Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
larusso
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
61.
▲
by
larusso
10mo ago
The keys never leave the 1Password store. So you don’t have the keys on the local file system. That and that these keys are shared over the cloud was the seller for me. I guess security wise it’s a bit of a downgrade compared to resident ke
62.
▲
by
larusso
10mo ago
I did the switch this year after getting yet another personal computer. I have 4 in total (work laptop, personal sofa laptop, Mac Mini, Linux Tower). I used Yubi keys with gpg and resident ssh keys. All is fine but the configuration needed
63.
▲
by
larusso
10mo ago
Thanks. I was wondering what this means practically. So they rolled this back because Google who compile with warnings as errors can’t fix these lines? Must be great to be Google and on all these boards. I on the other hand have to deal con
64.
▲
by
larusso
10mo ago
This year I had to create SBOM files for our Unity projects. Of course there is nothing. For all that don’t know: UPM (Unity Package Manager) is a way to easily install packages in Unity. And as a side note, for whatever reason they decided
65.
▲
by
larusso
10mo ago
I spend well over a month now on the topic to implement the different half cooked APIs into our apps. The chance that this gets overturned or blocked was high but we had to race anyways. I’m curious what this means for similar legislations
66.
▲
by
larusso
10mo ago
Just teaches you that wild fires, maybe not as devastating than that one, are parts of nature. They have a great exhibition at Wind Cave NP in South Dakota. They show a series of photos explaining how the prairie recovers after a wild fire.
67.
▲
by
larusso
10mo ago
I don’t want to throw process at the problem. I think GH should provide a better system not the developers locking down dependencies and adding extra processes and steps to update the CI via a PR workflow. Not like PRs became the developmen
68.
▲
by
larusso
10mo ago
Maybe the few dozen developers not working on something that can be build with Linux only?
69.
▲
by
larusso
10mo ago
1 store my ssh key in 1Password and use the 1Password ssh agent. This agents asks for access to the key(s) with Touch ID. Either for each access or for each session etc. one can also whitelist programs but I think this all reduces the secur
70.
▲
by
larusso
10mo ago
There is the FIDO feature which means you don’t need to hackle with gpg at all. You can even use an ssh key as signing key to add another layer of security on the GitHub side by only allowing signed commits.
71.
▲
by
larusso
10mo ago
Yes. In the example of gradle I setup all specifics to the well know lifecycle tasks: check, assemble and in some cases publish. Some projects are more complicated specifically when you can really use the rule of: 1 project one assembly. S
72.
▲
by
larusso
10mo ago
This story reminds me of a similar issue people love to solve with the same idea. Software builds. The can’t we have a simple make file or worse just a shell script to build. And just like described in the post it starts the same. Simple sc
73.
▲
by
larusso
10mo ago
I think this is true for nearly all compiled languages. I had the same fun with rust and openSSL and glibC. OP didn’t mentioned the fun with glib-c when compiling on a fairly recent distro and trying it to run on an older one. There is the
74.
▲
by
larusso
10mo ago
I think the HDMI connectors popped up at the same time screens switched from 16:10 (VESA compatible at the time) to 16:9 to be more cost effective for the manufacturers. But I’m not sure why. I looked at graphicscards and wondered why HDMI
75.
▲
by
larusso
10mo ago
Paired with a long lived GitHub access token that had more access than needed for this operation. GitHub Actions has some features for short lived tokens that are not stored in static action secrets. I’m not quite sure why a bot user was ac
76.
▲
by
larusso
11mo ago
Didn’t know this term. After reading I wonder why short lived tokens get this monocle. But yeah I prefer OIDC over token based access as well. Only small downside I see is the setup needed for a custom OIDC provider. Don’t know the right te
77.
▲
by
larusso
11mo ago
Ah cool. I worked around by storing the public keys in my dot repo and use the identity file ssh config option for said host. Great if I don’t have to do this anymore. Next level config madness: Use different ssh keys per GitHub org ;).
78.
▲
by
larusso
11mo ago
The trusted publishing is rather new or? Awesome to see that they implemented it. Just saying that maven central required it already years ago.
79.
▲
by
larusso
11mo ago
You are right. I remembered it wrong. https://rust-lang.github.io/rfcs/0940-hyphens-considered-har... Was from 2015 and the other discussions I remember were around default style and that cargo already blocks a crate w
80.
▲
by
larusso
11mo ago
I agree partly. I love cargo and can’t understand why certain things like package namespaces and proof of ownership isn’t added at a minimum. I was mega annoyed when I had to move all our Java packages from jcenter, which was a mega easy se
81.
▲
by
larusso
11mo ago
Ok I wished for this kind of feature for years. I started using a yubikey with an ssh key via gpg ssh-agent in 2018 or 2019. When resident ssh keys came around I switched over to FIDO2 based keys on my yubikey. The main issue with both was
82.
▲
by
larusso
11mo ago
This item didn’t get sold yet or? It’s says it’s valued at 9million. So somebody gave it that number.
83.
▲
by
larusso
11mo ago
Ah damn. I forgot to add in the whole world of art collection which of course this item belongs in as well. Still baffles me how we humans can put such high prices on some items
84.
▲
by
larusso
11mo ago
It is interesting to me that something like this can have such a high value. It speaks meanly for the our shared cultural global connection when it comes to items like these. For what purpose other than saying: “I have a …” would you buy th
85.
▲
by
larusso
11mo ago
Love the name of the executable ;) For my taste it just sounds right. BS as in Bullsh#t :)
86.
▲
by
larusso
11mo ago
Ah well yes. We have this as well but I think it is still under control for us. We fight more the sheer amount of channels. It’s so damn easy to create channels and invite people to channels etc. But that is also true for Teams.
87.
▲
by
larusso
11mo ago
It’s one of the topics I feel I’m too biased since I spend 10 years as a flash developer. The requests for widgets and or small applications we got where simply impossible to write in a frontend only fashion at the time. And a lot of my pee
88.
▲
by
larusso
11mo ago
Not to be too snarky but I really detest teams. We use Slack in our company but the mothership is all teams. Every time I have to use it I spit in anger. It’s the sum of all these weird usability issues etc. so my personal recommendation wo
89.
▲
by
larusso
11mo ago
The mirror board is an interesting idea as it allows to start with a normal keyboard and one could then switch to a smaller board with the muscle memory trained. I would prefer a different switch key though. I use cap lock as a layer switch
90.
▲
by
larusso
11mo ago
Don’t know about the story telling as in a story about the past of the laptop. I have a lot of colleagues who come back with a full plastered laptop the second day they receive a new machine. I think that there is a culture of either leave
More ›