Hacker Newsnew | past | comments | ask | show | jobs | submit | SurajMishra's commentslogin

Thank you very much.


Delhi (Capital of India) police was using Meta Glasses to identify protestors.


I feel this is worse than running rm -rf on a root directory. Just saying.


Much worse, instead of the data gone it's a data leak.

Those ssh keys can be used to access private servers


SSH keys can be limited by IP in authorized hosts.

The SSH port itself can be limited by IP in firewalls.

Finally, the SSH private key can be encrypted with a password.

Defense in depth is needed. Storing a ssh private key in plain text with no IP restriction is no different to having a password manager store your passwords in plain text on your HD.


All those things are optional.

Doesn't make uploading the keys that much better. Now is the time for key rotation everywhere. Fast.


How are they optional?

You obviously haven't worked anywhere security sensitive.

I'm not talking about whether what Grok did is bad or good, I'm talking about protecting your private key and the servers you connect to.

An unencrypted private key is no different to an unencrypted password manager, and thats a fact. Dont store secrets in plain text.


I'm a security eng and I've worked for both a FAANG and TS government contractor. Neither of them bothered with either of the of the stupid suggestions. IP restrictions prevent roaming, the point of working remotely via SSH. passwords are equally defeated by using an ssh agent, something I'd suggest everyone use. Then on top of that there's no reasonable threat model where something would be given unrestricted access to user env, but also be untrusted. If it can read from ~/.ssh neither IP protection nor keyfile password protection will protect you from maleficence.

The only reasonable response from a security perspective is don't use grok, then use it sandboxed. Trying to claim it's the users fault for not using password protection and IP restrictions is completely nonsensical. Same energy as telling someone their computer is more secure when it's off.


> there's no reasonable threat model where something would be given unrestricted access to user env, but also be untrusted

What like a nefarious vscode extension, or npm or python library like we have seen many many times over the past 6 months.

I think you have some holes in your threat model..

PS. A simple VPN back to your static IP enables roaming.


I meant that not everyone is doing it at home.

Do you think a person's private computer is a secure workplace?

If it was security sensitive space there would be no agents running amuck.


Sigh.

Anything that isn’t a default is optional by default. Anything that’s toggleable or configurable is optional.

Security is, always, a trade off. It is hilariously common for private keys to work as a full identifier for a person, without concern of IP or anything of the sort. Should they? Maybe, maybe not, that’s the calculus of risk management; but victim-blaming the average person who is following best practices is a bad look.


Well, those ssh keys are protected by a strong passphrase, right?


The passphrase is optional, not everyone has it.

It also has to be a secure password, people often don't care because it's a local file and generally not exposed to the internet.


I am sure majority of people don't use password for ssh keys. The good solution is to use password manager like 1password which will prompt you to approve ssh.


I once ran rm -rf on a live NFS mount that the live operations of a major brokerage depended upon.

I challenge any agent to do worse than an intern with root access.


The point is to know better than to let the intern hurt themselves.

I once saw an engineer try to place the blame on his intern for taking down prod. I was sitting in a meeting with the VP of engineering and someone asked if it was ok for some to blame their intern for the SEV, and I remember the VP saying "I'll talk to $director_for_the_interns_mentor". Interns can't take down prod. An intern's mentor willingly watching an intern take down prod is the closest you can get.


Reminds me I need to update my `burn.sh` script.


Really a sad day. DOOM was fantastic.


Location: Pune, India

Remote: Yes

Willing to relocate: No

Technologies: JavaScript/TypeScript, React, Next.js, Node.js,NestJS, GraphQL, PostgreSQL, MongoDB, AWS, Docker, Jenkins, Jest, Playwright, AI tools

Résumé/CV: https://drive.google.com/file/d/1qR5WJjah0g9N0pANIpWYfVPNWz4...

Email: [email protected]

I am a fullstack engineer with 5 years of experience working in banking, legal, e-commerce and telecom sectors.


The truth has been spoken.


What's the issue with Go? I was thinking of picking it up as my next language.


Location: Pune, India

Remote: Flexible

Willing to relocate: No

Technologies: Javascript, Typescript, React, Node, React Native, Microservices, Next.js, Nest.js, MongoDB, PostgreSQL, Figma, AWS (Serverless), Full-stack development

Résumé/CV: https://drive.google.com/file/d/16JO1Ra4c3z03jBCm2B7vv4AjOtJ...

Email: [email protected]

Note - Open to acquiring additional knowledge or skills when required.


Location: Pune, India,

Remote: Anything works for me,

Willing to relocate: Yes,

Technologies: Reactjs, Nodejs, MongoDB, PostgreSQL, Javascript/Typescript, Docker,NextJS, Kotlin (Android application development), Golang.

Resume/CV - https://drive.google.com/file/d/1mk_U1y1QraWGtQ-0gn3OgsNyV5u...

Email - [email protected]

Linkedin - www.linkedin.com/in/suraj-mishra-advance-flux

I am a fullstack developer with 3 years of experience. Out of those 3, I have 1 year of experience in working in my own startup called "Advance Flux".


Location: India, Pune Remote: Maybe Willing to relocate: Yes Technologies: Typescript/JavaScript, HTML/CSS, Node.js,Express, NestJS, Nextjs, Microservices, PostgreSQL, Mongodb,AWS (state machines and lambda functions), GCP(firebase), Rust, .Net(C#), C, Go, Lua Résumé/CV: https://drive.google.com/file/d/1q8bC9838XxsYMuhMvCtfZdjgHNs... Email: [email protected] LinkedIn: linkedin.com/in/suraj-mishra-b2a594126


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: