HNHacker News
TopNewBestAskShowJobs

nfm

1,293 karma · joined March 24, 2011

Co-founder and CTO of Lyssna (https://lyssna.com). Previously co-founded Paydirt (https://paydirtapp.com).

You can get in touch with me at nicholas@lyssna.com.

submissionscomments
nfm··on Tech employment now significantly worse than the 2008 or 2020 recessions
100% this. AI is automating the code generation.

Being able to clearly describe a problem and work with the AI to design a solution, prioritise what to put the AI to work on, set up good harnesses so the quality of the output is kept high, figure out what parallelises well and what’s going to set off agents that are stepping on each others toes… all of this needs experience and judgement and delegation and project organisation skills.

AI is supercharging tech leads. Beginners might be able to skill up faster, but they’re not getting the same results.

nfm··on How will OpenAI compete?
Google Search has no stickiness and they managed to build a behemoth.

ChatGPT is a great product, but the lack of stickiness comes into play because there are many viable alternatives.

They’re all going to have to monetise the consumer segment at some stage, and I think that’s likely to be via ads on a freemium tier in most instances.

nfm··on Turn Dependabot off
The number of ReDoS vulnerabilities we see in Dependabot alerts for NPM packages we’re only using in client code is absurd. I’d love a fix for this that was aware of whether the package is running on our backend or not. Client side ReDoS is not relevant to us at all.
nfm··on A16Z AI Voice Update 2025
I dunno, that seems a bit narrow minded to me. You're making an assumption about talking to AI being a worse experience than talking to a person (which is frequently _terrible_).

What if you were able to get helpful support, 24/7/365, with no time waiting in a queue, in your own language (regardless of the service provider's location and 'native' language support)? And the company was able to provide the product and support for it cheaper, resulting in less cost to you?

We're far from there, but I expect it'll happen.

nfm··on Traffic spikes are bad for your product
My take is that they’re not necessarily harmful in and of themselves, but it’s absolutely harmful to think that this is the way to grow and get traction. It’s not a repeatable approach and it’s likely to pump some top of funnel metrics temporarily without having meaningful impact to the bottom line.

This can be very distracting if you’re pursuing it intentionally and treating ‘going viral’ as a prerequisite to success.

nfm··on Thank HN: My bootstrapped startup got acquired today
Annual growth rate is typically a big factor in PE acquisition multiples. At a 4x multiple of ARR, I’d hazard a guess that this was on the lower side.
nfm··on Introducing S2
List pricing is $0.05 per GB after 150TB and at high volume it’s cheaper than that
nfm··on Gaining access to anyones Arc browser without them even visiting a website
From the quoted snippet, every page load is leaking both the domain and authed user’s ID to Firebase.
nfm··on AutoCodeRover: Autonomous Program Improvement
I agree in principle, but if it also generated a test, how would you know that was valid?

The value I get from copilot is the ability to code faster, not the ability to code.

nfm··on Show HN: Online database diagram editor
DBML (https://dbml.dbdiagram.io/docs/) is the only thing I've seen in this space.
nfm··on More product, fewer product managers
What kinds of products were those teams building?
nfm··on Additional critical Metabase security vulnerabilities announced today
Metabase announced a patch release for a critical vulnerability a little over a week ago: https://www.metabase.com/blog/security-advisory

Today they have announced further, related vulnerabilities, and if you're running your own instance you should patch again, or disable your instance until you have a chance to do so.

The vulnerabilities allow an unauthenticated attacker to run arbitrary commands with the same privileges as the Metabase server on the server you are running Metabase on. This would allow arbitrary querying of any database that Metabase is connected to.

nfm··on Migrating from Supabase
https://www.postgresql.org/docs/current/app-pgdump.html

> pg_dump is a utility for backing up a PostgreSQL database. It makes consistent backups even if the database is being used concurrently.

nfm··on Ask HN: Who is hiring? (April 2023)
UsabilityHub | Engineering | Remote (Australia or New Zealand) | Full-time, 9 day fortnight, or 4 day week | https://usabilityhub.com/careers

Hey HN, Nick here, CTO and co-founder at UsabilityHub.

