HNHacker News
TopNewBestAskShowJobs

bobbiechen

4,767 karma · joined June 16, 2018

Writing about connections at digitalseams.com and personally at bobbiechen.com

<first two letters + last four>@twilio.com

submissionscomments
bobbiechen··on Eating Fruit Skins
It's a variant of a Chinese wintermelon soup like https://thewoksoflife.com/winter-melon-soup-pork-ribs/ ! It's a great sponge for the soup flavors.
bobbiechen··on Eating Fruit Skins
I do like to save watermelon rinds and cook them into soup.

Anyone have a use for banana peels?

bobbiechen··on Show HN: GlassBox – what the browser reveals, and how identifiable you are
Shocking, this site assigned me a UUID and I found it listed here! https://everyuuid.com/
bobbiechen··on Man loses so much weight employer doesn't recognize him
It's an interesting story as some people see facial biometrics (with increasing fidelity) as an escape from document verification deepfaking threats.

But people's biometrics really can change over time, and I don't think there's a clean way out. Back to expensive and inconvenient in-person checks?

bobbiechen··on Air Theremin – A browser theremin you play by waving at your webcam
Very impressed by the responsiveness of this. But I gotta say, it's much more fun to play a physical theremin, which has slightly different controls (two antennae, one controlling volume and the other pitch).

https://www.gaudi.ch/OpenTheremin/ will run with an Arduino and it's very satisfying to get better at controlling.

bobbiechen··on Ask HN: Does anyone else feel like nothing matters anymore?
>Is it that I want it to be done? Would it have been done if I didn't? (Additionality)

>Is it that I want to have done it? Would I be happy if someone else did it? (credit)

>Is it that I want to be doing it? (achievement/process)

>I want to have a mix. I want to do some things for the experience and some things for the accomplishment. I want to do some easy things and some hard things. Some fun things and some unfun things. Some things just for me and some things for others.

Amit Patel, via https://digitalseams.com/blog/amit-patel-on-making-things

bobbiechen··on The Valley of Webhooks
Is it accurate to say this is something like long polling except you continue to hold the connection open for subsequent updates? Does this mean a server potentially needs to hold open a very large number of connections (one per client) even if there are no updates?

And why formalize on HTTP rather than on a similar protocol over websockets?

bobbiechen··on Trusted URLs via Cryptographic Signatures
It looks like this is a project for nicer signed attestations. But it doesn't seem very opinionated about:

1. What is the attester (signer) attesting to, exactly?

This URL example is exactly this problem. And if you're really precise about it, they get less and less useful: "I attest that when I accessed this site at XYZ timestamp, it contained ABC content, and I saw ABC happen in person." or maybe alternatively to get away from the URL control, "I attest that these three non-malicious archives of this URL at this timestamp..."

And 2. Why should I trust the attester?

bobbiechen··on San Francisco: Don't Fall for Industry Defense of Surveillance Pricing
I had an interesting conversation with an coworker recently -

If you give an agent a budget of $500 to buy a flight, and the airline knows this and bumps your price to $499 even though it will offer the same flight at $300 to someone else, is there harm done? I argued it feels unjust. He said it's totally fair, it's within budget so what's the problem?

Naturally this trends towards a sort of principal-agent problem where the airline is incentivized to bribe your agent for up to $198 to max out your budget (which is a problem if you're not running your own agent).

But for general personalized pricing, there is the same dynamic to posture that you have a limited budget so that companies offer you better prices (regardless of whether you really do or not). This is haggling culture at scale.

I worry about a world trending towards this sort of thing and away from clearly universal prices and wrote about this at the beginning of the year: https://digitalseams.com/blog/the-behavioral-cost-of-persona...)

bobbiechen··on Most Googlebots Are Fake
That's a shame, I wonder where he draws the line.

While herding to the majority of latest Chrome makes his life easier, there really is a very long tail of real users who are not there. I get way too many challenges on my personal laptop running Firefox on Ubuntu (including infinite redirect loops).

bobbiechen··on Cloudflare's new AI traffic options for customers
The vast majority of Googlebot user agents are lying. Real Googlebot is pretty well behaved in my experience. You should use reverse DNS or IP lists to check: https://developers.google.com/crawling/docs/crawlers-fetcher...
bobbiechen··on Proving a Human Wrote Something
Here's another similar project: https://writetrack.dev/

There's plenty of microbehavioral analysis we can do that is initially effective but will get bypassed (with GANs being the purest way, or something more domain-specific).

You could imagine a livestream that's permanently published somewhere. But the verification of the livestream takes longer than reading the piece itself (and is itself vulnerable to faking).

Personally I think it comes back to something like writing under your real name - staking your reputation - as the most trustworthy indicator. At least people in your circles can trust you.

bobbiechen··on Cornell's Interactive Wall of Birds
I've used Merlin for a while and I'm still impressed by Merlin's sound identification, it continues to inspire me.

