HNHacker News
TopNewBestAskShowJobs

tasn

1,902 karma · joined October 4, 2014

Founder and CEO of the Svix Webhooks Service (YC W21) - https://www.svix.com

https://stosb.com

https://www.etebase.com

https://www.etesync.com

https://github.com/tasn

https://mastodon.social/@tasn

https://twitter.com/TomHacohen

Contact: at tom @ any of the domains above.

submissionscomments
tasn··on Why Go Is an Ideal Language for AI-Assisted Software Engineering
It's a matter of expressiveness, Rust expresses more.

E.g. make a table that's 3x3 is easier to read (Go), but the equivalent line in Rust would also include material, angles, height, etc. because the type system encodes much more information.

Though I always found Go to be significantly harder to read than Rust. Sure Rust has some crazy syntax at the edges, but Go makes it very hard to know where imports come from (and thus what they do), and the imperative style + lack of clarity about mutability makes code much harder to reason about.

tasn··on The Valley of Webhooks
I know (from our customers) that some of their customers make buying decisions based on the availability of webhooks. I'm unaware of anyone doing it based on the availability of our other functionality (but it could be I just don't have the data).

Though the data I do have: how many people adopt these advanced endpoints in practice (as we offer these), and it's less than webhooks.

tasn··on The Valley of Webhooks
We (Svix, webhooks infra) actually help our customers directly write to Kafka topics, S3 buckets, SQS, etc. and have for a few years now. There are definitely people that adopt that, but receivers as well prefer the simplicity of webhooks.
tasn··on The Valley of Webhooks
Webhooks are simple and ubiquitous, and that's both a weakness and a strength. It's also why they are used for a lot of things, even things they are not great for (state sync).

These weaknesses are why we[1] added FIFO endpoints, Polling Endpoints, and what we call "Svix Stream" as ways to do ordered state synchronization (each with its own tradeoffs). This lets people consume the events in the way that best fits their use-case. We are working on more things to make the state sync even easier. I'd love to hear about more challenges people are facing with webhooks, as we want to make these things better.

OP: I'd love to hear more about your thoughts there, and will send you an email in a moment.

P.S, if you're unfamiliar, please check out Standard Webhooks[2]. It's a spec we created to help with signature verification that has been adopted by OpenAI, Anthropic, Google, and many others. We are chipping at one webhook challenge at a time. :)

1: I'm the founder of Svix (mentioned in the post), we do webhooks infrastructure as a service.

2: https://www.standardwebhooks.com/

tasn··on Superlogical
Dupe: https://news.ycombinator.com/item?id=49098965
tasn··on EU Parliament greenlights Chat Control 1.0
I've lived both in the US and the UK.

The US has the 5th amendment protecting you from self-incrimination, while in the UK you can go to prison for not divulging your encryption password (even if you forgot it!).

The US doesn't have ISP/DNS level blocking for all I'm aware of, but there's the ultimate blocking that sometimes does happen (FBI raiding your servers, even if outside of the US).

The US has the 1st amendment protecting speech, while in the UK people routinely get arrested for social media posts.

Maybe there are areas where the UK is better about privacy/freedom than the US, but no examples immediately come to mind.

tasn··on EU Parliament greenlights Chat Control 1.0
This, and other similar legislation, serve as a constant reminder of why the American founding fathers had to revolt against tyranny, and why constitution amendments like the 1st and 4th exist. The 4th in particular was written as a response to a British law similar to Chat Control (writs of assistance).
tasn··on 'No way to prevent this,' says only package manager where this regularly happens
It has build.rs, which has essentially the same problems.
tasn··on Rewrite Bun in Rust has been merged
How is that different (in this sense) to any "slower" rewrites or other significant changes?
tasn··on F-15E jet shot down over Iran
I wasn't comparing to Iran, I was just saying that putting an F-35 and a $2m drone on the same list and same count was funny.

As for the $40m number: I also saw this number, but I don't think it's correct. E.g. Germany recently bought 140 of them for $165m. Ref: https://www.i24news.tv/en/news/israel/defense/1649255166-ger...

tasn··on F-15E jet shot down over Iran
Sure. But looking at all of the downed Israeli crafts, they are all $2-5m drones (all 18 of them).

For perspective: Patriot missiles cost $4m each.

tasn··on F-15E jet shot down over Iran
It's a bit weird counting drones in the same list as expensive fighter jets (and other expensive planes).
tasn··on Go hard on agents, not on your filesystem
I use bbwrap to sandbox Claude. Works very well and gives me a lot of control and certainty around the sandbox.
tasn··on A pig's brain has been frozen with its cellular activity locked in place
Just buy the family pack and get your wife and kids on it too.

