HN user

Azeralthefallen

423 karma
Posts2
Comments45
View on HN

Hi since i know you will never respond to this or hear this.

We spent almost 2 months fighting with you guys about basic questions any B2B SaaS should be able to answer us. Things such as invoicing, contracts, and security policies. This was for a low 6 figure MRR deal.

When your sales rep responds "I don't know" or "I will need to get back to you" for weeks about basic questions it left us with a massive disappointment. Please do better, however we have moved to Copilot.

Without it i would have never been able to succeed in life. For me it was the single greatest decision i have ever made in my life. I simply could not focus on anything important, I was a miserable mess.

I was a consistent grade D student in high school, I was that werido in class who everyone hated. In my final year my parents realizing I was not going to have a great future, decided to bring me to our doctor, I was prescribed Dexedrine for ADHD.

That Pill completely and utterly changed me in my final year, i could think clearly. I understood what was being said, it completely changed me. I suddenly decided to go to University for CS, forcing me to do a victory lap in high school. I was able to get into University on an amazing scholarship.

However the biggest thing was the few people who i was vaguely friends with me praised my 180 personality change, they liked being my friend.

I am now 36 years old taking the same dose of meds i have been for the last 20 years. It works for me, immensely. At the same time there is a huge stigma around ADHD medication. My ex hated the idea of me taking meds saying its big pharma pushing this, i don't need this, i just need exercise, etc. She changed her tune after she saw me not on my medication.

I know there are probably people out there that don't need this or abuse it. Sure, but that is true for almost everything.

It is already difficult enough to come up with naming things that makes sense. I kind of get "master" when used in the context, however things like "owner" i struggle extremely hard with. Especially since major companies like Microsoft use it.

I remember asking what did they suggest instead of owner, and they basically gave a list of synonyms that frankly did not really work the same way, or are insanely long e.g. "Primary Account Holder".

Honestly the person running the seminars was very very strict. Several people said "I don't really care what people call me by", or can I just leave it blank to be what people want. The person explained how that attitude is disrespectful to people who do care about these things, and how it can foster an environment of hostility towards people who put them. Which in turn marginalizes those people etc.

However in January the entire sales team removed them after apparently a customer reacted negatively to the inclusion. Which lead to other external facing teams removing it to prevent the same issue. Most people have removed it from emails, and honestly many people just don't seem to care, and HR doesn't seem to be enforcing it.

The company I work for did something similar at the end of last year. We had consultants who went over everything, and made a massive document of all sorts of things they deemed "problematic". Along with a week long of seminars/training/workshops on sensitivity/inclusion/etc.

- Everyone had to list what pronouns they wanted people to use. In slack / our email footers everything. This was not optional. We were also told that referring to people by their names instead of pronouns can be offensive.

- Words such as "master", "owner", among some other ones were deemed problematic and needed to be changed. Ironically they also said use of "CRUD" was inappropriate because it was slang for poop.

- We have a bunch of things where we have an owner of users/reports/etc, and we have a bunch of code with stuff like "listUsersOwnedByUser", which apparently could be construed as offensive by certain groups of people.

- A bunch of verbs such as "see", or "visible" could be ablest, etc.

- Our company had a completely optional get out/get exercising type of thing since everyone is WFH, and apparently exercise could be considered offensive to people.

- Our company of 300 people does not have some sort of LGBTQIA+ outreach program.

Some of it made sense, but a lot of it was frankly so nitpicky and difficult to even understand. Pretty much everything we were told/taught went out the window almost immediately.

I hate this. We moved from Okta a few years ago after we were basically received almost no actual real support for a bunch of issues, even though we were paying a premium cost. Nobody cares about issues on their Github, the kicker was a when we received a support response as suddenly something was no longer working after an update, we got help in the form of "We have no plans to address this anytime soon." when asking for an ETA.

