HNHacker News
TopNewBestAskShowJobs

rdegges

3,526 karma · joined May 14, 2012

meet.hn/city/us-Bend

Socials: - github.com/rdegges - linkedin.com/in/rdegges - reddit.com/user/rdegges - instagram.com/randalldegges - https://bsky.app/profile/rdegges.com

---

I'm just a happy programmer that likes to hack stuff.

You can contact me via my site: https://www.rdegges.com/ or via email r@rdegges.com

submissionscomments
rdegges··on Ask HN: I built it and nobody came. What got you your first users?
I've built quite a few projects from 0 -> business over the last 20 years, and I think the fundamentals are still true today.

First rule: if you're building the product solo, is it something you're the target user of? I've always felt like the biggest "cheat code" for building successful products is just making them for people like you. I know that goes against a lot of lean startup methodology (talk to users, etc.), but it has always worked in my experience. Use your unique domain knowledge to make something meaningfully better, cheaper, more accessible/simple than the competition.

Second rule: marketing is important. Almost all the things I've built are developer services, so to get user feedback and early traction, I'd submit to go speak at the local meetup groups in my area, talk about the tech stuff I worked on as part of the product, then give people a free shirt if they'd give me some in-person feedback after the event. I made some good friends that way (hello, SoCal Pythonistas!), and also made meaningful product growth. Don't be a shill, just genuinely nerd out about the things you're doing in an authentic way. People like that.

Third rule: write well. Don't use LLMs to spam blog content that's low quality about your product. Write about it yourself. Show examples, highlight features. Don't use marketing words, use simple descriptions.

rdegges··on Skillbench
Nice project!

One question I have on the `tool boundary` methodology -- does this penalize a skill for having any sort of scripts/ embedded? I've found it really helpful to take larger skills, like ones I've built at Snyk which handle data processing, and encode the process in the SKILL.md, but also ship it with python/go code in scripts/ to deterministically handle a lot of data validation/etc. For data analysis skills I feel like it's really hard to just encode teaching logic without costing a fortune in inference.

rdegges··on Architecting Secure Prompt Caching
Good post, breaks down the threat models really well. =)

One small note, I think there may be a small issue in one of the code blocks explaining the client key:

> cache_namespace = tenant_id || client_secret

I believe that should say `tenant_id + client_secret`, ya? To append them together? If you OR them out it'll default to the `tenant_id`, which isn't what you want in this case, I believe.

rdegges··on Stop Using JWTs
:o
rdegges··on Stop Using JWTs
=0 I stumbled across this post and was thinking that it's interesting to see this topic trending now, since I've done a lot of work on it in the past. Then I clicked through and realized the author is linking to some of my stuff! What a blast from the past.

Anyhow, there are way smarter people than myself who have covered this topic extensively over the years, but I still think that, even in 2026, JWTs are the wrong tools for web auth. They're fine to use for service-to-service stuff, but if you have the option, just use PASETO -- it solves a lot of the issues!

rdegges··on Tom Homan confirms ICE to be at airports starting Monday
> Yes US citizens that are putting themselves in a situation they shouldn’t have been in to begin with while threatening and provoking a violent reaction.

This is not at all true. Plus, it's inconsequential -- ICE agents have no authority over US citizens except in extremely limited circumstances (https://www.perplexity.ai/search/9f4518c4-8a32-474a-bd92-3f1...), and even if they did, being able to arrest someone, file charges, and work their way through the justice system is the answer... Not killing people on the streets.

rdegges··on Tom Homan confirms ICE to be at airports starting Monday
Throwaway accounts and more propaganda isn’t proof of anything. I think it’s pretty clear that untrained, unaccountable armed people who have already killed multiple US citizens that they have no jurisdiction over is a real-world worry that people have.

It’s silly to dismiss rational, logic-based worry as “propaganda”.

rdegges··on Tom Homan confirms ICE to be at airports starting Monday
This is straight up untrue. There are clean bill proposals to fund TSA that Republicans have rejected. https://www.perplexity.ai/search/are-the-proposed-tsa-fundin...
rdegges··on Tom Homan confirms ICE to be at airports starting Monday
Straight white US citizen male here. This scares the shit out of me. I travel for work all the time, but understanding that we will now have barely trained, and in many cases completely lawless, consequence-free federal officers in direct, high stress, public areas where lots of people are constantly passing through seems like an absolute recipe for tragedy.

