HNHacker News
TopNewBestAskShowJobs

sleepyhead

1,552 karma · joined September 8, 2010

I make https://makeplans.com
submissionscomments
sleepyhead··on Show HN: MCP Server for Appointment Booking
Hi HN, founder here!

MakePlans is a SaaS for online scheduling. After 15 years of having an API we now also added an MCP server. So you can add it to your favourite AI assistant and ask things like "Book Anna in for a massage on Friday at 14:00". Hope to have all API endpoints available in the MCP server soon.

Let me know if you have any questions about how we implemented this in a Rails app.

sleepyhead··on The Boeing 747 begins its final descent
I flew 747 last month with Lufthansa and asked one of the crew how long they will keep it in operation. «I retire in two years so I don’t care» a very German response but at least they hadn’t made any announcement that he seem to be aware of.

Always fun to be on the second floor despite the seat configuration being a bit dated.

sleepyhead··on European Alternatives
Their servers are in the US
sleepyhead··on [dead]
> stop putting words in my mouth

I literally quoted you.

> clear definition of fascism ... attitudes as a business leader

FYI https://www.merriam-webster.com/dictionary/fascism

sleepyhead··on [dead]
Claiming DHH is a fascist is such a dumb take. The article is vile; claiming DHH died. "'DHH has brain worms' is a fact and valid" - grow up.
sleepyhead··on Why does software have to be part of the left wing or right wing?
> DHH's views would be considered centrist at most

That's not very accurate.

sleepyhead··on ETFs now hold more than $3.1T worth of just top US companies
No it's not. Actively managed funds will in most cases not beat an index fund. Investorers have learned this and has chosen passive funds. This together with more people investing in funds has increased the size of passive ETFs in the market.
sleepyhead··on Heroku Is Down
Their EU region was down for 8 hours last November and it took 2 hours before they were aware of it so submitting a ticket is definitively worth while. I'm suspecting their monitoring is not good enough.
sleepyhead··on Dear "Security Researchers"
"Security Researchers" does not know security.txt exists anyways.
sleepyhead··on Switching to BunnyCDN in Less Than 2 Hours
If Trump steps back from the GDPR US-EU data transfer agreement then your political stance is irrelevant.
sleepyhead··on Argentinian Farmer Finds Family of 20k-Year-Old Car-Sized Armadillos
Milei deflation
sleepyhead··on 418 I’m a teapot
Sure, but if the server is returning 418 by an error it is likely that it would return some other 4xx error instead of 5xx. 418 is irrelevant here, the server is rogue.
sleepyhead··on 418 I’m a teapot
I don't get it. If the system is so broken it is returning some random http code then I don't see how returning some other random http code is better?
sleepyhead··on Database Design for Google Calendar: A Tutorial
Most data formats used in high performant scenarios, for example in finance, are very basic for a reason. You also get the benefit of being able to start processing the file immediately line by line, instead of having to read and parse the entire file.
sleepyhead··on Database Design for Google Calendar: A Tutorial
Showing duration is helpful but so is the exact end time. Visually as a user I would like to see the exact time when the appointment ends instead of calculating it in my head. While it is not that hard to process when an appointment with a duration of 4:15 ends after starting at 2:30 but still.

As for API it makes a lot of sense to expose end time. If you for example are creating a calendar widget then it has start and end datetime for all events. With only duration available in the API output you know how to calculate the end time. More lines of codes for you.

Fetching from the API you would in most cases limit it to certain dates, for example next week. So now you suddenly do have to deal with start and end time. Not having it otherwise makes no sense.

Never had any developers ask for outputting duration in our scheduling API. It would be useful to include it but since no one have asked about it then I think having end time is more critical. https://developer.makeplans.com/#attributes-1

sleepyhead··on Database Design for Google Calendar: A Tutorial
That would be problematic for database performance. You would have to calculate the duration on demand when querying.
sleepyhead··on Database Design for Google Calendar: A Tutorial
> you can tell it was designed before XML/JSON were "hot

or you can tell it was designed by people who care more about performance.

sleepyhead··on My daughter (7 years old) used HTML to make a website
More correct html than a senior react dev.
sleepyhead··on Second factor SMS: Worse than its reputation
It’s for the booking site so most visitors come to make a booking thus conversion rate would be high generally. We never had passwords there so can’t compare conversion rates.

