384 karma · joined February 13, 2012
Same for sops.
> The equivalent in vercel would be encrypted in the database (the encrypted '.env' file), with a decryption key in the backend
The encrypted .env file is actually committed to source code, and the decryption key is placed in Vercel's environment variables dashboard. The attacker only gained access to the latter here if using dotenvx so they can't get your secrets. Unless they also gained access to the codebase in which they have terabytes of data to go through and match up private keys from the database with encrypted .env files from the source code exfiltration - much more effort for attackers.
There is no silver bullet, but Dotenvx splits your secrets into two separate locations.
1. The private decryption key - which lives on Vercel in this example 2. The encrypted .env file which lives in your source code pushed to Vercel
Attackers only got access to the first (as far as I know was reported). So your secrets would be safe in this attack if using Dotenvx. (A private key is useless without its corresponding encrypted .env file. Attackers need both.)
The whitepaper goes into the problem and solution in more detail: https://dotenvx.com/whitepaper.pdf
to prevent this, use:
$ dotenvx ext precommit --install
Inertia. This is everything. It takes effort to be around people unlike those currently around you.
We all have personal biases against the strata economically above us and below us. I think most of the individuals that move up economically are able to get beyond these biases for one reason or another. Otherwise, even the most hardworking individuals tend to self-sabotage when they start to feel out of place.
Anyone have one and like it? Or recommend a different dumb phone?
2. Start building. It will attract people. Don't go out and find them.
I was personally interested in HCQ before Trump ever tweeted it - turning it political. It was looking promising and still does.
After further personal study, I would like the conversation to continue.
[1] https://energycommerce.house.gov/sites/democrats.energycomme...
Email would only be allowed into my inbox if it was signed. Then, layer 2, it would only allow signed emails from senders whom I've accepted their public key.
A separate tab would show me all incoming request to accepts public keys (request to send email)
Now to opt-in to a marketing email I first accept their public key. To opt-out I delete their public key. Their email now goes to /dev/null.
Senders wouldn't have to re-implement unsub/subscribe, spammers would be /dev/nulled, and we could later add encryption on top of signing as a requirement.
Tangentially related, iOS mail app has a VIP setting.
Have you used Stripe as well? Authorize.net always got the job done. Then Stripe came along. I was honestly surprised of its success at the time. It was mainly just more of a joy to use - not cheaper or much easier. Just 'fun' as I remember it.
I'm not making HTTP requests here, but, to your point, I am mutating the document at that url.
Maybe the protocol would somehow store the diff between those 2 documents somewhere. There could be an organization, similarly structured to ICANN, that stored and surfaced those diffs long term to users.
4. Every document is version controlled
That way, as Daniel puts it, "[the document] will not magically alter its contents tomorrow". Or if it does, I can see a history of what was altered. Ideally, this would somehow be built into the protocol/browser rather than be a burden to the publisher.
Also, maybe after a certain amount of time I can no longer modify my document. If I'm the New York Times, this means when I publish a news article document, and it contains an advertisement, that same advertisement forever lives on that document - just like physical newspaper.
Great concept.
CPU, bandwidth, electricity, it's all just energy. And to a significant degree, money is just energy stored. I generate energy with my own work, store it in the form of money, and then transfer that energy to someone else, maybe to heat my home or cook me a meal.
Before money, I had to barter for those things. Maybe conceptually the internet is in a similar state at the moment. It doesn't have 'money'. Why can't I put CPUs in my wallet and then spend them? And why can't I charge visitors to my site by the CPUs they are costing me?
Instead, I have to, in a way, barter. For example, maybe I use ad revenue to earn my income, so I generate all this content, I barter that to the search engines, which barter with the advertisers, which barter with me, and I barter back to security guards to protect me from 'bad' actor bots. I'd really just like to receive CPU and bandwidth payments from them.
I've found it very good at letting me quickly transfer my system ideas to paper. It gets out of the way and works with quick keystrokes.
But it breaks down when trying to use it for presentation. It is too difficult to show and hide different states of the system when presenting to others. It's slow changing between each state by showing and hiding different nodes.
I'm looking forward to trying your tool for this reason. I just wish it was a local program.
What a wonderful mental model. Thank you for that phrasing.
My tendency, and I think most people's tendency around me, is to discuss stress in terms of how to limit it.
Taking it on changes my relationship to it (at least in my mind). Taking it on, gives me control over it.
Location: Los Angeles
Remote: ok
Willing to relocate: no
Technologies: Ruby, Rails, NodeJS and much more
Résumé/CV: http://www.scottmotte.com/assets/resume.pdf
Email: scott@scottmotte.com
Your cross-functional engineer. $150/hr.If you need a way to accept donations worldwide - without a merchant account and without the donor even needing a credit card or bank account - it might be worth a look.