We're looking to hire a couple of engineers, with some flexibility on seniority level. We're a remote first and cross functional team, and UsabilityHub is a bootstrapped and successful business that's been focused on sustainable growth over the last ten years.

The team is small, close knit, and has some really excellent engineers and designers. The focus of these roles is building new customer facing functionality - we're effectively building three new products this year so there's lots of greenfields work to do.

The big pieces of our tech stack are Ruby, Rails, Typescript, Postgres. We're not fussy if you haven't used some or any of those, but prefer T-shaped developers that are keen and able to pick new things up quickly and contribute throughout the stack.

For the three roles we have open, starting compensation ranges from $120k AUD to $160k AUD (or NZD equivalents) plus ESOP and profit share. We review this every six months and adjust upwards based on performance in the role.

There's lots more info about these specific roles on our careers page at https://usabilityhub.com/careers. Feel free to reach out to me directly with any questions (email is in profile).

nfm··on Employees are feeding sensitive data to ChatGPT, raising security fears
Yep: https://openai.com/blog/march-20-chatgpt-outage

Some kind of concurrency bug in a library they were using to retrieve cached data from Redis led to this leak.

> We took ChatGPT offline earlier this week due to a bug in an open-source library which allowed some users to see titles from another active user’s chat history. It’s also possible that the first message of a newly-created conversation was visible in someone else’s chat history if both users were active around the same time.

nfm··on Twilio’s toll fraud problem
Surely they can aggregate this across all customers though.

If Twilio cops an unexpectedly high settlement for sending an SMS to +1234567890 in January, can they assume that a separate customer sending an SMS to that number in February will end up in the same boat?

I'd be very surprised if the toll fraudsters weren't using the same numbers to hit multiple Twilio accounts.

nfm··on Twilio’s toll fraud problem
Solving this is squarely Twilio's business!

They know how much to bill the customer, so they must know how much it costs to send to a number.

nfm··on Soft deletion probably isn't worth it
Yes, but other queries (any aggregate queries that don't join the soft deleted table, any joins to other tables) will now return rows that would have been deleted under hard deletion with cascade.
nfm··on Ruby 3.1
For diff, see: https://github.com/ruby/ruby/commit/a91605c9dafe70a95a1c4a02...
nfm··on The Google home page is 500K
> Performance only matters if you are in competition with others.

I'm not sure that's right. There's a strong link between performance and repeat usage. Even in the complete absence of competition, Google search being fast could result in more searches per user being conducted and more revenue as a result.

nfm··on Security issue related to the NPM registry
Because this is buried in the post and people don't seem to be grokking it:

> Second, on November 2 we received a report to our security bug bounty program of a vulnerability that would allow an attacker to publish new versions of any npm package using an account without proper authorization.

They correctly authenticated the attacker and checked they were authorised to upload a new version of their own package, but a malicious payload allowed the attacker to then upload a new version of a completely unrelated package that they weren't authorised for. Ouch!

nfm··on It’s hard work to make ordering groceries online so easy
I used to pack shelves for a supermarket and I believe at the time (~15 years ago) we had a two hour window in which perishables could be out of the fridge. Usually we'd wheel out pallets from the stockroom fridge or freezer onto the floor, move all the boxes off the pallet into their rough locations on the floor, and then pack each box into the fridges sequentially (effectively batching up the sorting/locating/carrying work). If stock sat on the floor without getting into the fridge for more than two hours, or in the rare occasion there was a power outage and the fridges or freezers were out for more than two hours, stock had to be written off.

All that to say the allowed timeline might be longer than you expect (or desire)!

nfm··on "Equal pay for equal work" in remote jobs
It shouldn't be a question of cost of living. Companies pay significantly more (or less) in local markets because of supply and demand in those local markets.

Historically those markets have been localised due to the fact that few companies employed full time remote team members, and relocating countries is intentionally made difficult and expensive.

If we see a sustained transition where a significant percentage of companies (even in just particular industries) support full time remote work, we should expect to see supply and demand for talent in that market to become less localised (time zones are still a thing, and full time remote is different to full time remote _and_ distributed).

If that plays out, you'd expect locations with historically lower compensation to get a bump (regardless of cost of living), and locations with historical higher compensation to get a reduction (again, regardless of cost of living).

