound you hear in English using the Devnagari script, but not the other way around. Not true. There are phonemes which are similar but distinct. For example - `v and w`
209.
▲
by
ashishb
1y ago
Many foreign learners have written about it. Essentially, one can follow conventions around oneself or try to write and get an English spelling that sounds closest to Hindi pronunciation. And there are no academic rules around it that one i
210.
▲
by
ashishb
1y ago
In the long term markets usually specialize https://ashishb.net/tech/the-android-chrome-merger-saga/
More ›