HNHacker News
TopNewBestAskShowJobs

cddotdotslash

2,860 karma · joined October 12, 2012

Building https://wut.dev (a simpler AWS dashboard where everything's a table).

Cloud security, tech startups, NYC.

EM, Cloud Security at Stripe. Previously: founder of CloudSploit (cloud security platform), acquired by Aqua Security in 2019.

submissionscomments
cddotdotslash··on How to search Remote-from-Anywhere jobs
They exist in a few forms:

- The company is smaller and/or already geo-distributed and doesn't have the ability (or awareness) to monitor employee locations or deal with the tax/compliance obligations and so turns a blind eye, intentionally or not. The employees are generally operating in a grey area - either on tourist visas or for a company that isn't registered to employee people in their locale.

- The company actively creates a remote-first environment, working with their employees to employ them (compliantly) in their locale, usually through a third-party employer of record. These are very few and far between, but they exist.

- Companies, like Airbnb, that allow for a certain amount of time outside of a "home locale" per year (IIRC, it's 90 days). This isn't truly "global remote" but employees can move around more freely than in-office or locale-only employers.

cddotdotslash··on I almost got hacked by a 'job interview'
It’s incredibly annoying to read. So many super short sentences with the “not just X. Also Y” format. Little hooks like “The attack vector?”

“Not fancy security tools. Not expensive antivirus software. Just asking my coding assistant…”

I actually feel like AI articles are becoming easier to spot. Maybe we’re all just collectively noticing the patterns.

cddotdotslash··on Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised
I wonder who actually discovered this attack? Can we credit them? The phrasing in these posts is interesting, with some taking direct credit and others just acknowledging the incident.

Aikido says: > We were alerted to a large-scale attack against npm...

Socket says: > Socket.dev found compromised various CrowdStrike npm packages...

Ox says: > Attackers slipped malicious code into new releases...

Safety says: > The Safety research team has identified an attack on the NPM ecosystem...

Phoenix says: > Another supply chain and NPM maintainer compromised...

Semgrep says: > We are aware of a number of compromised npm packages

cddotdotslash··on NPM debug and chalk packages compromised
Nathan, do you work for Socket? I think you should at least disclose that when sharing posts here.
cddotdotslash··on NPM debug and chalk packages compromised
NPM deserves some blame here, IMO. Countless third party intel feeds and security startups can apparently detect this malicious activity, yet NPM, the single source of truth for these packages, with access to literally every data event and security signal, can't seem to stop falling victim to this type of attack? It's practically willful ignorance at this point.
cddotdotslash··on Launch HN: Datafruit (YC S25) – AI for DevOps
I can see the value, but to do the things you're describing, the AI needs to be given fairly highly-privileged credentials.

> Right now, Datafruit receives read-only access to your infrastructure

> "Grant @User write access to analytics S3 bucket for 24 hours" > -> Creates temporary IAM role, sends least-privilege credentials, auto-revokes tomorrow

These statements directly conflict with one another.

So it needs "iam:CreateRole," "iam:AttachPolicy," and other similar permissions. Those are not "read-only." And, they make it effectively admin in the account.

What safeguards are in place to make sure it doesn't delete other roles, or make production-impacting changes?

cddotdotslash··on What services or apps did you see abroad and wonder: why don't we have them?
In China, nearly everything works via the same app (WeChat) and via QR code. Every grocery store, coffee shop, train station, or point of sale has the same scanner, where you can flash your QR code. I don't think I saw a single physical currency exchanged in the entire 6 weeks I was there.

I keep hearing that X wants to be the "everything" app. WeChat is _already_ the everything app. It's DoorDash, Venmo, Facebook, Instagram, and about 500 other apps in one.

I will say that I disliked the pattern of every restaurant using a WeChat "mini app" where it basically loads an entirely new app within WeChat just to see the menu or order. It felt much clunkier than just using a web page.

cddotdotslash··on GitHub was having issues
Companies should automate this. Write their own outage monitoring, feed the results, plus the cumbersome format you have to send to the provider, into an LLM, have it spit out an email requesting SLA credits or whatever the contract specifies.

