Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
CER10TY
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
CER10TY
27d ago
Satellite Reign was fun. Not sure if I'd call 2015 _recent_ though :)
2.
▲
by
CER10TY
28d ago
Hi HN, Over the last few months, I invested pretty heavily into setting up SSO for my self-hosted stack. However, some apps gate SSO behind paid plans, meaning accounts and thus MFA need to be set up outside of the IdP. This leaves me with
3.
▲
Show HN: RecoveryCodes – MFA inventory for auth outside IdPs
(recoverycodes.eu)
2 points
by
CER10TY
28d ago
|
1 comments
4.
▲
by
CER10TY
1mo ago
Does Cursor allow you to blacklist certain commands as well? I know OpenCode has this, where you can both whitelist things like grep/ls but then also blacklist things like cat .env, or rm -rf. I usually copy paste my configs nowadays,
5.
▲
by
CER10TY
2mo ago
Not a mobile dev so I'm leaning quite heavily on other people's experiences here. It's my understnading that setting up cookies to work on mobile is quite painful, though it depends on the platform. IIRC iOS has gotten better
6.
▲
by
CER10TY
2mo ago
Cookies also don't work on mobile, so you inevitably have to maintain 2 different login flows. But they're still the superior choice for authN on the web, because if you want to, you CAN configure cookies to be secure. Yes, attack
7.
▲
by
CER10TY
5mo ago
They use Persona for their new "Trusted Access for Cyber": https://chatgpt.com/cyber , at least according to the FAQ
8.
▲
by
CER10TY
7mo ago
IIRC the creator specifically said he's not reviewing any of the submissions and users should just be careful and vet skills themselves. Not sure who OpenClaw/Clawhub/Moltbook/Clawdbot/(anything I missed) was market
9.
▲
by
CER10TY
7mo ago
It swings both ways though. I've seen plenty of older engineers dismiss the "new guys" effort and claim that everything had to be custom written, because there's no way a common framework like Django could cover their us
10.
▲
by
CER10TY
9mo ago
Only for public repos though - if you're in an org with private repositories you don't get access to them (yet).
11.
▲
by
CER10TY
10mo ago
Personally, I'd just use common sense and good judgment. At the end of the day, would you want someone to hand your address, and other private data to OpenAI just like that? Probably not. So don't paste customer data into it if yo
12.
▲
by
CER10TY
10mo ago
Presumably they'll threaten to sue you and/or file a criminal complaint, which can be pretty hard to deal with depending on the jurisdiction. At that point you'll probably start asking yourself if it's worth publishing a
13.
▲
by
CER10TY
1y ago
That's a good catch. I knew these flags existed, but I figured they'd require at least a human in the loop to verify, similar to how Claude Code currently asks for permission to run code in the current directory.
14.
▲
by
CER10TY
1y ago
Personally, I'd expect Claude Code not to have such far-reaching access across my filesystem if it only asks me for permission to work and run things within a given project.
15.
▲
by
CER10TY
1y ago
Talk to people outside tech. Lots of small problems worth solving, but not in tech. Also, just because it's a problem in someone's day to day won't mean they'll pay to fix it. Good luck!
16.
▲
by
CER10TY
1y ago
Isn't that pretty much how every "Trusted by these companies" marketing badge works nowadays?
17.
▲
Show HN: SpecGate – Validate API responses against OpenAPI in real-time
(github.com)
1 points
by
CER10TY
1y ago
|
0 comments
18.
▲
by
CER10TY
1y ago
Or, far more likely, they'll reach out to someone in their network. To land in that network, you have to market your services. LinkedIn is somewhat useful for that, but less so nowadays.
19.
▲
by
CER10TY
1y ago
I guess the thinking goes like this: Why start a business, get a higher paying job etc if you're getting ~2k€/mo in UBI and can live off of that? Since more people will decide against starting a business or increasing their income
20.
▲
Ask HN: Would you soft-launch a landing page in 2025?
3 points
by
CER10TY
1y ago
|
5 comments
21.
▲
by
CER10TY
1y ago
That takes 2 seconds. But the PO usually expected a detailed breakdown of what went well or bad and what could be improved right then and there. Simply saying "Yeah, I'm doing X, still doing it, bye" would be bad, because you
22.
▲
by
CER10TY
1y ago
We were 5 people total - PO, Scrum Master, 3 devs. Been years since I was in that team but it was expected that everyone would give a lengthy update about the previous day
23.
▲
by
CER10TY
1y ago
I‘m long gone from that team (thankfully). But hey, the Scrum Master was certified, I‘m sure it‘s all proper /s
24.
▲
by
CER10TY
1y ago
Props to you if you manage to follow this and squeeze it into 15 minutes. I‘ve genuinely never had a daily last less than 60 mins.
25.
▲
by
CER10TY
1y ago
The issue is that it‘ll absolutely _suck_. If I tell Claude Code to scaffold a web app from 0 outside of React it‘s terrible. So no, imho people with no app dev skills cannot just build something over a weekend, at least something that won‘
26.
▲
by
CER10TY
1y ago
It‘s easier, since you don‘t have to stare at your monitor for 4 hours straight. But still, people expect availability since you‘re paid for 8 hours.
27.
▲
by
CER10TY
1y ago
That‘s corporate jobs for you. It‘s about appearance, not results. That‘s why you make a big deal out of everything you work on.
28.
▲
Ask HN: Are you designing APIs to be "AI-ready"?
1 points
by
CER10TY
1y ago
|
1 comments
29.
▲
by
CER10TY
1y ago
SEEKING WORK | Germany | Fully Remote I help startups implement secure API architectures through audits, strategy development, or ongoing support. As a solo consultant with 10 years of experience across startups to enterprise, you work dire
30.
▲
Ask HN: How do you deal with API security in your org?
3 points
by
CER10TY
1y ago
|
0 comments
More ›