This will 100% make me reconsider travel and avoid airports with ICE agents. I think the writing on the wall is clear, nobody is safe.

rdegges··on Show HN: Agentseed – Generate Agents.md from a Codebase
This is such a great idea. When I'm building net-new projects, I typically end up working with the AI assistant to build a comprehensive AGENTS.md as the first thing before any work gets done: specify tools, dependencies, architecture requirements, style, etc.

I end up getting way better quality.

The same is true for existing projects, but it always takes a whole lot longer as I'm typically chatting with my AI assistant to figure out what conventions are there that I forgot, etc., before building an AGENTS.md to make future changes simpler.

Love how this takes care of that.

rdegges··on Beej's Guide to Learning Computer Science
He also taught me networking in C in the early 2000's! A few years ago I moved from the Bay Area up to Bend, Oregon and ended up running into him in-person at one of the tech meetups.

I was so floored to meet him in person, and as you'd probably imagine, he's super kind and relaxed =D

A++ human being who's contributed so much to our field.

rdegges··on MCP-Scanner – Scan MCP Servers for vulnerabilities
I believe one of the main differences is that our scanner looks for toxic flows between mcp endpoints regarding how they interact with one another. Unless I'm missing something, the Cisco tool does not support this.

Our research lab discovered this novel threat back in July: https://invariantlabs.ai/blog/toxic-flow-analysis and built the tooling around it. This is an extremely common type of issue that many people don't realize (basically, when you are using multiple MCP servers that individually are safe, but together can cause issues).

rdegges··on MCP-Scanner – Scan MCP Servers for vulnerabilities
At Snyk, we've been working on this for a while. Here's our flagship open source project consolidating a lot of the MCP risk factors we've discovered over the last year or so into actionable info: https://github.com/invariantlabs-ai/mcp-scan
rdegges··on Using AI to secure AI
Here's a better option -- what we've been working on at Snyk.

- Take something like Cursor and plug the Snyk MCP server into it: https://docs.snyk.io/integrations/developer-guardrails-for-a... (it has a one-click install) - Then, either within your project or via global settings, create some human-language rules for your AI code editor to use (this works basically the same between all editors: Claude Code, Cursor, Windsurf, etc...)

For example, a rule might state:

"If you add or change any code, run a Snyk Code scan on the modified files then fix the detected vulnerabilities. When you're done fixing them, perform another scan to ensure they're fixed, and if not, keep iterating until the code is secure."

Obviously, there are other rules you can use here, such as using Snyk's open source dependency testing to identify vulns in third-party dependencies and handle package updates/rewrites/etc., but you get the idea.

This works insanely well -- I've been playing around with it for a while now and we're getting close to rolling this out to all of our users in a major way =)

The best part about it is that you can just "vibe code" whatever you want, and you get really accurate static analysis security testing incorporated by default automagically.

I recorded a little video here that walks through this in-depth (https://www.youtube.com/watch?v=hQtgR1lTPYI), if you want to see the part I'm referencing, jump to 20:09 =)

rdegges··on We built audio/video RAG
Great article. This may be my all-time favorite deep dive post on RAG strategies.

It’s super interesting to me how the process of fully making audio/video searchable requires so much processing. Like, extracting the audio and video, transcribing the audio, chunking the video into 15-sec scenes and describing them visually, etc.

I wonder if as a test you could use the video descriptions, run them as a prompt through something like Veo, then stitch them together into something close to the original. Wild.

rdegges··on Ask HN: To anyone who cares to read this. How old are you roughly?
Turning 37 in two days. =D

Been programming since I was 12. The passion has never left. <333

rdegges··on "Goodwill", key member of the SoCal Python Community has passed away
I wasn't sure if I should post this or not, but if you ever met Michael you probably remember him. He was a kind soul and helped grow the Python developer community in LA for well over a decade.

In addition to being an excellent engineer and human, Michael was also the definition of a hacker. It feels suitable to share the news here.

He was an incredible person and touched many lives. If you ever got to meet him (in person or online), please share your experiences on his in memoriam page.

rdegges··on Ask HN: Did someone dig into the JFK files?
Ragie (a RAG company) published an interactive chatbot that lets you ask questions about the JFK files. It’s pretty interesting, they had to do a lot of OCR on old docs to get it to a usable state.

https://chat.ragie.ai/o/jfk-files

rdegges··on SAML's signature problem: It's not you, it's XML
The way XML digital signatures work is so weird. This routinely comes up year-after-year. When I was working at Okta this also resulted in a number of annoying breaches, including this one: https://developer.okta.com/blog/2018/02/27/a-breakdown-of-th...
rdegges··on Don't sell space in your homelab (2023)
I’m not aware of any!
rdegges··on Don't sell space in your homelab (2023)
I have a decently-sized homelab and I've been renting out unused disk space. I actually allocated 20TB of disk space (RAID 1) and have been renting the space out via the Storj network (https://www.storj.io).

