HN user

mkenyon

732 karma

Staff Software Engineer at 1Password. I work on Developer Ecosystems. We focus on the experience for our most powerful users. Whether it's the 1Password CLI, our Touch ID-enabled SSH agent, service accounts, IDE extensions, CI/CD integrations, and much much more... that's all under my umbrella.

[ my public key: https://keybase.io/michaelabon; my proof: https://keybase.io/michaelabon/sigs/wdKvMDbGsLWjF0XvngW3kHD5s9F1mhx82RQUQlX67Kw ]

Posts1
Comments52
View on HN

Staff dev on 1Password’s developer tools here. We screwed this up in our first few releases of the 1Password CLI, largely out of ignorance. Those releases stored config in $HOME/.op at first. But early feedback pointed us to XDG, so we migrated. Now we check:

1. $XDG_CONFIG_HOME/.op (if var is set) 2. $HOME/.config/op 3. $HOME/.op

I hate to be the dev who says “I don’t know why those other code bases find it so difficult that they put up a fight” but our `findConfigDirectory()` function isn’t exactly complicated, even when you consider all the operating systems that the 1Password CLI supports.

(Sorry for the formatting, I’m on my phone.)

I've been a happy Fastmail customer for years prior to working on this feature. I've used a wildcard with my Fastmail account, created a new email address for each service I sign up with, and stored that email address in 1Password. All by hand. It's a tiny hassle, but one that I think is worth it.

The Masked Email integration makes that entire process automatic. It's even easier than before. It's enough to convince a few Fastmail-using friends to start doing it.

That's a good concern.

I can't fully speak for the Fastmail folks, but I know that there are a few upper limits for how many masked email addresses that one account can create. We tried to set them unreasonably high to allow for all manner of legitimate use while still preventing bad actors. They're also monitoring usage and tuning that limit. Plus, you can always email support and ask for a increase for your specific account, if you ever bump up against it.

Definitely! You can decide within Fastmail’s settings[0] which domain you want to use for masked emails. It can be fastmail.com, one of their fun domains like afcrichmond.uk, or one of your own. I've even seen some 1Password coworkers buy a brand new domain purely for their masked emails, so you can generate a “good.castle3827@youdontneedtoknowme.com” while still using “me@mydomain.ca” for your actual personal email.

[0] https://www.fastmail.com/settings/domains

True! I've been doing wildcard.company.name@mydomain.com for a few years now with Fastmail. This makes it one step easier to generate that email address, as well as one-click blocking any alias that starts receiving spam.

Those +plus aliases still make it easy for people find your actual email address.

We go one step further and generate a random email address for each new service you sign up with. It'll look something like "hot.potatoes4827@mydomain.com".

You can create a new masked email anywhere you have the 1Password browser extension, including our brand new iOS Safari extension.

Hi, one of the 1Password engineers who worked on this. Glad to hear that you like the idea!

One of the really nice parts of building this out with Fastmail is that you can create Masked Emails for your own domain. So, if you ever decide that Fastmail isn’t right for you, then you still receive all of those emails when you set up a wildcard alias with your new email provider.

Similarly, if you ever decide that 1Password isn’t right for you, that doesn’t stop you from receiving your emails. And the email addresses should still be part of your 1Password export.

1Password | Backend Engineer | Full-time | REMOTE + FULLY DISTRIBUTED (Canada, USA)

1Password is the world’s most-loved password manager.

I’m the tech lead on the Administrator Tools team. We build products, feature sets, and tools for our most powerful users. From building usable and scalable means of managing vaults, groups, and users, to making account recovery simple, and secure, we enable administrators to manage 1Password for their entire company.

You may be a fit for the role if you:

* Are excited to learn new things as you tackle new features and make existing ones better * Have a critical eye for detail and you understand that perfection is the enemy of good * Show a healthy balance of being able to work collaboratively while also taking responsibility for the tasks assigned to you * Show a penchant for clean, idiomatic code that's easy to read and maintain * Have a strong understanding of web server and RESTful API design * Are proficient in writing well-optimized MySQL database queries * Know secure coding practices * A thorough grasp of how networking works

Bonus points if you have:

* Experience with Golang. It's certainly nice, but not required. Show us that you have a great understanding of any modern programming language, and we'll trust that you'll learn Go just fine. * Experience with JavaScript, Typescript, and/or React.js. Sometimes you’ll need to dive into the frontend to understand how a feature works.

[ Administrator Tools, Backend Engineer ] https://jobs.lever.co/1password/7166a990-80c2-4cdb-b619-0fab...

Feel free to contact me if you have questions or are curious: michael.abon @ 1password dotcom

Fundzinger had a clause in their contract that if you for any reason cancel the project before the end of the campaign, they would bill you at their hourly rate.

For Fundzinger, we got on the phone with them and explained the situation in detail. They were more than understanding, and offered a deal that worked for us.

Visual Studio 2013 13 years ago

I think it's the "well-configured" part. While I love using vim, my .vimrc file and .vim folder have been crafted and maintained over years. I can't give those to beginners without explanation. VS needs no setup. Intellisense is free.

Microsoft does this. I have helped port a few apps that are popular on other platforms. The incentive for the company was, in fact, quite sizable.

I want to point out that "fair use" or, even more generally, First Amendment rights, are not involved here.

The statement that the NSA issued, that no one is allowed to use the Seal without written consent, is strictly false.

Section 15.a states explicitly that you may not use the Seal "in a manner reasonably calculated to convey the impression that such use is approved, endorsed, or authorized by the National Security Agency."

This t-shirt does not give you the impression that such use is approved, endorsed, or authorized by the National Security Agency. Fair use, parody, satire, doesn't matter.

I linked the CNET article because the FBI did the same thing a few years back:

"While we appreciate your desire to revise the statute to reflect your expansive vision of it, the fact is that we must work with the actual language of the statute, not the aspirational version of Section 701 that you forwarded to us," Mike Godwin, general counsel for Wikimedia Foundation, the nonprofit company that runs Wikipedia, wrote the FBI in response.

I suppose it was more of a "This is interesting. While we are here..." addition to the data.

I didn't mean to insult your intelligence regarding Tux. I just know that I would rather people not assume that I know things, especially when responding on the Internet.

It is not protected under that law. Satire is most certainly allowed (and not just under First Amendment rights). The FBI tried to remove its seal from Wikipedia[0] and similarly miscited the appropriate law.

Sec. 15. (a) No person may, except with the written permission of the Director of the National Security Agency, knowingly use the words 'National Security Agency', the initials 'NSA', the seal of the National Security Agency, or any colorable imitation of such words, initials, or seal in connection with any merchandise, impersonation, solicitation, or commercial activity in a manner reasonably calculated to convey the impression that such use is approved, endorsed, or authorized by the National Security Agency.

It is that last bit that matters here.

[0] http://news.cnet.com/8301-1023_3-20012575-93.html

Defeated 13 years ago

I have let to see a local business in the US use a metal detector. Most will use shoplifting-detection gates at the exits. An "empty your pockets and purse" metal detector is terrible for business.

It's a generous payout. The cuts seem indiscriminate when I look at all the talented people being cut. I imagine that it is hard to surgically remove 20% of your workforce.

Right now, I'm torn between looking for work immediately and asking for a delayed start, or going on vacation now and looking for work when I get back.

All I know is that Mars Bar (the local bar) will be busy tonight.