HNHacker News
TopNewBestAskShowJobs

gmalette

37 karma · joined November 2, 2013

submissionscomments
gmalette··on Think your dog can understand words? This scientist says you might be right
Look into Bunny the sheepadoodle https://www.instagram.com/whataboutbunny?igsh=cHNtZTk0Y3dsND.... She makes consistent phrases like “look look outside squirrel” or “dad upstairs poop”.
gmalette··on A free, unlimited online PDF converter with Privacy focus
Really nice! PDF editing is super underserved relative to its usage IRL, it’s always great to see new tools.

My partner needed one that has total data residency (can’t upload it) so I ended up building one as an app. It doesn’t have half the features of QuicklyPDF tho.

https://github.com/gmalette/pdf-rancher

gmalette··on Hurl, a terrible (but cute) idea for a language
A few years back I wrote a language called “exceptional” based on some shared ideas. Hurl is super neat and you took things further than I did.

https://github.com/exceptional-lang/exceptional

gmalette··on Why Ruby Is More Readable Than Python
I saw you closed my ticket on sorbet for generics + sealed + exhaustiveness, that’ll allow some very welcome code cleanup!
gmalette··on Why Ruby Is More Readable Than Python
Depends who accessed it first ;)
gmalette··on Why Ruby Is More Readable Than Python
That’s without even mentioning the footguns available in @@count

Jez!

gmalette··on Jepsen: Radix DLT 1.0-Beta.35.1
I live outside the United States and have never seen mm mean anything other than millimeter
gmalette··on Show HN: My SSH server knows who you are
> If I push a repo to Heroku that includes submodules, presumably Heroku then fetches those submodules

You're missing the point. You may use submodules hosted on github with Heroku, but you don't use Heroku to host that repo. You're not going to `git submodule add git@heroku.com:project`. So for the sake of argument, if we pretend that git repo hosts do need to use `git@`, I don't see a single reason why Heroku would.

> And if you're going to suggest that it should only consult users who have access to the repo, for a public project that's everybody, which makes it functionally identical to git@

Now you're confusing two things. Do you want to clone a public module as a subrepo, or allow commit access? Public repos can be cloned without identification. If you want commit access, why would project-level not work?

> Sure it does. IdentityFile is explicitly allowed to be specified multiple times for a single host, and the files will be tried in turn

Again, missing the point. If you don't specify a different host, you'll always be identified and authenticated as the first key that matches, therefore you'll only use a single account. That's why you have to use different hosts.

> And no, your own anecdotes do not constitute proof that providers often have to deal with this.

If you're not going to believe anything I say, I got nothing. Otherwise, 2 things

- I opened an issue and the response was basically "Ooooo that explains some of those tickets". They specifically mentioned issues with vagrant. - I presented this at a local meetup and someone else had put themselves in this position.

> Your work is handing out a shared public/private keypair and encouraging people to set this up as a default identity in SSH?

No. As I said, it was meant to setup the vagrant box and then not be used. By default vagrant connects using an insecure keypair.

gmalette··on Show HN: My SSH server knows who you are
> and it's easily solved by a small SSH config change on their end

The article does mention it. The issue is not fixing the problem, it's actually finding it.

> [...] that URL wouldn't work for anyone else, which breaks git-submodules, breaks any kind of config file that specifies repositories (e.g. for use by a CI server)

It doesn't explain why Heroku uses it. Do you really push different submodules to Heroku?

For Github et. al, that's easily solved by project-level or organization-level identity.

> that URL wouldn't work for anyone else

And using `git@` doesn't work if you use multiple accounts because you'd specify the IdentityFile by host.

> nobody really cares because it's never going to happen accidentally

Except it does. Those service providers often get contacted because this happens BY ACCIDENT.

I've done it to myself by adding my public key to my work account. I couldn't access my personal stuff without changing my SSH config.

A while ago at work, we were using a shared key that was used to setup the initial vagrant config. New hires often added that key to their github or heroku account.

I've heard similar stories elsewhere too.

gmalette··on Show HN: My SSH server knows who you are
I'm not arguing they're not, but that they shouldn't be used as a means of identification
gmalette··on Show HN: My SSH server knows who you are
Or simply to DOS you out of your other accounts. https://news.ycombinator.com/item?id=10005358
gmalette··on Show HN: My SSH server knows who you are
You may be interested in knowing that you can DOS someone if you know only their public keys. https://medium.com/@gmalette/mistaking-authentication-for-id...