Probably not worth it for low cost services, but if you’re paying GitHub $x millions per year, maybe it is.

cddotdotslash··on Ask HN: What are you working on? (July 2025)
I'm still working on https://wut.dev/ - a simpler, privacy-focused, read-only AWS resource viewer. I did a "show Reddit" post a few weeks back and it got quite a bit of interest, so doubling down with actual user feedback now.
cddotdotslash··on OpenCut: The open-source CapCut alternative
https://github.com/OpenCut-app/OpenCut/issues/192

I don't know if this style of... discussion is something the Cluely team made popular recently, or if it took off sooner, but I really hope it doesn't catch on further.

cddotdotslash··on Ask HN: What Are You Working On? (June 2025)
Much appreciated! I just put this homepage together recently, so this is really helpful feedback.
cddotdotslash··on Ask HN: What Are You Working On? (June 2025)
Wut.Dev (https://wut.dev) - a fast, client-side, privacy-focused, alternative to the AWS console.

I got tired of using the AWS console for simple tasks, like looking up resource details, so I built a fast, privacy-focused, no-signup-required, read-only, multi-region, auto-paginating alternative using the client-side AWS JavaScript SDKs where every page has a consistent UI/UX and resources are displayed as a searchable, filterable table with one-click CSV exports. You can try a demo here[1]

[1] https://app.wut.dev/?service=acm&type=certificates&demo=true

cddotdotslash··on Base44 sells to Wix for $80M cash
This "AI will never replace _my_ job" attitude by security folks (and I say this as a security engineer myself) is insufferable. Yeah, there are likely lots of vulnerabilities getting vibe coded into apps right now. But AI is improving rapidly, and in a few years you'll likely look back wondering what happened to the job market. Adapt or don't, I suppose.
cddotdotslash··on Google Cloud Incident Report – 2025-06-13
It’s interesting that multi-region is often touted as a mechanism for resilience and availability, but for the most part, large cloud providers seem hopelessly intertwined across regions during outages like these.
cddotdotslash··on GCP Outage
I can recall plenty of times HN has been down.
cddotdotslash··on Ask HN: What are you working on? (May 2025)
Wut.Dev - a "better" AWS console (https://app.wut.dev)

I got tired of using the AWS console (the UI is inconsistent across services, resource-heavy, and loaded with things I don't need)

I've built a handful of features, mostly to scratch my own itch, including:

• Multi-region mode (select 2+ regions and see all your resources on the same page)

• Automated diagrams (tree-style resource relationships)

• Easy export to CSV

• Reference matrix of AWS service/region availability

The best way to explain it is with a demo, so I built a demo version: https://app.wut.dev/?service=acm&type=certificates&demo=true

cddotdotslash··on Show HN: Keep track of why you muted someone on X
I wish X would allow you to mute lists of people. I keep a list for insufferable VCs, and it would be nice to mute the whole list at once.

Maybe a feature request for your extension: take a list and mute everyone on it, and periodically check for new additions and mute those too. That way I can have the list be the source of truth, rather than commenting on every person I mute individually.

cddotdotslash··on Meta puts stop on promotion of tell-all book by former employee
I bought this book immediately after the last post here on HN about it. Good read so far!
cddotdotslash··on Ask HN: Am I the only one who hates the new AWS UI?
I haven’t been a fan of the UI for a while, although admittedly it’s a tough job - there’s a lot to cram in there! I started building a simpler alternative, where everything is just a simple, sortable, exportable table (details in profile). It’s been fun to build, but the sheer number of services has been a slog.
cddotdotslash··on Ask HN: What are you working on (September 2024)?
Oh, that's neat! I've found it to be really flexible, although some of the really nice features are (understandably) locked behind the expensive "Pro" version (like right-click context menus, etc.). Will check out your examples!
cddotdotslash··on Ask HN: What are you working on (September 2024)?
Thankfully programmatic. It’s a common UI table widget, essentially, and I’ve written some custom code to handle multi-region support, updating the AWS credential handler, pagination, and response processing. From there, it’s a matter of plugging in some common options for each AWS service: the service name, SDK method to call, pagination property (annoyingly, AWS API has numerous ways of paginating responses), etc. Takes about five minutes to add a new service.
cddotdotslash··on Ask HN: What are you working on (September 2024)?
I've been working on https://wut.dev in my spare time.

