Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ctmnt
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
31.
▲
by
ctmnt
7mo ago
I agree. It’s a neat idea and I’d be interested in seeing the details. A downloadable tarball is a lot better than nothing, but it still makes more work to evaluate a random project than I’m inclined to perform. It makes me assume the commi
32.
▲
by
ctmnt
7mo ago
I’m not sure what you’re referring to. It’s not (typically, as far as we know) a secret designation. We know of other companies designated as supply chain risks: Huawei, ZTE, and Kapersky are the first ones that come to mind.
33.
▲
by
ctmnt
7mo ago
One interesting change between the last statement and this one: In the last statement Dario said that this designation had “never before been applied to an American company”. In the latest one the phrase is “never before publicly applied to
34.
▲
by
ctmnt
7mo ago
It’s always a gamble, but no, lots of it is still good. There are many photographers still working with it. Jean-Andre Antoine [1] is one of the more famous; if you’re ever in NY, go see him in SoHo, he’s a super nice guy and a fantastic ph
35.
▲
by
ctmnt
7mo ago
Agreed! The whole film world is on fire right now, it’s pretty cool to see.
36.
▲
by
ctmnt
7mo ago
“Still” isn’t the right word. Once Polaroid stopped making the film, closed their factories, and sold or junked their machines, their supplies did the same, and so some of the components stopped being manufactured and available for purchase
37.
▲
by
ctmnt
7mo ago
I did not realize that macOS was officially certified Unix. Interesting, thanks. I guess that makes my laptop a multi-user Unix.
38.
▲
by
ctmnt
7mo ago
Are there any publicly accessible Unixes these days?
39.
▲
by
ctmnt
7mo ago
For the people who are downvoting me: I’m being totally sincere. This is not an ad hominem attack. You didn’t see his other comment, it was genuinely concerning.
40.
▲
by
ctmnt
7mo ago
I read the README and did not find answers to my questions.
41.
▲
by
ctmnt
7mo ago
Based on this and your other comments, including the one that’s no longer visible: Please phone a friend. Or find a professional to talk to. I say that with nothing but compassion.
42.
▲
by
ctmnt
7mo ago
Ah right, thanks! But it seems he meant literal evil maids. Which I guess count as the figurative kind too.
43.
▲
by
ctmnt
7mo ago
Also, evil maids, what?
44.
▲
by
ctmnt
7mo ago
Hard to say. Claude’s very good at writing READMEs. In fact, Copilot often complains about docs that sound like they’re about current capabilities when in fact they’re future plans or just plan aspirational. Without downloading and testing
45.
▲
by
ctmnt
7mo ago
Wait, are you suggesting that OP broke in to your server and stole code and is republishing it as these repos? I have questions. Have you reviewed the code here to see if it matches? What, more specifically, do you mean when you say someone
46.
▲
by
ctmnt
7mo ago
You can just set `"deny": ["Read(./.env)", "Read(./.env.*)"]` if you want to keep it simple and rely on Claude's own mechanisms.
47.
▲
by
ctmnt
7mo ago
But that's moving the whole LLM agent into the cloud, which creates its own difficulties. Not really a solution to the local secrets problem.
48.
▲
by
ctmnt
7mo ago
It doesn't even have to change the code to get the secret. If you're using env variables to pass secrets in, they're available to any other process via `/proc/<pid>/environ` or `ps -p <pid> -Eww`. I
49.
▲
by
ctmnt
7mo ago
OP isn't talking about giving agents credentials, that's a whole nother can of worms. And yes, agreed, don't do it. Some kind of additional layer is crucial. Personally I don't like the proxy / MITM approach for tha
50.
▲
by
ctmnt
7mo ago
Just use gitleaks or trufflehog?
51.
▲
by
ctmnt
7mo ago
I think we're both right about zeroize. Added a reply to clarify. In short, yes, the key and password are getting zeroized, but not the actual secrets. Which seems like the thing that matters in this context, at least given the tool&#x
52.
▲
by
ctmnt
7mo ago
Yeah, if you want .env-ish behavior, use sops + age. Or dotenvx.
53.
▲
by
ctmnt
7mo ago
Really depends on your threat model and use case. The problems with .env files: plain text on disk, no access control, no rotation mechanism, no audit trail, trivial to leak accidentally, secrets go into env variables (which are exposed and
54.
▲
by
ctmnt
7mo ago
To be clear: `zeroize()` is called, but only on the key and password. Which is what the docs say, so I was being unfair when I lumped that under grand claims not being met. However! The actual secrets are never zeroized. They're loaded
55.
▲
by
ctmnt
8mo ago
This suffers from all the usual flaws of env variable secrets. The big one being that any other process being run by the same user can see the secrets once “injected”. Meaning that the secrets aren’t protected from your LLM agent at all. So
56.
▲
by
ctmnt
8mo ago
I agree that they’re bad patterns (the three dot menu particularly so, it often just looks like a mistake), but what would be more functional on a small screen? I’d love to see some good alternatives that I could adopt in my own projects.
57.
▲
by
ctmnt
8mo ago
Thanks for the explanation! As you can tell, I'm very ignorant of Forth. But I'm not sure I quite follow what you're saying. Forth has early binding, explicit forward declarations, and message passing but not in the usual OOP
58.
▲
by
ctmnt
8mo ago
If only. But `jj undo`?
59.
▲
by
ctmnt
8mo ago
I assume you mean what’s more properly called Java style [1], where the first curly brace is on the same line as the function declaration (or class declaration, but if you’re using Allman style you’re probably not using classes; no shade, I
60.
▲
by
ctmnt
8mo ago
Yeah, I didn’t mean far out as in good. Some people would say that the important thing to take from OOP is message passing. Which I assume is a no go in Fort? Regardless of dialect.
More ›