Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
scottmotte
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
scottmotte
18d ago
I'm the creator of Node dotenv and I gave this a lot of thought a couple years back. I put together a whitepaper on this. Ultimately your secrets do still have to hit your environment. But at-rest they should be split from the environm
2.
▲
by
scottmotte
4mo ago
Cryptographic systems are mostly designed for machines, not humans. We end up staring at long strings. I wanted to experiment with how to better visualize them - in a more human way. The result is KEYSEE⎔. Try it out and hope you enjoy! The
3.
▲
Show HN: Keysee – deterministic identicons for public keys
(keysee.io)
1 points
by
scottmotte
4mo ago
|
1 comments
4.
▲
by
scottmotte
5mo ago
> If you did 'dotenvx run -- env', all your secrets would be printed right there in plaintext Same for sops. > The equivalent in vercel would be encrypted in the database (the encrypted '.env' file), with a decrypt
5.
▲
by
scottmotte
5mo ago
Creator of dotenvx here. There is no silver bullet, but Dotenvx splits your secrets into two separate locations. 1. The private decryption key - which lives on Vercel in this example 2. The encrypted .env file which lives in your source cod
6.
▲
Show HN: Vestauth – Auth for Agents
(github.com)
11 points
by
scottmotte
7mo ago
|
1 comments
7.
▲
by
scottmotte
2y ago
Encrypting your .env file with dotenvx, or something similar, can help mitigate this need for trust.
8.
▲
by
scottmotte
2y ago
> developers could still potentially commit private keys the repo or commit the decrypted env file to prevent this, use: $ dotenvx ext precommit --install
9.
▲
What Does #1 on Hacker News Get You
(dotenvx.com)
11 points
by
scottmotte
2y ago
|
0 comments
10.
▲
Show HN: From dotenv to dotenvx – better config management
(dotenvx.com)
354 points
by
scottmotte
2y ago
|
206 comments
11.
▲
Show HN: A better dotenv – dotenvx
(github.com)
8 points
by
scottmotte
3y ago
|
2 comments
12.
▲
by
scottmotte
3y ago
I've tried all four, and Render is the closest experience to Heroku. It still isn't as easy to use as Heroku, but it is close.
13.
▲
by
scottmotte
4y ago
> people are most comfortable being around people like themselves Inertia. This is everything. It takes effort to be around people unlike those currently around you. We all have personal biases against the strata economically above us an
14.
▲
by
scottmotte
4y ago
I love the look of the Punkt. I ordered one 3 years ago but because of delays, and then Covid, gave up on receiving it. They issued me a refund but I'd still like to get one - in a reasonable amount of time. Anyone have one and like it
15.
▲
by
scottmotte
4y ago
1. On twitter 2. Start building. It will attract people. Don't go out and find them.
16.
▲
by
scottmotte
6y ago
I posted this myself as well a couple days ago. I was personally interested in HCQ before Trump ever tweeted it - turning it political. It was looking promising and still does. After further personal study, I would like the conversation to
17.
▲
by
scottmotte
7y ago
Generic drugs [1] [1] https://energycommerce.house.gov/sites/democrats.energycomme...
18.
▲
Testimony of Rosemary Gibson to US Commerce Subcommittee on Health (2019) [pdf]
(energycommerce.house.gov)
2 points
by
scottmotte
7y ago
|
0 comments
19.
▲
Ask HN: Quickest way to acquire a US passport for children?
1 points
by
scottmotte
7y ago
|
1 comments
20.
▲
Ask HN: What search engine do you use for Netflix, Hulu, Amazon Video?
1 points
by
scottmotte
7y ago
|
1 comments
21.
▲
by
scottmotte
7y ago
Yeah it would be great to see some numbers from anyone who might have them. I'd put money on SPAs being slower, inside the bell curve than, than the average traditional page load app.
22.
▲
The Seif Handshake
(crockford.com)
3 points
by
scottmotte
7y ago
|
0 comments
23.
▲
by
scottmotte
7y ago
Why hasn't someone built an email system that only accepts signed payloads? Email would only be allowed into my inbox if it was signed. Then, layer 2, it would only allow signed emails from senders whom I've accepted their public
24.
▲
by
scottmotte
7y ago
I wish there was a standardized or common methodology for classifying notifications. App developers could adopt this and consumers could take the pattern with them across all types of interfaces - desktop, smartphone, speakers, tv. Maybe so
25.
▲
by
scottmotte
7y ago
That's a novel thought. I imagine then the native mail apps would expand in settings in order to block some bad senders from abusing that email header. Tangentially related, iOS mail app has a VIP setting. [1] https://suppor
26.
▲
by
scottmotte
7y ago
I believe that is for the all-in-one option. And I do not believe Authorize.net offered that a decade back. Anyways, if you already have your merchant account, it is only 10cents a transaction.
27.
▲
by
scottmotte
7y ago
That brings me back. I remember Authorize.net before there was the ActiveMerchant gem (ruby). Have you used Stripe as well? Authorize.net always got the job done. Then Stripe came along. I was honestly surprised of its success at the time.
28.
▲
by
scottmotte
7y ago
Doesn't Google Analytics support this using user IDs?
29.
▲
by
scottmotte
7y ago
Novel and I like the mental model. It seems like this pushes more of the management to the user - to manage the key. Or providing the user nice consumer tools to manage the key - adjacent to your core product. The hard part here is probably
30.
▲
Ask HN: How do you currently solve authentication?
114 points
by
scottmotte
7y ago
|
99 comments
More ›