<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: cddotdotslash</title><link>https://news.ycombinator.com/user?id=cddotdotslash</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Wed, 29 Apr 2026 20:30:33 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=cddotdotslash" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by cddotdotslash in "How to search Remote-from-Anywhere jobs"]]></title><description><![CDATA[
<p>They exist in a few forms:<p>- The company is smaller and/or already geo-distributed and doesn't have the ability (or awareness) to monitor employee locations or deal with the tax/compliance obligations and so turns a blind eye, intentionally or not. The employees are generally operating in a grey area - either on tourist visas or for a company that isn't registered to employee people in their locale.<p>- The company actively creates a remote-first environment, working with their employees to employ them (compliantly) in their locale, usually through a third-party employer of record. These are very few and far between, but they exist.<p>- Companies, like Airbnb, that allow for a certain amount of time outside of a "home locale" per year (IIRC, it's 90 days). This isn't truly "global remote" but employees can move around more freely than in-office or locale-only employers.</p>
]]></description><pubDate>Sun, 11 Jan 2026 15:28:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=46576535</link><dc:creator>cddotdotslash</dc:creator><comments>https://news.ycombinator.com/item?id=46576535</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46576535</guid></item><item><title><![CDATA[New comment by cddotdotslash in "I almost got hacked by a 'job interview'"]]></title><description><![CDATA[
<p>It’s incredibly annoying to read. So many super short sentences with the “not just X. Also Y” format. Little hooks like “The attack vector?”<p>“Not fancy security tools. Not expensive antivirus software. Just asking my coding assistant…”<p>I actually feel like AI articles are becoming easier to spot. Maybe we’re all just collectively noticing the patterns.</p>
]]></description><pubDate>Wed, 15 Oct 2025 20:15:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=45597832</link><dc:creator>cddotdotslash</dc:creator><comments>https://news.ycombinator.com/item?id=45597832</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45597832</guid></item><item><title><![CDATA[New comment by cddotdotslash in "Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised"]]></title><description><![CDATA[
<p>I wonder who actually discovered this attack? Can we credit them? The phrasing in these posts is interesting, with some taking direct credit and others just acknowledging the incident.<p>Aikido says:
> We were alerted to a large-scale attack against npm...<p>Socket says:
> Socket.dev found compromised various CrowdStrike npm packages...<p>Ox says:
> Attackers slipped malicious code into new releases...<p>Safety says:
> The Safety research team has identified an attack on the NPM ecosystem...<p>Phoenix says:
> Another supply chain and NPM maintainer compromised...<p>Semgrep says:
> We are aware of a number of compromised npm packages</p>
]]></description><pubDate>Tue, 16 Sep 2025 13:31:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=45262019</link><dc:creator>cddotdotslash</dc:creator><comments>https://news.ycombinator.com/item?id=45262019</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45262019</guid></item><item><title><![CDATA[New comment by cddotdotslash in "NPM debug and chalk packages compromised"]]></title><description><![CDATA[
<p>Nathan, do you work for Socket? I think you should at least disclose that when sharing posts here.</p>
]]></description><pubDate>Mon, 08 Sep 2025 19:44:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=45172994</link><dc:creator>cddotdotslash</dc:creator><comments>https://news.ycombinator.com/item?id=45172994</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45172994</guid></item><item><title><![CDATA[New comment by cddotdotslash in "NPM debug and chalk packages compromised"]]></title><description><![CDATA[
<p>NPM deserves some blame here, IMO. Countless third party intel feeds and security startups can apparently detect this malicious activity, yet NPM, the single source of truth for these packages, with access to literally every data event and security signal, can't seem to stop falling victim to this type of attack? It's practically willful ignorance at this point.</p>
]]></description><pubDate>Mon, 08 Sep 2025 17:05:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=45170804</link><dc:creator>cddotdotslash</dc:creator><comments>https://news.ycombinator.com/item?id=45170804</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45170804</guid></item><item><title><![CDATA[New comment by cddotdotslash in "Launch HN: Datafruit (YC S25) – AI for DevOps"]]></title><description><![CDATA[
<p>I can see the value, but to do the things you're describing, the AI needs to be given fairly highly-privileged credentials.<p>> Right now, Datafruit receives read-only access to your infrastructure<p>> "Grant @User write access to analytics S3 bucket for 24 hours"
>    -> Creates temporary IAM role, sends least-privilege credentials, auto-revokes tomorrow<p>These statements directly conflict with one another.<p>So it needs "iam:CreateRole," "iam:AttachPolicy," and other similar permissions. Those are not "read-only." And, they make it effectively admin in the account.<p>What safeguards are in place to make sure it doesn't delete other roles, or make production-impacting changes?</p>
