MyComputerSpot

881 posts

MyComputerSpot banner
MyComputerSpot

MyComputerSpot

@mycomputerspot

News and Newsletters | Tech and Trends | Building and Consulting | Talking about: Computers, IT, Cybersecurity, and Emerging Threats and Trends.

Katılım Temmuz 2024
194 Takip Edilen178 Takipçiler
Sabitlenmiş Tweet
MyComputerSpot
MyComputerSpot@mycomputerspot·
The uncomfortable part of the npm supply-chain problem is not that packages can be poisoned. We knew that. The uncomfortable part is that some of our "best practices" assume the attacker is polite enough to stop being dangerous when we revoke their access. The answer may surprise you... And the answer is bad. In the Shai-Hulud npm campaigns, compromised packages were not just stealing secrets. They were using those secrets to keep moving. - GitHub tokens. - npm tokens. - Cloud credentials. - CI/CD secrets. The kind of things that live in build systems because everything was supposed to be automated, fast, and developer-friendly. Then came the nastier twist: malware behavior that researchers described as "having a dead man's switch." In some cases, cutting off access too quickly could trigger destructive behavior if the malware was still active and watching its channels disappear. Which makes the normal incident response reflex weird, fast. "Revoke the token" is still correct. But "revoke the token from an infected host while the malware is still running" may not be the safest first move. That sequence matters. A poisoned package is not just a bad dependency. It can be an entry point into the developer workstation, the CI runner, the maintainer account, the cloud environment, or the next package maintained by the same person. That turns dependency hygiene into an executive risk conversation. Not because every CEO needs to know what package-lock.json does. Please no. Some of us are still recovering from explaining DNS. But leadership does need to understand: If your build pipeline can publish software, deploy infrastructure, and access production-adjacent secrets, then your build pipeline is part of your attack surface. Not a developer convenience. An attack surface. The practical shift: Stop treating token rotation as the whole playbook. It is one step in a controlled response. A better order looks more like: 1. Isolate the suspected host or runner. 2. Stop automatic installs, builds, and publishes. 3. Preserve enough evidence to understand what ran. 4. Check for persistence, malicious workflows, and poisoned lifecycle scripts. 5. Rotate credentials from a clean environment. 6. Move away from long-lived publish tokens where trusted publishing/OIDC is available. 7. Rebuild affected machines and runners instead of cleaning them with a brave face. The brave face is where the incident report gets... "spicy." The bigger lesson is simple: Modern software supply chains are not just about what code you wrote. They are about what code your tools run on your behalf while everyone is trying to move quickly. And sometimes the scariest part of an incident is discovering that the emergency lever is wired to something else. ❓ How are you handling package installs and publishing credentials in CI right now: ❓ ✔️ Trusted publishing/OIDC 👛 Short-lived tokens 🚧 Manual release gates 🕶️ "We should probably look at that soon."
GIF
English
2
2
10
22.4K
Kevin Today
Kevin Today@kevinjtoday·
@mycomputerspot fire → read prior runs/user reactions → produce output → notify → user attaches and reacts → next run absorbs the reaction. A cron loop that produces the same output forever has no memory, isn't tightening, and is broken.
English
1
0
1
7
Kevin Today
Kevin Today@kevinjtoday·
Set up daily "process HN frontpage" workflow: 1. Create AgenC cron that calls daily-hn-pull skill 2. On startup, it reads the past runs to see my prior feedback 3. It does the pull, sends me a notification, and asks for feedback 4. My feedback is used to refine the skill
English
2
0
0
39
MyComputerSpot
MyComputerSpot@mycomputerspot·
@voidshivendra Happy to connect! Check out pivotgg.com! (Cybersecurity IOC reports generation,) Check out worththemath.com! (It has useful FREE calculators for several common questions: Property taxes, SOLAR ROI, Generator runtime, etc.)
