Remix.run Logo
hypfer an hour ago

Snake oil claude slop. No other words for it.

If someone or something is executing code on your machine, you have already lost. Making it _slightly harder_ for it to eventually get your passwords anyway is mostly a performative action.

__

Btw, enable "showdead" and enjoy OP actually pasting LLM output verbatim as a "defense".

- https://news.ycombinator.com/item?id=49317802

- https://news.ycombinator.com/item?id=49317819

Maybe claude can reword your claude slop for you. You can still edit those posts I guess.

__

bukershok 2 minutes ago [dead] | parent | context | flag | vouch | favorite | on: Show HN: Laptop is the last place your secrets are...

Worth separating two things here.

That's curl | tar, not curl | sh, as a few people noted. But the real answer is: don't use it. The recommended install is brew install jitpass/tap/jitpass.

Releases are Developer ID signed and notarized by Apple. Homebrew quarantines its download and Gatekeeper checks it against the notarization ticket before it runs. jit doctor reports the Team ID it verified, so you can check rather than take my word for it. jit upgrade refuses to install anything whose signature and checksum don't both verify, with no override flag.

The tarball line is there for people without Homebrew, and it is the weaker path precisely because curl sets no quarantine bit, so Gatekeeper never consults the ticket. Point taken: leading with it in the README undercuts the argument on the same page. I'll flip the order.

__

Sorry if this violates the "no dunking" rule or whatever, but this cancer needs to be eradicated.

bukershok an hour ago | parent | next [-]

Hypfer, I am a security leader at the age of 42 with more than 15 years of experience in the field, and I will tell you the truth: I lead a lot of cyber incidents. The purpose of this tool is to help you and companies protect yourselves from supply chain attacks and infiltrators for free no cost, no need for expensive 1Password tools. I put my heart into this tool, so give it a try and contact me directly if you need anything. I will be glad to get your feedback on the tool. No AI fluff :) linkedin - https://www.linkedin.com/in/menitasa/

hypfer an hour ago | parent [-]

Ayy, finally, a human response. And it's an appeal to authority/seniority.

Can you just.. not?

The intended purpose of the tool is perfectly clear. There was never any confusion about it.

bukershok 41 minutes ago | parent [-]

[flagged]

concinds an hour ago | parent | prev | next [-]

> If someone or something is executing code on your machine, you have already lost

This nonsensical attitude is thankfully dying out in favor of more sophisticated approaches.

hypfer an hour ago | parent [-]

What makes it nonsensical?

concinds 40 minutes ago | parent [-]

There is no objective or tangible reason you must give up at that stage. We all run untrusted code on our machines, whether it's third-party apps or visiting websites.

hypfer 38 minutes ago | parent [-]

How does (the unfounded claim of) "everyone is doing [X]" make "we probably shouldn't be doing [X]" "nonsensical"?

Sounds unconvincing. Can you elaborate further?

bukershok 21 minutes ago | parent [-]

[dead]

bukershok an hour ago | parent | prev [-]

[flagged]