HNHacker News
TopNewBestAskShowJobs

protoduction

864 karma · joined November 10, 2014

https://guido.io, e-mail me at me@guido.io.

Co-founder and CTO of https://friendlycaptcha.com.

Github: https://github.com/gzuidhof

submissionscomments
protoduction··on Show HN: Starboard – Fully in-browser literate notebooks like Jupyter Notebook
I don't have all the questions yet and there are definitely things that a Jupyter notebook does much better.

As for interacting with local files: I imagine a CLI tool that spawns a webserver that will serve local notebook files and perhaps the files in folders you point it at. Or: you generate a notebook file with the data baked into it (as a JSON blob or something).

As for security: I think the browser sandbox is a lot more safe than running Python (Jupyter) with a lot of dependencies you will have to verify.

And finally: you need to be able to get the data into the browser. For a company the most 'scalable' would probably be self-hosting Starboard and (setting up CORS to) allow reading from various datasources from your internal network, or otherwise authenticating the requests from notebooks.

Another thing that has worked well for me in the past with other web tools: support drag and drop. You drop in the file you want to visualize.

In the end Starboard notebook is a tool for creating a small website that you can instantly share, without needing a backing Python server always on, and without the need of any build tooling (webpack, what have you). It's good for small web tools, articles and tutorials. I hope this makes it a little bit more clear!

protoduction··on Show HN: Starboard – Fully in-browser literate notebooks like Jupyter Notebook
To answer some of your questions (let me know if I didn't answer all of them!)

- I think logic errors can't be solved or prevented when exposing vanilla HTML, CSS and JS. You can completely break the notebook if you want to. Like the sibling comment to this stated: the notebook is run in an iframe of a different origin so you (should!) not be able to break out of that iframe. But of course if you introduce some endless loop that crashes the browser (or maybe just the iframe depending on the browser), I can't stop that.

- No particular reason, but it was always a bit iffy getting the return value correctly. To support top level await your code actually gets wrapped into an async function, I don't know how nicely that plays with new Function.

In the future I want to support ES modules with import instead. Perhaps no magic will be required at all anymore and performance will probably be even better (https://2ality.com/2019/10/eval-via-import.html)

- Codemirror is very good and doesn't have a huge bundle size. I decided I wanted to support touchscreens. The monaco editor completely fails on my phone (if I type space it usually copies the word in front of it), whereas codemirror just works. The autocomplete and language support is much worse though, on a desktop I think I will always choose the Monaco editor.

- Probably not the most exiting answer, but for me it was just wanting to use Jupyter for things it was really bad at. There is Project Iodide which is very similar, but they made some different design decisions that move away from the code-output-code-output structure.

By putting the editor inside the sandbox things become much more straightforward and less "special" or "magic", that's another big difference from Project Iodide.

I think more and more fully client-side editors are becoming possible now due to dynamic import and webassembly, do share your project with me if you get the chance to work on it!

protoduction··on Show HN: Starboard – Fully in-browser literate notebooks like Jupyter Notebook
Correct, or you can set it as a property on the starboard-notebook web component HTML element.
protoduction··on Show HN: Starboard – Fully in-browser literate notebooks like Jupyter Notebook
I've had a look and wasn't able to get it to work yet, imports can be bit iffy: usually anything that exposes ES modules or puts variables on the window object work fine.

It looks like the reason it doesn't work here is because it relies on "this" being the window object. To make top-level await possible your code gets wrapped into a function, and in there "this" no longer points to the window. I am sure a workaround is possible, I'll make a ticket on github.

https://github.com/gzuidhof/starboard-notebook/issues/1

protoduction··on Show HN: Starboard – Fully in-browser literate notebooks like Jupyter Notebook
Thanks!

Answering your questions:

- If you log in and create a public notebook, it's stored on Starboard's server, then you can just share it by link. If you create an offline notebook it's stored in your browser's LocalStorage. Right now you can't create a notebook yet that only you can see or can be shared with a private link, to do!

But of course you don't have to use the Starboard website, you can just save it as a text file on your disk. In the future I want there to be a CLI tool that serves that notebook for you on localhost.

- No examples yet, it's future plans for now (but I hope to land that in a week or two!)

- No forecast.. It's just myself working on it, so you'll have to bear with me. I am working full-time on this.

protoduction··on Show HN: Starboard – Fully in-browser literate notebooks like Jupyter Notebook
Hi HN, I developed Starboard over the past months.

