HNHacker News
TopNewBestAskShowJobs

caloique

13 karma · joined August 22, 2018

Co-Founder & COO @BoxyHQ | Investor | Strategist | Former clown| Ex @Amazon | Open-source SAML SSO & Audit Logs
submissionscomments
caloique··on We built the fastest CI and it failed
Co-founder of BoxyHQ here - We've crafted an open-source enterprise SSO because we firmly believe that robust security shouldn't be a privilege limited to large organizations. Ideally, essential enterprise-level features like this should become commonplace for all.

While we acknowledge the reasons behind SSO being in the enterprise tier, we're all on a collective journey to enhance our security measures. Open Core models are indeed a good option (my preference), yet the dynamics vary across solutions and industries. It's up to each of us to explore, experiment, and discover what resonates with our market. In doing so, we can foster growth while maintaining our commitment to supporting the community in the long run.

caloique··on Supertokens: Open-Source Alternative to Auth0 / Firebase Auth / AWS Cognito
Supertokens also allows you to implement enterprise SSO through their integration to SAML Jackson (by BoxyHQ).

https://boxyhq.com/guides/jackson/integrations/supertokens

caloique··on [dead]
Reading this blog post made me think if there are other options for open source companies to generate revenue.

Besides Donations, Support, Licensing, Cloud-hosted Services or the Open-core model.

Any ideas/suggestions? And which one would you recommend (ideally based on experience)?

caloique··on Ask HN: What books helped you in your entrepreneurship journey?
1) The richest man in Babylon 2) The four agreement 3) Secrets of the Millionaire Mind
caloique··on Show HN: Open-source – Add Audit Logs to your SaaS app
Hey everyone, Retraced is an audit logs OSS product, that was initially built by Replicated and it has been enhanced by BoxyHQ.

With it you can now give your users the superpower to track every critical event within your product, and get full visibility over their account’s activities on your app. You will also allow them to send security-related events to their SIEM. It would be great to get your feedback.

Key features: - Compliant audit logs for your product - Record user and system activities - Admin UI to view logs. Also embed the viewer anywhere in your product - Export events to CSV or security systems like your favourite SIEM - Cryptographically guaranteed immutability of logs with a verifiable digest

caloique··on The Magic of Growing Trees (2021)
Plus one! I was recommended the book "The Hidden Life of Trees". Did anyone read it? Any related articles, please share :)
caloique··on Ask HN: Do developers care about security?
Thanks for the insights, have you seen any good practice (tips) on how 'security mechanisms for development' could actually help security teams and developers work smoothly? Instead of being the reason for conflict.
caloique··on Ask HN: Do developers care about security?
Interesting point, and why do you think is that?
caloique··on Penpot, Open Source Figma alternative, raises $8M in funding
Pricing is one aspect, but OSS solutions bring community and a level of transparency that most closed source companies don't.
caloique··on SaaS services behind a startup
Sounds like BoxyHQ could be relevant here. Plug-n-play for developers that need to build enterprise features like SSO, audit logs, directory sync, privacy vault and other boring stuff that are required to be compliant.

100% free & self-hosted. It's Open source (Apache-2.0 license) [I am one of the co-founders, sorry for the plug]

caloique··on Show HN: Open-Source Intercom with Help Center
Found it here: https://www.chatwoot.com/pricing

@pranav_rajs I couldn't see some enterprise-grade features like audit logs or privacy vault. Would love to help for free. Open source & plug-n-play: www.boxyhq.com

caloique··on Show HN: Enterprise-Ready SaaS Starter Kit
Enterprise-ready SaaS Starter Kit is a Next.js based SaaS Starter Kit that can save hundreds of development hours while building enterprise SaaS apps.

Even though there are many similar projects out there, focusing on the enterprise readiness aspect could help developers save some time. It still is in an early stage of development, that's why feedback would be great!

Github: https://github.com/boxyhq/saas-starter-kit

caloique··on Don't compare yourself to other entrepreneurs
Agree, I think it is impossible not to compare with others. I don't think you always have to "walk back from it", sometimes is good to achieve your goals, the challenge is doing it in a healthy way.
caloique··on A development process to ship features fast
Fair point, but going through the comments, I'm not trying to sell anything. One is reframing the suggested question and sharing a consolidated list of resources. The other two are on a free tool (not suggested before) to solve the problem stated, so the aim was to expand the options. But point taken ;)
caloique··on A development process to ship features fast
This is counterintuitive because the more productive your development team is the more security holes they will leave behind. The thing is how to keep the productivity while increasing the security.

