HNHacker News
TopNewBestAskShowJobs

tothrowaway

614 karma · joined April 6, 2014

submissionscomments
tothrowaway··on Estonia: Become an E-Resident
Yup. The remote worker visa application was simple enough (I'm self employed). I live in a nice apartment in Tartu for 800 euros, 40 for internet, 30-100 for utilities, 70ish for health insurance. I've got a gym, store and pizza place within a few blocks. Most people speak some English. Estonians definitely look grumpy (no offense), but generally lighten up when they realize they're dealing with a clueless American.

My main complaint is that the remote worker visa gives you the right to stay in Estonia...and nothing else. You don't get an Estonian ID which is necessary for all sorts of things like setting up internet, getting a local phone number, or getting books from the library, and you can't get a bank account to pay your rent. LHV, Coop and SEB all claimed I could open an account with just my passport and lease agreement, but denied my application (after paying several hundred in application fees). The e-resident card is basically useless.

The tax situation is unclear. You become a tax resident when you stay over 183 days. But all US citizens are tax residents of the USA, so the USA-Estonian tax treaty kicks in with its tie breaker rules. Because I have a house in the USA, it means I would be treated only as a tax resident of the USA, so I would only pay taxes there...I think? But I can't imagine why Estonia would offer this visa program if they weren't getting something out of it.

tothrowaway··on Ask HN: What's Your Favorite Algorithm?
The Hungarian algorithm. It solves the assignment problem (the optimal way to assign workers to tasks given their completion time of each task). The assignment problem looks hopelessly O(n!), but by some magic, the algorithm can solve it in polynomial time.
tothrowaway··on Show HN: Nudges.fyi – simple, unmissable reminders via phone/text/email
Something to consider: Make it possible to create a nudge without signing up. I would even go as far as making the homepage the interface to setup a notification (with ample explanatory text). I think it's much more likely to catch on that way.

You can include a magic link in the notification so the user can manage it without an account.

tothrowaway··on Ask HN: Have everything one could want but still nowhere near satisfied
A phrase constantly repeated in my anthropology class comes to mind: "to survive and reproduce". You have the survival part down, but you are missing the other half. I think anyone without kids is at high risk to feel empty as they get older (I say this as someone without kids).

Maybe adopt a dog? I think you can even foster them if you just want to try it out.

Lifting heavy does wonders for my mood. If you can motivate yourself to get to the gym, Starting Strength and 5x5 are good programs.

tothrowaway··on Engineers should do customer support and success
I'm in a similar boat. But try as I might, I have yet to find a solution for the "I forgot the email address I registered with, and I am too nervous/confused/unimaginative to try my other email addresses, nor will I click the 'Trouble logging in link?' to help myself, so I'll send you an email from an address you have no record of (using my maiden name), while providing no further information to help identify myself, demanding that you tell me my credentials" people.

I get just the right amount of these emails so it's not worth hiring someone for, while still enough to drive me nuts.

I wish there was a support-as-a-service company that had non-outsourced employees (not contractors) and charged per-minute (or 6 minutes) for support, with some fixed cost for training them how to use your app, and handle basic support questions.

tothrowaway··on Ask HN: Is anyone else trying to opt out of Equifax WorkNumber?
Gusto never responded. That is quite incriminating to me (you can't plea the 5th in the marketplace).
tothrowaway··on Ask HN: Is anyone else trying to opt out of Equifax WorkNumber?
I just emailed Gusto to find out if they are sharing data with Equifax. I did not see a way to opt out in the employer or employee interface.
tothrowaway··on Lessons learned since posting my salary history publicly
Do any UK people here know what the typical employer taxes are on payroll? US companies pay around 10% of the employee's salary in taxes (~8% for social security and some change for workers compensation, unemployment and whatever else the state demands). So if your salary is 100k, your actual value to the company is closer to 111k (plus whatever benefits they are paying like health insurance).

90k seems low compared to American salaries, but if the employer has to pay 50k in UK taxes to hire you, well, that (partially) explains it.

tothrowaway··on Ask HN: Best way to stop bot traffic?
Most bots don't bother setting cookies, or downloading CSS. Exploit this by including a dummy CSS file on your site that, on the backend, stores the visitor's IP in some kind of database, or sets a cookie. If you get multiple visits from an IP that never hit the CSS file, you can be reasonably confident the user is not legit. You need to be careful about not blocking good bots though. Do a reverse DNS lookup before actually blocking an IP to make sure it's not Googlebot, yandexbot, bingbot, slurp, etc. OpenResty is great for implementing this.

