What you say makes sense, but I think there can be reasons. For our military customers we offer an air-gapped version of our app early on because it was easier for customers than getting an ATO. Also as a bootstrapped company it was a lot cheaper than FedRAMP. I'm guessing I'd lean on a similar strategy if I had a health care startup.
HN user
SMrF
My name is Sean Fioritto. Why did I create this account if I never say anything?
http://www.planningforaliens.com | @sfioritto
email: sean@planningforaliens.com
SOFware | Remote (US) | Full-Time | https://sofwarellc.com/
I am the Director of Product Engineering at SOFware. We are a fully remote, small and profitable software company founded by a retired Navy SEAL turned Ruby on Rails dev. We serve the most elite units in Special Operations and Law Enforcement communities. We have a SaaS product for Assessment and Selection and Talent Management, (e.g. software for the selectors who decide who gets to be an operator plus ongoing measurement of individual performance once selected). We also staff and run traditional butts-in-seats DoD contracts for a few government-owned apps that we created, run and maintain.
If you're an experienced Ruby on Rails developer interested in working on hard, important technical problems for special operations and other military units we'd love to talk. If you're not so experienced but have a background in any of these communities please reach out anyway!
We are currently hiring for one position for a senior Ruby on Rails dev, details are here: https://sofwarellc.com/careers.html
If you have any questions I'm sean.fioritto at our domain.
SOFware LLC | Software Engineers | REMOTE (USA)| Full-Time
For the past 10 years we’ve helped in the selection and assessment of candidates involved in Elite Special Operations Forces and Federal Law Enforcement. We help deep select the best and put them in positions of leadership faster.
Our core team consists of Engineers and Former Operators. Some are both!
Our main technology stack is Ruby/Rails with some front end pieces built in React or Stimulus depending on the lift.
We believe in the strong link between developer productivity and happiness. So we encourage building tools to prevent mind numbing tasks: DSLs, Generators, and Scripts. We’re also big on collaborating. If you tend to be “married to your code” this role isn’t for you.
We work strictly remote but do sometimes send our developers onsite to interact with our analysts and users. We want to be sure everyone is understanding/building what the user needs.
Other benefits:
— Medical/Dental/yadda yadda
— Disability
— Life insurance
— 401(k) after three months of employment
— Company-provided laptop and home office allowance
— Federal holidays plus liberal PTO policy
This role would require you to get a SECRET security clearance which we would sponsor.You can check out our website but it’s dated and built to target DoD offices. https://sofwarellc.com/
Contact us at hn@sofwarellc.com
This position requires proof of vaccination to be provided by the date of hire, unless an accommodation request has been provided and granted pursuant to federal law.
SOFware LLC is an Equal Opportunity employer
This book is awesome! Really glad to see someone mentioned it. It has just enough about design so you can make something that doesn't look terrible. :-)
Honestly, hadn't thought about accessibility. Thank you for bringing it up! I'm going to start looking into captioning services.
Been lurking on HN forever, this is my first Show HN. This is my second product, the first was a book for web designers.
I used to run a meetup group for developers with side projects. We were all there for the same reason: we love programming and our jobs were not a great outlet for creativity or challenge.
This is basically a reaction to the fact that most of us never actually finished a side project, and most of us are still stuck in the same situation at work. :-(
Usually these "lessons learned" posts are very hand-wavy and hard to relate to. But this post has some great tips and the author sounds like me, just a regular person trying to sell a product.
I also think that building something beyond your authority is a really common failure pattern more people should be aware of.
Well, My book will not be low-quality. And it will be evident after I've written some high-quality sample content and guest blog posts. So the landing page is just the final step in the funnel.
That said I don't mean for it to look low-quality. That could just be a side-effect of my lack of design skills. :-)
I only have before data right now, and not a lot. I'll be sure to post data for the new landing page, just as soon as I get some.
The funny thing is I agree, but I don't think I'll do it. The old version is just so bad I feel like I'd be throwing away money. I'm not internet famous so traffic is hard for me to come by. Can I justify a split test?
So the question becomes do I trust the experts? I do. Therefore this landing page is my new baseline -- I'll split test from here.
Thanks Barry. It was nice to meet you there. It was such a great conference, I learned so much and met so many great, like-minded folks.
Not yet. I have some posts in the works for web designers so I'll see how they convert compared to the old page. I'm ignoring all stats while this article is on HN. This isn't exactly the target audience for my book.
Just a book. Software soon. I wanted to start with something small that I could do relatively quickly, so I'm writing a book. Then I will convert readers of my book into customers for my software.
Awesome. I'm glad it helped. BaconBizConf was awesome, I highly recommend it for bootstrappers.
This is surprising. It's just HTML on S3 with cloudflare in front. Maybe Typekit is slowing it down...
"Not only do those audiences not buy things, not only are they scattered and incoherent and unprofessional and in many cases incompetent and/or broke…"
Ok, so to perhaps answer my own question I'm just going to reverse this. A good niche buys things (specifically software if you're selling it). A good niche is well defined, easy to find and filled with competent people with money to spend.
I think it's interesting that we are defining a kind of person, not a job description or industry.
"I know Hacker News types think that’s a great list of niches, but it’s actually a really terrible one. You can’t sell to ANY of those people."
This piece of the conversation really left me wanting more, especially since I've been using that very same list with no success over the years. What are some good niches? Better yet, what's a heuristic for picking good niches? She seems to suggest we should focus on an audience we already have, as Nathan has with web developers (designers?), or that we could easily build. So I am the local corporate javascript expert: perhaps I could rally that into an audience of javascript developers or maybe even people that really need javascript developers?
I live in Chicago and I'm an experienced developer. I want to start a company but I don't want to go the seed funding route because I want to create a profitable small business, not a startup. Is there a Starter League for me?
Not that the non-existence of such a program would stop me...
"Nobody reads from just 15 or 20 sites a month. People read from hundreds of sites a month, creating a vast long tail of publishers."
And somewhere out there Ted Nelson is saying, "I told you so. We needed transclusion, transcopyright, and micropayments in our hypertext from the beginning!"
http://en.wikipedia.org/wiki/Project_Xanadu (p.s. not a xanadu zealot, just fascinated by the history)
I'll be surprised if a widely adopted single sign-on solution emerges from a standards body. Standards should be formed from working code, not the other way around.
Also, I'm not sure what standard you are talking about. They have a very nice spec here: https://wiki.mozilla.org/Identity/BrowserID But this is not a standard.
Mozilla's contribution to this space is obviously going to carry more weight than foamicate, but I say let the best solution win and let's see what else we can come up with. Don't shoot this down by saying it's not a standard.
It's insulting to be lumped into a stereotype, so it's hard for me to not get defensive. Chicago is one of the greatest cities on the planet. The population is very diverse. It's why I moved here in the first place and why I just bought a house here. So it's pretty strange for me to hear someone say we're all "midwestern". But we're used to name calling in the Windy City, so I'll let it go.
Bottom line the startup ecosystem in Chicago doesn't have it's fair share of Webvans for one simple reason: people go where the money is and the money is in Silicon Valley. It's an accident of history that all the money is in Silicon Valley. "Midwestern culture" has nothing to do with it.
Or maybe everyone is starting up in Silicon Valley because of the weather, I think PG mentioned this once. Well to that I say it's 70 degrees and sunny in Chicago as I type this...in the middle of March. Maybe global warming will mean we get a few pets.com here in the midwest.
"...creating 100% safe neighborhoods through smart surveillance. People are rapidly becoming accustomed to being tracked all the time, anyway."
This comment shocks me. I'm not sure what to say. Are you being sarcastic?
An apt metaphor for people becoming accustomed to surveillance is slowly boiling frogs to death. And what is your definition of safe? If it were up to me, nobody could wear the color black at night -- too dangerous! Also, drinking too much at the club is not acceptable in my society!
I'm being silly, but where do you draw the line? It's a slippery slope...
And then the article requires a Facebook account to comment.
"Hey look, we're quickly aggregating all of our personal data into one centralized place creating an obviously appealing target for authority as evidenced by this recent trend of college sports programs invading the privacy of students. Let's all talk about it on Facebook."
This is indeed very simple. But I'm afraid this will evoke what I call the "crypto gag reflex" which in this case would be, "client-side javascript + crypto === BAD."
How do you respond to this criticism? Is it valid in this case?
I feel like using localStorage to cache stuff that could be handled by http caching is probably a mistake. I'm in the process of caching a bunch of our application in localStorage because a quirk in our client-side architecture means I need to know if something is cached before making an asynch request for content, (which you can't do with the standard http cache). That means I'm reinventing a cache invalidation scheme -- which we all know is hard, right? Plus the space allocated for localStorage is pretty small, so I have to have a way to prioritize the cache and bump out old stuff to make way for new. It's all rather convoluted.
IMHO, edge cases aside, most people shouldn't do this.
Doesn't the using the application cache (e.g. the manifest file you speak of) cause a user prompt? That's a deal breaker in many situations.
Here's a pretty good summary of the main point.
"Therefore if we rely on consumers to factor in the total cost to society when making a decision, (which is what happens in a for-profit model), in most cases we will never discover the optimal solution for the market because of this basic flaw of human nature. Our reliance on for-profit entities means we often find ourselves stuck in a horrible equilibrium where each individual transaction seems to be worth making, for both parties, but the real net cost far outweighs the benefit."
Obviously this is not true of every market but examples abound, andI think Facebook Connect is one of them.
I think solving this problem is just a band-aid. As sites like Facebook and Twitter have become mainstream privacy concerns are also becoming mainstream. We're going to have to develop better ways of working with people's data -- kind of like PCI compliance but for personal data. I'm no fan of regulation, just making a prediction.
That said, if you don't need access to someone's entire social graph and just need an email, you should just ask for an email. Let's at least start there. But when the only business model anyone seems to know is "collect metric tons of data and sell it to advertisers" I'm probably yelling into the void.
Edit: err...oops. That probably sounded a bit spammy based on the down votes. Suffice it to say I'm starting a nonprofit in this vein. Info is in my profile.
Question 2: Do you think there is big enough market for the service AND the market is easy to reach (without spending bootloads of money)?
Isn't figuring out how to convert your market into customers without going broke the definition of the startup process? I think the answer to this question must be "I don't know, working on it" or you're probably delusional.
"Google's ad revenue is best protected by them respecting their users privacy."
Their economic incentives are aligned in exactly the opposite direction. The more they know about you the more money they make, ergo the recent privacy policy changes which now tie your data across all of their services. In my opinion this is already a privacy violation, even if they don't sell my data to unscrupulous marketers. It should be opt-in. I believe the relevant quote is from Eric Schmidt, ""Google policy is to get right up to the creepy line and not cross it."
If you read their privacy policy, there is an entire section called "Information we share" that is worth reading. It's short, so that's good.
But still, I don't completely buy the notion that as long as Google doesn't resell my data to some "unscrupulous" marketer they are respecting my privacy. If at some point in the future they buy-in to Zuckerbergs "everyone should be open about everything" philosophy and create another privacy policy that isn't opt-in... I guess we're all screwed.