Hacker Newsnew | past | comments | ask | show | jobs | submit | magackame's commentslogin

It seems only encrypt and throw away the key would be the acceptable strategy


They need to give your app the environment variables later so they cannot throw away the key.

For non-sensitive environment variables, they also show you the value in the dashboard so you can check and edit them later.

Things like 'NODE_ENV=production' vs 'NODE_ENV=development' is probably something the user wants to see, so that's another argument for letting the backend decrypt and display those values even ignoring the "running your app" part.

You're welcome to add an input that goes straight to '/dev/null' if you want, but it's not exactly a useful feature.


> You're welcome to add an input that goes straight to '/dev/null' if you want, but it's not exactly a useful feature.

Piping to /dev/null is of course pointless.

What you really want is the /dev/null as a Service Enterprise plan for $500/month with its High Availability devnull Cluster ;)

https://devnull-as-a-service.com/pricing/


Then you might aswell write them to /dev/null. Safer, has the same effect and faster.


Also gotta love the write-only disk as a hardware analogy. Insane write speeds and infinite capacity...


Huh? But there are integrity checks (none in htmx case, which is strange), to prevent exactly this attack.


I'm not sure I follow. How does an integrity check help when the source is compromised? The developer doesn't know that their repo is compromised. They continue posting legitimate hashes because the repo is legitimately compromised.


Should work on building the AI Jensen. Maybe it's already the AI Jensen


Cancel right away? Or are Amazon subs different?


Noooo. Makes me wonder how much money do you need to buy up all the ad slots in the world and replace them with blanks.


So much money that only running your mega ad operation would allow you to cover the costs.


If it's known why show it off as if it works?


Why hide it?


Don't people do this too all the time?


:shush:


AI bad, AI bad, AI bad. bad bad bad, AI-bad.


I didn't see any complaints about any kind of artificial intelligence, research or otherwise, besides large language models, in this article.

Large language models are a single kind of AI, and a particularly annoying kind when you are forced to use them for deterministic or fact seeking tasks

or did you read the article? you're probably an LLM. why am I here? fuck this website


True but LLMs are all that are being sold right now. Mainly because people think they are intelligent because they're basically bullshit artist simulators.

I don't think the future of AI is with LLMs either. Not only LLMs anyway.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: