MyComputerSpot

890 posts

MyComputerSpot banner
MyComputerSpot

MyComputerSpot

@mycomputerspot

News and Newsletters | Tech and Trends | Building and Consulting | Talking about: Computers, IT, Cybersecurity, and Emerging Threats and Trends.

Inscrit le Temmuz 2024
194 Abonnements178 Abonnés
Tweet épinglé
MyComputerSpot
MyComputerSpot@mycomputerspot·
The uncomfortable part of the npm supply-chain problem is not that packages can be poisoned. We knew that. The uncomfortable part is that some of our "best practices" assume the attacker is polite enough to stop being dangerous when we revoke their access. The answer may surprise you... And the answer is bad. In the Shai-Hulud npm campaigns, compromised packages were not just stealing secrets. They were using those secrets to keep moving. - GitHub tokens. - npm tokens. - Cloud credentials. - CI/CD secrets. The kind of things that live in build systems because everything was supposed to be automated, fast, and developer-friendly. Then came the nastier twist: malware behavior that researchers described as "having a dead man's switch." In some cases, cutting off access too quickly could trigger destructive behavior if the malware was still active and watching its channels disappear. Which makes the normal incident response reflex weird, fast. "Revoke the token" is still correct. But "revoke the token from an infected host while the malware is still running" may not be the safest first move. That sequence matters. A poisoned package is not just a bad dependency. It can be an entry point into the developer workstation, the CI runner, the maintainer account, the cloud environment, or the next package maintained by the same person. That turns dependency hygiene into an executive risk conversation. Not because every CEO needs to know what package-lock.json does. Please no. Some of us are still recovering from explaining DNS. But leadership does need to understand: If your build pipeline can publish software, deploy infrastructure, and access production-adjacent secrets, then your build pipeline is part of your attack surface. Not a developer convenience. An attack surface. The practical shift: Stop treating token rotation as the whole playbook. It is one step in a controlled response. A better order looks more like: 1. Isolate the suspected host or runner. 2. Stop automatic installs, builds, and publishes. 3. Preserve enough evidence to understand what ran. 4. Check for persistence, malicious workflows, and poisoned lifecycle scripts. 5. Rotate credentials from a clean environment. 6. Move away from long-lived publish tokens where trusted publishing/OIDC is available. 7. Rebuild affected machines and runners instead of cleaning them with a brave face. The brave face is where the incident report gets... "spicy." The bigger lesson is simple: Modern software supply chains are not just about what code you wrote. They are about what code your tools run on your behalf while everyone is trying to move quickly. And sometimes the scariest part of an incident is discovering that the emergency lever is wired to something else. ❓ How are you handling package installs and publishing credentials in CI right now: ❓ ✔️ Trusted publishing/OIDC 👛 Short-lived tokens 🚧 Manual release gates 🕶️ "We should probably look at that soon."
GIF
English
2
2
10
22.4K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@BlackDumpling DMing is writing, acting, scheduling, therapy-adjacent listening, and math you did not ask for. So yes.
English
0
0
0
7
BLACK DUMPLING™
BLACK DUMPLING™@BlackDumpling·
The most difficult of the performing arts is the Dungeon Master. The table top role playing kind. And there is no other form of artistry in the lexicon of man that even comes remotely close. While it's certainly not the most dangerous, or physically demanding, the sheer and staggering number of disciplines that have to come together all at once, on demand, in a distinctly improvisational environment while ensuring everyone around you has fun? And I know you think I'm taking the piss, but read for yourself and tell me if anything is missing or doesn't belong because the depth and breadth of what's required to be a DM is astonishing.. Narrative & Storytelling Arts: 1. World-building and lore crafting (mythology, anthropology, history, ecology, speculative fiction, comparative religion, geography, economics, politics). 2. Plot structure, dramatic arcs, pacing, foreshadowing, and multi-threaded storytelling. 3. Descriptive language, sensory immersion, and evocative prose (poetry, literary techniques, metaphor). 4. Thematic depth and philosophical exploration (ethics, psychology, social commentary). Performance & Acting Disciplines: 1. Voice acting (accents, dialects, pitch, timbre, projection, emotional range). 2. Physical embodiment and presence (gesture, posture, facial expression, mime, stage combat basics). 3. Character creation and consistent role embodiment (method acting, commedia dell'arte). 4. Showmanship, stage presence, comedic timing, and dramatic flair (public speaking, hosting). Improvisation & Adaptability: 1. "Yes, and..." reactive storytelling and collaborative emergence. 2. Real-time decision-making and consequence generation under uncertainty. 3. Handling derailments, player agency, and "failing forward". 4. Risk assessment and flexible pivoting while maintaining coherence. Directing & Facilitation: 1. Player/ensemble management and group dynamics (spotlight balance, encouraging participation). 2. Session pacing, structure, and energy management (like real-time film editing). 