It has the nice side effect of protecting you from run-of-the-mill DDoS attacks too.

(I realize half my comments here are about OpenResty, but I have no affiliation with them. I'm just a happy user.)

tothrowaway··on Stripe is PayPal circa 2010
Unless something has changed, Adyen only works with businesses with payment volumes in the millions. They don't have a sign up form. It's a "Contact Us" kind of thing.
tothrowaway··on Ask HN: How do we feel about Canadian businesses charging customers cc fees?
There's a cost to handling cash. It can get stolen by employees or robbers. It can leak away when giving incorrect change. There's a chance you get counterfeit bills. The bank charges you to deposit it. And most brick and mortar businesses aren't paying the 3% that Stripe & friends charge. They get much better rates.
tothrowaway··on Ask HN: Companies of one, what is your tech stack?
When a resource is cached, how do you know ahead of time how long to cache it for? If you set X-Accel-Expires to 5 minutes, but the resource is edited 3 minutes later, how do you evict the item from the nginx cache?

You can figure out where the item is in the nginx cache directory and delete it. But that is complicated by the fact that your app and nginx run as different users. Or you can send a specially crafted HTTP request to nginx assuming you have some kind of backdoor proxy_cache_bypass setup. But that's ugly too. You either have a race condition, or you have to hang your app's response until the invalidation request completes.

If there's another way to evict an item from the cache, I'm all ears.

tothrowaway··on Ask HN: Companies of one, what is your tech stack?
When a non cached request comes in to the Python layer, I set a response header with that object's modified date. Lua intercepts that response header, and stores the modification date in a shared dictionary under that object's cache_key.

When the next HTTP request comes in to view that object, I lookup the object's date in the shared dict. If the modified date is > now(), I set the bypass flag to 1, so nginx updates its cache.

tothrowaway··on Ask HN: Companies of one, what is your tech stack?
I run several SaaS apps on a single big OVH server. It handles 6 million non-cached requests per day. The backend stack is pretty basic: Django/Python, MySQL, redis (pub/sub) for websockets. But the secret sauce is OpenResty. I use Lua scripts to do more sophisticated page caching (because the builtin nginx caching is so primitive), DDoS protection, handling websockets, offloading long running requests, and routing between my unix socket upsteams. It's a poor man's Cloudflare in 1500 lines of Lua.

The apps were made long before Docker was a thing, so they just run as regular ol' processes, locked down as much as possible with systemd magic. I originally used uwsgi as my wsgi server, but it turns out gunicorn is vastly more efficient so I use it exclusively now.

I run a warm standby server at Hetzner so I can route traffic there in a pinch. I have a second warm standby running at my house because I'm truly paranoid about automated account bans (despite the very innocuous nature of my business). Backups are at rsync.net.

My single point of failure is DNS. I had a good relationship with DNSMadeEasy so I was not too worried about automated bans. But they were just bought by DigiCert, so that's a problem now.

Payments are handled with Stripe and PayPal. I added PayPal (despite my hatred of the company) just because I'm scared Stripe will ban me without warning, for no reason, and won't communicate with me.

For user uploads, I have an aiohttp Python server that streams files to Wasabi and Backblaze, and caches them in nginx at the same time. So my cloud bandwidth bill is usually 0.

The websocket layer is kind of wonky. Originally, I used the Python websockets asyncio library to do everything. It worked for a while, and then I had to make it multi-process to spread the load. But it was just eating resources like crazy. I decided to use OpenResty's websocket stuff to handle the connections, but I didn't want to write all the complex application logic in Lua. So I used Redis pub/sub to pass messages back and forth from OpenResty-land to a pool of (sync) Python processes. It worked much better. That said, I'm a novice with asyncio, so I could very easily be to blame for the original performance problems.

