Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
lumberjack24
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
22 ms
·
1.
▲
by
lumberjack24
3y ago
Forest Admin's out-of-the-box admin panel + the convenience of the cloud, this is all developers ever wanted for their internal tools!
2.
▲
by
lumberjack24
4y ago
To Casablanca, Morocco.
3.
▲
by
lumberjack24
4y ago
Hey, maybe try running a GitGuardian [1] scan on all those repositories to look for hardcoded secrets. GitGuardian can also test in some cases if the secrets are valid or not, meaning you have to revoke and rotate them asap. I hope this hel
4.
▲
by
lumberjack24
4y ago
geez.
5.
▲
by
lumberjack24
4y ago
“dark matter” sounds like marketing speak.
6.
▲
by
lumberjack24
4y ago
well, they haven’t turned my building’s heating on yet.
7.
▲
by
lumberjack24
4y ago
Here's a checklist [1] (again, from gitguardian) of steps to follow before open-sourcing projects and [2] a guide on how to remediate hardcoded/exposed secrets. [1] https://blog.gitguardian.com/safely-open-source-s
8.
▲
by
lumberjack24
4y ago
Great idea, but hard to enforce. Just use a scanning CLI like TruffleHog, Gitleaks, or ggshield from GitGuardian to catch all sorts of hardcoded secrets.
9.
▲
by
lumberjack24
4y ago
GitGuardian actually does this, it monitors an extended perimeter of devs and their personal/open-source repos for corporate secrets or keywords – https://www.gitguardian.com/monitor-public-github-for-secret...
10.
▲
by
lumberjack24
4y ago
In the meantime, try ggshield cli https://github.com/GitGuardian/ggshield
11.
▲
by
lumberjack24
4y ago
The access model on platforms like GitHub is flawed, a single account can be used for both professional and personal projects/repositories, leading to “fat finger” errors like this one here...
12.
▲
by
lumberjack24
4y ago
I can’t help but wonder why qursān ended up being the final form instead of qursāl.
13.
▲
by
lumberjack24
4y ago
That hardcoded secret in the powershell script really was the key to the Uber ride-hailing kingdom – https://blog.gitguardian.com/uber-breach-2022 .
14.
▲
by
lumberjack24
4y ago
open to referrals?
15.
▲
by
lumberjack24
4y ago
show me the mrr
16.
▲
Ggcanary – detect compromised DevOps environments with exposed AWS secrets
(blog.gitguardian.com)
3 points
by
lumberjack24
4y ago
|
0 comments
17.
▲
by
lumberjack24
4y ago
Photos don’t load on mobile :/
18.
▲
by
lumberjack24
4y ago
These folks must be retired by now and they have lived enough to find out they lost their crusade against computers.
19.
▲
by
lumberjack24
4y ago
Try https://www.specifyapp.com and thank me later!
20.
▲
Song predicted the rise of smartphones back in 2002
(open.spotify.com)
1 points
by
lumberjack24
4y ago
|
3 comments
21.
▲
by
lumberjack24
4y ago
Just like shrimps are sea cockroaches.
22.
▲
by
lumberjack24
4y ago
I’m 28 y.o and this is the first time I hear about garlic in a jar. U.S.A never ceases to amaze me.
23.
▲
by
lumberjack24
4y ago
My brother in Christ, you have an email job and you definitely don't need this browser.
24.
▲
by
lumberjack24
4y ago
A few days before this attack campaign started, I wrote a guide to help security and engineering teams prioritize and remediate thousands of secrets-in-code incidents. Hope it can help some of the organizations dealing with this right now!
25.
▲
by
lumberjack24
4y ago
A few days before this attack campaign started, I wrote a guide to help security and engineering teams prioritize and remediate thousands of secrets-in-code incidents. Hope it can help some of the organizations dealing with this right now!
26.
▲
by
lumberjack24
4y ago
The other day I wrote a guide to help security and engineering teams prioritize and remediate thousands of such incidents. Hope it helps! https://blog.gitguardian.com/a-practical-guide-to-prioritize...
27.
▲
Surviving the GitHub OAuth hack – remediating thousands of hardcoded credentials
3 points
by
lumberjack24
4y ago
|
1 comments
28.
▲
by
lumberjack24
5y ago
If you're looking to add secrets management and scanning to the curriculum, take a look at GitGuardian– https://www.gitguardian.com/monitor-internal-repositories-fo... .
29.
▲
Scan Docker images for hardcoded credentials (Dockerfile, build args, filesys)
(github.com)
2 points
by
lumberjack24
5y ago
|
0 comments
30.
▲
Separating work and personal Git accounts on your laptop
(blog.gitguardian.com)
6 points
by
lumberjack24
5y ago
|
0 comments
More ›