Here is a list of OSS developer security tools: https://github.com/boxyhq/awesome-oss-devsec

caloique··on The many problems with implementing Single Sign-On
https://github.com/boxyhq :)
caloique··on The many problems with implementing Single Sign-On
Not necessarily, there are actually 3 options: Buy vs Build vs Use OSS :) > https://github.com/boxyhq/jackson
caloique··on The many problems with implementing Single Sign-On
Curious to hear more about other alternatives to building it internally, lately I've heard a few people claiming that they built it in 1 - 2 days. Still don't know how.

There are good open source solutions that let you plug and play these enterprise features (I am biased here). But instead of thinking about the problems with implementing Single Sign-On, I think we should focus on a bigger problem: How can we make security accessible and simple for developers? I am not saying don't charge for SSO, I know it helps startups be sustainable, but here is where I truly believe that open source is one of the key answers.

caloique··on The many problems with implementing Single Sign-On
Indeed, people forget about the cost and pain of supporting these things. For full disclosure, I am a co-founder @BoxyHQ, an open source devtools startup providing free enterprise SSO (called SAML Jackson), directory sync (beta - feedback is welcome), audit logs and so on.

Pricing is tricky, and as you said, people complain a lot. Since this is because we all have different points of view, we will never agree. But there are some things that most of us should agree, like the fact that we need to raise the security standards. Then the question is what we can do as a community - besides trying to avoid being on the sso.tax list.

caloique··on Event: Security for Developers
Do you know other relevant events for Developer-first Security?
caloique··on Show HN: Open-source Developer Security tools
Thank you for sharing it alek_m! Still early days but we are building this list of awesome open-source Developer-first Security tools to help the community. We’d love your feedback and contributions if possible. > devsecmesh.boxyhq.com

And if you are passionate about Developer Security (DevSec) it would be great if you could join our Discord community: https://discord.com/invite/uyb7pYt4Pa

caloique··on Be enterprise-ready: reasons not to build enterprise features
Cool insights, thank you for taking the time to go deeper. I'll share it with the team to explore further. Good vibes!
caloique··on Be enterprise-ready: reasons not to build enterprise features
Indeed, thanks for sharing! We will take a look at it, sounds interesting.
caloique··on Be enterprise-ready: reasons not to build enterprise features
Fair point, thanks for bringing this up. Never thought of it as a distraction, but I will consider it for my next blog posts. But please bare with me; I used to be a profesional clown (no joke), so I'm usually fooling around :)
caloique··on Be enterprise-ready: reasons not to build enterprise features
I understand why it's perceived as a narrow definition, and your point makes totally sense, usually we as startups think of our own product as a pain killer, but there is an end to end bigger problem for the enterprise and our solution is just a piece of it.

We are initially focused on common undifferentiated enterprise features, but this is just the first step, we have broader plans for developer-first security tools.

caloique··on Be enterprise-ready: reasons not to build enterprise features
Would love to hear more about the "framework for managing workflow / action assignment & tracking" that you are looking for. Could you please elaborate a bit more?
caloique··on Be enterprise-ready: reasons not to build enterprise features
I just read your blog post and found it interesting; thanks for sharing it. I'm one of the co-founders at BoxyHQ, agree that there is more to it, enterprise requirements are always different, some certifications could be standard but if you double click each enterprise has its own complexities.

From our side, we have started with these features since we have seen they are common pain for early-stage startups, but in terms of our vision, we are focusing on developer-first security tools. And we believe that there are many opportunities to help close the gap between compliance and security.

caloique··on Be enterprise-ready: reasons not to build enterprise features
That's a good point; at @BoxyHQ we experienced the same in the past and we are open source for this specific reason.
caloique··on Show HN: BoxyHQ – open-source alternative to Auth0/WorkOS
> Our core will always be free (Apache 2.0 license) and our commercials will be based on the following models: 1) A hosted solution in the future 2) Premium features on top of our core (To ease deployment, administration and integrations with Enterprise security products) 3) Vertical specific solutions for regulated industries like Healthcare and Finance.