I checked other similar threads on HN, but they don't mention an actual Google Meet call with a scammer.
284 karma · joined July 14, 2015
I checked other similar threads on HN, but they don't mention an actual Google Meet call with a scammer.
A few weeks ago, I had an interview with a CTO of a totally legit company. It was weird because he had disabled the camera, and the person had a strong accent. But everything else sounded like a normal screening interview, and the person definitely knew what he was talking about. At the end of the interview, he explained to me that during the technical interview I would need to make some modifications to their project (it's an OSS product), so he asked me to clone the repo and check the setup.
Later, the HR person said the CTO got sick, so the interview would be postponed. But a few days later, the HR profile was deleted from LinkedIn. It was super weird, but it didn't trigger my suspicion until I saw this post on HackNews. I checked, and the repo I was cloning and running during the interview had a malware payload.
P.S. I think it was a targeted attack because in the past I maintained a very popular NPM package with 43+M weekly downloads. That's my only explanation for why someone would carry out such a sophisticated social-engineering attack against me.
P.P.S. It's great that I have 2FA everywhere, and I always publish NPM packages manually without using tokens. But I need to wipe my laptop and reinstall everything.
After that, we are happy to assist you with an integration. Feel free to contact us on GitHub or directly https://apis.guru/about/
BTW. We also included it in our list of public GraphQL APIs: https://github.com/APIs-guru/graphql-apis
> people using GraphQL[1] more these days
I fully agree. That's why we also maintain a list of GraphQL APIs: https://github.com/APIs-guru/graphql-apis
> solves the problem of API schema discovery because it's one endpoint with built-in introspection
You're absolutely right. We plan to do a few interesting projects around GraphQL. Subscribe to our blog to not miss announcements :)
I'm the author, and I definitely know about Swagger/OpenAPI. By coincidence, I'm maintainer of the collection of 250+ Swagger specs for public APIs: https://github.com/APIs-guru/openapi-directory
But I have learned the hard truth over last two years: API catalogs aren't scalable solutions for API discovery. That's why I'm pushing this.
P.S. it is pretty easy to generate Schema.org type based on Swagger/OpenAPI spec.
Yes, this is exactly the problem which I try to solve with my collection.
> Per the SDKs ... what if there was a NPM.org or rubygems equivalent of high quality SDKs that get automatically generated whenever I push a new API specification?
You can run the same tool on API owner side you don't need to publish your spec for that. I did a couple of interviews with API owner and they fear to loose control over SDKs, Docs, etc.
> Curious if you are able to share how much work it is for you to get access to the specifications in order to make this possible?
No, it's public info since my entire work is open-sourced under MIT license. I try to make process automatic as much as possible, so it starts from scraping. For example, I scrape Github for Swagger specs: https://morph.io/IvanGoncharov/API_specifications When I need to filter test, example, etc. APIs and find specs for real-life APIs. But get spec source is just first step, I need to fix errors in it(~80% have them), get additional info(logo, link to API key registration, etc.). But most time consuming is update them every day. My update/convert/validation scripts not ideal so I need to manually inspect all changes.
> ould you have spent a lot more time on making cool integrations vs mining specs?
Actually not I learn a lot from it, for example, you can fix all mistakes in API owner specs. Instead, you should give them a tool which will automatically inspect API spec and output errors/warnings/recommendations/hints. Together with my friend we working on OpenAPI/Swagger linter.
If you want to discuss more here is my Skype(ivangon4arov) and Hangouts(ivan.goncharov.ua@gmail.com) or APIs.guru public chat https://gitter.im/APIs-guru/api-models
IMHO key component here is automatic integration, you simply publish a link to your spec and you magically have integration with a number of 3rd-party tools/services.
I currently work on catalog which does exactly this, and you can see list of integrations here: https://github.com/APIs-guru/api-models#existing-integration...
I'm maintainer of this API collection: https://github.com/APIs-guru/api-models Thank you for sharing a word about my project.
One thing to note is http://apis-guru.github.io/ was created as proof of concept and example of what you can do with API to collection: https://github.com/APIs-guru/api-models/blob/master/API.md So it's more like side-project to API catalog.
Adding tags is tricky since it require a lot of manual work. Go through a documentation for all 200+ APIs and manually tag them. If someone decide to volunteer for this task I created issue on Github: https://github.com/APIs-guru/api-models/issues/54
Biggest upcoming feature is "Run in Postman" button: https://www.getpostman.com/docs/run_button_ux Spoke with guys from Postman and waiting for them to open up API to their Postman Cloud.