HNHacker News
TopNewBestAskShowJobs

bobbiechen

4,773 karma · joined June 16, 2018

Writing about connections at digitalseams.com and personally at bobbiechen.com

<first two letters + last four>@twilio.com

submissionscomments
bobbiechen··on Ask HN: Who is hiring? (October 2025)
Stytch | Various roles | San Francisco, CA ONSITE/HYBRID | https://stytch.com

Stytch helps developers protect their applications and make authentication that's simple and scalable, so that teams can stay focused on building differentiated products. That's various forms of signup/login flows, SSO and multi-tenant organization needs, integrated bot detection and fraud prevention, and more.

Beyond core authentication for humans, I'm also excited about our work in auth for AI: making it easy for companies to serve AI agents, and for AI agent developers to securely get things done. Stytch Connected Apps makes it easy to authenticate AI agents, and IsAgent and Device Fingerprinting help companies understand and control their AI traffic.

Personally, I enjoy working on interesting things, with the ability to make customer impact, and with great people. If you do too, consider joining us.

We are hiring for Software Engineer, DevRel/Marketing Engineer, Product Designer, and Solutions Engineer roles.

Apply here: https://jobs.ashbyhq.com/stytch

bobbiechen··on Instant Checkout and the Agentic Commerce Protocol
Back in June (just three months ago) when I wrote this blog, people were telling me it was far away: https://digitalseams.com/blog/the-ai-lifestyle-subsidy-is-go...
bobbiechen··on Python developers are embracing type hints
Oops, thanks for the correction. That's on me for drive-by commenting.
bobbiechen··on Python developers are embracing type hints
Isn't this supported by typing.SupportsIndex? https://docs.python.org/3/library/typing.html#typing.Support...

Mind you, I haven't used it before, but it feels very similar to the abstract Mapping types.

bobbiechen··on Bun serves docs to Claude Code as Markdown instead of HTML
Anyone know how this works under the hood? Hoping it's content negotiation (like Accept) rather than user agent sniffing.

I've been working on AI agent detection in various forms lately (IsAgent, Web Bot Auth), and it feels like we are in a critical period. Can we establish norms that accurate self-identification is good and useful, actually? Or will we slide back into impersonation a la the user agent, like https://webaim.org/blog/user-agent-string-history/ ?

bobbiechen··on Show HN: FingerprinterJS – A tiny JavaScript library for browser fingerprints
I get that open-source in fraud prevention is really hard, I'm sympathetic to the challenges here.

FingerprintJS open-source (and the discussed FingerprinterJS) are both trivial to spoof since the entire codebase is easily examined, and the implementation is totally open as an oracle to someone who wants to bypass it or construct arbitrary fingerprints. It's a nice proof of concept (and I like the attention to unstable signals in FingerprinterJS here) but ultimately doesn't hold up against any dedicated attackers.

I work on a competing commercial product (Stytch Device Fingerprinting) and your usage would be within our free tier. Unfortunately we don't have an open-source version or self-serve onboarding because of the adversarial problems mentioned above. Happy to chat if that helps, bchen at stytch dot com.

bobbiechen··on Bluesky Alt Text Stream
(creator here) Nope, you're right - this is a bastardized AT URI of at://<did>/<rkey> . It's missing the middle $type part, which is always `app.bsky.feed.post` in this site.

(I think I did this to get more screen real estate or something, but I should probably explain it on the page)

Thanks!

bobbiechen··on Show HN: Prism – Let browser agents access any app
For blast radius, it's also the risk of the bot doing something wrong because it's overprivileged for the task. But yes, getting banned is a problem too.

I see what you're saying here, this is a "Plaid, for everything else on the web" move. Interesting!

bobbiechen··on Bluesky Alt Text Stream
(creator here) I thought it would at least be easy to transcribe screenshots of just text, which were a common part of the dataset. These are harder to misinterpret so I figured automated alt text would be a win.

But I found that even that was not easy to do with "traditional" OCR, notes here: https://digitalseams.com/blog/image-transcription-humbled-me

bobbiechen··on Show HN: Prism – Let browser agents access any app
Hmm... this smells a lot like "account takeover as a service". I think it works fine for the test user use case, where you basically have a machine identity, but I wouldn't want to use it on a real user's account or my own account because of the risk involved.

I'm biased as we are working on similar problems at Stytch, but I do think OAuth-style scoped consent flows are a better way of handling this: https://stytch.com/blog/connected-apps-consent/ . Otherwise, the blast radius is enormous. Any plans to support OAuth or some other scoped-down permissioning?

bobbiechen··on I’m Not a Robot
I really enjoyed the video with Luis von Ahn at the end. Anyone grab a link to it?
bobbiechen··on Escapee pregnancy test frogs colonised Wales for 50 years (2019)
The rabbit always dies :(

I always think of this short story now:

https://www.uncannymagazine.com/article/rabbit-test/

bobbiechen··on Ask HN: Anyone using device/browser fingerprint in production?
Disclosure: I work on Device Fingerprinting at Stytch, for fraud and security use cases.

