HNHacker News
TopNewBestAskShowJobs

protoduction

863 karma · joined November 10, 2014

https://guido.io, e-mail me at me@guido.io.

Co-founder and CTO of https://friendlycaptcha.com.

Github: https://github.com/gzuidhof

submissionscomments
protoduction··on Ask HN: What are 100K dollar ideas but not million dollar ideas?
I think the main direction of $$$K dollar ideas are those in the area of consulting, do those count? It can scale well beyond that, but at that point you're an agency.

I believe that coming up with product ideas that can work at the indie level (bootstrapped/without raising millions) is a matter of training, validating the idea is the hardest part (and not falling into the trap of building it first). The main target of those ideas is often something that can sustain you with under a hundred customers, which rules out building a new social network.

One idea I had recently is on the edge of consumers and businesses: it might make sense to have groupon-like websites for niches. These could be geographical, or around a certain activity. For instance if you are into craft beer, why not create a "deal" website for it? Call up shops that sell brewing equipment, walk in to local bars and ask if they would like to come up with some craft beer tasting event. The model is here that you get a kickback if people take you up on your offers. The more niche the better.. It could be as specific as "young parents who love craft beer and live in New York". That sounds like it could be in the 100k range.

A small plug, for fun I've been writing up some ideas that fit this description [0].

[0]: https://indieideas.substack.com/archive?sort=new

protoduction··on Botspam apocalypse
I'm sorry to hear that. We offer free and small plans for small use-cases, but I also understand that some projects don't have a budget at all.

There is a blessed source-available version of the server that you can self-host [0]. It is more limited in its protection, but it is probably good enough for hobby projects.

[0]: https://github.com/FriendlyCaptcha/friendly-lite-server

protoduction··on Botspam apocalypse
I’m the co-founder of Friendly Captcha [0], we offer a proof of work-based captcha since two years or so. Happy to answer any questions.

A big part of what makes our captcha successful in fighting abuse is that we scale the difficulty of the proof-of-work puzzle based on the user’s previous behavior and other signals (e.g. minus points if their IP address is a known datacenter IP).

The nice thing about a scaling PoW setup is that it’s not all-or-nothing unlike other captcha’s. Most captcha’s can be solved by “most” humans, but that means that there is still some subset of all humans that you are excluding. In our case if we do get it wrong and wrongly think the user is a bot, the user may have to solve a puzzle for a while, but after that they are accepted nonetheless.

[0]: https://friendlycaptcha.com

protoduction··on Ask HN: Who is hiring? (August 2022)
Friendly Captcha | Backend and DevOps Engineers | REMOTE (EU) | FULL-TIME, PART-TIME or FREELANCE | Munich, Germany | https://friendlycaptcha.com

At Friendly Captcha we do one thing and we do it well: we protect websites from malicious actors and bots. We are building privacy-friendly and accessible anti-bot solutions that don’t annoy users with tasks like clicking fire hydrants.

We’re a small, growing, profitable company. Our revenue mostly comes from medium to large German-speaking enterprise and governments.

We aim for reliability and simplicity in our stack - and the same goes for our engineering. You can work fully remote or from our Munich office, anywhere between 3 to 5 days per week.

Stack: Golang | Typescript/Vue | Postgres | Clickhouse | Redis | Ubuntu

E-mail me at guido < at > friendlycaptcha.com or fill this form for more information: https://friendlycaptcha.com/company/jobs/apply/

protoduction··on Literate programming: Knuth is doing it wrong (2014)
You might like Starboard Notebook (https://starboard.gg), it's in-browser and mixed multi-language, as well as diffable/version control friendly. (I'm building it).

https://starboard.gg

protoduction··on A state syncing framework based on Vuex and rollback netcode
Sounds really interesting! Is this open source somewhere? Or perhaps you could share some gist to learn from?
protoduction··on Magic Login Is Dead
Given that it's not a commercial product anyway at this point, the plan is to open source the project in its entirety.

If it catches on, and there seems to be a demand for a managed version of it, then I (or someone else) can pick it up again under a different name.

protoduction··on Ask HN: What you up to? (Who doesn't want to be hired?)
I'm not sure yet - but for sure I'll post a link up on https://magiclogin.net (or you could follow me on Github, username @gzuidhof)
protoduction··on Magic Login Is Dead
I didn't want to have any free tier (for now), but also it wasn't worth my time to actually implement payments until I had enough users - a point it didn't reach.

So every user was in a trial that never expired, despite what it said on the frontpage.

protoduction··on Ask HN: What you up to? (Who doesn't want to be hired?)
Half a year back or so I built a mini SaaS product that failed, now I'm in the process of open sourcing it so that everybody can freely host it for themselves. Here's the project homepage https://magiclogin.net, it was/is transactional e-mails and e-mail authentication as a service.

Getting it ready for open sourcing is a lot more work than I anticipated, I don't want to just dump it in a Github repo and have nobody be able to actually use it, so I'm making deployment easier and writing docs on how to run it yourself.

I didn't build the project to make money necessarily, it was mostly a learning project. That doesn't mean that I didn't hope it would be at least moderately succesful financially. But it was a case of "build and they won't come" and my other projects took off much more so I couldn't justify trying to market/pivot it. The final nail in the coffin came when I received a cease and desist letter because apparently a vc-funded auth provider trademarked the term "Magic Login".. So yeah..

protoduction··on Miniflare – Simulator for developing and testing Cloudflare Workers
What I constantly ran into was disconnecting from the server I was connected to and wrangler not being able to handle that. At the time I had a somewhat spotty connection (nothing terrible), but it made wrangler dev very painful - so much so that I ended up writing my own node.js wrapper around it for local development. The lock-in to webpack also isn't great when I am nowadays accustomed to esbuild which is so much faster.

Happy to see miniflare now :)

protoduction··on Ask HN: Care to share your personal site?
My personal site does the job (https://guido.io), it lists some old and current projects and it allows me to post some snippets of knowledge every now and then as a blog. There are a hundred ways I want to improve it, but it is rarely at the top of my priority list.

I started with just some HTML and CSS, and later shoe-horned it into a Hugo template which required some awful custom theme hacks.

> But I'm also curious about what stack was used to make your site. I've looked at static site generators, but none I found felt right to me. I guess it's one of those cases where if there is no clear winner, then the problem hasn't really been solved yet.

It's fairly simple to create your own static site generator in any programming language with different tradeoffs, I think that is one of the main reasons why there are so many out there. It's about the content and your visitors won't care which framework you used anyway - so just pick one and be done with it. You can port your content over if you ever want to switch.

protoduction··on Voila – From notebooks to standalone web applications and dashboards
Check out Starboard (https://starboard.gg, I'm the creator). I think it's exactly what you're looking for (you can use plain dom, html, css, javascript, python).
protoduction··on Voila – From notebooks to standalone web applications and dashboards
You could consider an in browser notebook to get your cost down to near nothing - it depends a bit on what kind of tasks your students do whether they fit in the browser (one wouldn't train a large neural network in one for instance)

There's Starboard (which I'm building, it's built specifically for the browser and can integrate into a larger app deeply) and JupyterLite (the closest you will get to JupyterLab in the browser), either can be a good choice depending on your requirements. Both use Pyodide for the Python runtime.

[1]: https://github.com/gzuidhof/starboard-notebook, demo: https://starboard.gg

[2]: https://jupyterlite.readthedocs.io/en/latest/

protoduction··on Ask HN: Companies of one, what is your tech stack?
I'm the technical founder of FriendlyCaptcha [1], a privacy friendly proof of work alternative to reCaptcha that doesn't suck for end users (and also doesn't need any tracking or cookies so legal/compliance teams like it too). While not a one-man company anymore, I've been the only engineer of it for a long time that I think it qualifies :)

* We use cloudflare workers for our API endpoints which have given us amazing reliability and scalability (which is of course very important for our service)

* We use cloudflare KV and cloudflare cache for some caching and logged in user sessions.

* Mailgun, FaunaDB, Sentry, LogDNA, Stripe, BigQuery.

* The web app is good old server side rendered html and css with a tiny bit of JS here and there.

* The widget is open source, written in Typescript (and as it has to run in really old browsers there's Babel to transpile. The solver inside of it and the proof of work library is AssemblyScript (i.e. WASM), with a JS fallback.

* PHP for our wordpress plugin.

The way we operate is that we provide free (or very low cost) plans for hobby users and stuff like small (wordpress) blogs to hopefully make a dent into recaptcha's market share, it's a bit of a social mission. Larger companies pay for more advanced protection features, EU-only endpoints, (as well as custom agreements and other paperwork). That balance has worked well for us, and even the small customers that use the free service contribute to our protection.

