<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: ebfe1</title><link>https://news.ycombinator.com/user?id=ebfe1</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 10 Oct 2026 05:14:47 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=ebfe1" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by ebfe1 in "Incident with Github.com"]]></title><description><![CDATA[
<p>It's DNS issue, i'm telling ya!</p>
]]></description><pubDate>Mon, 17 Aug 2026 14:06:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=49331203</link><dc:creator>ebfe1</dc:creator><comments>https://news.ycombinator.com/item?id=49331203</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49331203</guid></item><item><title><![CDATA[Show HN: Yes, I vibed coded something But not sure what to do with it]]></title><description><![CDATA[
<p>A friend passed away last year from cancer and I wanted to make a simple app to help delivering her message to love ones but work and responsibilities got in the way before I could finish it. Fast forward to a few weekends ago, I picked it up again, this time, I fully vibed coded it and tell it to build the way I wanted to and try to make it as cheap to run as possible.<p>Now it is up... It can send messages, it can let you record messages/voice, video... It encrypts messages in the browser with personalised key and it let you even set a password to further protect the message (unrecoverable if you forget it as password never send back to my server).<p>Well... I did it, I have an app after a few days and I want to make it free/pay as you want for people to send messages/voice, video to love ones beyond the grave but now I have no idea if it would be practical for me to host it and who would even trust a random person's vibe coded app on internet... And how can I keep it running even after I die lol ... What do you think? Any advice?</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=48218743">https://news.ycombinator.com/item?id=48218743</a></p>
<p>Points: 2</p>
<p># Comments: 2</p>
]]></description><pubDate>Thu, 21 May 2026 06:40:13 +0000</pubDate><link>https://trustenvelope.com/</link><dc:creator>ebfe1</dc:creator><comments>https://news.ycombinator.com/item?id=48218743</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48218743</guid></item><item><title><![CDATA[New comment by ebfe1 in "Ask HN: Do you use your phone as hotel/free WiFi condom for laptops?"]]></title><description><![CDATA[
<p>I will look into that, thanks for the recommendation!</p>
]]></description><pubDate>Thu, 27 Nov 2025 09:52:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=46067594</link><dc:creator>ebfe1</dc:creator><comments>https://news.ycombinator.com/item?id=46067594</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46067594</guid></item><item><title><![CDATA[New comment by ebfe1 in "Ask HN: Do you use your phone as hotel/free WiFi condom for laptops?"]]></title><description><![CDATA[
<p>TIL! Thank you!</p>
]]></description><pubDate>Thu, 27 Nov 2025 09:51:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=46067591</link><dc:creator>ebfe1</dc:creator><comments>https://news.ycombinator.com/item?id=46067591</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46067591</guid></item><item><title><![CDATA[Ask HN: Do you use your phone as hotel/free WiFi condom for laptops?]]></title><description><![CDATA[
<p>While we try our best to lock down our laptop, close open ports, run littlesnitch, ufw but it is always an unease to connect them directly to an public wifi, worrying about some 0day that allow someone in local lan to hack it.<p>What I sometimes do is to use my phone connecting to the free wifi and simultaneously hotspotting it to my laptop - It feels better to have something in between blocking random nmap scans.<p>Anyone else doing this? Is there other tricks you do?</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46065362">https://news.ycombinator.com/item?id=46065362</a></p>
<p>Points: 4</p>
<p># Comments: 5</p>
]]></description><pubDate>Thu, 27 Nov 2025 03:45:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=46065362</link><dc:creator>ebfe1</dc:creator><comments>https://news.ycombinator.com/item?id=46065362</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46065362</guid></item><item><title><![CDATA[New comment by ebfe1 in "Shai-Hulud malware attack: Tinycolor and over 40 NPM packages compromised"]]></title><description><![CDATA[
<p>Anyone know if there is a public events feed/firehouse for npm ecosystem system? Similar to GitHub public events feed?<p>We, at ClickHouse, love big data and it would be super cool download and analyse patterns of all these data & provide some tooling to help with combatting this wide spread issue.</p>
]]></description><pubDate>Tue, 16 Sep 2025 17:28:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=45265188</link><dc:creator>ebfe1</dc:creator><comments>https://news.ycombinator.com/item?id=45265188</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45265188</guid></item><item><title><![CDATA[New comment by ebfe1 in "S1ngularity/nx attackers strike again"]]></title><description><![CDATA[
<p>I found there are many links from stepsecuritiy, socket.dev but aikido seems to have the most up to date information about this ongoing npm hack.</p>
]]></description><pubDate>Tue, 16 Sep 2025 14:48:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=45263056</link><dc:creator>ebfe1</dc:creator><comments>https://news.ycombinator.com/item?id=45263056</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45263056</guid></item><item><title><![CDATA[S1ngularity/nx attackers strike again]]></title><description><![CDATA[
<p>Article URL: <a href="https://www.aikido.dev/blog/s1ngularity-nx-attackers-strike-again">https://www.aikido.dev/blog/s1ngularity-nx-attackers-strike-again</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=45263055">https://news.ycombinator.com/item?id=45263055</a></p>
<p>Points: 1</p>