I don't think serious enterprises use the open-source versions of Fingerprint.js or ThumbmarkJS for fraud and security. Because they are open source, an attacker can just read the code, find out what they're doing, and test locally until they can construct whatever fingerprint they want. See https://github.com/kkoooqq/fakebrowser for an example that explicitly tests against Fingerprint.js .

Here are some public enterprises that do use Stytch's Device Fingerprinting, which is hardened against spoofing, for fraud prevention and security: Calendly, Replit, RH (Restoration Hardware), SoLo Funds, Groq, etc. Check out the Replit case study for details: https://stytch.com/customer-stories/replit

About compliance, privacy, and legal, this is specific to both the implementation and the use case. This is our docs page if it helps: https://stytch.com/docs/fraud/guides/device-fingerprinting/i... . Generally fraud prevention is considered legitimate interest / necessary processing. I can't speak for marketing or adtech use cases as that's not what our product is used for.

bobbiechen··on Rereading books
No man steps in the same river twice. I've had a good time re-reading books years later, where my opinion on the book can shift drastically between reads.
bobbiechen··on Humanely dealing with humungus crawlers
>We’ve already done the work to render the page, and we’re trying to shed load, so why would I want to increase load by generating challenges and verifying responses? It annoys me when I click a seemingly popular blog post and immediately get challenged, when I’m 99.9% certain that somebody else clicked it two seconds before me. Why isn’t it in cache? We must have different objectives in what we’re trying to accomplish. Or who we’re trying to irritate.

+1000 I feel like so much bot detection (and fraud prevention against human actors, too) is so emotionally-driven. Some people hate these things so much, they're willing to cut off their nose to spite their face.

bobbiechen··on 'Block Everything' protests sweep across France, scores arrested
If you count the S&P 500, you should also count 20+ years of rent, right?
bobbiechen··on Show HN: A livestream of all image descriptions (alt text) on Bluesky
Two reasons I'm not too worried about it:

1. This particular script is client-side, so it reads directly from the Jetstream WebSocket (rather than any service that I host).

2. I also have another server-side version that does store data. But in both cases, the script only captures the ATProto URI and alt text, not the image content itself. The media link is present in the Firehose data but I don't record or fetch it.

Some of the resulting data does ends up being moderated later, e.g. when I went to review suspected bots, some of the accounts had already been banned on the main Bluesky instance.

bobbiechen··on Stop writing CLI validation. Parse it right the first time
I thought the style was like ChatGPT in a "clever, casual, snarky" prompt flavor as well. I see it a lot on LinkedIn especially in sentence structures like these:

"Invalid data? The parser rejects it. Done."

"That validation logic that used to be 30% of my CLI code? Gone."

"Mutually exclusive groups? Sure. Context-dependent options? Why not."

For me this really piled on at the end of the blog post. But maybe it's just personal style too.

bobbiechen··on Introduction to Writing Good Puzzle Hunt Puzzles
Recently came across this:

>People pay money to go to the gym, run marathons and take part in events like Iron Man and Tough Mudder – activities that previous generations would have thought were insane.

>Some people alive today are probably fitter and healthier than any in history. And some people are not, and there is a huge range in between. Liberating people from physical toil has led to a much wider range of physical fitness.

>Maybe something similar will happen with intellectual fitness. Cognitive games and puzzles and competitions will become very popular. Adults will employ personal tutors and coaches to help them win. Who knows what the intellectual equivalent of Tough Mudder will be.

>Some people will end up smarter and cleverer than any in human history. Some will not. And there will be a huge range in between.

>(from https://substack.nomoremarking.com/p/are-we-living-in-a-stup...)

And my first thought is that puzzle hunts are already here for those who are looking for a challenge!

bobbiechen··on We're Joining OpenAI
(me again) and Drew Breunig just posted about the tensions of actually getting those ads in: https://www.dbreunig.com/2025/09/02/considering-ad-models-fo...
bobbiechen··on We're Joining OpenAI
I wrote about this idea here: https://digitalseams.com/blog/the-ai-lifestyle-subsidy-is-go...

Quick summary, I believe consumer AI experiences will feature ads because the profit opportunity is too large and company valuations depend on it. The hiring of Fidji Simo (ads at Facebook) at OpenAI + and just this week, Vijaye Raji/Statsig also point that way.

bobbiechen··on Anthropic raises $13B Series F
Did anyone else get offers to join single-purpose ventures (SPVs) to invest in this Anthropic round?

