1,399 karma · joined March 25, 2012
What happened to Allen here sucks. I've messaged the team so we can dig into this specific case. More generally, we know that Slides needs to be bulletproof when presenting, and nothing less than that is acceptable.
As an FYI, we _do_ use Figma Slides internally for pretty much everything, from internal meetings to major events. As a PM I use it every week, and our internal feedback channel for Slides is super active with folks like me requesting improvements. Figma is also a pretty unique place, where it's more likely our senior leadership request quality improvements than chase for deadlines - we know how critical the user experience is. We don't always get it right, but when we don't we're committed to fixing it.
Do you have recommendations for folks who can only do a shorter trip (say, a long weekend, or a week)?
If your company just wants alerts when their keywords are mentioned on social media then mentions.us should work great for them. If you work for Coca Cola then you likely need something very different from your social listening tool!
I’m not optimising to extract every possible $ from the market with that pricing strategy. Instead I hope it will maximise the number of users whilst breaking even on costs.
Interesting feature request! I’ll have a think on it.
For LinkedIn monitoring we use the voyager APIs. It’s not perfect because it gets posts but not comments, but it’s pretty good.
I do have a paid plan for people who want Slack notifications, and I think those folks ought to be happy to pay. My hope is that I'll eventually get a few paid signups and that those will cover the costs of the service (which are minimal).
I know I lose a bit of revenue with the above approach, but it's a tradeoff I'm happy to make.
It's been a fun project. Dealing with the scale of Reddit (~300 posts/second) creates some interesting technical challenges. It's also let me polish up my frontend development skills.
I don't think it will ever be a money spinner - it has ~70 folks using it buy they're all on the free tier. It's felt really good to build something useful, though.
[1]: https://mentions.us
* Reported to the maintainers privately
* Patch published and CVE issued before wider disclosure
* Automated fix PRs created within minutes of public disclosure (and for folks doing proactive updates, before)
The above is _really_ excellent. Compare that to Log4j, which no CVE and no patch at the time it became public knowledge, and it's clear we've come a long way.
Supply chain security isn't a solved problem - there's lots we can still improve, and not everything here was perfect. But hats off to @leerob and everyone else involved in handling a tough situation really well.
Solopreneurs are amongst the most resourceful folks out there, and also the most price sensitive, so we're a tricky market to go after.
Right now I'm working on adding LinkedIn support now (trawling through private APIs).
My plan over the next couple of months is to build the option for users to enter the kind of things they want to scan for, have AI convert that to keywords, use the keywords for the (fast) scanning, and then apply additional filtering using AI to the small number of posts that match.
Not built yet, but I think there's a bunch of promise to using AI to find relevant conversations online.
Re: APIs, yep, all APIs. I'm not doing any web scraping at the moment
It has taken a couple of months to go from idea to a product that's polished enough for other people to use, and I've been full time on it. It has a couple of dozen companies using it now, almost all from the last couple of weeks. That's been a big boost!
However, if you learn well by doing, or by reading, there are loads of other great ways to improve technically. I’ve made big leaps forward in my skills by building (relatively large) side projects, where I can safely experiment with different design decisions and see the consequences over time. I’ve also got a huge amount out of just sitting down and reading the docs for tech I’m interested in - some frameworks (like React) have fantastic resources that can take you from good to great.
Good luck!
Pincites is automating contract review with AI. We integrate with Microsoft Word to help in-house legal teams review and redline contracts faster. You can read more at pincites.com.
We're early stage (YC S23), growing fast, and are looking for engineers who are excited about building the next generation of legal tooling. We write a lot of Go and TypeScript (with React) and are currently looking for an experienced frontend developer.
GitHub has really focussed on preventing credential leaks. It's particularly good at scanning for highly identifiable patterns and preventing pushes that include them. That makes sense for GitHub: they're in the best position to prevent leaks (by rolling out push protection to all users) and they're big enough to influence the industry to switch to using highly identifiable patterns for API keys. However, it's at the expense of scanning for unstructured secrets (like passwords) where GitHub isn't as deep yet.
TruffleHog has focussed on scanning for credentials _after_ they've leaked. They scan for a broader range of things (including unstructured secrets like passwords). That naturally has a higher false positive rate, which they combat by automatically verifying some of their findings (by making requests to the corresponding services). GitHub does that too (for patterns it can't push protect) but it hasn't gone as deep on it yet. The delta is relatively small, though - as you can imagine, it's a long tail of patterns / credential types.
Right now there's space for both solutions - you want prevention when you can get it (without creating a bad developer experience with false positives), but you also want breadth. In the long run, though, GitHub is probably better positioned to offer both.
For context, about 200 new GitHub personal access tokens (PATs) are exposed in public repos every day, together with many more tokens from other providers. GitHub automatically revokes the PATs it finds, and notifies many partners if/when keys to their services are found, but we always felt it would be better to prevent the leaks from happening in the first place.
AI has definitely made it easier to generate more plausible-looking spam, and removed one way to easily identify bad accounts, but it hasn’t changed the underlying behaviour differences that put a lower bound on how bad the problem can become (as long as GitHub has the team and tools in place to use them in defence).
https://web.archive.org/web/20160811170408/http://www.coned....
FWIW, I think it's worth clarifying that PyPI is already involved in malware detection and takedowns (as are almost all the package registries). The curation that commercial vendors offer is a little more nuanced than excluding known malware (for example, allowing users to restrict their downloads to a "known good" set of packages, rather than "only" excluding "known bad" ones).
(It's worth noting that any secrets in your Actions secret store will already be redacted in any Actions logs, so those won't leak there.)