And sorry, I won't tell you the name of my apps (I don't need any more competitors!)

tothrowaway··on Pingora, the proxy that connects Cloudflare to the Internet
Does anyone know why nginx used separate processes for workers, instead of threads? This post makes it sound like threads are the way to go, but presumably nginx had a reason for using processes back in the day.
tothrowaway··on Ask HN: Travelers of HN What's the Most Useful Thing You Own?
A Costco mixed nut container. Eat the nuts, scrape off the label, and you've got something more useful than a typical packing cube. You can densely pack clothes in it, or use it as a catch all container for loose items. It's clear, so you can pick the items out easily (and the bureaucrats can inspect it), and it's rigid, so things won't get banged up. When you're at your destination, you can use it as a general purpose storage container. It also fits under your airplane seat so you can use it inside your "personal item".
tothrowaway··on Ask HN: What country is easiest to go from USA and have insurance without job?
You have to read the fine print, but generally they do. The coverage is limited to the time period you purchased it for, and they are unlikely to renew it if you get cancer. To work the system, you need to ensure you're covered until Jan 1 of the following year. Then in November (during open enrollment), either get a USA policy (if you have cancer), or at the end of open enrollment, extend your travel insurance for another year.
tothrowaway··on Show HN: I built a quizlet clone in 2 hours
On behalf of HN (which I have no authority to speak for) please disregard that bizarre rant by our resident curmudgeon.

If you really did all that in 2 hours, that's quite an accomplishment! But I think it's a little early for a Show HN. It's tough to use without any kind of instructional text. Repost when you've got a more usable interface, and I think you'll get more traction here.

I really like how you don't require people to register. I do the same thing for all my apps, and it's great for getting people hooked. No one likes a sign up form. Just store people's data in a cookie, or localstorage until they make the decision to sign up.

Your Anki comment is spot on. When I downloaded it (a few weeks ago actually), I spent 5 minutes making sure that website was _really_ the Anki I heard about on HN.

asuth was around 15 when he built Quizlet and now it's (somehow) worth a billion. There's plenty of room for a newcomer in the market especially since Quizlet started putting things behind a paywall. Good luck!

tothrowaway··on Namecheap vulnerability they refuse to fix: no 2FA on support portal login
I moved away from Namecheap because they threaten to deactivate one of my domains within 24 hours after receiving a fabricated abuse complaint from a reputation management company. I saw from my logs that Namecheap did not even visit the page in question. I couldn't trust Namecheap after that and moved to Porkbun. I can't say with any certainty Porkbun would handle that situation any better. But I like the fact that if they try to pull some Google-esque automated ban, I can drive to their HQ.
tothrowaway··on Toptal trying to sue us for saying there are Toptal alternatives that cost less
I wonder if this person knows that you do not have to respond to a C&D or submit to its demands? If a party makes a frivolous demand like this, yes, they can file a lawsuit against you. But the chances of that happening are quite slim. Even the most unethical lawyers hesitate to bring junk like this in front of a judge.

Unfortunately, if you talk to a typical lawyer, they will always say that it is in your best (legal) interest to send a strong response back (at a mere $300 hour, or $3000 flat fee).

tothrowaway··on TIFU by using Stripe as a payment processor for my small business
Putting my dang hat on. Related:

Tell HN: Stripe brought my business to a dead stop - https://news.ycombinator.com/item?id=21030633 - September 2019

Tell HN: Stripe shut down my 4-year business with no explanation - https://news.ycombinator.com/item?id=28085706 - August 2021

Stripe banned us for payment disputes but we never had a single dispute - https://news.ycombinator.com/item?id=28522784 - September 2021

Stripe Shut Us Down - https://news.ycombinator.com/item?id=28881026 - October 2021

Help HN: Stripe shutting us down with 48 hours notice on a holiday skeleton crew - https://news.ycombinator.com/item?id=29712023 - December 2021

I'm probably missing a lot of threads.

tothrowaway··on Analyzing Indie Hacker Products with Verified Revenue
Why is revenue the prevailing number used for measuring a business? I see revenue cited almost universally these days, with no mention of profit.

A hardware company that makes $100k in revenue (with no profit) is very different than a SaaS product that makes $100K with 90% profit. Why don't we just use profit?

tothrowaway··on The New American Micro-SaaS Dream
Go to indiehackers.com and find out what profitable businesses people have created. Make a competitor. The profit margins in SaaS are phenomenal so there is always room for new entrants.

You can throw some keywords into the Google Keyword Planner tool, and see what people are searching for. Or just run a normal google search for "tools for <industry>" and see what pops up.

Don't be discouraged by competitors. Their existence basically pre-validates the market for you. Just make sure you can differentiate yourself somehow (usually, on price because your product will be less feature rich initially).

