Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
tompic823
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
tompic823
6y ago
Thanks for that feedback, I completely agree. I've updated the linked page to mention this more explicitly.
32.
▲
by
tompic823
6y ago
Great question! We tokenize all secrets and then store the tokens in our database. The raw secrets are stored with our tokenization provider, VGS. When you fetch your secrets, either via our dashboard or CLI, we exchange the token for the r
33.
▲
by
tompic823
6y ago
Server access is an interesting scenario to explore. If we're considering an attacker gaining server access, what's to stop that attacker from shipping a modified EnvKey binary that steals your customers' secrets and their en
34.
▲
by
tompic823
6y ago
Hey Dane- totally fair points. Agreed that Doppler and EnvKey have different threat models. Regarding your point about malicious JavaScript- I'd encourage you to take a look at our Content Security Policy. We've gone to great leng
35.
▲
by
tompic823
6y ago
Absolutely, we use Doppler ourselves in this way with puppeteer for our E2E tests. You would simply wrap your orchestrator (like puppeteer) with our Doppler CLI [0] to make the secrets available via environment variables. For example, `npm
36.
▲
by
tompic823
6y ago
Thank you! Full props to our design guru and CEO @bvallelunga for that one.
37.
▲
by
tompic823
6y ago
You can indeed! You can manage all of your secrets from the Doppler CLI [0]. Specifically, you'd want the `doppler secrets update` command. [0] https://github.com/DopplerHQ/cli
38.
▲
by
tompic823
6y ago
Great question! We address this in detail on our Security page [0], but I'm happy to give a high-level overview here: 1. Don't go down! We run two independent compute clusters on different managed infrastructure products (GKE and
39.
▲
by
tompic823
6y ago
Your point about not being an early adopter is well taken. We fully expect a segment of the market will be disinterested in using a relatively new product like ours. If we were a customer considering a new secrets manager, we would likely w
40.
▲
by
tompic823
6y ago
Great point about dynamic secrets. This is an area we currently don't address, but it is definitely on our roadmap. There is a segment of the market for which dynamic secrets are an absolute requirement and we fully acknowledge that.
41.
▲
by
tompic823
6y ago
We were waiting to see how long it took someone to notice that :) That key has already been rolled and instantly redeployed via our Heroku integration, but nice catch!
42.
▲
by
tompic823
6y ago
Tom here from Doppler. I'm a founding engineer at Doppler and work on most of our security. Feel free to hit me with any security questions about our product, philosophy, etc.
43.
▲
by
tompic823
6y ago
I enjoyed this article's perspective, particularly its mention of Apple and California acting as the US's de facto privacy regulators. There is one line I don't understand though: > Second, you can no longer assume that th
44.
▲
by
tompic823
6y ago
Couldn't agree more. I don't have the time right now to commit to another project, but I always love picking off a quick task if it's helpful. As proof, GitPals posted[0] their own project on GitPals. The sole comment mention
45.
▲
by
tompic823
6y ago
One company featured in the article, VotingWorks, recently provided electronic voting machines in Mississippi. They're a non-profit and were funded in YC's W19 batch. They made this short film documenting the voting machine procur
46.
▲
by
tompic823
6y ago
> It seems like very little effort to implement this yourself in a way that doesn't involve completely trusting a different company. What about cookie configuration (secure, httpOnly, samesite), signing, expiration, session manageme
47.
▲
Cryptographic Right Answers (2018)
(latacora.micro.blog)
1 points
by
tompic823
6y ago
|
0 comments
48.
▲
by
tompic823
6y ago
This post taught me about two GitHub Actions features I've been wanting and didn't know existed: 1. You can schedule workflows. This is super useful for running dependency vulnerability scanners on repos that don't see active
49.
▲
by
tompic823
6y ago
I commend Zoom for listening to the outcry over E2EE being limited to paid users. Between this move and their quick acknowledgement of mishandling the shutdown of accounts when asked by China, they're doing a better job than most of re
50.
▲
by
tompic823
6y ago
It's fascinating that desk fans have had such a consistent design for over 100 years. Most surprising to me is that they've been able to oscillate for that long, too (since 1904!): > Direct current desk fans were added in 1899.
51.
▲
by
tompic823
6y ago
I can't speak to the implication, but I've yet to read a policy that didn't explicitly outline how it handles business transfers. Some examples from different industries (the first 3 random sites I thought of): AirBnB [0] >
52.
▲
by
tompic823
6y ago
I read the initial post when it was trending on HN, and had previously noticed that line in Stripe's Privacy Policy. I remember checking immediately afterward that my company was only loading Stripe's js on our billing page. I
53.
▲
Update on Slack Office Closure
(slackhq.com)
1 points
by
tompic823
6y ago
|
0 comments
54.
▲
by
tompic823
7y ago
> Meanwhile, the firm saw a fall in costs, with 23.1% less electricity used and 58.7% fewer pages printed over the period. The 23.1% figure makes intuitive sense; the 58.7% figure seems astronomical. Why would employees being out 1/
55.
▲
by
tompic823
7y ago
Lock files are useful in production environments where you want to ensure the exact same package versions are being used that you tested with. A package.json file specifies package names and versions, but theres no guarantee your package re
56.
▲
Internal FAA Review Saw High Risk of 737 Max Crashes
(wsj.com)
102 points
by
tompic823
7y ago
|
71 comments
57.
▲
by
tompic823
7y ago
I had no idea that the old Embarcadero Freeway ran directly in front of the ferry building, before it was rebuilt in its current location in South Beach. The article includes a great photo that really highlights how different the city must
58.
▲
San Francisco November 2019 Election Results Summary
(sfelections.sfgov.org)
1 points
by
tompic823
7y ago
|
0 comments
59.
▲
WebKit Goals for 2020
(trac.webkit.org)
170 points
by
tompic823
7y ago
|
149 comments
60.
▲
by
tompic823
7y ago
From another article the OP linked to: > By Tuesday, rebellious staffers were filling the site with entirely non-sports stories — and the site’s deputy editor said he had been fired for refusing to follow the directive. Ok, so these jour
More ›