As for traveling to the future: that sounds like fun!

tasn··on Show HN: I got tired of rewriting webhook verification for every provider
Tip: if you implemented support for Clerk, you also support all the rest of Svix customers, and compatible with https://www.standardwebhooks.com/

So you support many more than you realize!

tasn··on Tell HN: YC companies scrape GitHub activity, send spam emails to users
Cluely is not YC.
tasn··on Farewell, Rust for web
These are two sides of the same coin. Go has its quirks because they put things in the standard library so they can't iterate (in breaking manners), while Rust can iterate and improve ideas much faster as it's driven by the ecosystem.

Edit: changed "perfect" to "improve", as I meant "perfect" as "betterment" not in terms of absolute perfection.

tasn··on Xfwl4 – The Roadmap for a Xfce Wayland Compositor
Thanks for the context!
tasn··on Scaling PostgreSQL to power 800M ChatGPT users
Very cool, thanks for sharing! Please let me know if you end up open sourcing this!
tasn··on Xfwl4 – The Roadmap for a Xfce Wayland Compositor
Very interesting that they opted for a rewrite in Rust instead of adjusting the existing codebase.

I wonder how long it'll take them writing a compositor from scratch.

tasn··on iPhone 5s Gets New Software Update 13 Years After Launch
Pixels are pretty weak hardware wise in the areas people care about (heavy, relatively slow charging, big, etc.); I'd probably recommend people buy Samsungs which also get long term software updates nowadays.
tasn··on Scaling PostgreSQL to power 800M ChatGPT users
How did you implement this runtime check? Is it a lint rule, or using the type system?
tasn··on C Is Best (2025)
I think this framing is a bit backwards. Many C programs (and many parts of C programs) would benefit from being more like Go or Python as evident by your very own sds.c.

Now, if what you're saying is that with super highly optimized sections of a codebase, or extremely specific circumstances (some kernel drivers) you'd need a bit of unsafe rust: then sure. Though all of a sudden you flipped the script, and the unsafe becomes the exception, not the rule; and you can keep those pieces of code contained. Similarly to how C programmers use inline assembly in some scenarios.

Funny enough, this is similar to something that Rust did the opposite of C, and is much better for it: immutable by default (let mut vs. const in C) and non-nullable by default (and even being able to define something as non-null). Flipping the script so that GOOD is default and BAD is rare was a huge win.

I definitely don't think Rust is a silver bullet, though I'd definitely say it's at least a silver alloy bullet. At least when it comes to the above topics.

tasn··on C Is Best (2025)
The recent bug in the Linux kernel Rust code, based on my understanding, was in unsafe code, and related to interop with C. So I wouldn't really classify it as a Rust bug. In fact, under normal circumstances (no interop), people rarely use unsafe in Rust, and the use is very isolated.

I think the idea of developers developing a "bugs antenna" is good in theory, though in practice the kernel, Redis, and many other projects suffer from these classes of bugs consistently. Additionally, that's why people use linters and code formatters even though developers can develop a sensitivity to coding conventions (in fact, these tools used to be unpopular in C-land). Trusting humans develop sensibility is just not enough.

Specifically, about the concurrency: Redis is (mostly) single-threaded, and I guess that's at least in part because of the difficulty of building safe, fast and highly-concurrent C applications (please correct me if I'm wrong).

Can people write safer C (e.g. by using sds.c and the likes)? For sure! Though we've been writing C for 50+ years at this point, at some point "people can just do X" is no longer a valid argument. As while we could, in fact we don't.

tasn··on Hardware Touch, Stronger SSH
This is how I've been doing it: https://stosb.com/blog/using-openpgp-keys-for-ssh-authentica...

Slightly different as I generate a PGP key on the computer and then load it to the Yubikey, which means I can have backup keys with the same secret keys.

I never really got "touch to use" working though, if anyone knows how to do it with GPG keys I'd really appreciate it!

tasn··on OpenRouter Broadcast
I'm sure that if they don't already support it, they will add it. TBH, we at first didn't have it either, and then we added both that as well as custom attributes as we realized the way people setup their observability stack is extremely varied!
tasn··on OpenRouter Broadcast
Congrats OpenRouter on the launch! I'm a big fan of this pattern. We do the same in Svix for our customers, but also we now make it easy for our customers to do the same.

For other companies looking to build something similar, you can use Svix Stream[1] that offers a lot of these integrations out of the box, with more coming.

1: https://www.svix.com/stream/

tasn··on How fast can browsers process base64 data?
Thanks for sharing!

Incredible that FF is even slower than a JS only implementation running in FF.

tasn··on How fast can browsers process base64 data?
Even if true (and I agree with sibling that I don't think that it is), base64 encoding/decoding feels like one of those things you'd have a micro benchmark for regardless. It's also shocking that the gap is so wide, as I feel like people working on such things would start with a fairly optimized v1.

I wonder if this is why Firefox feels so sluggish with some more complex SPAs.

tasn··on How fast can browsers process base64 data?
Does anyone know why Firefox/Servo are so slow compared to the rest?
Page 1 of 18Next →