HNHacker News
TopNewBestAskShowJobs

caydenm

130 karma · joined April 1, 2012

submissionscomments
caydenm··on Keeping our free tier sustainable by preventing abuse
I was referring to generated or disposable card numbers rather than stolen. maybe that is the confusion?

An concrete examples of converting a user using these types of cards for free trial abuse is a user who signed up 8 week in a row using different emails, names, IPs and cards. Nudging of these users was enabled and on trying to sign up for their 9th trial they immediately switched back to their original account and converted at full price.

caydenm··on Keeping our free tier sustainable by preventing abuse
100%! This was easy and now it is frustrating to get to the thing they want, the service, and the easiest route is to pay.
caydenm··on Keeping our free tier sustainable by preventing abuse
There are obviously people who are doing free trial abuse for commercial gain eg. Signing up 1k accounts to get test credit cards or to resell accounts. They are not going to convert (although sometimes you can successfully convert them into affiliates)

We have seen individuals just trying to get free accounts week after week, who when nudged once pay immediately thousands of dollars even after using fake, stolen or empty cards.

These individuals think they are being cheeky and when they are 'caught' they revert to doing the right thing.

caydenm··on Keeping our free tier sustainable by preventing abuse
Free tier and free trial abuse is a huge problem, but also a huge opportunity.

We have seen customers where free tier abusers created 80k+ accounts in a day and cost millions of dollars. We have also seen businesses, like Oddsjam add significant revenue by prompting abusers to pay.

The phycology of abuse is also quite interesting, where even what appears to be serious abusers (think fake credit cards, new email accounts etc.) will refuse a discount and pay full price if they feel they 'got caught'

caydenm··on 10 Second Teleportation
OP here, I was trying to say that these pages were behind an authwall and loading with userids from a specific user but without any of their cookies to support that auth.

This led us to believe this page was MitM rather than crawled directly (as they would not be able to impersonate the user)

caydenm··on 10 Second Teleportation
This looks exactly like it!! Nice find!
caydenm··on 10 Second Teleportation
Josh on our team is so happy people discovered and liked his easter egg!
caydenm··on 10 Second Teleportation
Browser extension is what we originally thought for exactly the same reasons you did. We started to see some requests show up from iOS devices which didn't support extensions so that made us think MitM corporate proxies.

The diversity of cloud networks looks to be due to these being deployed by individual institutions (eg. universities, corporations etc.) rather than only run from Palo Alto Network's data centers.

We also saw slightly different configurations with different browser versions, but with the same pattern of behaviour.

caydenm··on 10 Second Teleportation
That was on my list of candidates as well! Those usually have a specific user agent making it clear what they are, they appear from a companies netblock (eg. Facebook, Microsoft) and cannot access authed pages (unless the key is in the url).

In this case these appeared to be all MitM'ed pages from a security device since the key wasn't in the url and it contained userids for a specific user.

caydenm··on 10 Second Teleportation
Exactly! Our library is embedding in these pages and similar to Segment or other analytics tools will get told information about user events from that state. Sometimes that state is stored in the page that is sent over the wire (eg. userid) and as such we get a request saying a particular user is on the other side of the world.
caydenm··on 10 Second Teleportation
It appears this is to find threats that might have no otherwise triggered or work out is particular sites are dangerous without monitoring a users machine.

It is scary that for people in a corporate environment this could be rendering banking, messaging or any other pages contents.

caydenm··on 10 Second Teleportation
I thought I messed it up! I had no idea this was a thing.
caydenm··on Ask HN: Are job referrals worthless now?
The strength of a referral, the proximity and seniority of the referrer and role fit all come into play.

A strong referral by a knowledgeable person often skips that person to the front of interview queue. I have hired a number of people based on referrals from team members, VCs and previous coworkers.

Many referral systems have a how good do you think this personal really is field and often an option for "I don't know this person that well I am just referring them to say I did".

If you are asking for a referral, make it as easy as possible for the referer to make you look great. They probably don't remember all your awesome work like you do, so make sure you give them simple impactful points.

caydenm··on Making product friends and influencing the roadmap
I have spent most of my career as a product person before becoming a founder and one of the things I saw was a disconnect between sales and product.

The right feedback wasn't getting to product, so the right problems weren't getting solved and sales and customer success teams weren't feeling heard or empowered to get things fixed.

I wrote this as a bit of a guide on how I have solved these problems in the past and hopefully it will help others do so too.

Found something that works well? I would love to hear about it

caydenm··on Visualizing Account Sharing
We are excited to share some rare behind the scenes from some of the tooling we use to evaluate account sharing.

Happy to answer any questions

caydenm··on How companies like Linear and Miro design for team growth
https://www.datocms-assets.com/65181/1662686325-iconiq-analy...

Is the correct one. I will fix in the original, Thanks!

caydenm··on How companies like Linear and Miro design for team growth
One thing this article doesn't mention is that if you start with a 'single-player' environment it can be hard to get people to change to 'multi-player'.

Not only because of habits, but also because people have set it up just for them and they feel they need to tidy it or make it good enough to share with others.