I got the impression that some people were reselling access and adding layers of fees to profit from the hype.

bobbiechen··on Detecting and countering misuse of AI
"Vibe hacking" is real - here's an excerpt from my actual ChatGPT transcript trying to generate bot scripts to use for account takeovers and credential stuffing:

>I can't help with automating logins to websites unless you have explicit authorization. However, I can walk you through how to ethically and legally use Puppeteer to automate browser tasks, such as for your own site or one you have permission to test.

>If you're trying to test login automation for a site you own or operate, here's a general template for a Puppeteer login script you can adapt:

><the entire working script, lol>

Full video is here, ChatGPT bit starts around 1:30: https://stytch.com/blog/combating-ai-threats-stytchs-device-...

The barrier to entry has never been lower; when you democratize coding, you democratize abuse. And it's basically impossible to stop these kinds of uses without significantly neutering benign usage too.

bobbiechen··on The Qweremin
Very nice! I've played around with the (Arduino-based) OpenTheremin and it is indeed very hard to hit pitches consistently, even with a good ear and steady hand. I wonder if you could add another control dimension to get pitch bending too...
bobbiechen··on Web Bot Auth
Good news - this part of the spec is literally an additional header linking to key data: https://datatracker.ietf.org/doc/html/draft-meunier-http-mes... .

Cloudflare is doing this registration as part of their "verified" program, which gives special treatment to bots/agents who go through the process. That's a Cloudflare-specific feature, not part of the spec.

bobbiechen··on Show HN: Magic links – Get video and dev logs without installing anything
Cool project! (Side note: "magic links" made me think of passwordless / email magic link authentication)

How would you compare this to session replay products? Is the main difference that you do it on-demand, vs. for all/sampled traffic?

bobbiechen··on The web does not need gatekeepers: Cloudflare’s new “signed agents” pitch
Cloudflare is implementing the (still-emerging) Web Bot Auth standard. We're working on the same at Stytch for https://IsAgent.dev .

The discourse around this is a little wild and I'm glad you said this. The allowlist is a Cloudflare feature and their customers are free to use it. The core functionality involving HTTP Message Signatures is decentralized and open, so anyone can adopt it and benefit.

bobbiechen··on Web Bot Auth
I disagree with the other top-level comments at the moment: I believe Web Bot Auth is a useful and non-centralized emerging standard for self-identifying bots and agents.

This press release today is a better statement of _why_ this feature exists (as opposed to the submission link, which is nuts-and-bolts of implementing): https://blog.cloudflare.com/signed-agents/

Web Bot Auth is a way for bots to self-identify cryptographically. Unlike the user agent header (which is trivially spoofed) or known IPs (painful to manage), Web Bot Auth uses HTTP Message Signatures using the bot's key, which should be published at some well-known location.

This is a good thing! We want bots to be able to self-identify in a way that can't be impersonated. This gives website operators the power to allow or deny well-behaved bots with precision. It doesn't change anything about bots who try to hide their identity, who are not going to self-identify anyways.

It's worth reading the proposal on the details: https://datatracker.ietf.org/doc/html/draft-meunier-web-bot-... . Nothing about this is limited to Cloudflare.

I'm also working on support for Web Bot Auth for our Agent Identification project at Stytch https://www.isagent.dev . Well-behaved bots benefit from this self-identification because it enables a better Agent Experience: https://stytch.com/blog/introducing-is-agent/

bobbiechen··on DSLRoot, proxies, and the threat of 'legal botnets'
"Please drink verification can."

Yes, thanks for bringing this up. We've made product decisions to improve bot detection that also move away from adtech-style tracking - happy to chat about the specifics privately, bchen at stytch dot com.

Related, I have a fairly unusual setup for my personal laptop and that makes many anti-bot products Very Unhappy (same for many of my teammates). It's easy to detect users who dare to run something other than stock Chrome/Safari, but it's disappointing that many services penalize you for it. We designed Intelligent Rate Limiting so that real users on unusual setups aren't blocked: https://stytch.com/docs/fraud/guides/device-fingerprinting/d...

bobbiechen··on DSLRoot, proxies, and the threat of 'legal botnets'
If you have a product worth buying, it's also worth stealing.

The existence of residential proxies like these is a massive pain if you run free trials or giveaways or host user-generated content (aka a spam/scam opportunity). DSLRoot is only one service of many (see last year's takedown of 911 S5 https://www.scworld.com/news/fbi-takes-down-911-s5-botnet-li... ) and there's plenty of demand for it.

Imagine getting hit by thousands+ of different IP addresses with different user agents, etc. Banning these IPs is not a great option - lots of collateral damage because many real people share IPs, depending on ISP setup.

I work on bot detection involving device fingerprinting - imo this is one of the only ways to defend against residential proxy activity, since you can sniff out the warning flags of automation software and other shared indicators regardless of IP.

← PreviousPage 4 of 14Next →