HNHacker News
TopNewBestAskShowJobs

CER10TY

72 karma · joined September 19, 2019

submissionscomments
CER10TY··on The Lost Treasure of Sid Meier's Pirates
Satellite Reign was fun. Not sure if I'd call 2015 _recent_ though :)
CER10TY··on Show HN: RecoveryCodes – MFA inventory for auth outside IdPs
Hi HN,

Over the last few months, I invested pretty heavily into setting up SSO for my self-hosted stack. However, some apps gate SSO behind paid plans, meaning accounts and thus MFA need to be set up outside of the IdP. This leaves me with a weird mix of accounts handled by the IdP and those that I need to track manually.

There wasn't really a good way to track this mixture, especially once you add multiple MFA devices and sensitive data like recovery codes, because the IdP has one half and the password manager has the other (+ maybe it's the second factor itself).

That's why I built RecoveryCodes. It allows me to track all my accounts, see which MFA devices I've enrolled (I usually enrol 2 per account, in case one is lost) and also gives me a place to store recovery codes (instead of copy pasting them into a random .txt file).

Obviously I'm n=1, so I'm interested in hearing from slightly larger companies how you're dealing with this mix? Spreadsheets maybe, or are most of the accounts covered by IdPs and the rest don't really matter?

CER10TY··on Auto mode is now the default in Claude Code
Does Cursor allow you to blacklist certain commands as well? I know OpenCode has this, where you can both whitelist things like grep/ls but then also blacklist things like cat .env, or rm -rf. I usually copy paste my configs nowadays, so I very rarely get prompted for any permissions (except when using Claude, which somehow decided that all users live in ~/Users, even on Linux)
CER10TY··on What's the best way to do authentication in modern applications
Not a mobile dev so I'm leaning quite heavily on other people's experiences here.

It's my understnading that setting up cookies to work on mobile is quite painful, though it depends on the platform. IIRC iOS has gotten better at it with a shared cookie storage, but Android requests are still stateless by default, so you basically have to manually wire up a cookie jar and carry it around everywhere you go, so to speak.

Attributes like SameSite also behave differently, and WebViews don't share the same cookie jar as native requests as far as I understand.

Bottom line is that maybe "Cookies also don't work on mobile" is a bit of a wrong statement, but it's certainly more of a hassle and a path lined with more footguns than just wiring up an OAuth provider and sending access and refresh tokens back and forth using Authorization headers. The great thing with Session cookies on desktop is simplicity, which you sort of lack on mobile.

CER10TY··on What's the best way to do authentication in modern applications
Cookies also don't work on mobile, so you inevitably have to maintain 2 different login flows.

But they're still the superior choice for authN on the web, because if you want to, you CAN configure cookies to be secure. Yes, attackers can ride the session, but it's dependent on the user being on the tab and you being able to consistently execute JS. Client-side compromise (ie attacker controls the entire browser) is not feasible to defend against anyway.

The main issue with JWT+localStorage is you can actually execute one-off JS, exfiltrate the token and come back later. I've _never_ seen a well-executed JWT+localStorage implementation in 10 or so years, because teams inevitably realise they can't reliably revoke sessions (another advantage of cookies) and then start giving out long-lived access tokens but adding them to the database. Or some variation of that.

CER10TY··on Claude may require identity verification in some cases
They use Persona for their new "Trusted Access for Cyber": https://chatgpt.com/cyber, at least according to the FAQ
CER10TY··on Top downloaded skill in ClawHub contains malware
IIRC the creator specifically said he's not reviewing any of the submissions and users should just be careful and vet skills themselves. Not sure who OpenClaw/Clawhub/Moltbook/Clawdbot/(anything I missed) was marketed at, but I assume most people won't bother looking at the source code of skills.
CER10TY··on AI is killing B2B SaaS
It swings both ways though. I've seen plenty of older engineers dismiss the "new guys" effort and claim that everything had to be custom written, because there's no way a common framework like Django could cover their use case. The same type of engineer has never once worked with a common framework though, so they don't know what's included nowadays.

Turns out it's a lot easier to build on top of a common framework than do everything from scratch.

CER10TY··on Pricing Changes for GitHub Actions
Only for public repos though - if you're in an org with private repositories you don't get access to them (yet).
CER10TY··on Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files
Personally, I'd just use common sense and good judgment. At the end of the day, would you want someone to hand your address, and other private data to OpenAI just like that? Probably not. So don't paste customer data into it if you can avoid it.

On the other hand, minified code is literally published by the company. Everyone can see it and do with it as they please. So handing that over to an AI to un-minify is not really your problem, since you're not the developer working on the tool internally.

