953 karma · joined May 14, 2013
Socials:
- linkedin.com/in/christophe-hartwig-ba228a5
Interests: Cybersecurity, Entrepreneurship, DevOps, Digital Nomading
---
I'm adding pointers to specification documents, and it saves me from the /new dumb coding agent that sees your code base for the first time and knows nothing about architecture, concepts, code organisation, etc...
I'm using no cookie cutter directives though (except maybe "do not attempt to deploy, we're using CI CD to deploy" to avoid an automatic "wrangler deploy" to Cloudflare)
You can deploy it in minutes on your Cloudflare account.
- create an App in https://Pushover.net - click the Deploy on Cloudflare button on the Github Readme - configure the two Pushover secrets (User key and App token) in the form
Enjoy.
You could have asked me what reasonable use cases exist.
There are extremely valid use cases for anonymity in B2C, most likely none in B2B.
I respect your disgust, and I feel the same towards your entitlement and presumptions.
I'll fix the percentage, it's 0.01%.
When things are tagged "cybersecurity", compliance/budget/manager/dashboard/education/certification are the usual response...
I don't think it would be an appropriate response for code quality issues, and it would likely escape the hands of the very people who can fix code quality issues, ie. developers.
You can't have a government issue a Self-Sovereign identity to you, it's an oxymoron. They can only issue credentials. But then they'd feel like they're losing control, so they pervert it. Now they call it SSI but it's just digital credentials.
The very title says it all: German implementation of eIDAS will require Google or Apple ID. That's not self-sovereign identity.
And that's why I find it lame.
I'm not arguing against government ID, I'm saying identity doesn't have to be that piece of paper, or that Google ID.
Analogy: if google ID is your primary key in your User table, then you're cooked. Instead use a uuid for the PK, and add Google ID as just another id. But the identity is the PK.
A paper or certificate can prove an entity trusts your identity to be <firstname, lastname, etc...> but that shouldn't be your identity.
You just are. Not your google Id, not your Apple Id either of course.
Governments are lame.
As for wildcard certs, I agree there are use cases where we really need them like dynamic subdomains {customer}.status.com
Can you share how they make ACME client configuration easier?
It's not as convenient, but it's the best SSLBoard can do...
I was a kid in France, now I'm working remotely from Bangkok: dreams come true after all.
I intend to make it "too cheap to pass", because we should all be able to monitor Certificate Transparency.
Email me if you want to be a design partner!