]]></description><pubDate>Tue, 02 Sep 2025 16:52:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=45105695</link><dc:creator>cddotdotslash</dc:creator><comments>https://news.ycombinator.com/item?id=45105695</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45105695</guid></item><item><title><![CDATA[New comment by cddotdotslash in "What services or apps did you see abroad and wonder: why don't we have them?"]]></title><description><![CDATA[
<p>In China, nearly everything works via the same app (WeChat) and via QR code. Every grocery store, coffee shop, train station, or point of sale has the same scanner, where you can flash your QR code. I don't think I saw a single physical currency exchanged in the entire 6 weeks I was there.<p>I keep hearing that X wants to be the "everything" app. WeChat is _already_ the everything app. It's DoorDash, Venmo, Facebook, Instagram, and about 500 other apps in one.<p>I will say that I disliked the pattern of every restaurant using a WeChat "mini app" where it basically loads an entirely new app within WeChat just to see the menu or order. It felt much clunkier than just using a web page.</p>
]]></description><pubDate>Wed, 20 Aug 2025 15:11:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=44962656</link><dc:creator>cddotdotslash</dc:creator><comments>https://news.ycombinator.com/item?id=44962656</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44962656</guid></item><item><title><![CDATA[New comment by cddotdotslash in "GitHub was having issues"]]></title><description><![CDATA[
<p>Companies should automate this. Write their own outage monitoring, feed the results, plus the cumbersome format you have to send to the provider, into an LLM, have it spit out an email requesting SLA credits or whatever the contract specifies.<p>Probably not worth it for low cost services, but if you’re paying GitHub $x millions per year, maybe it is.</p>
]]></description><pubDate>Tue, 12 Aug 2025 15:42:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=44877771</link><dc:creator>cddotdotslash</dc:creator><comments>https://news.ycombinator.com/item?id=44877771</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44877771</guid></item><item><title><![CDATA[New comment by cddotdotslash in "Ask HN: What are you working on? (July 2025)"]]></title><description><![CDATA[
<p>I'm still working on <a href="https://wut.dev/" rel="nofollow">https://wut.dev/</a> - a simpler, privacy-focused, read-only AWS resource viewer. I did a "show Reddit" post a few weeks back and it got quite a bit of interest, so doubling down with actual user feedback now.</p>
]]></description><pubDate>Sun, 27 Jul 2025 19:56:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=44704142</link><dc:creator>cddotdotslash</dc:creator><comments>https://news.ycombinator.com/item?id=44704142</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44704142</guid></item><item><title><![CDATA[New comment by cddotdotslash in "OpenCut: The open-source CapCut alternative"]]></title><description><![CDATA[
<p><a href="https://github.com/OpenCut-app/OpenCut/issues/192">https://github.com/OpenCut-app/OpenCut/issues/192</a><p>I don't know if this style of... discussion is something the Cluely team made popular recently, or if it took off sooner, but I really hope it doesn't catch on further.</p>
]]></description><pubDate>Mon, 14 Jul 2025 00:03:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=44554968</link><dc:creator>cddotdotslash</dc:creator><comments>https://news.ycombinator.com/item?id=44554968</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44554968</guid></item><item><title><![CDATA[New comment by cddotdotslash in "Ask HN: What Are You Working On? (June 2025)"]]></title><description><![CDATA[
<p>Much appreciated! I just put this homepage together recently, so this is really helpful feedback.</p>
]]></description><pubDate>Mon, 30 Jun 2025 02:33:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=44418678</link><dc:creator>cddotdotslash</dc:creator><comments>https://news.ycombinator.com/item?id=44418678</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44418678</guid></item><item><title><![CDATA[New comment by cddotdotslash in "Ask HN: What Are You Working On? (June 2025)"]]></title><description><![CDATA[
<p>Wut.Dev (<a href="https://wut.dev" rel="nofollow">https://wut.dev</a>) - a fast, client-side, privacy-focused, alternative to the AWS console.<p>I got tired of using the AWS console for simple tasks, like looking up resource details, so I built a fast, privacy-focused, no-signup-required, read-only, multi-region, auto-paginating alternative using the client-side AWS JavaScript SDKs where every page has a consistent UI/UX and resources are displayed as a searchable, filterable table with one-click CSV exports. You can try a demo here[1]<p>[1] <a href="https://app.wut.dev/?service=acm&type=certificates&demo=true" rel="nofollow">https://app.wut.dev/?service=acm&type=certificates&demo=true</a></p>
]]></description><pubDate>Mon, 30 Jun 2025 01:34:41 +0000</pubDate><link>https://news.ycombinator.com/item?id=44418320</link><dc:creator>cddotdotslash</dc:creator><comments>https://news.ycombinator.com/item?id=44418320</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44418320</guid></item><item><title><![CDATA[New comment by cddotdotslash in "Base44 sells to Wix for $80M cash"]]></title><description><![CDATA[
