HNHacker News
TopNewBestAskShowJobs

bobbiechen

4,773 karma · joined June 16, 2018

Writing about connections at digitalseams.com and personally at bobbiechen.com

<first two letters + last four>@twilio.com

submissionscomments
bobbiechen··on The behavioral cost of personalized pricing
(author here) I believe I had checked first in this case, which is why it was surprising. Sorry not to mention that in the post. This was in San Francisco, and there were multiple cars shown on the map.

In my experience, I usually don't see this kind of price change before the request has actually been confirmed - and I have seen Lyft change the price between showing me the estimate and confirming the request (with an apologetic confirmation dialog, possibly only after some holding period has timed out).

Maybe in my case where the high quote came first, the opposite scenario happened - a glut of drivers appeared between my request and hers, raising supply.

Opaque pricing is powerful partly because we don't know. This enables people to construct a plausible story to explain any price.

bobbiechen··on Ask HN: Share your personal website
https://bobbiechen.com/ https://digitalseams.com/
bobbiechen··on Command K Bars
Too humble to mention that you're the creator :) thank you Ben! In my opinion, Slack is the application that really popularized the command bar/palette in the mainstream.
bobbiechen··on Why do SublimeText, VSCode Ctrl-Shift-P instead of Ctrl-K for the command bar?
(author here) Thanks for posting! I need to update/post a follow-up with a couple of notes since I wrote that post:

* Ben van Enckevort, the original creator of the Slack quick-switcher with Ctrl/Cmd-K, showed up in the StackOverflow thread to tell us the choice of "K" was fairly arbitrary: https://ux.stackexchange.com/a/153937 . Thanks AJ Montoya for pointing it out too :)

* Dean Jackson pointed out TextMate as the predecessor to Sublime, including fuzzy search jump-to-file

* Amit Patel suggested Emacs as a potential originator, which led us to find Richard Stallman's manual for Emacs 150 (1980) which does have the Meta-X "extended command" that is very similar to today's command palette. A 1978 TECO manual doesn't mention this, so right around 1980 would be the right time frame.

bobbiechen··on Ask HN: What are you working on? (January 2026)
I'm very excited to be interviewing people who are creating interesting things with software for upcoming blog stuff at digitalseams.com !

As I've grown older, I've found myself more interested in people and their stories and motivations - especially as I know a bunch of people who are technically skilled, but feel unable or unworthy to create instead of consuming. So it's inspiring to hear really great creators talk about those same burdens and how they overcome them.

If this sparks your interest shoot me an email at bobbie @ (site above in comment)

bobbiechen··on How your high school affects your chances of UC Admission
Back when I was applying to college, there was the idea of "yield protection": a college might decline overqualified students to optimize for their "yield" (the percentage of admitted students who accepted). The yield might affect college rankings.

I'm not sure whether yield protection is actually practiced vs. just a paranoid student meme, but it was the first thing I thought of here and I'm surprised it wasn't mentioned in the article.

bobbiechen··on Arnaud Benard's website is automatically generated by AI every day
(click the floating calendar at the bottom-right to view past versions)
bobbiechen··on Ask HN: When do we expose "Humans as Tools" so LLM agents can call us on demand?
My thought as well - the infra already exists through MTurk, as well as the ethical and societal questions. You can already pay people pennies per task to do an arbitrary thing, chain that into some kind of consensus if you want to make it harder for individuals to fudge the results, offer more to get your tasks picked up faster, etc.
bobbiechen··on Kitchen optimizations
I'm a mise en place hater personally, since I make a lot of things that are essentially stir fries or stews where some ingredients need significantly more time. Sure, go for it on more complicated recipes, but it's really overkill for lots of daily cooking.
bobbiechen··on Show HN: Stop AI scrapers from hammering your self-hosted blog (using porn)
There are lots of people pretending to be Google and friends. They far outnumber the real Googlebot, etc. and most people don't check the reverse DNS/IP list - it's tedious to do this for even well-behaved crawlers that publish how to ID themselves. So much for User Agent.
bobbiechen··on Yep, Passkeys Still Have Problems
In the United Stages, RUFADAA provides this legal framework and I think it's quite reasonable.

I wrote about it here: https://digitalseams.com/blog/what-happens-to-your-online-ac...

bobbiechen··on SMS phishers pivot to points, taxes, fake retailers
I got this interesting pair of messages from Schwab recently - not sure if any other companies do this

On login:

Schwab Watch out for scams. DON'T share this security code with anyone, EVEN IF THEY CLAIM to be from Schwab. Your code for online login is XXXXXX

And then on a later phone call with an agent:

Schwab: XXXXXX is your Schwab security code to confirm your identity with the agent.

This is a nice touch, though I'm not sure how much it would help in a real scam situation for say, my grandma.

bobbiechen··on Anthropic taps IPO lawyers as it races OpenAI to go public
Not sure for Claude Code specifically, but in the general case, yes - GPT4Free and friends.

I think if you run any kind of freely-accessible LLM, it is inevitable that someone is going to try to exploit it for their own profit. It's usually pretty obvious when they find it because your bill explodes.

bobbiechen··on Show HN: Explore what the browser exposes about you
I believe this comes from the (browser self-reported) navigator.platform, which is reported as MacIntel on all Chrome for Mac versions including Apple Silicon.
bobbiechen··on Oracle hit hard in Wall Street's tech sell-off over its AI bet
Indeed, bad for consumer AI. But I would expect B2B spending on AI dwarfs consumer spending, I wonder what that comparable B2B revenue would be.
bobbiechen··on iPhone Pocket
That makes much more sense, even "a seamless piece of cloth" would have been much less ridiculous.
bobbiechen··on Show HN: Settling the Score – A point-and-click adventure rhythm game
I liked the concept! Some thoughts from me:

1. The game was fairly fetch quest-y but I think even the fetch quest format could be interesting with more storytelling around the instruments/people involved.

