HNHacker News
TopNewBestAskShowJobs

IvanGoncharov

284 karma · joined July 14, 2015

submissionscomments
IvanGoncharov··on I Inspected My Take-Home Interview Project. It Was a Whole Operation
I just checked my calendar, and it was a 45-minute interview scheduled on Calendly. HR person sent me a link to Calendly so I could schedule an interview with the CTO. I actually talked with someone pretending to be the CTO for 45 minutes.

I checked other similar threads on HN, but they don't mention an actual Google Meet call with a scammer.

IvanGoncharov··on I Inspected My Take-Home Interview Project. It Was a Whole Operation
Wow, after reading this article, I figured out I was hacked, but with a way more sophisticated attack.

A few weeks ago, I had an interview with a CTO of a totally legit company. It was weird because he had disabled the camera, and the person had a strong accent. But everything else sounded like a normal screening interview, and the person definitely knew what he was talking about. At the end of the interview, he explained to me that during the technical interview I would need to make some modifications to their project (it's an OSS product), so he asked me to clone the repo and check the setup.

Later, the HR person said the CTO got sick, so the interview would be postponed. But a few days later, the HR profile was deleted from LinkedIn. It was super weird, but it didn't trigger my suspicion until I saw this post on HackNews. I checked, and the repo I was cloning and running during the interview had a malware payload.

P.S. I think it was a targeted attack because in the past I maintained a very popular NPM package with 43+M weekly downloads. That's my only explanation for why someone would carry out such a sophisticated social-engineering attack against me.

P.P.S. It's great that I have 2FA everywhere, and I always publish NPM packages manually without using tokens. But I need to wipe my laptop and reinstall everything.

IvanGoncharov··on Show HN: ChatGPT App That Solves LLM Randomness Problem No One Talks About
Here is a link to an article we wrote: https://keenethics.com/blog/llm-randomness-problem It has way more details, but for some reason, I can't post it on HN.
IvanGoncharov··on Show HN: GraphQL Voyager – Represent Any GraphQL API as an Interactive Graph
After you click on "Custom Introspection" card you will see "Copy Introspection Query" link. Just click on it and query will be copied into the buffer.
IvanGoncharov··on Show HN: GraphQL Voyager – Represent Any GraphQL API as an Interactive Graph
Definitely yes, it would be great to see Voyager as a part of graph.cool. It's our first React+Redux app so we need a few days to do refactoring, more details here: https://github.com/APIs-guru/graphql-voyager#contribution

After that, we are happy to assist you with an integration. Feel free to contact us on GitHub or directly https://apis.guru/about/

IvanGoncharov··on Show HN: GraphQL Voyager – Represent Any GraphQL API as an Interactive Graph
Thank you for making your GraphQL API publicly accessible. Can you suggest a better name to be used in our demo?

BTW. We also included it in our list of public GraphQL APIs: https://github.com/APIs-guru/graphql-apis

IvanGoncharov··on Show HN: GraphQL Voyager – Represent Any GraphQL API as an Interactive Graph
Good catch! Just added the LICENSE file. https://github.com/APIs-guru/graphql-voyager/blob/master/LIC...
IvanGoncharov··on Show HN: GraphQL Voyager – Represent Any GraphQL API as an Interactive Graph
It was our initial goal but we decided to proceed with smaller steps and that's why we've released this MVP.
IvanGoncharov··on API Discovery: Can we do better?
It was a joke to make article easy to read.

> people using GraphQL[1] more these days

I fully agree. That's why we also maintain a list of GraphQL APIs: https://github.com/APIs-guru/graphql-apis

> solves the problem of API schema discovery because it's one endpoint with built-in introspection

You're absolutely right. We plan to do a few interesting projects around GraphQL. Subscribe to our blog to not miss announcements :)

IvanGoncharov··on API Discovery: Can we do better?
Hi,

I'm the author, and I definitely know about Swagger/OpenAPI. By coincidence, I'm maintainer of the collection of 250+ Swagger specs for public APIs: https://github.com/APIs-guru/openapi-directory

But I have learned the hard truth over last two years: API catalogs aren't scalable solutions for API discovery. That's why I'm pushing this.

P.S. it is pretty easy to generate Schema.org type based on Swagger/OpenAPI spec.

IvanGoncharov··on Why isn't your API specification public?
> The catch 22 here is that it is hard for people to innovate around API specifications when they are so hard to get!

Yes, this is exactly the problem which I try to solve with my collection.

> Per the SDKs ... what if there was a NPM.org or rubygems equivalent of high quality SDKs that get automatically generated whenever I push a new API specification?

You can run the same tool on API owner side you don't need to publish your spec for that. I did a couple of interviews with API owner and they fear to loose control over SDKs, Docs, etc.

> Curious if you are able to share how much work it is for you to get access to the specifications in order to make this possible?

No, it's public info since my entire work is open-sourced under MIT license. I try to make process automatic as much as possible, so it starts from scraping. For example, I scrape Github for Swagger specs: https://morph.io/IvanGoncharov/API_specifications When I need to filter test, example, etc. APIs and find specs for real-life APIs. But get spec source is just first step, I need to fix errors in it(~80% have them), get additional info(logo, link to API key registration, etc.). But most time consuming is update them every day. My update/convert/validation scripts not ideal so I need to manually inspect all changes.

> ould you have spent a lot more time on making cool integrations vs mining specs?

Actually not I learn a lot from it, for example, you can fix all mistakes in API owner specs. Instead, you should give them a tool which will automatically inspect API spec and output errors/warnings/recommendations/hints. Together with my friend we working on OpenAPI/Swagger linter.

If you want to discuss more here is my Skype(ivangon4arov) and Hangouts(ivan.goncharov.ua@gmail.com) or APIs.guru public chat https://gitter.im/APIs-guru/api-models

IvanGoncharov··on Why isn't your API specification public?
I think API owner need to see some value in publishing spec. And SDK generation, not a strong argument for publishing since it can be done on API owner side with more control and better quality.

IMHO key component here is automatic integration, you simply publish a link to your spec and you magically have integration with a number of 3rd-party tools/services.

I currently work on catalog which does exactly this, and you can see list of integrations here: https://github.com/APIs-guru/api-models#existing-integration...

IvanGoncharov··on Wikipedia for REST WEB APIs
Hi @gabamnml

I'm maintainer of this API collection: https://github.com/APIs-guru/api-models Thank you for sharing a word about my project.

One thing to note is http://apis-guru.github.io/ was created as proof of concept and example of what you can do with API to collection: https://github.com/APIs-guru/api-models/blob/master/API.md So it's more like side-project to API catalog.

Adding tags is tricky since it require a lot of manual work. Go through a documentation for all 200+ APIs and manually tag them. If someone decide to volunteer for this task I created issue on Github: https://github.com/APIs-guru/api-models/issues/54

Biggest upcoming feature is "Run in Postman" button: https://www.getpostman.com/docs/run_button_ux Spoke with guys from Postman and waiting for them to open up API to their Postman Cloud.

IvanGoncharov··on Show HN: AnyAPI – Over 100 High-Quality APIs
What about "REST API"?