HN user

loginatnine

237 karma
Posts3
Comments74
View on HN

Send them a request to have Trusted publishers support at central-support (at) sonatype.com

I did that a couple of weeks ago and received an acknowledgment "Another request on Trusted Publishing option. Assigning to Product for review and further action." so this is a bit encouraging.

At least Maven dependencies don't execute scripts on install, but Maven plugins could have a big blast radius.

This is good, just bear in mind that if you put the hash of an external composite action and that action pulls on another one without a hash, you're still vulnerable on that transitive dependency.

This week, Hydro-Québec, the nationalized company that provide electricity to residents of the province, has announced a major investment program to reduce electricity usage by using smart thermostats. I'm extremely worried about the life expectancy of those smart thermostats in the long run and whether it's a good use of public funds. I'm also not super thrilled of the amount of functional regular thermostats that will end up in landfills because of that initiative.

[1]https://news.hydroquebec.com/en/press-releases/2172/hydro-qu...

I've been working with an app that uses Google to login for the past 10 years, and I've had problems with sub changing when these situations happened : - Domain change - Company being bought by another one and being integrated in their Google Workspace - Employee leaving and coming back

To us, it's very very far from the quoted 0.04% which is to me very high. I had to deal with it 5-6 times in the past 10 years but of course that number will vary depending on the usage of your app and I'm not gonna venture and put a percentage on it.

At my current company, if an employee leave and come back, they'll keep the same OID in Entra but they'll get a new `sub` in Google workspace. We had to put in place a process to be able to use an internal tool that used the login with Google.

That's most likely dependant on how the IT department handled the deprovisioning/provisioning of users in our Google Workspace, I unfortunately don't have the details for that.

I really don't understand here, the proper way to use Google's OpenID implementation to authenticate someone is to use the `sub` claim. Don't use the email, don't verify it yourself, use the `sub` claim. It's a known fact and is properly documented[1].

If the `sub` changes, it's because it's not necessarily the same person so have a flow ready for that. It could be an employee left and came back, a domain change, an IT error that lead to a reprovisioning of the user, etc.

I also fail to see how the proposed solution of having a 'A unique user ID that doesn’t change over time' is different from the `sub` claim. However, the new ID associated to the domain could make sense to enforce a strong 'Everyone from the @domain.com has access' statement.

[1] https://developers.google.com/identity/gsi/web/reference/js-...

Good find! I've dug a bit and the extension, at least for now, does not send any metadata associated to your browser[1], only a comma separated list of extension IDs. Of course the IP could be easily used.

Looking at the result from the API of one extension I had installed[2], it lists metadata associated to the developer. I've tried to use the `chrome.management.get(id)` Chrome API and it does not return this information, and there does not seem to be a way to get the content of the manifest.json programatically. Therefore, to do the job of the extension as it is, it does need an external source.

[1] https://github.com/classvsoftware/under-new-management/blob/...

[2] https://api.extensionboost.com/v1/developer?extension_ids=gh...

I understand your desire to build out an "ecosystem" of app and everything, however, I'd really like an option to go fully on my own and skip your iOS/android app.

Is it something that you plan on doing and document? Or is there an easy way I can ssh into the device and figure out on my own?

TIA!

EDIT : well, 1 minute later you answered part of my question here : https://news.ycombinator.com/item?id=37645339. How about ssh-ing?

+1

I use BW for my personal use with my SO and 1P at work. I hit some errors in 1P that were crypting, stuff like "Failed to add this record" with no details, no help button, I had to fire up the chrome console for the extension to find out it was a 401 to our 1P portal. Very poor experience, probably related to our SSO setup but still.

Never had any weird issue like this with BW and I love the autofill shortcut and the absence of a popup when I access a password field like 1P.

So yea, YMMV as usual but definitely not miles ahead.

I'm part of the cult, LV has some unique and quality items that are only available there, especially for woodworking and kitchen. Durable items that will last a lifetime, clear concise description, no BS website.

I had to call once for some backordered item and was pleasantly surprised that someone just picked up the phone, no automated system, no wait time.

OpenWRT 22.03.4 3 years ago

I second Merlin's recommandation, it's just the right amount of stock+custom features I want for my day to day. Rock solid for stability.

Gail.com FAQ 4 years ago

French canadian here and same comment, ploum does not mean anything. Even plouf (for us).