A pretty straightforward solution is to have an isolated service that keeps the private key and hands back the temporary per-repo tokens for other libraries to use. Only this isolated service has access to the root key, and it should have fairly strict rate limiting for how often it gives other services temporary keys.
Yikes, this is a pretty bad vulnerability. It's good that they fixed it, but damning that it was ever a problem in the first place.
Rule #1 of building any cloud platform analyzing user code is that you must run analyzers in isolated environments. Even beyond analysis tools frequently allowing direct code injection through plugins, linters/analyzers/compiler are complex software artifacts with large surface areas for bugs. You should ~never assume it's safe to run a tool against arbitrary repos in a shared environment.
I also ran a code analysis platform, where we ran our own analyzer[1] against customer repos. Even though we developed the analyzer ourself, and didn't include any access to environment variables or network requests, I still architected it so executions ran in a sandbox. It's the only safe way to analyze code.
Unfortunately nuance is dead. I too wish Musk had tried to empower USDS instead of immediately alienating many of the people best positioned to improve things.
I'm not here to defend DOGE, but you're making the same mistake as the article of assuming the DOGE approach has no merit.
Deleting processes somewhat randomly, then listening for the pain, is a pretty well-known technique for understanding and cleaning up legacy systems. Of course, it should only be used on systems where (temporary) failures are tolerable.
There are parts of the government where that is true, and parts where it is dangerous. The problem on both sides is assuming the same techniques should be applied across the entire government, when some services are indeed life-and-death and others absolutely should be deleted.
The efficiency comparison is interesting, since it starts relatively evenly but quickly dismisses the value of the DOGE approach. Everyone I know who worked at USDS has been talented and well-meaning, but I can't help but feel they've been hamstrung specifically by
1. Methodical improvements mostly work to improve processes as they are. They don't delete processes that shouldn't exist.
2. Agency "empowerment" often means working with a lot of incumbent teams that are simply not suited to digital work and sinks way too much time/energy into stakeholder management.
USDS has done good work, but could have done a lot more if they were actually empowered.
That's not a good assumption to make for everyone. There are many people who do grow income without growing expenses (see the whole financial independence movement).
I spend about as much now as I did 7 years ago when I made 4x less.
You're right. I was bucketing the pricing/payout issues into the loan terms but they equally apply if you don't take out the loan.
Obviously there are many better ways to structure this if a sophisticated counterparty actually wanted a good investment opportunity for the community. Sadly that's not in anyone's interest.
Yeah I personally think the valuation is the least egregious part. If they get sued, they’ll have a defense for how they arrived at that number. It’s not 10x off.
OP would have to speak to his experience, but between a Google IPO and the $10M Virgin acquisition I would be surprised if he didn't average >$200k lifetime.
Throughout this thread, it's clear you have an ax to grind. Startups are obviously not for you, but many enjoy them and benefit.