The past half year or so we learned that our customers that bring in the lion share of the revenue really prefer it if we keep their processing and data in Europe (our privacy friendliness and our EU-basedbess are big selling points, even more than improved ux+accessibility). So much so that we are heavily investing into that, and we are slowly moving in favor of our own infra in Hetzner (Germany).

There our tech stack is fully Golang (Fiber framework), with Redis, Postgres and Clickhouse as data stores. The way that our system works is that we look at patterns of access, and we can tweak the difficulty of the proof of work challenge on a request by request basis. One nice property is that it's not all or nothing: if we suspect a puzzle request is from a spammer they will get a rather difficult puzzle which will take a while to solve, but at least it won't lock out any false positives. Clickhouse is fantastic for this purpose (putting in millions of events is not even close to its capacity, it's lightning fast). Of course the widget itself also has the most basic of anti headless browser checks, but that will only deter the most naive spammers.

Of course no captcha system is perfect and will protect against a spammer who is willing to spend real resources (e.g. pay compute, or human labelers) to spam, but so far we're happy with its effectiveness, and it warms our hearts when we receive messages from blind or even deaf-blind users that encountered our captcha and web out of their way to say thank you :). I hope that at some point captcha labeling tasks can be a thing of the past.

[1]: https://friendlycaptcha.com

protoduction··on Show HN: Imnew.to – get added to a group chat with other newly relocated people
Cool idea :), currently this seems to go through Facebook groups mostly - maybe that's a good place to spread the word?
protoduction··on Implement window.{alert, prompt, confirm} removal from cross-origin iframes
I'm building https://starboard.gg, it has the same issue. The iframe is important for sandboxing user code, and alert is often used in tutorials (despite being bad practice, it's intuitive for beginners).
protoduction··on Launch HN: Tavus (YC S21) – AI-generated personalized videos for sales outreach
Maybe it's a silly question, but do you think that putting a small message at the start or in the corner saying it's computer-generated would help or hurt?

I personally would feel it is less manipulative and think of it higher.. but perhaps your goal is so people never find out?

protoduction··on What if JavaScript had a synchronous async flavor?
I'm following hyperscript's development keenly :). I've considered putting together a small hyperscript plugin for Starboard Notebook. Often one simply wants to put together a quick interface with some interactivity, together with lit-html and bootstrap styles this could be really productive.
protoduction··on Show HN: Walking simulator fitness game. Walk to unfold a thriller story in app
This looks great, I would love to give it a try (but I only have an Android phone).
protoduction··on What if JavaScript had a synchronous async flavor?
Thank you for taking the time to explain :)

I completely see that this will break existing code, but I don't see how this is different from the behavior of Go (where the setTimeout code would be something in a different goroutine) or Python?

protoduction··on What if JavaScript had a synchronous async flavor?
You are right that it's a terrible idea (I hope it was clear from the article that it's an experiment and should stay that way), but could you help me understand why this is fundamentally broken?

I would say that by using setInterval you are buying into this kind of behavior and would have to create your own synchronization.

If you are saying that this transpilation step changes the semantics of the code, then I completely agree!

protoduction··on What if JavaScript had a synchronous async flavor?
That's right. And it also makes every function async. Literal expressions are not awaited - a tiny optimization ;)
protoduction··on Mind reading technology: helmet aims to unlock brain's secrets
Having worked on BCI tech a little bit as a student assistant (which were not fNIR based though) there were a few directions:

* Medical settings in which patients are slowly losing the ability to move or communicate, being able to look at a keyboard to type messages to your loved ones or perform basic actions (e.g. turning music on) make a terrible situation a tiny bit better.

* Entertainment/gimmicks: you go to Disneyland and you put on a cap/helmet and suddenly you can interact with objects just by looking at them (they have a flickering light next to them that pulses in a certain binary pattern) - it's like magic.

The second usecase is very difficult today though, the tech that I worked with (+5 years ago) needed to be trained for every new user and a training time of 10 minutes was considered very short. That of course makes the Disneyland usecase more difficult. Also you need to make sure you don't move or blink too much - maybe fNIR has less issues with that.

protoduction··on I want to learn D3. I don’t want to learn Observable. Is that ok?
As someone building an in-browser notebook I have a lot of opinions on notebook environments. Notebooks serve different purposes, sometimes the notebook itself is the end-goal because the author is creating an interactive tutorial or explaining a complex concept with a bunch of visualizations. Observable is a fantastic tool for that, and the kind-of-Javascript reactive programming system it is built on is a great fit for that.