For signups to our app (to get an account with a booking site) we require a password.

sleepyhead··on Second factor SMS: Worse than its reputation
It's not really 2FA even. More like a magic link (which is what we use for verification via email). The customer has no password, just verifies using a code via sms/email.
sleepyhead··on Second factor SMS: Worse than its reputation
It is not but CCC is indicating that this provider was only used for 2FA. Sorry I was getting a bit ahead of myself here, this was earlier exposed as a breach of Twilio's vendor (IdentifyMobile). In the case of Twilio they offer an API for 2FA, Twilio Verify. I wanted to clarify that this breach was not only for 2FA, Verify API in the case of Twilio, but for all SMS sent through IdentifyMobile.
sleepyhead··on Second factor SMS: Worse than its reputation
Apparently the messages on the S3 bucket were updated every five minutes: https://www.zeit.de/digital/datenschutz/2024-07/it-sicherhei...

The CCC definition of this being only 2FA-SMS is incorrect though. It was not only Twilio Verify (2FA API) that was affected, it was all SMS sent through this vendor.

sleepyhead··on Second factor SMS: Worse than its reputation
We at MakePlans were affected by this breach as we use Twilio. We are not using Twilio Verify (their 2FA api) but rather handle 2FA SMS ourselves in our app using Twilio as one of our providers. So the CCC definition of this being only 2FA-SMS is incorrect, it was all SMS sent through this Twilio third party gateway that was exposed to a limited set of countries (France, Italy, Burkina Faso, Ivory Coast, and Gambia).

GDPR is not necessary applicable here. An SMS gateway is most likely classified as a telecom carrier, and thus any local telco laws would be applicable and not GDPR. That applies only to the transfer of the SMS though, so for example a customer GUI of sent SMS would be out of that scope.

(And before someone tells us that SMS 2FA is insecure I would like to point out that we use this for verification purposes in our booking system when a customer makes a booking. So for end-customers, not for users. It is a chosen strategy for making verification easy as alternatives are too complex for many consumers. All users however authenticate with email and password, and have the option of adding TOTP 2FA).

sleepyhead··on Twilio Notice of Security Incident with 3rd Party Carrier
Yes I received more info as well. Apparently they think that GDPR does not apply to them in this case. Good luck with that.

"To answer your questions:

1. Only France, Italy, Burkina Faso, Ivory Coast, and Gambia were impacted by this incident, only the traffic sent to these countries.

2. To provide you more context, Twilio’s carrier partners are not considered to be Twilio's processors (or Twilio's customers' subprocessors) under the GDPR because carriers transmitting communications content (i.e., Customer Content) are not considered to be processing the personal data contained in the communication. There are a number of reasons behind this positioning: • “Disclosure by transmission” is called out in the GDPR definition for 'processing' rather than transmission without disclosure. • A processor role does not fit the nature of telecoms services and the telecoms value chain; Confidentially (and security) of communications is safeguarded by the ePrivacy framework. • Guidance from the EDPB specifically covers “telecom operators” and does not specify a role for the carrier with respect to the content of the communication. • Communications content merely transits a communications network or service, without significant processing being involved as confidentiality of communications prohibits the carrier from gaining access. • Any other position would be impossible to implement given the complexity of the telecommunications value chain, with many parties involved in the origination, transit, and termination of communications content."

sleepyhead··on Twilio Notice of Security Incident with 3rd Party Carrier
I will also ask their support:

1) Which countries it applies to. 2) What is their current and past policy for carriers storing message data.

sleepyhead··on Twilio Notice of Security Incident with 3rd Party Carrier
The email is unfortunately lacking in some details. Does this include all messages sent through Twilio or just in the country of this provider?

And why is this carrier storing messages on an S3 bucket? I don't see why they should store messages at all after the message has been processed, storing metadata should be sufficient for their records. It would be definitively be problematic according to GDPR, if IdentifyMobile is a Briths company then similar privacy laws should be in place?

sleepyhead··on Nvidia is about to pass Apple in market cap
> Apple is only sticky to those who buy into the ecosystem

That's half of the total market in many countries.

sleepyhead··on Nvidia is about to pass Apple in market cap
"Apple's all products can easily be replaced."

- No wireless. Less space than a Nomad. Lame.

sleepyhead··on Campfire
Your expectations might have changed. Most users are quite happy with core chatting features. And in the case of Slack those features have become a bit too intrusive and disorganised, so that is one of the selling points of Campfire.
sleepyhead··on Campfire
Campfire was originally launched way before Slack though.
Page 1 of 18Next →