HNHacker News
TopNewBestAskShowJobs

cvince

4 karma · joined June 3, 2012

submissionscomments
cvince··on Show HN: ClickBench Playground – a playground for 110 database systems
Really cool idea. Skimmed the writeup, but none of this is emulated???
cvince··on Show HN: Capy – A Git-style platform for managing your team's secrets
Absolutely. Doppler custodies the credentials entirely themselves, and Infisical ditched zero-trust earlier on citing complexity and UX concerns - IMO they just didn't try hard enough ;)

I also decided to embrace .env because that's how humans (and apparently agents -- for now) like to work when building stuff. Except Capy is the only solution I know of that allows you to cryptographically revoke access to those .env files in real time.

Regarding the MCP, watch this space: https://www.capy.sc/

cvince··on Show HN: Capy – A Git-style platform for managing your team's secrets
I'd say the two biggest things are Portability, and Ergonomics.

For portability your secrets in those platforms can't move around with you, but with Capy they can move with you wherever you're doing your work. Your local machine, your sandbox, etc.

Capy also helps you deploy your secrets into Coder, Claude, Copilot and whatever other Clever product you prefer to use ;)

For ergonomics, Capy is built from the ground up as a CLI, which means it's extremely flexible in where you want to use it. I'm also working currently on making it work SUPER well in agentic coding workflows. There's going to be more on that coming soon!

cvince··on Show HN: Modern Browsers Don't Need the Cookie Anymore
This is such a clever technical demo. Do you work for Posthog? LOL
cvince··on Show HN: Capy – A Git-style platform for managing your team's secrets
I love this question, because it's something I've been thinking about a lot for the next evolution of this product. My solution, currently, is that the CLI provides all the guardrails.

All the security and logical primitives are enforced via the CLI's command layout, similar to how it is done with git, and the human is still in the loop for the most critical stuff like initial onboarding, saving secrets, resolving conflicts, running deployments, and performing rotations.

I do eventually want to find safe ways for agents to take over those tasks, and there is a lot to learn from how software factory agents currently work with git. The thing is, even with software factories, the VERSION CONTROL gates are also usually still defined by humans (when to commit, merge, deploy, etc.). Whatever it is, the same level of automation ought to exist for secrets and configuration.

To that end, I have an upcoming MCP that acts as a wrapper for orchestrating sequences of Capy CLI commands (but never the contents of them). In the preliminary MCP implementation there's nothing the agent is actually able to interpret, besides maybe identifying variable names, what the stack looks like, and what services the application likely uses.

cvince··on Show HN: Agents keep running with the lid closed
https://compyl.com/blog/soc-2-software-timeout-requirements/

See CC6.2 Creation and Removal of User Credentials and CC6.6 External Protections, but if you don't work in a regulated environment, world's your oyster!

cvince··on Show HN: Diffing Binary Files
Great showcase for what your company does!
cvince··on Show HN: Capy – A Git-style platform for managing your team's secrets
Thanks! Try it out and let me know what you think!
cvince··on Show HN: Capy – A Git-style platform for managing your team's secrets
On the crypto side, the values are encrypted client-side before they’re sent. This means the service stores ciphertext it has no ability to decrypt. So the worst case for a backend compromise is someone getting encrypted blobs plus some metadata.

On the controls side, SAST scanning in CI, and minimizing deps as much as possible in the client and the service.

cvince··on Tl;Dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
People really dont take this stuff seriously enough, but my experience with Firestore (circa ~2014) was that it was too "easy" with a lot of stuff.

Not sure how to describe this, but it's almost like the product gives you the false impression that you're done setting it up when there's still things like security rules that you need to learn and know about.

cvince··on Show HN: Capy – A Git-style platform for managing your team's secrets
Capy uses a split-key encryption model, meaning secrets are encrypted client-side before reaching our servers—so the backend never sees or stores raw plaintext keys. The design is also pretty unique in that it can be used to cryptographically revoke local secrets remotely.

You can read more about it here: https://www.capy.sc/docs/internals/zero-trust

In addition, the company is right around the corner on our SOC2 Type I audit. It should be available within the next week!

https://trust.capy.sc/

cvince··on A tier list of secrets managers, after using all of them
Full disclosure, I am making a secrets management product myself, but thought this market research might be of interest to y'all.

My question would be where you think this space is moving next? I have my own hypotheses but before sharing I'd love to hear your thoughts!

cvince··on Why I'm still building a SaaS company in 2026
I think your insight is spot on. We're already starting to see the shift towards "hard/deep tech". My observation is that investors are scrambling away from pure software plays and LLM wrappers, and more towards foundational tech or infrastructure.

IMO that's still "tech moat" thinking. The real moat nowadays is GTM traction, and "creativity/taste". All software can be copied, but the creation of new concepts/solutions and trends, is still uniquely something that requires a deep understanding of the "WHYs" and "HOWs" as I've described in my writing.

cvince··on On Rendering Diffs
Of course you can. It doesn't replace the dom, just changes how it's calculated. https://chenglou.me/pretext/dynamic-layout/
cvince··on On Rendering Diffs
I think it's amazing how deep you can go in something as simple as rendering diffs, and I'm really grateful you shared that writeup (in fact I've been following you loosely since the Kiip days as a then aspiring designer+developer type).

I've always been curious how products like ag-grid are able to allow you to lazy-load 10,000,000+ rows in a table without the blanking you described, and I imagine this type of method describes how it can be done.

cvince··on On Rendering Diffs
Whatever happened to all the pretext hype? I feel like that would be perfect for rendering huge diffs.