If you haven't heard of it, Storj is essentially a distributed S3 that's been around for many years now, and the way it works is that various people run Storj nodes while the Storj company runs a proxy server that breaks files up into small encrypted chunks and stores them across N peers for redundancy.

In my case, I back up my family photos/videos/documents to a Synology NAS, and my NAS is backed up to Storj. So when I run a Storj node with part of my disk space, the payments they give me essentially cover my own backups. I'm not making a ton of money or anything, but it's enough to pay for my own backups and that's a great deal.

If you're looking to do what the OP is talking about in a simple way, this is by far the best way I've found to do it.

rdegges··on Why I don't discuss politics with friends
I totally get where you're coming from. But regardless of their reason for voting for a candidate, if the net effect is that 150m+ women lost rights and other horrible outcomes, it's the same as endorsing it.
rdegges··on Why I don't discuss politics with friends
In my case, my goal isn't to change anyone's mind. It's to preserve sanity -- I can't in good faith "pretend" to get along and have normal conversations when people are actively engaging in behavior that directly harms myself and others.
rdegges··on Why I don't discuss politics with friends
I'll provide an opposing viewpoint. In the last 10 years, I've lost friendships and family because people in my life have voted for candidates that stripped rights away from women, minorities, etc.

Having a vast difference between opinions is fine, but some of their decisions are fundamentally against my core beliefs and have done literal harm to many people I know.

For that reason, terminating family and friendships has been absolutely worth it for me.

Until we can live in a world where fundamental rights are protected and respected, we have no common ground, and it's pointless to tiptoe around these insanely harmful beliefs while maintaining a facade of friendship.

rdegges··on Excitable cells
I had something similar for many years (triggered by an episode of afib brought-on by triggering my vagus nerve). The one thing that has helped me fully get rid of these (after YEARS of trial-and-error) was getting onto beta blockers (Propranolol).

These have COMPLETELY gotten rid of my ectopic beats and also helped me deal with the health anxiety.

If you ever want to talk, feel free to hit me up (contact info in profile).

rdegges··on Arcade raises $12M from Perplexity co-founder's fund to make AI agents less bad
It's just super easy to use. You give it some natural language prompting and it handles all of the work of figuring out the tools, making the calls, and stitching responses back together. It's nice =D
rdegges··on Arcade raises $12M from Perplexity co-founder's fund to make AI agents less bad
I like the way Arcade handles the agents -- I actually built a simple internal web app that we're using at Snyk to help with employee promotion, on top of Arcade's social integrations: https://github.com/snyk-labs/ai-promoter
rdegges··on Fitness Trackers Are Only 67% Accurate, New Research Finds
I love his channel. The TL;DR of it is that Apple Watch generally has the best overall health accuracy when compared to other wearables.
rdegges··on Obscura VPN – Privacy that's more than a promise
Question: mullvad doesn't traditionally support any of the streaming services (netflix, etc.). Since Obscura is using mullvad, does that mean it also won't?
rdegges··on Why do startups often have blog pages? is it for SEO?
Ha! I have a ridiculous amount of insight into this =)

For over a decade now I've been building and leading Developer Relations teams at developer companies. The reason why so many startups have a blog is because... It's one of the best ways you have to attract users to your service in a high-ROI way.

Think of it like this: you're a startup founder for a developer company. You want to get developers to know about your product, and ideally, try it out. How do you do it? You have a handful of options!

- Paid Advertising (expensive, hard to manage, immediately stops working once you stop advertising)

- Cold outreach (aka, outbound sales and prospecting, it works but nobody likes it and it's labor/time intensive, immediately stops working once you stop it)

- Organic outreach (aka, blog posts, YouTube videos, etc.) <--- This is the only category of things that last for a long time: once you've published an article or video, it'll be around as a reference that people will stumble upon in searches, LLM training sets will pick it up and potentially use it for future recommendations, etc. It has a long shelf-life.

When I ran DevRel at Stormpath (acquired by Okta), and later Okta, here's a fun secret most people won't know: a majority of our business and new developer users came from our developer blog. Shocking, right? Even at a large post-IPO company like Okta, the developer blog (back when I was there, anyhow), represented a massive portion of ALL website visits.

The amount of influence you have through educational content is truly massive, and can make or break even the largest tech companies.

Page 1 of 11Next →