Cell-by-cell notebooks like Jupyter are great for prototyping, explaining and exploration, but their dependence on a Python server (with often undocumented dependencies) limits their ability to be shared and remixed. Now that browsers support dynamic imports, it has become possible to create a similar workflow entirely in the browser.

That motivated me to build Starboard Notebook, a tool I wished existed. It's:

* Run entirely in the browser, there is no server or setup, it's all static files.

* Web-native, so no widget system is necessary. There is nearly no magic, it's all web tech (HTML, CSS, JS).

* Stores as a plaintext file, it will play nicely with version control systems.

* Hackable: the sandbox that your code gets run in contains the editor itself, so you can metaprogram the editor itself (e.g. adding support for other languages such as Python through WASM).

* Open source (https://github.com/gzuidhof/starboard-notebook).

You can import any code that targets the browser directly (e.g. puts stuff on the window object), or that has exports in ES module format.

I'm happy to answer any questions!

protoduction··on [dead]
Brute force attack just means an attack that isn't smart and instead relies on just trying a lot.

For instance, if you have a padlock with 3 dials on it, I can just try 000 through 999 and at some point I will find the correct solution. A smarter attack could be to try and watch you close the padlock. A more efficient brute force attack could be to try popular combinations first (e.g. 000, 123, 987).

Your question is not very specific as it doesn't contain the context of the attack, are we talking about cracking a user's password? Usually a simple first mitigation for bruteforce attacks is to limit the user's attempts (e.g. if you get your password wrong 3 times, you are locked out for 10 minutes). Another good practice is to make sure people's passwords are at the very least 8 characters long, then trying every attempt becomes quite difficult just because of the amount of possibilities.

protoduction··on Ask HN: Is open source reducing engineer's jobs?
I think it reduces jobs the same way as having tools like electronic screwdrivers available cheaply reduces jobs.

Instead of everybody having to create their own screwdrivers prior to starting a construction job, they can focus on building whatever they want to build.

I would argue that's a good thing: it increases productivity and decreases duplicated effort.

protoduction··on Show HN: FriendlyCaptcha – a privacy friendly proof-of-work based CAPTCHA
I built FriendlyCaptcha over the past 2 months because I was tired of there being no good alternatives to Google's reCAPTCHA and the like that your users won't hate you for. FriendlyCaptcha is based on proof-of-work (think hashcash): instead the user labeling fire hydrants in images, they commit their device to doing computations for at least a couple of seconds. The idea is that the cost of an attack is not so different for a spammer: instead of running a ML model to label the images (or solve the audio challenge) they would need to solve the proof-of-work challenge. That's probably good enough for most if not all websites, and compares favorably against ReCAPTCHA which has many issues (privacy, accessibility, bundle size & bandwidth, menial tasks, customizability, closed-source).

The attacker shouldn't be able to use much more optimized code, which is where WebAssembly comes in: the FriendlyCaptcha solver is WASM based (with JS fallback) which achieves close to native speeds. The solver [0] and widget [1] are all open source so you can play with it or customize it for your website.

The question is if this is what people want for their website, or maybe what the world needs is just a less evil reCAPTCHA?

In case you missed it on the main website, there is a demo here [2].

[0]: https://github.com/gzuidhof/friendly-pow

[1]: https://github.com/gzuidhof/friendly-challenge

[2]: https://friendlycaptcha.com/demo

protoduction··on Show HN: Object-visualizer – Chrome-console-like JSON object visualizer in DOM
This is great, I've wrapped react-inspector in the past into a webcomponent for this, but shipping React and ReactDOM just for this functionality always felt a bit wrong, although from what I understand this requires Vue instead?

I am still hoping for someone to wrap the chromium dev tools in an easy to use webcomponent

protoduction··on Show HN: FriendlyCaptcha – a privacy friendly proof-of-work based CAPTCHA
I built FriendlyCaptcha over the past 2 months because I was tired of there being no good alternatives to Google's ReCAPTCHA and the like that your users won't hate you for.

FriendlyCaptcha is based on proof-of-work (think hashcash): instead the user labeling fire hydrants in images, they commit their device to doing computations for at least a couple of seconds. The idea is that the cost of an attack is not so different for a spammer: instead of running a ML model to label the images (or solve the audio challenge) they would need to solve the proof-of-work challenge. That's probably good enough for most if not all websites, and compares favorably against ReCAPTCHA which has many issues (privacy, accessibility, bundle size & bandwidth, menial tasks, customizability, closed-source).