We ended up switching to Auth0, after we had a few calls with them. We shaved a decent amount off our costs with Auth0's Enterprise plan, and their webtask based rules worked. While the migration sucked for a bit, in the end we were much happier.

Why isn't Auth0 on that list? For most enterprise customers SAML is required for SSO. However SAML is locked behind their enterprise plan (and enterprise is stupidly expensive).

On top of that now enterprise plans now require you to pay by connection as well. So if you want to allow multiple customers SSO connections the cost starts increasing drastically.

I guess my issue is that we didn't want or need support. We just wanted x-pack features such as Auth and the Alerting plugins.

We were already hosting it fine ourselves on AWS, as we had devops people very familiar with ES. However the price they quoted us per year was insane for our cluster size for ~20 nodes.

I love React Hooks 7 years ago

We write tests to verify if things are working correctly using Cypress + Mocha. We have simple unit tests for validating basic functionality and extensive integration tests. We typically have a set of tests per feature.

The problem i have noticed is that people say "well it works in isolation", but on integration with other components it doesn't work properly. Unfortunately this is a huge problem i find, and frankly the idea of numerous shared hooks and ensuring they are side affect free is very painful.

I love React Hooks 7 years ago

Honestly i struggle when people argue that 'this' and class components are complicated, and that hooks remove that complexity. Yet then i see people composing together dozens of various hooks and HoC's to achieve the same balance is beyond confusing.

Recently i was assigned a PR for a component (a login form) i wrote about a two years ago which was a whole 300 lines. The person who wrote the PR also took the time to make it "functional", which has now resulted in it being split into almost a dozen different files. I don't find this cleaner or easier to understand at all.

Current team i am on uses MobX, and Typescript for our app and frankly it is painfully simple, and yet people keep arguing that we should drop mobx, and switch to hooks and i don't see any benefit.

The company isn't in a third world country they are basically reliant on an extremely specialized piece of software/hardware that doesn't work on anything more modern.

Unfortunately this is basically what i am dealt with and i don't have any real options of changing the environment.

Afaik they cannot upgrade because they are heavily reliant on a specialized piece of software that:

1. Requires a dongle attached to a parallel port for it to function. 2. The company who made it went out of business over 15 years ago.

They have plans in the future to migrate to linux, but that isn't in the card for a few years unfortunately.

Idea 1: Is out because they are not actually connected to the outside internet from their workstations.

Idea 2: Not viable due to the sheer number of users most likely.

Idea 3: We tried to get virtualbox to run on their machines, which we found most only have a ~4 GB of ram and it makes hosting an entire other OS a very painful experience.

Idea 4: Looks more and more likely. :(

That is something a coworker is looking into, the biggest problem is we are expected to have ~5,000+ users of our app internally providing them all with VM's is way beyond the scope of what we support.

Even getting our app running on premise was a nightmare, and resulted in us just buying a rack mount and having them put it inside their DC, after everything they gave us was pretty awful.

Honestly we told them our requirements well over a year ago. Which wasn't an issue apparently, even when we did a pilot in their internal labs which they were running Ubuntu.

It only came up after we started the rollout, when someone from their side who was asked to write documentation about how our app would work into their workflow, realized our app didn't work at all on his station. Which lead to oh no their requirements are horribly wrong.

To me it was a communication breakdown on both sides, but i doubt i can get them to change.

I am going to give getting electron built in Virtual Box and see if i have any luck with it.

So basically you are running two graphql services, and using the private one as an ORM?

Doesn't that drastically increase complexity in the fact that you now need to maintain multiple services? Why not just skip postgraphile and just use an ORM in your business layer? As opposed to being required to maintain multiple services.

It also feels very odd that since you can't even expose your private one to other internal services because all your authorization and access restrictions are now sitting in your business layer, which to me seems like a huge waste.

Except utilizing loopback i simply define my models, what fields are exposed by models, and their relationships. I can easily implement RBAC restrictions via a simple access hook or ACL's.