<p># Comments: 1</p>
]]></description><pubDate>Tue, 16 Sep 2025 14:48:15 +0000</pubDate><link>https://www.aikido.dev/blog/s1ngularity-nx-attackers-strike-again</link><dc:creator>ebfe1</dc:creator><comments>https://news.ycombinator.com/item?id=45263055</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45263055</guid></item><item><title><![CDATA[New comment by ebfe1 in "DuckDB NPM packages 1.3.3 and 1.29.2 compromised with malware"]]></title><description><![CDATA[
<p>Is it just me who think this could have been prevented if npm admins put in some sort of cool off period to only allow new versions or packages to be downloaded after being published by "x" amount of hours? This way the npm maintainer would get notifications on their email and react immediately? And if it is urgent fix, perhaps there can be a process to allow npm admin to approve and bypass publication cool off period.<p>Disclaimer: I don't know enough of npm/nodejs community so I might be completely off the mark here</p>
]]></description><pubDate>Tue, 09 Sep 2025 11:54:16 +0000</pubDate><link>https://news.ycombinator.com/item?id=45180683</link><dc:creator>ebfe1</dc:creator><comments>https://news.ycombinator.com/item?id=45180683</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45180683</guid></item><item><title><![CDATA[New comment by ebfe1 in "Show HN: PinSend – Share text between devices using a PIN(P2P, no login)"]]></title><description><![CDATA[
<p>I don't see mentioning of e2e encryption, that would be nice but I love the webrtc usage here!<p>Shameless plug: I built small file sharing tool with encryption in browser and added a "tunnel" feature to make it easier for sharing between personal devices : <a href="https://www.relaysecret.com/tunnel/" rel="nofollow">https://www.relaysecret.com/tunnel/</a><p>The aes256 key is derived from hashing the tunnel name but never sent back to backend as it is behind anchor tag and the tunnel name is derived from substring of this hash. It is quite fun to use and share files. The file never lives more than 10 days (bucket lifecycle) but user can reduce this to delete upon download and the code can easily be reviewed (back end is a single lambda function to generate signed url):)</p>
]]></description><pubDate>Tue, 03 Jun 2025 23:58:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=44176012</link><dc:creator>ebfe1</dc:creator><comments>https://news.ycombinator.com/item?id=44176012</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44176012</guid></item><item><title><![CDATA[New comment by ebfe1 in "Texas secures $1.38B settlement with Google over data privacy"]]></title><description><![CDATA[
<p>Honest question: So who gets this $1.38B? The user? Some company? The government/treasury?</p>
]]></description><pubDate>Sat, 10 May 2025 04:35:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=43943265</link><dc:creator>ebfe1</dc:creator><comments>https://news.ycombinator.com/item?id=43943265</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43943265</guid></item><item><title><![CDATA[New comment by ebfe1 in "How to harden GitHub Actions"]]></title><description><![CDATA[
<p>Yea hence it prompts for you to check the first time but once you verify the hash for particular version of action, it would automatically apply the hash to that same version of action everywhere. Also you can reuse the same config for all other repos so it is only tedious the first time but after that it is pretty quick to apply to the rest of the org :)<p>The tool is indeed meant for semi-auto flow to ensure human eye looked at the action being used.</p>
]]></description><pubDate>Fri, 09 May 2025 14:10:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=43936975</link><dc:creator>ebfe1</dc:creator><comments>https://news.ycombinator.com/item?id=43936975</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43936975</guid></item><item><title><![CDATA[New comment by ebfe1 in "How to harden GitHub Actions"]]></title><description><![CDATA[
<p>Yeap - that is exactly what it does ;)<p>Example:<p>uses: ncipollo/release-action@440c8c1cb0ed28b9f43e4d1d670870f059653174 #v1.16.0<p>And for anything that previously had @master, it becomes the following with the hash on the day it was pinned with "master-{date}" as comment:<p>uses: ravsamhq/notify-slack-action@b69ef6dd56ba780991d8d48b61d94682c5b92d45 #master-2025-04-04</p>
]]></description><pubDate>Fri, 09 May 2025 02:45:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=43933364</link><dc:creator>ebfe1</dc:creator><comments>https://news.ycombinator.com/item?id=43933364</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43933364</guid></item><item><title><![CDATA[New comment by ebfe1 in "How to harden GitHub Actions"]]></title><description><![CDATA[
<p>oh damn - that is a great point! thanks matey!</p>
]]></description><pubDate>Fri, 09 May 2025 02:27:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=43933283</link><dc:creator>ebfe1</dc:creator><comments>https://news.ycombinator.com/item?id=43933283</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43933283</guid></item><item><title><![CDATA[New comment by ebfe1 in "How to harden GitHub Actions"]]></title><description><![CDATA[
<p>After tj-actions hack, I put together a little tool to go through all of github actions in repository to replace them with commit hash of the version<p><a href="https://github.com/santrancisco/pmw">https://github.com/santrancisco/pmw</a><p>It has a few "features" which allowed me to go through a repository quickly:<p>- It prompts user and recommend the hash, it also provides user the url to the current tag/action to double check the hash value matches and review the code if needed<p>- Once you accept a change, it will keep that in a json file so future exact vesion of the action will be pinned as well and won't be reprompted.<p>- It let you also ignore version tag for github actions coming from well-known, reputational organisation (like "actions" belong to github) - as you may want to keep updating them so you receive hotfix if something not backward compatible or security fixes.<p>This way i have full control of what to pin and what not and then this config file is stored in .github folder so i can go back, rerun it again and repin everything.</p>
