HNHacker News
TopNewBestAskShowJobs

tothrowaway

614 karma · joined April 6, 2014

submissionscomments
tothrowaway··on What One-person SaaS Healthchecks.io uses for hosting, hardware and software
I didn't realize you were getting that many requests per second. That's quite remarkable when you only have 18 app cores available. In my experience, you're lucky if you can get Django to service a request in 10ms. So I'd expect closer to 40 cores to handle that level of traffic. I suppose since it is spiky, and not a particularly latency sensitive application, you can get by with fewer cores.
tothrowaway··on What One-person SaaS Healthchecks.io uses for hosting, hardware and software
Can you share more details about what the 4 HAProxy servers are doing? I run a SaaS too, but on a single beefy machine handling web and DB stuff. I'm curious what I'm missing out on not using HAProxy in front.
tothrowaway··on I won free load testing
OpenResty (Nginx + LuaJIT) can help you limit the damage of unsophisticated DDoS attacks like these. I keep a count of the requests-per-second I'm getting in each nginx worker. I also set a special cookie for every response from the upstream (it could literally be foo=bar). When the RPS goes approve a certain threshold, if the special cookie is not present, I serve a static HTML page (bypassing the upstream) that sets the cookie and reloads the page (Nginx can do 20K+ RPS without breaking a sweat). In my experience, these fly by DDoS attacks never use cookies, so legitimate users can get through, but the bots are blocked.

Of course, if you get hit with something slightly more targeted, this defense is worthless.

tothrowaway··on The Sound of Silence: A Noise Map of the U.S.
The cars, trucks and motorcycles with booming exhaust pipes are insufferable. I despise hearing them revving by. I feel like I'm crazy for how much it bothers me. But then I read a story about a man shooting a driver who was just revving up and down his street, so I'm not alone.

I spent a week in Helsinki, and was blown away by how quiet it was despite being far more dense than my city.

tothrowaway··on Follow up to Show HN: I’m a pregnant hacker. Here is my side project
It sounds like your project could have been an ideal "lifestyle" business. Going from 0 to 1 employee must have been a big step. How did you decide to hire your first employee (and what did early employees do)?

And congratulations on the achievement!

tothrowaway··on Ask HN: Have your ever faced a DDoS attack?
I occasionally receive application layer DDoS attacks generating around 20k requests per second (where typical legitimate traffic is 100 r/s). So nothing huge, but enough to cause problems for ordinary Django/Python applications like mine.

To fight them, I use OpenResty (which doesn't seem to get much attention on HN). OpenResty is basically Nginx with Lua scripting capabilities. Before any HTTP request hits my (slow) backend, it goes through a set of hand written Lua rules where I check very basic things about the client and HTTP request like how many requests/second (or minute) the client is generating, does it have any authentication cookies set, what is the client's ASN, how many times has it hit this particular route, etc. If there is a red flag, I quickly render a page (in OpenResty/Lua -- which can easily handle thousands of requests per second) with a captcha on it. The client then submits the captcha, and the server side Lua code sets a signed cookie authenticating their session (so it is not blocked for future requests).

One gotcha I remember was having to take special care to handle POST parameters from the initial request but otherwise, it was fairly simple.

My "web application firewall" has some fancy things like hot-reloading rules, fetching ASN numbers from the IP, and checking for legit bots (with reverse DNS lookups). I like to imagine it as an early form of Cloudflare.

I should note that my "captcha" is actually just a static image (with the alt/title attribute as the correct response). The people who attack my sites never bother to customize their attack. If it becomes an issue, I'll have to use a real captcha, but for now, it works.

I feel like these people just hit random websites to test their DDoS capabilities.

tothrowaway··on Ask HN: How do you handle user-generated content in your apps?
I would love a "Backblaze of user generated content". The existing players in the market are way too expensive (likely because they run off the cloud cartel and pass along their bandwidth tax). Basic image handling isn't too hard to deal with on your own, but video and audio is a huge pain. The uploading (which needs to be fault tolerant and resumable), encoding (which takes a long time), storage (which is large) and playback (which requires a half-dozen different formats) is all very annoying to deal with. So much so, for my SaaS products, I only allow my users to upload images!

I had the exact same idea as you, and shelled out a few hundred dollars for a domain from a squatter. My prototype basically reinvents fault tolerant resumable uploads (like tus.io). On the backend, it streams the file to Wasabi and Backblaze. That's as far as I got. Video/audio scares me, but I'll get to it eventually.