And I'll throw this in without any kind of justification: don't make a SaaS for other developers, or lawyers.

tothrowaway··on FDIC Failed Bank List
I would never keep more than $250K in a bank. Many people (and even tellers at the bank) don't understand FDIC insurance ownership categories. You probably don't have as much insurance as you think. Bank failures do happen, and you don't want to lose thousands of dollars when it takes a few minutes to open up a second savings account. Ally, Barclays, American Express, Discover are all fine choices for parking money.

If you have tons of cash (nice problem to have), you can open up brokerage accounts (Schwab, Fidelity, Vanguard are good ones), drop your money in a money market, and SIPC insurance is good for $500K.

There are also "cash accounts" at some banks that will spread your money around for you to maximize FDIC coverage. I don't like this, because you're putting all your faith in one bank saying "trust us".

tothrowaway··on Ask HN: What is the best way to Upload Images to AWS S3?
I used S3 a few years ago so this might not be as big of a problem now. But when I started using presigned POST requests to upload documents directly to S3 from the client, there were sporadic problems from the US military, some corporations, and many K-12 schools. S3 would be blocked on their end (likely because someone downloaded a malicious file from S3, and a system admin blocked the whole domain without realizing what they were doing).
tothrowaway··on Show HN: Domfetch.com - free tool to find expired domains with history
This is great! On minor thing: you should scroll to the top of the page when the next button is clicked.

I found some not so terrible domains that are actually available:

repofire.com - Sounds like one of those named security exploit websites

startrekfirstcontact.com - Need I say more?

mscave.com - Man cave for the misses

mailomega.com - Ship via USPS, UPS, FedEx, DHL and more!

healthwestern.com - Sounds like a legit business

rethical.com - Tethics but with an R

shopfitr.com - Web 2.0 clothes shopping

cokego.com - Coke in an easier to carry can so you can do cool stuff

xscut.com - As seen on TV exercise machine or diet pill

coughbank.com - What were they thinking?

blingstack.com - The latest craze in web development: bash, linux, indigestion, netcat, and ghostscript

bankwestbank.com - Banking services by the Department of Redundancy Department

myonefamily.com - Anti DNA testing lobby group

itsorigin.com - Prequel to It the movie

awayget.com - Vacations for dyslexics

I'll see myself out...

tothrowaway··on Ask HN: Employee wants stock; what do I do?
Have you considered offering the employee a profit sharing arrangement instead? That would keep your S-Corp administration simpler and save you a lot of paperwork.

I run a small SaaS myself, and would never consider adding a shareholder unless it was tremendously beneficial to the company. If you already had other shareholders, I might understand giving some stock away on a less than ideal basis. But not when you have 100%.

tothrowaway··on The Great Cloudwall
OVH has DDoS protection, and using OpenResty as a WAF works well for me. I have a hundred(ish) lines of Lua code to handle attackers that get through OVH. I think most people could manage with a similar setup because most DDoS attacks are not very sophisticated (you're basically dealing with `ab -c 1000 -n 1000000 nickjjswebsite.com` from a bunch of hosts on DigitalOcean and Linode that some teenager hired a guy on Fiverr to execute so he wouldn't have to do his homework assignment).
tothrowaway··on For $5/mo, you can steal $38,000/month from your enemies
Small business here. I get hit with DDoS attacks (sometimes as large as 1 Gbps) frequently enough that I won't touch cloud services. I do use Backblaze and Wasabi for user uploads but I proxy them through Nginx (with local caching). My host, OVH, does OK filtering some of the obvious bad traffic, but application level DDoSs get through.

I don't really understand the CDN business. I've got a ~130ms ping to my web apps from where I am right now, and can't say I've noticed it compared to the 60ms ping I had before. If I put my stuff on a CDN, it speeds up loading static assets the first time the page loads (nice). But then I have to worry about the CDN going down and taking me with them, or getting my account disabled by some algorithm in the fraud department (see Cloudflare posts from last week). Seems like a high price to pay.

tothrowaway··on Google will not let me pay an invoice they sent me
That happened to me. After a few years, Google sent the money to some state agency. I filled out a form and submitted evidence that it was my money. Eventually I got a check in the mail from the bureaucrats. I was surprised it actually worked.
← PreviousPage 2 of 4Next →