]]></description><pubDate>Thu, 08 May 2025 14:29:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=43926389</link><dc:creator>ebfe1</dc:creator><comments>https://news.ycombinator.com/item?id=43926389</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43926389</guid></item><item><title><![CDATA[New comment by ebfe1 in "Jury orders NSO to pay $167M for hacking WhatsApp users"]]></title><description><![CDATA[
<p>Ok ....where is the form so as an ex-whatsapp user, I can get a piece of that 167M pie? Oh... there isnt one... :)</p>
]]></description><pubDate>Wed, 07 May 2025 07:10:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=43912999</link><dc:creator>ebfe1</dc:creator><comments>https://news.ycombinator.com/item?id=43912999</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43912999</guid></item><item><title><![CDATA[New comment by ebfe1 in "Judge said Meta illegally used books to build its AI"]]></title><description><![CDATA[
<p>And this is how Chinese model will win in long term, perhaps... They will be trained on everything and anything without consequences and we will all use it because these models are smarter (except for area like Chinese history and geography). I don't have the right answer on what can be done here to protect copyright or rather contributing back to authors of a paper without all these millions dollar wasted in lawsuits.</p>
]]></description><pubDate>Mon, 05 May 2025 15:10:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=43895945</link><dc:creator>ebfe1</dc:creator><comments>https://news.ycombinator.com/item?id=43895945</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43895945</guid></item><item><title><![CDATA[New comment by ebfe1 in "On Not Carrying a Camera – Cultivating memories instead of snapshots"]]></title><description><![CDATA[
<p>Like any tech nerds, I went through "camera phase" and carried canon 350d, 50d then 6d everywhere i go with my 50mm and 135mm ... but they were indeed bulky, it was a hassle to get people to pose for photos while i run 100m back so my 135mm can capture them perfectly... i couldn't enjoy the moment, i was that "camera friend" that would fly around everyone like fly, capturing them doing things and feeling proud that i got a good photo for them... But coming back from these trips, i realized i didnt spend enough time strolling the street with friends,  talking about life, enjoying the moment so i stopped... especially now with kids.<p>If only people are not so against camera recording them, i think a rayban meta idea would have been cool but it needs to constantly recording like those car dash cam and when you just shared a perfect funny moment, you can immediately hit save to preserve that moment for later. So many times i wished i recorded the moment my childrens do things or being funny but it was too late.<p>I love taking photo with phone still and when my wife dress in her favourite coat and the setting is right, i would go back to being the "camera dude" using my best framing technique i learnt to capture the moment, at least the experience from those years did not go to waste.<p>Last but not least, one of the best purchase i ever done was the insta link wide bluetooth printer... it let me print, sign the date and gift my friends who visit something to take home and put on their fridge to remember the time we spent together.</p>
]]></description><pubDate>Mon, 05 May 2025 09:19:06 +0000</pubDate><link>https://news.ycombinator.com/item?id=43893203</link><dc:creator>ebfe1</dc:creator><comments>https://news.ycombinator.com/item?id=43893203</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43893203</guid></item><item><title><![CDATA[New comment by ebfe1 in "Everyone knows your location, Part 2: try it yourself and share the results"]]></title><description><![CDATA[
<p>Not exactly related but on the topic of finding target's location, A few years ago i used to run a little demo of capturing probe wifi ssid network on prefered network list of nearby devices and used <a href="https://wigle.net/" rel="nofollow">https://wigle.net/</a> to identify places that people has visited... it was eye opening for some people in the audience for sure.</p>
]]></description><pubDate>Sun, 20 Apr 2025 01:16:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=43740821</link><dc:creator>ebfe1</dc:creator><comments>https://news.ycombinator.com/item?id=43740821</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43740821</guid></item><item><title><![CDATA[Show HN: Pin My Workflow]]></title><description><![CDATA[
<p>Last friday i went through a bunch of our workflows and started pinning their hashes... it got annoying so i created a little app to assist, it is quite simple, you can add a list of workflow org you are ok with version tags (if you want to keep them up-to-date) , as the app search through the repo and find dubious workflow, it will prompt and let you know what hash it is updating it to and link for you to verify... if you accept, it add to config and automatically replace the ones that matches the same version tag in the future, saving you time. The config can be saved in same repository so you can rerun anytime.</p>
<hr>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=43606843">https://news.ycombinator.com/item?id=43606843</a></p>
<p>Points: 2</p>
<p># Comments: 0</p>
]]></description><pubDate>Mon, 07 Apr 2025 02:04:54 +0000</pubDate><link>https://github.com/santrancisco/pmw</link><dc:creator>ebfe1</dc:creator><comments>https://news.ycombinator.com/item?id=43606843</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43606843</guid></item></channel></rss>