To me having to maintain two separate graphql services for a single API seems extremely convoluted. I can't expose the private api to any other internal services, because all the authorization and restrictions are done on the application layer.

To me isn't that just using a GraphQL server as an ORM? To me that seems like an extremely roundabout way to do something like that.

I recently moved one of our API's from Loopback to GraphQL using Postgraphile. It has been a nightmare.

- Access restrictions, and security is very painful. Trying to enforce RBAC through postgresql policies over hundreds of tables with slightly different policies is a nightmare. Hiding all this on the DB's end and burying this stuff in migrations sucks for anyone trying to develop on it.

- I still have not found a good solution to querying/filtering over things like nested JSONB objects without writing my own resolver functions, which then complicates numerous things.

- Versioning is a mess, especially when you don't have an easy way to force clients to upgrade (i.e. mobile apps), along with other parties using your graphql api directly.

- However the worst thing so far to me has been i have watched as UI developers go from writing simple rest queries, and doing a bit of work on the front-end to writing extremely inefficient and convoluted queries. Even worse is when a third party is doing it and i have no say over what they do with it.

Remote Only 8 years ago

I worked for a company that was mostly a remote workplace for almost a year, and there were a lot of problems i found while trying to manage a team.

Time zones, were a huge issue and pain point when trying to get a large number of people on the same page. I found my self often having to give the same meeting twice, which put more pressure on me. Even worse was when i would have to go over points only for someone who wasn't available for the first meeting, to raise issues that we didn't notice, and so on.

After 6 months the team basically felt like it dissolved into the European team, and the North American Team. With me trying to ferry information from one team to another.

So many times regardless of how amazing the latest tools we tried were, it still pales in comparison to a whiteboard. The company bought me a high end digital whiteboard, that allowed me to pass control to other people, it was a buggy POS. On top of that since i was the only one unfortunately with the white board, it meant i was the one who was always doing the drawing and trying to extrapolate a diagram from what someone says.

Sometimes some team members would spend hours drawing up a digital mock up of what they were going to push for only for it to become completely useless within a very short time.

I also found some people no matter how hard i tried, some people seemed to interpret working remote meant, they got to work in their own silo, and would ignore 99% of everything going on around them. This lead to numerous conflicts, and other issues.

Also one other thing i found, was that 1 on 1's became super impersonal, and frankly felt extremely uncomfortable.

I would love to be able to pay and just block ads on YouTube forever. Unfortunately a lot of the music i like listening to, just isn't available anywhere aside from YouTube.

Even more frustrating is lately i am getting pop ups every 2-3 songs asking if i am still watching. The solution to prevent this is to get YouTube red. Unfortunately it isn't available where i live.

I guess my question is from a security standpoint, how do you prevent something like this if you were facebook? Do you ask any company who does a huge number of API requests requesting peoples friends lists? To verify how they are using the data? How do you actually confirm they are doing what they said?

According to the article only ~200k people installed the app and consented. Unless there was an exploit, you get a minimal version of the data in their friend list (user id, name, that is all i really see) not a full profile. So didn't they only really get the names of 49.8 million people?

Is the solution to just not allow allow a third party token to access a friend list, and only your personal information?

I am not trying to defend what is going on, i am just struggling to see how they were able to use the extremely minimal amount of information the friend list api returns to make a full profile on 50 million people.

Maybe i am misunderstanding something about this whole issue, but was there an exploit or a bug that allowed this to happen on Facebooks end?

I guess my confusion is that whenever someone grants third party access to your facebook, you can query that users list of friends (which i have seen used for things like games and high scores, etc). But you didn't get the full friends profile, instead you got a small subset of it. Did they find some way around that and managed to retrieve the full user profile?

If not then isn't Cambridge Analytica at fault here for misusing someones data? Facebook provides an API and users consented to allowing a third party to access their data. I guess you could remove the friends list, from the API.