It's essentially a simpler, read-only, AWS dashboard where everything is a filterable, searchable, exportable-to-CSV table, with some extra features like multi-region mode, saved notes, and a debugger for access denied errors.

It uses the AWS SDK for JavaScript, so everything is run client-side from your browser. I'm not 100% sure what direction I'm taking it yet, but it's been fun to hack on!

There's a live demo here: https://wut.dev/?service=ec2&type=instances&demo=true if you want to try it out.

cddotdotslash··on MTA Open Data Challenge
> There were more geoblocks when the EU law went into action a couple of years ago. There are less now.

Source for that?

cddotdotslash··on MTA Open Data Challenge
Expect to see more of this, especially when the audience is local/US. IIRC, some newspapers are already doing region blocks. Why should website owners targeting US visitors spend _any_ amount of money making their content comply with asinine regulations (like cookie banners)?
cddotdotslash··on Ask HN: AWS CloudWatch Fraud?
Based on "GetMetricData", you're not paying for services, but rather something with access to your account is making API requests to CloudWatch. Do you have any third-party monitoring tools (Splunk, Datadog, etc.) in use? Can you check your IAM portal to see if you have any users/roles with recent access?
cddotdotslash··on Rush hour isn't what it used to be. 10-4 is the new 9-5, commuting data shows
This is why I like to go in at 9, and leave at 5, to avoid the rush.
cddotdotslash··on Ask HN: What are you working on (August 2024)?
Oh that’s so nice to hear! It’s quite an early alpha, but I’ve working to expand support for more resource types and details. Feedback is very welcomed.
cddotdotslash··on Ask HN: Who's building an AI-free product?
I’ve been working on https://console.wut.dev as an alternative, simpler AWS console. Given that AWS has recently started embedding Q (their AI tool) into their UI, I’ll likely keep Wut AI-free.

That being said, there are a few features I’ve been thinking of where AI could theoretically make sense (like summarizing recent changes to cloud resources from CloudTrail logs) but if I build that, I’m going to focus on the feature/use case and not try to just “jam AI into it.”

cddotdotslash··on Ask HN: What are you working on (August 2024)?
I've been working on https://console.wut.dev/

Right now it's a collection of a few tools:

• AWS Resource Explorer - a lighter-weight version of the AWS console where everything is just a sortable/filterable/searchable table.

• Access Denied Debugger - paste an "AccessDenied" message and get back a stack-trace style UI showing all the resources involved, reason for the error (e.g., which policy is missing a permission), recent changes via CloudTrail, etc.

• AWS Organizations / SCP Viewer - generates a tree-diagram style UI showing all your AWS accounts, which policies apply to them, etc.

Still working on merging these into a cohesive application (mostly just been scratching my own itches so far). I'm trying to consider privacy/security carefully, so everything is client-side, using the AWS JavaScript SDK, and creds/data are only stored locally.

cddotdotslash··on Ask HN: What Are You Working On? (August 2024)
I’ve been working on a tool for managing AWS Organizations, SCPs, and IAM policies. At the moment it’s more a collection of scratch-my-own-itch features (interactive tree view for accounts, access denied debugger, and a few tools related to seeing how SCPs are inherited through the OU structure). Hosting it at wut.dev if this sounds interesting to you.

One neat thing (although makes it more challenging to build) is that I’m using the AWS JS SDK to do everything client side. So the whole app is basically a single HTML/JS page with no API, creds are only stored locally, etc.

Page 1 of 16Next →