2. The rhythm game part was fine and straightforward but would get repetitive fast. I have like a million hours on Crypt of the Necrodancer though, which has lots of novelty in it.

3. It could also be interesting to do something like Terry Rileys's "In C" (or perhaps more interactively "In Bb" https://www.inbflat.net/ ), have you considered it? Though I did like hearing some of the parts line up together too.

bobbiechen··on Show HN: Shadcn/UI theme editor – Design and share Shadcn themes
As opposed to username/password, where... An attacker that controls the email address can log right in.

Unless you mean to say I should set up 2FA for my CSS theme variable helper website?

Passkeys and OAuth/social login are great, but everyone has an email. And I don't think any mainstream site supports only passkey as an auth method (and no other way).

bobbiechen··on U.S. details gambling cases involving pro athletes and mafia families
Update next day, I can't believe it was X-rays... https://news.ycombinator.com/item?id=45693599
bobbiechen··on U.S. details gambling cases involving pro athletes and mafia families
I think this refers to RFID-embedded playing cards, which have apparently been used at the World Series of Poker before: https://www.wsop.com/news/wsop-livestreaming-all-summer-with...

>The card information will be known to the viewers by using RFID (radio-frequency identification) technology for the very first time at the WSOP. Each card has a microchip embedded in it that has no impact on the cards or play, but with a specially-outfitted poker table, can send an encrypted signal to decipher the card’s rank and suit. The WSOP has used this technology during the 2012-13 WSOP Circuit season with success, and it is found throughout European poker events as well.

bobbiechen··on Today is when the Amazon brain drain sent AWS down the spout
Well, there was a software change to smooth out how the bars would display.. https://9to5mac.com/2025/10/08/a-15-year-mystery-solved-the-...
bobbiechen··on Credential Stuffing
There are a lot of dedicated anti-detect browsers, you can search for that term or fingerprint switcher, multi-accounting browsers, etc. Many of them are based on Chromium.

In my experience they're generally detectable by mismatches in various attributes compared to the "real" browser whose user agent they are spoofing (though of course, the ground truth of adversarial detection is always hard to know for sure).

bobbiechen··on Credential Stuffing
The author, Dan, is at FusionAuth, so that might be a good place to start.

I work for Stytch (another CIAM provider) on the fraud and security side and we do these too. I'd say you see credential stuffing defenses integrated into the auth provider rather than standalone rate limiting because so much of the relevant context is tied up in the auth side.

And, all the error messages end up being bad, as is the case for many security things. For our own features like Intelligent Rate Limiting https://stytch.com/docs/fraud/guides/device-fingerprinting/d... it's usually a bad idea to tell a user "You hit the limit, come back in an hour or contact support" because it gives an attacker information on how to improve. And we regularly see probing behavior where an attacker is trying to find the edges of a defense before starting a full-scale attack.

On the side topic of error messages - if you've ever seen "If your account exists, the password has been reset" that's another useless error message because "No account exists with that email" enables account enumeration.

bobbiechen··on Bots are getting good at mimicking engagement
It's a problem even on the company side. If the people responsible for marketing are judged on vanity metrics, they'll assume a conversion problem is later in the funnel. And even for venture-backed startups, I feel there is an incentive to turn a blind eye to bot signups since it juices numbers for investors who aren't paying attention.
bobbiechen··on DOJ seizes $15B in Bitcoin from 'pig butchering' scam based in Cambodia
That's interesting - I had seen some news articles reporting that some Chinese pig butchering scammers were encouraging others to target foreigners only, and exclude the mainland Chinese. Like this one: https://globalinitiative.net/analysis/chinas-acquiescence-to...

It's reminiscent of stories about Russian malware doing nothing on machines with Cyrillic keyboard layouts.

bobbiechen··on Captcha Welcome Mat
I loved the chatbot where you can haggle a bit. I really need that back and forth in my online shopping experiences.
bobbiechen··on Does our “need for speed” make our wi-fi suck?
To this day I expect my wifi to drop whenever I hear a microwave, thanks to the one in my parents house: https://digitalseams.com/blog/microwave-ovens-wi-fi-and-http
bobbiechen··on A competitor crippled a $23.5M bootcamp by becoming a Reddit moderator
Agreed. Every now and then I search the name of my employer on Reddit, which pulls up a bunch of plausible looking comments that recommend a variety of tools. Then if you look at the comment closely, it doesn't make any sense. And if you look at the account, they only makes comments that mention an assortment of companies + one specific one that they're really shilling.

There's a variety of these marketing spambots on Reddit, and I'm sure like the toupee effect, there are more subtle ones that I'm not noticing. I think this is existential in the long run for Reddit as a platform, but maybe the owners/employees are happy to milk all the value out and walk away from the husk.

bobbiechen··on A recent phishing attack on GitHub
I also mentioned this here the day I saw it: https://news.ycombinator.com/item?id=45308596

If you were targeted, you might have dangling notifications in the GitHub UI, that you can't clear since the repo has been taken down. This community discussion includes a script to get rid of those: https://github.com/orgs/community/discussions/174283#discuss...

bobbiechen··on The Answer (1954)
Gotta be Ted Chiang. Try his short story collection titled Exhalation: Stories.
← PreviousPage 3 of 14Next →