3. Feedback integration and iterative group direction Rules Adjudication & Game Design: 1. Mechanical mastery and consistent rulings (probability, statistics, game theory). 2. Homebrewing, system hacking, and custom content design. 3. Procedural fairness and social contract enforcement. Visual, Spatial & Multimedia Arts: 1. Cartography, battlemaps, and visual aids (graphic design, perspective, illustration). 2. Prop crafting, set design, and terrain building (3D printing, papercraft, painting). 3. Sound design and music curation (audio editing, ambient scoring, effects). 4. Digital tools and VTT performance (Foundry, Roll20, streaming tech, lighting). Psychological & Interpersonal Disciplines: 1. Audience (player) psychology and engagement styles. 2. Conflict resolution, inclusion, and emotional intelligence. 3. Motivational leadership and fostering investment. Research, Scholarship & Preparation: 1. Broad interdisciplinary knowledge (history, science, linguistics, military tactics, folklore). 2. Organizational skills (campaign bibles, note-taking, asset management). 3. Time management, prep efficiency, and endurance. Reflective & Educational Practices: 1. Self-critique, session review, and continuous iteration. 2. Pedagogy and mentoring (teaching rules, onboarding players). Ancillary & Technical Disciplines: 1. Writing (adventures, backstories, handouts, letters). 2. Marketing and community building (for public or ongoing games). 3. Physical/mental stamina and voice care. 4. Tech troubleshooting (audio/video, hybrid play) 5. Legal/ethical basics (copyright, accessibility). Even the disciplines themselves are broken down into further subdisciplines, and even those disciplines are tempered by the ruleset you're using and those rulesets can then be further subdivided into editions. And even then it's not merely that the DM has to do these things, she has to do them well enough that everyone around her has a good time and wants to come back. Remember, we're talking genuine competence across nearly all of these fields simultaneously in a live, highly randomized, co-created environment. Often for four to give hours or more at a given stretch. Which I suppose is just a lot of words to say it's a hell of a lot of work to be all powerful.
English
26
7
113
2K
Lisa
Lisa@lisathebeauty1·
Notes app be like: call dentist grocery list why did he look at me like that charger 8473hshs movies to watch
English
3
30
121
2.5K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@BugmaniaL Pet meds are frustrating because it feels like paperwork when you are trying to protect an animal. Clean vet notes at least make the back-and-forth less painful.
English
0
0
0
1
PepperMan
PepperMan@BugmaniaL·
You can order boner pills and all sorts of prescription meds without a prescription online, but I need a prescription from a vet for flea and tick meds for my pets? This country is plain stupid. 👊
English
10
3
51
994
MyComputerSpot
MyComputerSpot@mycomputerspot·
@thejustinwelsh Simple systems are underrated. The business should not require a ceremony every time you need to know if you made money.
English
0
0
0
36
Justin Welsh
Justin Welsh@thejustinwelsh·
Don't build a unicorn company. Build a small business that has profitable days, simple systems, and a flexible schedule. Over-ambition is exhausting. Cash flow with less effort is where it's at.
English
211
81
1.3K
41.3K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@Kalshi Cash flow does not care how good the business looks from the outside.
English
0
0
0
3
Kalshi
Kalshi@Kalshi·
JUST IN: Small business bankruptcies rose 36% in past year
English
99
174
1.2K
103.4K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@shub0414 AI can produce code faster than teams can build taste, review habits, and ownership. That gap gets expensive.
English
0
0
0
3
Shub
Shub@shub0414·
AI is pushing so much garbage code in production now that very soon they'll have to rehire more human than they laid off just to fix bugs created by AI and vibe coding.
English
129
47
469
157K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@ritu_twts Yes. Learn enough to know when the machine is lying to your face.
English
0
0
0
2
Reethu
Reethu@ritu_twts·
Be honest devs, Is coding still worth learning in the AI era?
Reethu tweet media
English
320
26
816
192.4K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@karrisaarinen Yes. The review step matters more than people want to admit. Agents can move fast, but somebody still needs to know what changed and why.
English
0
0
0
41
Karri Saarinen
Karri Saarinen@karrisaarinen·
I want an agent workflow tool. It should let me: - describe work items and plans - assign tasks to agents - review code diffs - work multiplayer with my team - collect customer context from many places -define shared skills and MCP servers - use it fully from slack
English
45
6
412
48.1K
MyComputerSpot
MyComputerSpot@mycomputerspot·
pivotgg.com build log: I keep coming back to one thing: Threat intel should help the analyst move. Not just stare at IOC verdicts. Evidence, next steps, detections, handoff. That is what I am trying to make cleaner. Tell me if that is useful or if I am just decorating my own headache.
English
0
0
0
6
Kevin Today
Kevin Today@kevinjtoday·
@mycomputerspot fire → read prior runs/user reactions → produce output → notify → user attaches and reacts → next run absorbs the reaction. A cron loop that produces the same output forever has no memory, isn't tightening, and is broken.
English
1
0
1
10
Kevin Today
Kevin Today@kevinjtoday·