I really like the content moderation as a service (via AI, or humans) idea that others have mentioned.

tothrowaway··on Beware HN: The rise of weaponized "abuse" reports
I had to respond since I didn't want Namecheap to remove my business from the internet. The response from the support agent was:

""" The preceding report appears to have been sent to you in error. Please accept our apologies for the mix-up and the false positive alert.

Please let us also assure you that we do value our long-term partnership with you and value you as our loyal customer. The situation experienced is no more acceptable to us than it was to you.

Such a time frame was specified in our initial email as phishing is considered to be a time-sensitive issue. However, we try to extend the time frame provided to our loyal customers to the maximum possible extent. Hence, the 24-hour time frame would have been extended in case of no-response from your side and we would tried to reach you again. """

I CC'd the CEO, but haven't heard anything direct. I can't have my domains with a company that has their trigger finger glue to the "suspend" button. I just don't know who else to register with. It's all a race to the bottom in terms of service and pricing. There doesn't seem to be a middle ground between MarkMonitor and Namecheap.

tothrowaway··on Fire declared in OVH SBG2 datacentre building
I'm at OVH as well (in the BHS datacenter, fortunately). I run my entire production system on one beefy machine. The apps and database are replicated to a backup machine hosted with Hetzner (in their Germany datacenter). I also run a tiny VM at OVH which proxies all traffic to Hetzner. I use a failover IP to point at the big rig at OVH. If the main machine fails, I move the failover IP to the VM, which sends all traffic to Hetzner.

If OVH is totally down, and the fail over IP doesn't work, I have a fairly low TTL on the DNS.

I backup the database state to S3 every day.

Since I'm truly paranoid, I have an Intel NUC at my house that also replicates the DB. I like knowing that I have a complete backup of my entire business within arm's reach.

tothrowaway··on Ask HN: Are there any good open source tax software projects?
If a rich person shorts Intuit stock, spend $5-10 million developing a really slick tax program, and releases it for free, could they break even?

They could make it a charity, and the $5-10 million would be tax deductible on top of it.

At that point, maybe Intuit wouldn't have the motivation to keep the tax code complicated. Then we could move to a simplified system at the speed of congress.

tothrowaway··on Our Dumb Security Questionnaire
> it probably won't be cost-effective for most vendors to gather and collate this documentation, as well as answering these questions, just like it's not worth it to ink a custom contract on a smaller deal, where legal fees alone might eat up the entire profit margin or even push it negative.

Indeed. I get these security "wall of questions" for my $10/lifetime SaaS product (it's a dumb little puzzle maker). I can't fathom why anyone thinks a vendor would spend the time answering their questions for that kind of money.

In their defense, it's probably a standard part of the procurement process and they don't even look at the app before sending the questionnaire.

tothrowaway··on No meetings, no deadlines, no full-time employees
Health insurance premiums are deductible for self-employed people (and 2%+ S-corp shareholders): https://www.irs.gov/publications/p535#en_US_2019_publink1000...
tothrowaway··on Azlo Bank Is Closing
I hear Mercury is an alternative. I didn't have any luck signing up with them though (they refused me service for the bizarre reason that I couldn't provide the EIN registration form I got from the IRS a decade ago).
tothrowaway··on Ask HN: Best Paid Gmail Replacement?
The Fastmail web interface currently hijacks the clipboard and "helpfully" appends the URL to your clipboard anytime you copy text from a link. It's absolutely maddening.

Aside from that, I have no complaints about their service.

tothrowaway··on A collection of deliberately inconvenient everyday objects
This has been submitted to HN before, but I was inspired to post it again after encountering the digital equivalent of it in one of Fastmail's "features".
tothrowaway··on Is there still somebody in the Cairo community who is able to make a release?
resvg - https://github.com/RazrFalcon/resvg

The developer also produced an incredibly useful SVG test suite comparing various libraries https://razrfalcon.github.io/resvg-test-suite/svg-support-ta...

tothrowaway··on Standing on our own two feet
> As of January 11, 2021, we’re planning to make a change to our API so that ACME clients will, by default, serve a certificate chain that leads to ISRG Root X1.

Ouch. So anyone who wants to support older devices 3 months from now needs to add `--preferred-chain "DST Root CA X3"` to their certbot command. When that chain is completely retired in September next year, certbot appears to fallback on the default (even with that argument present).

tothrowaway··on Ask HN: Cards rejected by Stripe are accepted by PayPal
Are you using the older (and simpler) synchronous "Charges" Stripe API? Many non-US payments require a text message for verification by the card holder. Using the asynchronous "Payment Intents" stuff should fix that. I recently switched, and it dramatically improved the charge success rate for non-US customers.
tothrowaway··on Ask HN: How many hours per day are you working?
I tracked my productive time down to the minute for 4 years when I was working for a consulting company. I could do 4-6 hours of actual programming work in a 9 hour time span. Any more than that, and I was exhausted.