<p>This "AI will never replace _my_ job" attitude by security folks (and I say this as a security engineer myself) is insufferable. Yeah, there are likely lots of vulnerabilities getting vibe coded into apps right now. But AI is improving rapidly, and in a few years you'll likely look back wondering what happened to the job market. Adapt or don't, I suppose.</p>
]]></description><pubDate>Thu, 19 Jun 2025 14:08:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=44318823</link><dc:creator>cddotdotslash</dc:creator><comments>https://news.ycombinator.com/item?id=44318823</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44318823</guid></item><item><title><![CDATA[New comment by cddotdotslash in "Google Cloud Incident Report – 2025-06-13"]]></title><description><![CDATA[
<p>It’s interesting that multi-region is often touted as a mechanism for resilience and availability, but for the most part, large cloud providers seem hopelessly intertwined across regions during outages like these.</p>
]]></description><pubDate>Sun, 15 Jun 2025 11:22:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=44281738</link><dc:creator>cddotdotslash</dc:creator><comments>https://news.ycombinator.com/item?id=44281738</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44281738</guid></item><item><title><![CDATA[New comment by cddotdotslash in "GCP Outage"]]></title><description><![CDATA[
<p>I can recall plenty of times HN has been down.</p>
]]></description><pubDate>Fri, 13 Jun 2025 01:17:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=44264843</link><dc:creator>cddotdotslash</dc:creator><comments>https://news.ycombinator.com/item?id=44264843</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44264843</guid></item><item><title><![CDATA[New comment by cddotdotslash in "Ask HN: What are you working on? (May 2025)"]]></title><description><![CDATA[
<p>Wut.Dev - a "better" AWS console (<a href="https://app.wut.dev" rel="nofollow">https://app.wut.dev</a>)<p>I got tired of using the AWS console (the UI is inconsistent across services, resource-heavy, and loaded with things I don't need)<p>I've built a handful of features, mostly to scratch my own itch, including:<p>• Multi-region mode (select 2+ regions and see all your resources on the same page)<p>• Automated diagrams (tree-style resource relationships)<p>• Easy export to CSV<p>• Reference matrix of AWS service/region availability<p>The best way to explain it is with a demo, so I built a demo version: <a href="https://app.wut.dev/?service=acm&type=certificates&demo=true" rel="nofollow">https://app.wut.dev/?service=acm&type=certificates&demo=true</a></p>
]]></description><pubDate>Mon, 26 May 2025 19:53:18 +0000</pubDate><link>https://news.ycombinator.com/item?id=44101037</link><dc:creator>cddotdotslash</dc:creator><comments>https://news.ycombinator.com/item?id=44101037</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44101037</guid></item><item><title><![CDATA[New comment by cddotdotslash in "Show HN: Keep track of why you muted someone on X"]]></title><description><![CDATA[
<p>I wish X would allow you to mute lists of people. I keep a list for insufferable VCs, and it would be nice to mute the whole list at once.<p>Maybe a feature request for your extension: take a list and mute everyone on it, and periodically check for new additions and mute those too. That way I can have the list be the source of truth, rather than commenting on every person I mute individually.</p>
]]></description><pubDate>Wed, 21 May 2025 14:27:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=44051807</link><dc:creator>cddotdotslash</dc:creator><comments>https://news.ycombinator.com/item?id=44051807</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44051807</guid></item><item><title><![CDATA[New comment by cddotdotslash in "Meta puts stop on promotion of tell-all book by former employee"]]></title><description><![CDATA[
<p>I bought this book immediately after the last post here on HN about it. Good read so far!</p>
]]></description><pubDate>Mon, 17 Mar 2025 12:23:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=43387727</link><dc:creator>cddotdotslash</dc:creator><comments>https://news.ycombinator.com/item?id=43387727</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43387727</guid></item><item><title><![CDATA[New comment by cddotdotslash in "Ask HN: Am I the only one who hates the new AWS UI?"]]></title><description><![CDATA[
<p>I haven’t been a fan of the UI for a while, although admittedly it’s a tough job - there’s a lot to cram in there! I started building a simpler alternative, where everything is just a simple, sortable, exportable table (details in profile). It’s been fun to build, but the sheer number of services has been a slog.</p>
]]></description><pubDate>Tue, 17 Dec 2024 01:33:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=42437469</link><dc:creator>cddotdotslash</dc:creator><comments>https://news.ycombinator.com/item?id=42437469</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42437469</guid></item><item><title><![CDATA[New comment by cddotdotslash in "Ask HN: What are you working on (September 2024)?"]]></title><description><![CDATA[
<p>Oh, that's neat! I've found it to be really flexible, although some of the really nice features are (understandably) locked behind the expensive "Pro" version (like right-click context menus, etc.). Will check out your examples!</p>
]]></description><pubDate>Tue, 01 Oct 2024 21:45:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=41714571</link><dc:creator>cddotdotslash</dc:creator><comments>https://news.ycombinator.com/item?id=41714571</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=41714571</guid></item></channel></rss>