258 karma · joined December 27, 2019
We, at ClickHouse, love big data and it would be super cool download and analyse patterns of all these data & provide some tooling to help with combatting this wide spread issue.
Disclaimer: I don't know enough of npm/nodejs community so I might be completely off the mark here
Shameless plug: I built small file sharing tool with encryption in browser and added a "tunnel" feature to make it easier for sharing between personal devices : https://www.relaysecret.com/tunnel/
The aes256 key is derived from hashing the tunnel name but never sent back to backend as it is behind anchor tag and the tunnel name is derived from substring of this hash. It is quite fun to use and share files. The file never lives more than 10 days (bucket lifecycle) but user can reduce this to delete upon download and the code can easily be reviewed (back end is a single lambda function to generate signed url):)
The tool is indeed meant for semi-auto flow to ensure human eye looked at the action being used.
Example:
uses: ncipollo/release-action@440c8c1cb0ed28b9f43e4d1d670870f059653174 #v1.16.0
And for anything that previously had @master, it becomes the following with the hash on the day it was pinned with "master-{date}" as comment:
uses: ravsamhq/notify-slack-action@b69ef6dd56ba780991d8d48b61d94682c5b92d45 #master-2025-04-04
https://github.com/santrancisco/pmw
It has a few "features" which allowed me to go through a repository quickly:
- It prompts user and recommend the hash, it also provides user the url to the current tag/action to double check the hash value matches and review the code if needed
- Once you accept a change, it will keep that in a json file so future exact vesion of the action will be pinned as well and won't be reprompted.
- It let you also ignore version tag for github actions coming from well-known, reputational organisation (like "actions" belong to github) - as you may want to keep updating them so you receive hotfix if something not backward compatible or security fixes.
This way i have full control of what to pin and what not and then this config file is stored in .github folder so i can go back, rerun it again and repin everything.
If only people are not so against camera recording them, i think a rayban meta idea would have been cool but it needs to constantly recording like those car dash cam and when you just shared a perfect funny moment, you can immediately hit save to preserve that moment for later. So many times i wished i recorded the moment my childrens do things or being funny but it was too late.
I love taking photo with phone still and when my wife dress in her favourite coat and the setting is right, i would go back to being the "camera dude" using my best framing technique i learnt to capture the moment, at least the experience from those years did not go to waste.
Last but not least, one of the best purchase i ever done was the insta link wide bluetooth printer... it let me print, sign the date and gift my friends who visit something to take home and put on their fridge to remember the time we spent together.
https://play.clickhouse.com/play?user=play#c2VsZWN0ICogZnJvb...
https://play.clickhouse.com/play?user=play#c2VsZWN0ICogZnJvb...
Actions taken by the threat actor at the time can be seen here:
https://play.clickhouse.com/play?user=play#c2VsZWN0ICogZnJvb...
Also no 3rd party JS, no tracking etc..
This was my half day covid project to share file... inspired by firefoxsend a while back...
the infra is super lightweight and you can deploy yourself with aws account, it costed me nothing to run and quite useful when needed :)
- Password authentication (bcrypt, sha256 hashes) - Certificate authentication (Fantastic for server to server communication) - SSH key authentication (Personally, this is my favourite - every database should have this authentication mechanism to make it easy for Dev to work with)
Not very popular but LDAP and Http Authentication Server are also great options.
I also wonder how DeepSeek engineers deployed their ClickHouse instance. When I deployed using yum/apt install, the installation step literally ask you to input a default password.
And if you were to set it up manually with ClickHouse binary, the out-of-the-box config seal the instance from external network access and the default user is only exposed to localhost as explained by Alex here - https://news.ycombinator.com/item?id=42871371#42873446.
https://clickhouse.com/blog/building-a-logging-platform-with...
(Full disclosure: I work for ClickHouse and love it here!)
well guess what? it bypasses even your "Require approval for all outside collaborators" flag in your repo setting and trigger it on your self-hosted runner anyway...
This was brought up in recent BlackHat24:
https://github.com/AdnaneKhan/ConferenceTalks/blob/main/Blac...
And yes - it's another "Github won't fix"
There were 18 accounts involved - 14 of them are now deleted/deactivated and 4 of them are still active(may have been compromised account)
It seems github did take action and these comments are disappearing :)
Example of what this user JiaT75 did so far:
https://play.clickhouse.com/play?user=play#U0VMRUNUICogRlJPT...
pull requests mentioning xz, 5.6 without downgrade, cve being mentioned in the last 60 days:
https://play.clickhouse.com/play?user=play#U0VMRUNUIGNyZWF0Z...