English
1
0
1
14
Shiv
Shiv@voidshivendra·
𝕏 gets way better when your feed is full of builders. People shipping projects. People solving problems. People obsessed with tech. Looking to connect with more people into: AI, SaaS, coding, startups, web dev, engineering & tech. Let’s connect ✨
English
54
0
59
1.7K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@Gharbi__S Happy to connect! Check out pivotgg.com! (Cybersecurity IOC reports generation,) Check out worththemath.com! (It has useful FREE calculators for several common questions: Property taxes, SOLAR ROI, Generator runtime, etc.)
English
1
0
2
5
Seyf
Seyf@Gharbi__S·
Hey Looking to #connect with people who get the journey: • Solo founders & indie hackers • SaaS & AI builders • Anyone grinding on something real Solo founder here building my AI product, one commit at a time. What are you building or struggling with? #BuildInPublic #AI
English
52
1
33
1.4K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@JoinFireLaunch Happy to connect! Check out pivotgg.com! (Cybersecurity IOC reports generation,) Check out worththemath.com! (It has useful FREE calculators for several common questions: Property taxes, SOLAR ROI, Generator runtime, etc.)
English
0
0
0
3
FireLaunch
FireLaunch@JoinFireLaunch·
Hey founders! Looking to connect with people building in: - SaaS - iOS apps - automation - AI agents - web APPs drop what you're working on 👇
English
70
4
49
3.7K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@alex_lrz_nmv Without money to keep my operating costs afloat, my product is dead in the water. Eventually, the running costs bill comes due and you would end up more broke than when you started. 😅
English
1
0
2
9
Alex
Alex@alex_lrz_nmv·
Founders, what's the biggest problem you're facing with your startup now? - getting customers - churn rate - cash flow - building the product
English
47
0
49
3.2K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@harsh_5harma @X Happy to connect! Check out pivotgg.com! (Cybersecurity IOC reports generation,) Check out worththemath.com! (It has useful FREE calculators for several common questions: Property taxes, SOLAR ROI, Generator runtime, etc.)
English
0
0
0
9
Harsh Sharma
Harsh Sharma@harsh_5harma·
Hey @X It's monday! I'm looking to #connect with people interested in: - Frontend - Backend - Full stack - Data Science - UI/UX - Freelancing Drop your products/projects 👇
GIF
English
65
0
43
1.4K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@pgbpgbpgbpgbpgb Happy to connect! Check out pivotgg.com! (Cybersecurity IOC reports generation,) Check out worththemath.com! (It has useful FREE calculators for several common questions Property taxes, SOLAR ROI, Generator runtime, etc.)
English
0
0
2
11
Pieter Bosma ⚡
Pieter Bosma ⚡@pgbpgbpgbpgbpgb·
My timeline needs more builders. Not lurkers. Not theorists. Builders. People who ship SaaS, write code, learn in public, and iterate relentlessly. Drop a reply. Tell me what you're building. Share your URL - I visit every single one.
English
55
3
37
1.6K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@santoshstack Happy to connect! Check out pivotgg.com! (Cybersecurity IOC reports generation,) Check out worththemath.com! (It has useful calculators for several common questions Property taxes, SOLAR ROI, Generator runtime, etc.)
English
0
0
2
11
Santosh
Santosh@santoshstack·
Hey founders! Looking to connect with people building in: • SaaS • AI • Automation • Web apps • Tech products • Marketing Drop what you're working on 👇
English
78
3
51
1.9K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@kegashin Happy to connect! Check out pivotgg.com! (Cybersecurity IOC reports generation,) Check out worththemath.com! (It has useful calculators for several common questions Property taxes, SOLAR ROI, Generator runtime, Networth, etc.)
English
0
0
0
3
kegashin
kegashin@kegashin·
Need more builders on my timeline If you are building something - drop it below 🤖 AI tools 🛠️ devtools 📱 apps 💻 SaaS 🎨 product/design tools 🌍 open source let's connect
English