CER10TY··on Reverse engineering a $1B Legal AI tool exposed 100k+ confidential files
Presumably they'll threaten to sue you and/or file a criminal complaint, which can be pretty hard to deal with depending on the jurisdiction. At that point you'll probably start asking yourself if it's worth publishing a blog post for some internet points.
CER10TY··on Malicious versions of Nx and some supporting plugins were published
That's a good catch. I knew these flags existed, but I figured they'd require at least a human in the loop to verify, similar to how Claude Code currently asks for permission to run code in the current directory.
CER10TY··on Malicious versions of Nx and some supporting plugins were published
Personally, I'd expect Claude Code not to have such far-reaching access across my filesystem if it only asks me for permission to work and run things within a given project.
CER10TY··on Ask HN: Recently laid off developer looking for solo product ideas
Talk to people outside tech. Lots of small problems worth solving, but not in tech. Also, just because it's a problem in someone's day to day won't mean they'll pay to fix it.

Good luck!

CER10TY··on Notion releases offline mode
Isn't that pretty much how every "Trusted by these companies" marketing badge works nowadays?
CER10TY··on Sunny days are warm: why LinkedIn rewards mediocrity
Or, far more likely, they'll reach out to someone in their network. To land in that network, you have to market your services. LinkedIn is somewhat useful for that, but less so nowadays.
CER10TY··on AI is different
I guess the thinking goes like this: Why start a business, get a higher paying job etc if you're getting ~2k€/mo in UBI and can live off of that? Since more people will decide against starting a business or increasing their income, productive activity decreases.
CER10TY··on Small changes that made our daily stand-ups more useful
That takes 2 seconds. But the PO usually expected a detailed breakdown of what went well or bad and what could be improved right then and there. Simply saying "Yeah, I'm doing X, still doing it, bye" would be bad, because you're also not inviting _collaboration_.
CER10TY··on Small changes that made our daily stand-ups more useful
We were 5 people total - PO, Scrum Master, 3 devs. Been years since I was in that team but it was expected that everyone would give a lengthy update about the previous day
CER10TY··on Small changes that made our daily stand-ups more useful
I‘m long gone from that team (thankfully). But hey, the Scrum Master was certified, I‘m sure it‘s all proper /s
CER10TY··on Small changes that made our daily stand-ups more useful
Props to you if you manage to follow this and squeeze it into 15 minutes. I‘ve genuinely never had a daily last less than 60 mins.
CER10TY··on Things that helped me get out of the AI 10x engineer imposter syndrome
The issue is that it‘ll absolutely _suck_. If I tell Claude Code to scaffold a web app from 0 outside of React it‘s terrible.

So no, imho people with no app dev skills cannot just build something over a weekend, at least something that won‘t break when the first user logs in.

CER10TY··on Things that helped me get out of the AI 10x engineer imposter syndrome
It‘s easier, since you don‘t have to stare at your monitor for 4 hours straight. But still, people expect availability since you‘re paid for 8 hours.
CER10TY··on Things that helped me get out of the AI 10x engineer imposter syndrome
That‘s corporate jobs for you. It‘s about appearance, not results. That‘s why you make a big deal out of everything you work on.
CER10TY··on Ask HN: Freelancer? Seeking freelancer? (July 2025)
SEEKING WORK | Germany | Fully Remote

I help startups implement secure API architectures through audits, strategy development, or ongoing support. As a solo consultant with 10 years of experience across startups to enterprise, you work directly with me (no junior handoffs). My goal is to enable your team to develop secure APIs independently, not create long-term dependency.

My website has more info: https://www.soeren.codes/

You'll find additional contact info there as well - feel free to reach out!

CER10TY··on xAI dev leaks API key for private SpaceX, Tesla LLMs
Just remember to go through your commit history if you ever plan on making that repo public.
CER10TY··on Ask HN: How to make money in the new age of AI?
With the new API for GPT-4o image gen releasing soon, we'll probably see a wave of hype products (ie "generate your own Studio Ghibli-style photo album"). I expect these will die down rather quick, but first mover advantage should still net you some profit here.
CER10TY··on Tax/legal checklist for a subscription and revenue sharing model?
Which country is your company based in? And which countries are you selling your services to?

Legal/tax things are always different in every country. B2C also makes things a lot more complicated. Overall, lots of sharp edges to look out for.

CER10TY··on Moving away from US cloud services
Would you recommend moving from Google Workspace to Proton? Including emails and so on.
CER10TY··on Moving away from US cloud services
What's a good alternative to Proton? Still haven't migrated my business away from Google Workspace, and I was thinking Proton would be a good alternative, but apparently not if they don't even support IMAP/SMTP.
Page 1 of 2Next →