I wrote about it last year: https://digitalseams.com/blog/what-birdsong-and-backends-can...

bobbiechen··on AWS: Inaccurate Estimated Billing Data – $1.7 billion
AWS saw Anthropic billing a guy for $16 million on zero usage and thought, why stop at the millions?

https://www.techtimes.com/articles/320266/20260712/anthropic...

bobbiechen··on TK, or the secret to effortless writing (2024)
TK is a very standard term, see William Safire's usage in this 1996 NY Times article: https://www.nytimes.com/1996/10/06/magazine/of-hacks-and-tk....
bobbiechen··on Remote Attestation
Oh yeah, just like all cryptography is just a way for bad people to hide their criminal activity.

I'd read the confidential computing post! (used to work in this space myself)

bobbiechen··on Lost and Found
He's right up there with Neal Agarwal (neal.fun) and Nolen Royalty (eieio.games) for me. I recently got to interview Nolen on keeping the internet fun and creative for my blog: https://digitalseams.com/blog/nolen-royalty-on-making-things
bobbiechen··on Suspicious Discontinuities (2020)
The wash sale rule (in the US) makes it a lot harder to pull this off.
bobbiechen··on Blogging can just be stating the obvious
That makes a lot of sense! I recently interviewed several great creators on this exact topic and they all echoed similar ideas - although it's easy to fear that someone else has done it better, oftentimes they really haven't, and they'll never have your own unique perspective.

One challenge is that it takes repetitions to get good enough that you can even bring your ideas to life, and many people don't push through this (Ira Glass "taste gap").

Full interviews here: https://digitalseams.com/blog/making-things-interview-series

bobbiechen··on Ask HN: New clean macOS install. Must-have apps? Best browser?
Magnet app (for window splitting) is usually one of my first installs. I think I paid like $7 for it years ago and it's well worth it.
bobbiechen··on Bots flooded my anti-bot startup with 55,000 fake signups
A good reminder that signup is a surprisingly rich target.

>Every row has the same name: " Dene Hemen! 5K Lira Bonusunu Yakala" — Turkish for "Try it now! Grab the 5,000 Lira bonus." Casino spam.

>Each registration fired a verification email. 55K signups = 55K attempted sends to fake addresses — the kind of bounce storm that gets a sending domain blacklisted.

I'd be surprised if the email addresses were entirely fake - it doesn't make sense to advertise to just the website developer. It seems more likely that this spammer is targeting real email addresses from some dump (QQ is especially prone to this, since you can target random QQ ID numbers and get a lot higher of a hit rate).

bobbiechen··on Test-case reducers are underappreciated debugging tools
Nice share. Increasingly I am thinking about ways to improve verification ("interestingness tests"), ever since reading https://www.jasonwei.net/blog/asymmetry-of-verification-and-...
bobbiechen··on Launch HN: Intuned (YC S22) – Build and run reliable browser automations as code
Hey Omar, do you have any plan to add support for Web Bot Auth? https://datatracker.ietf.org/wg/webbotauth/about/

While I understand that not every business wants automation on their site, I know some businesses are totally open to it. But from a technical perspective, it's very difficult to allow well-behaved browser automation while still blocking abusive bots. Web Bot Auth gives website owners / security vendors a lightweight way to allow providers like Intuned.

(I work on the Web Bot Auth implementation for Stytch, now a part of Twilio: https://stytch.com/blog/stytch-supports-web-bot-auth/ )

bobbiechen··on Ask HN: Are Tech Meetups Dead?
I help run a tech/AI meetup in San Francisco - during the initial post-Covid period we often hit capacity limits since there wasn't much else going on.

But since late 2024 into 2025, meetups are extremely back in fashion here. Every day of the calendar has multiple meetups and it's impossible to avoid conflicts, so attendance rate can vary wildly.

bobbiechen··on The Ballad of TIGIT
It's just like a parallel of tech venture capital, where missing the next big thing is far more costly than making a wrong bet. No wonder we see herding in tech investments as well.
bobbiechen··on Launch HN: Chert (YC P26) – Twilio for iMessage
YC also funded Sendblue which does something similar: https://www.ycombinator.com/companies/sendblue

It looks like a straightforward ToS violation to me as well. I guess it's another "ask forgiveness, not permission" move.

bobbiechen··on Software Internals Book Club
Sending emails that bounce is a really good way to increase the chance that your subsequent emails end up in spam.
bobbiechen··on Temu is advertising filet mignon on X
I remember in 2021 or so there was a startup doing 20 minute grocery delivery in SF, $50 off on your first order.

I got some really nice steaks for free and the delivery actually arrived via motorbike in 10 minutes. They must have had delivery drivers waiting with their own inventory or something. Anyways, the VC funding dried up and the company was gone a few months later.

bobbiechen··on The Upper Middle Class Trap
I too hate this word. It is usually used where hectomillionaire should be.
bobbiechen··on Google Cloud fraud defense, the next evolution of reCAPTCHA
Yeah, I had the same question myself. I think that's what you would want to do to make it airtight (plus some amount of rate limiting or flagging for devices that are part of dedicated device farms).

But even if not, there's still value in raising the barrier to entry. For example, you can buy 1000 reCaptcha solves for $1-2 from various captcha-solver services. And yet that $0.001-per-request fee does discourage mass-scale bot attacks.

Page 1 of 14Next →