Viewing profile — cddotdotslash
cddotdotslash
HN member- Joined
- Fri, Oct 12, 2012, 9:53 PM UTC
- HN karma
- 2,860
- Public activity
- 479 items
- HN profile
- View on Hacker News ↗
About cddotdotslash
Cloud security, tech startups, NYC.
EM, Cloud Security at Stripe. Previously: founder of CloudSploit (cloud security platform), acquired by Aqua Security in 2019.
Recent public activity
-
comment
Comment #46576535
They exist in a few forms: - The company is smaller and/or already geo-distributed and doesn't have the ability (or awareness) to monitor employee locations or deal with the tax/co…
-
comment
Comment #45597832
It’s incredibly annoying to read. So many super short sentences with the “not just X. Also Y” format. Little hooks like “The attack vector?” “Not fancy security tools. Not expensiv…
-
comment
Comment #45262019
I wonder who actually discovered this attack? Can we credit them? The phrasing in these posts is interesting, with some taking direct credit and others just acknowledging the incid…
-
comment
Comment #45172994
Nathan, do you work for Socket? I think you should at least disclose that when sharing posts here.
-
comment
Comment #45170804
NPM deserves some blame here, IMO. Countless third party intel feeds and security startups can apparently detect this malicious activity, yet NPM, the single source of truth for th…
-
comment
Comment #45105695
I can see the value, but to do the things you're describing, the AI needs to be given fairly highly-privileged credentials. > Right now, Datafruit receives read-only access to your…
-
comment
Comment #44962656
In China, nearly everything works via the same app (WeChat) and via QR code. Every grocery store, coffee shop, train station, or point of sale has the same scanner, where you can f…
-
comment
Comment #44877771
Companies should automate this. Write their own outage monitoring, feed the results, plus the cumbersome format you have to send to the provider, into an LLM, have it spit out an e…
-
comment
Comment #44704142
I'm still working on https://wut.dev/ - a simpler, privacy-focused, read-only AWS resource viewer. I did a "show Reddit" post a few weeks back and it got quite a bit of interest, s…
-
comment
Comment #44554968
https://github.com/OpenCut-app/OpenCut/issues/192 I don't know if this style of... discussion is something the Cluely team made popular recently, or if it took off sooner, but I re…
-
comment
Comment #44418678
Much appreciated! I just put this homepage together recently, so this is really helpful feedback.
-
comment
Comment #44418320
Wut.Dev ( https://wut.dev ) - a fast, client-side, privacy-focused, alternative to the AWS console. I got tired of using the AWS console for simple tasks, like looking up resource …
-
comment
Comment #44318823
This "AI will never replace _my_ job" attitude by security folks (and I say this as a security engineer myself) is insufferable. Yeah, there are likely lots of vulnerabilities gett…
-
comment
Comment #44281738
It’s interesting that multi-region is often touted as a mechanism for resilience and availability, but for the most part, large cloud providers seem hopelessly intertwined across r…
-
comment
Comment #44264843
I can recall plenty of times HN has been down.
-
comment
Comment #44101037
Wut.Dev - a "better" AWS console ( https://app.wut.dev ) I got tired of using the AWS console (the UI is inconsistent across services, resource-heavy, and loaded with things I don'…
-
comment
Comment #44051807
I wish X would allow you to mute lists of people. I keep a list for insufferable VCs, and it would be nice to mute the whole list at once. Maybe a feature request for your extensio…
-
comment
Comment #43387727
I bought this book immediately after the last post here on HN about it. Good read so far!
-
comment
Comment #42437469
I haven’t been a fan of the UI for a while, although admittedly it’s a tough job - there’s a lot to cram in there! I started building a simpler alternative, where everything is jus…
-
comment
Comment #41714571
Oh, that's neat! I've found it to be really flexible, although some of the really nice features are (understandably) locked behind the expensive "Pro" version (like right-click con…
-
comment
Comment #41691174
Thankfully programmatic. It’s a common UI table widget, essentially, and I’ve written some custom code to handle multi-region support, updating the AWS credential handler, paginati…
-
comment
Comment #41690837
I've been working on https://wut.dev in my spare time. It's essentially a simpler, read-only, AWS dashboard where everything is a filterable, searchable, exportable-to-CSV table, w…
-
comment
Comment #41676905
> There were more geoblocks when the EU law went into action a couple of years ago. There are less now. Source for that?
-
comment
Comment #41672570
Expect to see more of this, especially when the audience is local/US. IIRC, some newspapers are already doing region blocks. Why should website owners targeting US visitors spend _…
-
comment
Comment #41506835
Based on "GetMetricData", you're not paying for services, but rather something with access to your account is making API requests to CloudWatch. Do you have any third-party monitor…