Having a very clear delimitation between what is a persons and what is a teams/organization is really important when moving from single -> multi.

I would love to hear what things people have found worked really well too!

caydenm··on How we discovered and dealt with someone impersonating our company
Yesterday someone tried to impersonate my company, Upollo. They cloned our site, had an upollo.tld domain and had also signed up for services under our business name.

I wanted to share how we dealt with it as apparently this is happening to a lot of companies and there isn't a good guide on how to deal with it.

caydenm··on Show HN: Free Segment company data enrichment
You can also see details on Segment here: https://segment.com/docs/connections/destinations/catalog/ac...
caydenm··on Ask HN: Why doesn't Stripe allow you to get BIN numbers?
Thanks for the quick reply Sam! We use them for purposes outside of fraud. Happy to chat more about our use case if that helps.

I was hoping there was a private API to support access?

caydenm··on Netflix loses 1M users in Spain over password policing
Netflix had some great quotes about this from their earnings and specifically called out Kantar's data would show less viewers in the short term.

They had noted they saw or expected the users who were on someone else's account and who used it actively to come back with their own accounts or convince the account holder to pay for them

I did more of a write up based on what they are shared in their earnings here: https://upollo.ai/blog/learning-from-netflixs-earnings

caydenm··on What we can learn about password sharing from Netflix's earnings
Would you ever have the family member pay instead of you paying?
caydenm··on Ask HN: Are Yearly Subscriptions Hard?
Are you charging yearly in advance or charging monthly but on a yearly contract?

To answer your question, yes they are hard, but they make sense from a retention and overall revenue perspective.

caydenm··on Falsehoods programmers believe about signup pages
@cratermoon, out of interest what is the biggest negative impact you have seen from this?

I have seen a lot of people suggest blocking all free email domains or only supporting a small subset of whitelisted domains, I expect businesses to see pretty quickly that they lose a decent percent of legitimate signups.

The legitimate signups being the good measure as if you are filtering out disposable emails for instance you will lower your overall signups but should have no negative impact on revenue (potentially positive as people who would signup with disposable accounts now signup with accounts you can contact them on and they are happy to convert to paying with).

We try to make this easy be doing email validation for free at any scale and only flagging the people we are sure are not valid (disposable, unreachable domains etc.)

caydenm··on Falsehoods programmers believe about signup pages
Is that this W3C page you were talking about? https://www.w3.org/International/questions/qa-personal-names

Great resource and definitely soon good things to add in for names, especially around changing them

caydenm··on Falsehoods programmers believe about signup pages
Inspired by Falsehoods programmers believe about phone numbers[1] and Falsehoods programmers believe about emails[2].

We wanted to share some of the data we have seen from analyzing signups at scale and insights from great companies like Hubspot.

It is by no means complete, so please share anything you believe is missing.

[1] https://github.com/google/libphonenumber/blob/master/FALSEHO... [2]https://beesbuzz.biz/code/439-Falsehoods-programmers-believe...

caydenm··on What is a good activation rate?
Activation, if done correctly, strongly correlate with long term retention and are very useful for experimentation where you don't want to wait 30 days for a result.

Activation rates make sense when you look at them as what does a user have to do to get value out of the product? It might be connect a bank account for an accounting tool or complete a social post for a tool like hootsuite.

Choosing the right one is important as you will start shaping your entire funnel to get users to complete that action and if it is only correlation and not causation you may find it leading the product in the wrong direction

caydenm··on Ask HN: Who is hiring? (November 2022)
Upollo | Engineering, Marketing & UX | Full-time | Sydney, Australia or Remote (± 3hrs AEST)

Upollo accelerates subscription businesses growth by turning repeat sign-ups, account sharers, and more into happy paying customers with unique user insights.

We are looking for graduate/junior engineers and our first marketer and designer to join an amazing team who has previously built amazing things at Google, Canva, Uber and Atlassian.

Reach out at (jobs at upollo dot ai)

Relevant keywords include: Go, GRPC, Typescript, ML, Data Science, GCP, low latency, Product led growth, product led sales

caydenm··on How to offer effective free trials
Thanks for all the comments and for sharing your experiences as well.

We are writing up some content about free tiers as a follow up based on the feedback we got from this thread. Looking forward to sharing it.

We just shared a follow up article on how to deal with repeated trials that expands up on what we included in this article

https://news.ycombinator.com/item?id=32696631 https://upollo.ai/blog/when-users-repeat-trials

caydenm··on How to offer effective free trials
We weren't as clear as we should have been here. Apologies for that!

The total number of subscribers you get at the end or total ARR is the key metric as you say, trial to paid is an important metric that goes into that analysis and is a good leading indicator.

You are 100% right that more friction makes people more likely to bail, lower the number of people who start a trial.

Credit cards in particular are an interesting one, because you are effectively asking people to sign up twice if you don't require them for the trial. Once when they create an account and again 7 or 30 days later when the trial ends.

That friction being added for people to continuing to use the product has worse outcomes that getting the friction out of the way up front.

Page 1 of 2Next →