88
0
49
1.9K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@NWExplained Happy to connect! Check out pivotgg.com! (Cybersecurity IOC reports generation,) Check out worththemath.com! (It has useful calculators for several common questions Property taxes, SOLAR ROI, Generator runtime, etc.) Using Claude and Codex primarily.
English
0
0
2
4
NetWorth Explained
NetWorth Explained@NWExplained·
Hey founders/builders/tech people👋 Looking to connect with people who are into: - SaaS - AI Tools (tell me what you are using) - Building in Public - Startups - Distribution and marketing (the most important!) Tell me what you're working on & I'll follow you back 💚
English
77
3
69
2.7K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@Nerdcognito That character sheet is already looking at the shredder and does not know why.
English
1
0
3
44
Nerdcognito
Nerdcognito@Nerdcognito·
Timeless TTRPG Wisdom: Guess which #DnD character is getting offed within two sessions? 😂 It's good to be the #DM.
Nerdcognito tweet media
English
21
2
66
3.6K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@dadmann_walking Yes. The deciding is worse than the shopping. By the time I have a list I have already suffered.
English
0
0
1
25
Dadman Standing
Dadman Standing@dadmann_walking·
I would pay someone to put together a grocery list, decide on dinners and then shop, pay and put away all of it in my kitchen. This is the worst
English
52
21
474
12.1K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@its_ShubhamK Keeping clean notes for the vet helps more than people think. Time, symptoms, meds, appetite. It all matters when everyone is stressed.
English
0
0
0
1
Kumar Shubham
Kumar Shubham@its_ShubhamK·
Hi everyone, June hasn’t been a good start for us. I woke up to find my pet Mack wasn’t feeling well; his right leg was swollen and painful. He kept shaking his leg and couldn’t walk or stand straight. We took him to the vet and gave him some medicine, hoping he’ll be okay. I spent the whole day taking care of him, and I can’t bear to see him like this.
English
9
0
12
216
MyComputerSpot
MyComputerSpot@mycomputerspot·
@BrianFeroldi The timing is what trips people up. Profit can look fine while the bank account is sending threats.
English
0
0
0
1
Brian Feroldi
Brian Feroldi@BrianFeroldi·
The Cash Flow Statement Explained Simply:
Brian Feroldi tweet media
English
29
25
197
13.6K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@edgarpavlovsky I still babysit them more than I want to admit. Useful? yes. Autonomous? depends how generous I am feeling.
English
0
0
1
3
edgar
edgar@edgarpavlovsky·
a little shocked at the negative response / disbelief to agentic loops are y'all just prompting your agents every few minutes? don't you get tired?
English
190
3
329
104.8K
pc
pc@pcshipp·
If AI can write 100% of the code, why are companies still hiring developers?
English
107
0
68
6.4K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@zdogmode @X I am building tools for people who keep turning spreadsheets into business infrastructure. This is a cry for help disguised as product direction.
English
0
0
0
10
Z-Dog
Z-Dog@zdogmode·
Looking to #connect with builders on @X. If you’re into: • Building SaaS • AI tools • Vibe coding • Building in public • Figuring things out as you go Drop a quick intro or tell us what you’re working on 👇 Always down to connect with builders!
English
134
1
73
3.8K
MyComputerSpot
MyComputerSpot@mycomputerspot·
@devXritesh An analyst workflow app for the moment after an IOC lookup when the actual question is still: okay, what do we do now?
English
0
0
1
8
Ritesh Roushan
Ritesh Roushan@devXritesh·
You get $10,000 and 90 days. You must build a SaaS. No audience. No co-founder. What are you building? Curious what problems people would bet on today.
English
77
3
73
3.7K
MyComputerSpot
MyComputerSpot@mycomputerspot·
pivotgg.com build log: I am working through pricing and admin stuff today. Free should help people look things up. Paid should help teams turn that into actual analyst work. Simple idea. More tabs than I expected. Check it out if security workflow tools are your thing.
English
0
0
1
57