The attacker shouldn't be able to use much more optimized code, which is where WebAssembly comes in: the FriendlyCaptcha solver is WASM based (with JS fallback) which achieves close to native speeds. The solver [0] and widget [1] are all open source so you can play with it or customize it for your website.

In case you missed it on the main website, there is a demo here [2].

[0]: https://github.com/gzuidhof/friendly-pow

[1]: https://github.com/gzuidhof/friendly-challenge

[2]: https://friendlycaptcha.com/demo

protoduction··on Ask HN: What projects are you working on now?
I'm building Chimera, which is project that brings sandboxed cell-by-cell (scientific) notebooks to the browser.

It's a blend of Jupyter Notebook, Project Iodide, JSFiddle, CodeSandbox, Glitch, and Observable.

Here are two screenshots:

- Notebook: https://i.imgur.com/nDUC817.png

- View Source: https://i.imgur.com/KhaiCfz.png

This is a tool that I wish existed after having worked with Jupyter notebooks a lot.

protoduction··on Ask HN: Those starting new side projects in 2018 – Show and tell
I'm working on a side project that involves getting useful NN based networks working in a browser.

There's some demos which for instance will do class prediction (cat vs dog), but who needs that? I would love to see stuff like colorization working in a static webpage, at decent speeds (under 5 sec for a big image). It should also be easy enough that my mother could use it.

protoduction··on Ask HN: Who wants to be hired? (January 2017)
Location: Nijmegen, The Netherlands

Remote: No

Willing to relocate: Yes!

Technologies: Python ML/Deep Learning stack (sklearn, numpy, scipy, pandas, gensim, Theano, Lasagne, TensorFlow), MATLAB, Java, JS/CSS/HTML5, Elixir, Git

Résumé/CV: http://guido.io/cv.pdf

Email: me@guido.io

AI student, looking for internship. I am looking to be part of a data science team.

I have most experience in image classification and segmentation problems (using CNNs), in particular those in the medical imaging/computer-aided diagnosis domain. I am however open to expanding to different (non-computer vision) domains as well.

protoduction··on Show HN: Tolk – Talk with strangers about topics anonymously (PWA)
Hey HN, I created this app as a hobby project over a lot of weekends. I was tired of existing random chat services that only end up in either A/S/L nonsense or me talking to a bot.

By asking for a topic, I hope to mitigate this problem and allow for more directed, meaningful conversations.

It's a progressive web app, using the Vue framework with the server running Elixir (Phoenix).

protoduction··on Ask HN: Who wants to be hired? (April 2016)

  Location: Nijmegen, The Netherlands
  Remote: No
  Willing to relocate: Yes
  Technologies: Python ML stack (sklearn, numpy, scipy, pandas, TensorFlow), MATLAB, Java, Hadoop, JS/CSS/HTML5, Git
  Résumé/CV: https://goo.gl/6S6ML6
  Email: guido@guido.io
AI student, looking for internship. I am looking to be part of a data science team.

I have experience with image classification (using CNNs) and text mining, but am open to expanding to different domains.

protoduction··on Ask HN: Interesting WebRTC projects to work on?
Using WebRTC datachannels for p2p networking in games is challenging and fun.

I am personally using it for networking in a WebVR side project (which is far from finished), where the challenges are the differences between clocks, interpolating between received positions, and more. You can try the current version here http://guido.io/WebMetaverse/ (open it multiple browsers and observe).

I ended up implementing a signalling server (in Elixir) and client, which made me understand much more of what is going on under the hood.

protoduction··on Ask HN: Best open source/free software in their own category?
OBS - Cross-platform broadcaster software (for recording and live streaming). Better than any of its competition in my opinion.

https://obsproject.com/

protoduction··on Ask HN: Your favorite technical/startup idioms?
Jeff Atwood had a blog post[1] containing a list of new programming jargon, although perhaps this is too 'programmer'-focused.

[1]: http://blog.codinghorror.com/new-programming-jargon/

protoduction··on From native code to browser: Flash, Haxe, Dart or asm.js?
There are other paths for Haxe, although they are probably not pretty. That is Haxe -> C++ -> Emscripten -> asm.js. Then there is another, Haxe -> Java -> GWT -> JS.

I think Haxe is underappreciated for areas other than game development. You can write serverside logic with it (compile to js for node.js, php, neko, java, c#, python), and target flash and js in the browser.

← PreviousPage 5 of 5