Companies don't care what your expenses are per se. The valley is an intensely competitive hiring market which forces up compensation, which in turn forces up cost of living - housing supply is very finite and many people living there have lots of disposable income.

nfm··on Stripe migrates Stripe Subscriptions users to more expensive Stripe Billing
Thanks for replying, I'm very excited to hear it's in the works!
nfm··on Stripe migrates Stripe Subscriptions users to more expensive Stripe Billing
Long term Stripe customer across multiple companies here.

I'm ok with paying for services like this that provide loads of value. I expect there's increasing diversity in terms of Stripe's customer base and how they use the product, and trying to pick a single percentage price point that works across all of them is no longer feasible.

That said, I'm quite unhappy with Stripe's pricing as an AU customer. We're paying exorbitant rates to convert USD to AUD (think retail bank rates despite transacting multiple millions a year, ~3x what we'd pay Transferwise). There's no option to settle in USD, and a lot of our expenses are in USD, so we then pay another currency conversion fee when we spend.

It's problematic to the extent that we're considering whether the ongoing costs and hassle of setting up a US entity, dealing with international tax, compliance, parent companies etc. would be worthwhile.

nfm··on Meeting everyone on a new team
At the exec level, a good 70-80% of your time is probably unable to budge, so 25 hours of discretionary time _is_ a big investment - probably most of your discretionary time for a calendar month. It sounds like it was well worth it though.
nfm··on 1Password for Linux development preview
I'm a happy 1password customer on Linux using the browser extensions. What advantages does a native client bring?
nfm··on Ask HN: Who is hiring? (December 2019)
UsabilityHub | Melbourne, Australia | Senior Software Engineers | Full-time | Onsite

UsabilityHub is hiring senior engineers to join our team in Melbourne. If you’re not familiar, we help businesses (including Amazon, NASA, and Reddit) be more human-centered by making user research easy to conduct and fun to participate in.

We’re a bootstrapped, profitable, and sustainable company, with a focus on building great products, not chasing growth for the sake of it.

Ideally you’re a generalist who is capable across back-end (Ruby, Rails, Postgres) and front-end (Typescript, React, Redux, Webpack), but if you specialize in one area and are still getting up to speed in the other, don’t let that dissuade you from applying. It’s more meaningful to us that you’re a great developer and a keen learner.

We’re offering…

- Competitive salary

- Employee profit sharing

- Choice of working 4 day week, 9 day fortnight or full-time hours

- Flexibility around working from home

- Generous paid parental leave (14 wks primary / 6 wks secondary)

- Warm, friendly and relaxed team

For more info, and to apply, see the full job listing: https://usabilityhub.com/careers/senior-fullstack-engineer

nfm··on Ask HN: Who is hiring? (November 2019)
UsabilityHub | Melbourne, Australia | Senior Software Engineers | Full-time | Onsite

UsabilityHub is hiring senior engineers to join our team in Melbourne. If you’re not familiar, we help businesses (including Amazon, NASA, and Reddit) be more human-centered by making user research easy to conduct and fun to participate in.

We’re a bootstrapped, profitable, and sustainable company, with a focus on building great products, not chasing growth for the sake of it.

Ideally you’re a generalist who is capable across back-end (Ruby, Rails, Postgres) and front-end (Typescript, React, Redux, Webpack), but if you specialize in one area and are still getting up to speed in the other, don’t let that dissuade you from applying. It’s more meaningful to us that you’re a great developer and a keen learner.

We’re offering…

- $120-$132k AUD base salary (FTE) + super

- the option to work 0.8, 0.9, or full time

- the option to regularly work from home

- generous paid parental leave (14 weeks primary / 6 weeks secondary)

- profit share scheme among employees

- a warm, friendly & relaxed team

For more info, and to apply, see the full job listing: https://usabilityhub.com/careers/senior-fullstack-engineer

nfm··on Malicious remote code execution backdoor discovered bootstrap-sass Ruby gem
A high dependency count does increase your vulnerability surface area. All it takes is one weak or reused password on an account without 2FA enabled for a malicious package to be uploaded. You're more vulnerable to this when you depend on more individual publishers to get it right.
Page 1 of 9Next →