I'm a solo dev now. I don't keep track of my time religiously but RescueTime reports I'm coding 3-4 hours a day plus 1-2 hours of email.

tothrowaway··on Ask HN: How do you deploy a Django app in 2020?
You'll probably get 10 different answers here too.

I use uwsgi in emperor mode. I have a Makefile that runs a few SSH commands on production to clone my git repo at a specific commit, builds a virtual environment from requirements.txt, and atomically swaps a symlink to a uwsgi socket. Nginx in front of it all. It's pretty much the Python equivalent of FTPing HTML files to a web server.

Uwsgi is terrifying because it has so many options (and I wonder how secure it is), but it has never failed me. Packaging and containerizing things sounds cool, but I just can't justify spending time on it when my setup works fine (I'm a solo dev).

tothrowaway··on Ask HN: PayPal Cards
FWIW, I also got an unexpected notice that a PayPal debit card is being shipped to me.
tothrowaway··on Building a Crossword Puzzle Generator with JavaScript
I have a great story about generating word searches. I once got an angry email from a superintendent at a school district in Washington state using my algorithm. He said 'the generator inserted the phrase "killanigger" in the middle of the word search. This is obviously intentional on the part of the programmer since the odds of a phrase of this length being generated randomly is exceedingly small.'

I was very confused because I had implemented a bad word filter which I knew worked (it was the most interesting part of building a word search). And obviously, I didn't hard code that string in my program!

I asked to see the offending puzzle. Upon inspection, I found that the word search contained the word "ORIGINAL". When reversed for the word search it is "LANIGIRO" (which contains the substring "NIGIRO"). The start of another word - "LAW" - was placed next to "LANIGIRO" (by random chance) creating the string "LLANIGIRO". The two preceding randomly chosen letters were "K" and "I", forming the string "KILLANIGIRO".

I explained it to the superintendent, and all was well again.

tothrowaway··on Ask HN: How much coffee do you drink as a programmer?
I hate the smell too. I commented to a friend that coffee smells like canned tuna. She thought I was making it up, and Googled it. Turns out, I'm not the only one:

http://thefrenchexit.blogspot.com/2012/02/why-does-coffee-sm...

tothrowaway··on Ask HN: Cease & Desist on using the word egress. Sign it away for eternity?
If you don't mind sharing, what kind of insurance policy did you obtain? It's surprising to hear an insurance product would cover your legal fees for something like this.
tothrowaway··on Milton Friedman: Is Capitalism Humane? (1977) [video]
Anyone looking for a challenging read should consider Milton Friedman's book "Capitalism and Freedom". It's short, but very dense. He covers topics like a negative income tax (which you've heard of) and ideas you've probably never considered (like school vouchers, elimination of occupational licensure, and elimination of tariffs).

The downside is, if you find his arguments convincing, it will leave you feeling even more angry about the current role of government in society.

tothrowaway··on Fintech startup Plaid raises $250M at a $2.65B valuation
When you sign up, you grant the service the limited power of attorney to login as you. Typically a POA needs to be witnessed and/or notarized. I'm not sure how they're getting around that.
tothrowaway··on Ask HN: What is your favorite screen recorder?
For simple recordings, I use https://screencast-o-matic.com
tothrowaway··on How did Google manage to screw up Google finance so badly?
Gmail, Google Maps, Google Fiance, Yahoo Finance, Reddit, Netflix and NewEgg.com are all significantly less useful/usable than they used to be.

We need a term for when a company purposefully makes their website worse. It's kinda like the digital equivalent of planned obsolescence.

tothrowaway··on Ask HN: Copying already existing product and making it better
That's my bread-and-butter. I take a good SaaS and strip it down so it's simpler for people to use (and for me to build). Then I sell it for significantly less than my competitor. Simple & cheap is "better" for some people.

The trick is to find a good niche, so you can build a bunch of semi-related SaaS apps and cross market them. I've found developer related SaaS (web browser testing, PDF generation, log analysis, cron notifications, etc) are highly saturated.

To be fair, none of my products qualify as "startups". But building a lifestyle business has a lot of perks (no stress).

tothrowaway··on Show HN: Termly – Free Policy Generators for Websites and Mobile Apps
You'll see similar language on LegalZoom, or any legal form website. Legal advice has a specific meaning in each state. Things like legal facts and forms are generally not considered "legal advice".
← PreviousPage 3 of 4Next →