HNHacker News
TopNewBestAskShowJobs

pop3zxcv

3 karma · joined August 3, 2026

submissionscomments
pop3zxcv··on Five Indie Platforms You Might Not Have Heard Of
All of them look interesting, especially the web 1.0 hosting, remind me of old days!, Thanks for sharing.
pop3zxcv··on JWT decoder with connect-src 'none', so it can't upload your token
I kept pasting production JWTs into random online decoders and then immediately regretting it. Most of them are client side, but you can't tell that by looking, and "trust me" isn't a security property.

So I built one where you don't have to.

The page sets Content-Security-Policy: connect-src 'none'. The browser then refuses every fetch, XHR, WebSocket and beacon the page could try. Keys go into WebCrypto with extractable: false, so the page can't read them back after import. And there's a Playwright test asserting zero outbound requests while decoding, verifying and signing. It runs on every deploy.

Two things worth mentioning before someone else finds them.

CSP doesn't block navigation. A malicious build could still leak a token via window.location, so this isn't a sandbox. What connect-src 'none' kills is every quiet channel, which is the part I actually cared about.

And Cloudflare injects its own analytics beacon into pages it serves, so you'll see a failed request to static.cloudflareinsights.com in the network tab with a CSP violation in the console. The policy stops it running. Rather point at it than have you spot it and wonder what else is in there.

If you want to check any of it: https://jamuny.com/verify/ walks through the network panel, reading the CSP, and just pulling your wifi and carrying on working.

Same idea behind 18 other text tools (JSON formatter, regex tester, diff, CSV to JSON, hashes, UUIDs): https://jamuny.com

Astro, no UI framework, fonts self hosted since loading Google Fonts would defeat the point somewhat. All static HTML, works with JS off.

Interested to hear where I've got the CSP wrong.

pop3zxcv··on Apple says more ex-employees may have taken confidential data to OpenAI
Does it matter? As long as the data is in the 1st brain and can be taken outside and used as a skill.
pop3zxcv··on How Cursor sets up their cloud agent environment
An interesting post!.
pop3zxcv··on Show HN: Do Codex skills save tokens? A six-run task-size benchmark
This depends; some really help in structuring the work, and some save a small amount of tokens.
pop3zxcv··on The AI Productivity Gap
I find myself in the same situation, baby sitting AI agent, monitoring them. It's like l've become a coordinator.
pop3zxcv··on Don't be a meat proxy
We're seeing this everywhere now, people generating thousands of lines of documentation or PR feedback in seconds, then dumping the actual labor of verification onto their teammates.