Outside of that use-case, I think notebooks are great for the first 20% of the effort that gets 80% of the work done. If it turns out one also needs to do the other 80% of the effort to get the last 20%, it is time to "graduate" away from a notebook. For instance if I am participating in a Kaggle machine learning competition I may train my first models in a Jupyter notebook for quick iteration on ideas, but when I settle onto a more rigid pipeline and infra, I will move to plain Python files that I can test and collaborate on.

This "graduation" from notebook to the "production/serious" environment should be straightforward, which means there shouldn't be too much magic in the notebook without me opting into it. Documentation in my eyes is not so different, I should be able to copy the examples easily into my JS project without knowing specifics of Observable and adapt it to my problem. Saying "don't be lazy and just learn Observable", or "you must learn D3 itself properly to be able to use it anyway" is not helpful. Observable being a closed, walled garden doesn't help: not being able to author notebooks without using their closed source editor is a liability that I can totally understand makes it a non-starter for some companies and individuals.

I think it's ok to plug my own project: It's called Starboard [1] and is truly open source [2]. It's built on different principles: it's hackable, extendable, embeddable, shareable, and easy to check into git (i.e. I try to take what makes the web so great and put that in a notebook environment). You write vanilla JS/ES/Python/HTML/CSS, but you can also import your own more advanced cell types. Here's an example which actually introduces an Observable cell type [3] which is built upon the Observable runtime (which is open source) and an unofficial compiler package [4]. I would be happy for the D3 examples to be expressed in these really-close-to-vanilla JS notebooks, but I doubt I can convince the maintainers to do so.

[1]: https://starboard.gg

[2]: https://github.com/gzuidhof/starboard-notebook

[3]: https://starboard.gg/gz/open-source-observablehq-nfwK2VA

[4]: https://github.com/asg017/unofficial-observablehq-compiler

protoduction··on D3 7.0
I wasn't sure whether I was going to comment, but this kind of comment is rather unhelpful and poor form. Some may prefer not to have a (mock) notebook runtime in their application for good reason that has nothing to do with their skill.

I see you are passionate about defending Observable, and that's cool - it's a great piece of tech, but please remember that everybody's requirements are different and valid too.

protoduction··on D3 7.0
I posted this on HN a little while back [1], it's an open source alternative editor/runtime for Observable as a plugin for Starboard.

[1]: https://starboard.gg/nb/nfwK2VA

protoduction··on Show HN: A simple JavaScript notebook in one file
Very cool, I'm building something similar (with a larger scope) [0] (it also has one-file exports, but it does load stuff from a CDN so it's not as contained to a single file as this project is.)

If you're looking for next steps: You can actually run user code using `import`, which will allow your users to import code from external websites using familiar `import {x} from "https://some-url.com/bla.js"` syntax at the top of cells. Here's how:

   const exportsInCell = await import(URL.createObjectURL(new Blob([USER_CODE], { type: "text/javascript" })));

And with some transpilation you can support top-level await in eval [1]. Just some pointers!

[0]: https://starboard.gg & https://github.com/gzuidhof/starboard-notebook

[1]: https://github.com/gzuidhof/starboard-notebook/blob/master/s...

protoduction··on Replit used legal threats to kill my open-source project
I'm building Starboard, https://starboard.gg, maybe that fits your needs? It runs in the browser itself and is open source.
protoduction··on Ask HN: Who is hiring? (June 2021)
Friendly Captcha (https://friendlycaptcha.com) | Remote, EU timezone | Part-time or hourly basis | Full-stack developer

We are a small, profitable company providing a privacy-friendly and accessible alternative to Google ReCAPTCHA based on proof of work. We are looking for a fullstack developer to help us further improve our anti-spam tools that don't carry an accessibility and privacy cost to end-users. The ideal candidate is a generalist, has strong knowledge of web APIs, has experience with open source, and has built a SaaS product before.

Technologies:

* Typescript, Go, HTML, CSS (and likely React in the future for a revamped customer/admin dashboard)

* Serverless (Cloudflare Workers) as well as good-old load balanced services (in Go)

* Redis, FaunaDB, Postgres, Clickhouse

* Git, Github Actions, Sentry, Stripe

* Plugins for Wordpress in PHP, and Flutter (Dart)

Reach out to me at guido@<our domain name>.

← PreviousPage 2 of 5Next →