Show HN: Laptop is the last place your secrets are still in plaintext
41–50 of 93 posts
Re: Show HN: Laptop is the last place your secrets are still in plaintext
#42Earlier quoted context omitted.
You're not downloading from github, but from dl.jitpass.com. And an executable can do exactly the same as a shell script. The point is that whatever you're executing isn't verified, whether it's a shell script or a binary.
The difference is you have the executable for examination (at least a quick virus scan) before you run it. Certanly not perfect, but what is?
Re: Show HN: Laptop is the last place your secrets are still in plaintext
#43Re: Show HN: Laptop is the last place your secrets are still in plaintext
#44The install procedure, for something that's supposed to be a security product: curl -sL https://dl.jitpass.com/jitpass/jit/releases/latest/download/jitpass_darwin_arm64.tar.gz | tar -xz jit sudo mv jit /usr/local/bin/ What could possibly go wrong?
Re: Show HN: Laptop is the last place your secrets are still in plaintext
#45Snake oil claude slop. No other words for it. If someone or something is executing code on your machine, you have already lost. Making it _slightly harder_ for it to eventually get your passwords anyway is mostly a performative action. __ Btw, enable "showdead" and enjoy OP actually pasting LLM output verbatim as a "defense". - https://news.ycombinator.com/item?id=49317802 - https://news.ycombinator.com/item?id=49317…
Re: Show HN: Laptop is the last place your secrets are still in plaintext
#46Re: Show HN: Laptop is the last place your secrets are still in plaintext
#47Snake oil claude slop. No other words for it. If someone or something is executing code on your machine, you have already lost. Making it _slightly harder_ for it to eventually get your passwords anyway is mostly a performative action. __ Btw, enable "showdead" and enjoy OP actually pasting LLM output verbatim as a "defense". - https://news.ycombinator.com/item?id=49317802 - https://news.ycombinator.com/item?id=49317…
Hypfer, I am a security leader at the age of 42 with more than 15 years of experience in the field, and I will tell you the truth: I lead a lot of cyber incidents. The purpose of this tool is to help you and companies protect yourselves from supply chain attacks and infiltrators for free no cost, no need for expensive 1Password tools. I put my heart into this tool, so give it a try and contact me directly if you need…
Can you just.. not?
The intended purpose of the tool is perfectly clear. There was never any confusion about it.
Re: Show HN: Laptop is the last place your secrets are still in plaintext
#48Earlier quoted context omitted.
If only there was a Markdown file in the repo, that explains it. It could have a URL, say, https://github.com/jitpass/jit/blob/main/docs%2Fgetting-star...
Please avoid the snark. I read the readme in full, I think that's an appropriate level of effort. Your link also still doesn't answer it, though it hints: 'A migrated .env is a live mount (a named pipe), not a plain file'. So is that a file system driver, or...? Even https://github.com/jitpass/jit/blob/main/docs/getting-starte... says it's a local encrypted store - and that's repeated many times across the docs Claud…
Re: Show HN: Laptop is the last place your secrets are still in plaintext
#49I don't get why you would have PRODUCTION secrets in those local .env files. It should only be dev tokens.
Re: Show HN: Laptop is the last place your secrets are still in plaintext
#50Snake oil claude slop. No other words for it. If someone or something is executing code on your machine, you have already lost. Making it _slightly harder_ for it to eventually get your passwords anyway is mostly a performative action. __ Btw, enable "showdead" and enjoy OP actually pasting LLM output verbatim as a "defense". - https://news.ycombinator.com/item?id=49317802 - https://news.ycombinator.com/item?id=49317…
This nonsensical attitude is thankfully dying out in favor of more sophisticated approaches.