Set up daily "process HN frontpage" workflow: 1. Create AgenC cron that calls daily-hn-pull skill 2. On startup, it reads the past runs to see my prior feedback 3. It does the pull, sends me a notification, and asks for feedback 4. My feedback is used to refine the skill
English
2
0
0
43
MyComputerSpot
MyComputerSpot@mycomputerspot·
@voidshivendra Happy to connect! Check out pivotgg.com! (Cybersecurity IOC reports generation,) Check out worththemath.com! (It has useful FREE calculators for several common questions: Property taxes, SOLAR ROI, Generator runtime, etc.)
English
1
0
1
16
Shiv
Shiv@voidshivendra·
𝕏 gets way better when your feed is full of builders. People shipping projects. People solving problems. People obsessed with tech. Looking to connect with more people into: AI, SaaS, coding, startups, web dev, engineering & tech. Let’s connect ✨
English
55
0
60
1.8K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@Gharbi__S Happy to connect! Check out pivotgg.com! (Cybersecurity IOC reports generation,) Check out worththemath.com! (It has useful FREE calculators for several common questions: Property taxes, SOLAR ROI, Generator runtime, etc.)
English
1
0
2
7
Seyf
Seyf@Gharbi__S·
Hey Looking to #connect with people who get the journey: • Solo founders & indie hackers • SaaS & AI builders • Anyone grinding on something real Solo founder here building my AI product, one commit at a time. What are you building or struggling with? #BuildInPublic #AI
English
71
1
41
1.8K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@JoinFireLaunch Happy to connect! Check out pivotgg.com! (Cybersecurity IOC reports generation,) Check out worththemath.com! (It has useful FREE calculators for several common questions: Property taxes, SOLAR ROI, Generator runtime, etc.)
English
0
0
0
4
FireLaunch
FireLaunch@JoinFireLaunch·
Hey founders! Looking to connect with people building in: - SaaS - iOS apps - automation - AI agents - web APPs drop what you're working on 👇
English
70
4
49
3.7K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@alex_lrz_nmv Without money to keep my operating costs afloat, my product is dead in the water. Eventually, the running costs bill comes due and you would end up more broke than when you started. 😅
English
1
0
2
9
Alex
Alex@alex_lrz_nmv·
Founders, what's the biggest problem you're facing with your startup now? - getting customers - churn rate - cash flow - building the product
English
47
0
49
3.2K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@harsh_5harma @X Happy to connect! Check out pivotgg.com! (Cybersecurity IOC reports generation,) Check out worththemath.com! (It has useful FREE calculators for several common questions: Property taxes, SOLAR ROI, Generator runtime, etc.)
English
0
0
0
9
Harsh Sharma
Harsh Sharma@harsh_5harma·
Hey @X It's monday! I'm looking to #connect with people interested in: - Frontend - Backend - Full stack - Data Science - UI/UX - Freelancing Drop your products/projects 👇
GIF
English
65
0
43
1.4K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@pgbpgbpgbpgbpgb Happy to connect! Check out pivotgg.com! (Cybersecurity IOC reports generation,) Check out worththemath.com! (It has useful FREE calculators for several common questions Property taxes, SOLAR ROI, Generator runtime, etc.)
English
0
0
2
11
Pieter Bosma ⚡
Pieter Bosma ⚡@pgbpgbpgbpgbpgb·
My timeline needs more builders. Not lurkers. Not theorists. Builders. People who ship SaaS, write code, learn in public, and iterate relentlessly. Drop a reply. Tell me what you're building. Share your URL - I visit every single one.
English
55
3
37
1.6K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@santoshstack Happy to connect! Check out pivotgg.com! (Cybersecurity IOC reports generation,) Check out worththemath.com! (It has useful calculators for several common questions Property taxes, SOLAR ROI, Generator runtime, etc.)
English
0
0
2
11
Santosh
Santosh@santoshstack·
Hey founders! Looking to connect with people building in: • SaaS • AI • Automation • Web apps • Tech products • Marketing Drop what you're working on 👇
English
80
3
52
1.9K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@kegashin Happy to connect! Check out pivotgg.com! (Cybersecurity IOC reports generation,) Check out worththemath.com! (It has useful calculators for several common questions Property taxes, SOLAR ROI, Generator runtime, Networth, etc.)
English
0
0
0
3
kegashin
kegashin@kegashin·
Need more builders on my timeline If you are building something - drop it below 🤖 AI tools 🛠️ devtools 📱 apps 💻 SaaS 🎨 product/design tools 🌍 open source let's connect
English
90
0
49
2K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@NWExplained Happy to connect! Check out pivotgg.com! (Cybersecurity IOC reports generation,) Check out worththemath.com! (It has useful calculators for several common questions Property taxes, SOLAR ROI, Generator runtime, etc.) Using Claude and Codex primarily.
English
0
0
2
4
NetWorth Explained
NetWorth Explained@NWExplained·
Hey founders/builders/tech people👋 Looking to connect with people who are into: - SaaS - AI Tools (tell me what you are using) - Building in Public - Startups - Distribution and marketing (the most important!) Tell me what you're working on & I'll follow you back 💚
English
77
3
69
2.8K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@Nerdcognito That character sheet is already looking at the shredder and does not know why.
English
1
0
3
48
Nerdcognito
Nerdcognito@Nerdcognito·
Timeless TTRPG Wisdom: Guess which #DnD character is getting offed within two sessions? 😂 It's good to be the #DM.
Nerdcognito tweet media
English
21
2
66
3.7K