Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
xinbenlv
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
Show HN: Propose and Dual-Control for DNS Changes
(loom.com)
2 points
by
xinbenlv
22d ago
|
0 comments
2.
▲
by
xinbenlv
29d ago
I have something embarrassing to share: my computer was compromised, and I don’t know whether my keys were leaked. It was an old computer that I had stopped using and let my family use. Most of the sensitive things had already been cleared,
3.
▲
Ask HN: Has anyone tried a minimal AGENTS.md that grows with you repo?
1 points
by
xinbenlv
1mo ago
|
0 comments
4.
▲
by
xinbenlv
2mo ago
Thanks, that's helpful. Do you use gitleaks or other library to do pre-commit protection? @toomuchtodo
5.
▲
Ask HN: Best practice to prevent credentials/secrets commit to Git repo
2 points
by
xinbenlv
2mo ago
|
3 comments
6.
▲
by
xinbenlv
2mo ago
And if you are interested in testing it please let me know
7.
▲
Show HN: 3-line calendar for Apple Watch – free, open source, no sign-in
(threelinecal.apps.zzn.im)
2 points
by
xinbenlv
2mo ago
|
1 comments
8.
▲
Ask HN: Does OpenClaw need a re-architecture to be usable?
4 points
by
xinbenlv
7mo ago
|
4 comments
9.
▲
Ask HN: Too many skills, how do you pick?
1 points
by
xinbenlv
8mo ago
|
2 comments
10.
▲
Show HN: CancelShouldBeEasy – Generate and co-sign consumer complaint letters
(cancelshouldbeeasy.com)
1 points
by
xinbenlv
8mo ago
|
0 comments
11.
▲
by
xinbenlv
8mo ago
Thanks @pjjpo, exactly. My bad to confuse people, no we don't put real prod-prod credentials in .env. We use mechanisms to ensure separation of secrets. Thank you for saying that it's a simple yet effective implementation. If you
12.
▲
by
xinbenlv
8mo ago
That's a good idea too, thanks for the suggestion
13.
▲
by
xinbenlv
8mo ago
Good points
14.
▲
by
xinbenlv
8mo ago
I am interested, that said, there are many memory and context services. What makes this one different?
15.
▲
Ask HN: Do you "micro-manage" your agents?
7 points
by
xinbenlv
8mo ago
|
8 comments
16.
▲
by
xinbenlv
8mo ago
It happened multiple times to me on Claude Code too, next time I caught it I will try to record its history and show it here
17.
▲
Tell HN: Cursor agent force-pushed despite explicit "ask for permission" rules
7 points
by
xinbenlv
8mo ago
|
9 comments
18.
▲
by
xinbenlv
8mo ago
My question is not about on or off storage, is more about when you give agent access, it assume the environment agent runs is safe
19.
▲
by
xinbenlv
8mo ago
What if you simply need to give them access. E.g if you want them to do code review you have to at least give them code repo read access. But you don't know if the environment where agent runs will be compromised
20.
▲
by
xinbenlv
8mo ago
is the permission device+client based or role based?
21.
▲
by
xinbenlv
8mo ago
Any prompt injection attack could by pass this by simply do a base64 or any encoding, I guess?
22.
▲
by
xinbenlv
8mo ago
Xoogler here too, yes, we used Gmail and Google Workspace at Google. You can search for an exact string if you use quotes. I think you can also filter out logos
23.
▲
Ask HN: Best practice securing secrets on local machines working with agents?
10 points
by
xinbenlv
8mo ago
|
12 comments
24.
▲
by
xinbenlv
8mo ago
We use infiscial and other mechanism but hey, wouldn't it be nice to have one less square inch of attack surface?
25.
▲
by
xinbenlv
8mo ago
Haha thanks my friend, well said.
26.
▲
by
xinbenlv
8mo ago
Exactly, exactly
27.
▲
by
xinbenlv
8mo ago
Thanks, glad you liked it!
28.
▲
Show HN: Dotenv Mask Editor: No more embarrassing screen leaks of your .env
(marketplace.visualstudio.com)
28 points
by
xinbenlv
8mo ago
|
27 comments
29.
▲
Show HN: Just built the best domain search engine
(search.labs.namefi.io)
1 points
by
xinbenlv
9mo ago
|
1 comments
30.
▲
Show HN: Namefi built WebGPU-powered in-browser LLM pure client-side infer UX
(search.labs.namefi.io)
1 points
by
xinbenlv
9mo ago
|
0 comments
More ›