HN user

bobbiechen

4,590 karma

Writing about connections at digitalseams.com and personally at bobbiechen.com

<first two letters + last four>@twilio.com

Posts346
Comments387
View on HN
amitp.blogspot.com 10d ago

LLMs and Shaders

bobbiechen
2pts0
digitalseams.com 17d ago

Zero-defects code: the prescient Microsoft memo from 1989

bobbiechen
9pts1
digitalseams.com 21d ago

When anything is possible, how do you decide what to create?

bobbiechen
1pts0
eieio.games 28d ago

Legibility of Effort

bobbiechen
3pts0
digitalseams.com 1mo ago

Seth Larson on Making Things

bobbiechen
2pts0
digitalseams.com 1mo ago

Morry Kolman on making things: "Keep it stupid"

bobbiechen
2pts0
uniba.jp 1mo ago

Uniba Embodied Virtuality

bobbiechen
1pts0
digitalseams.com 1mo ago

Nolen Royalty (One Million Chessboards) on Making Things

bobbiechen
2pts0
muniworm.probablyalex.com 1mo ago

SF MUNI Worm: the worm becomes the map

bobbiechen
2pts0
digitalseams.com 1mo ago

Amit Patel (Red Blob Games) on Making Things

bobbiechen
2pts0
digitalseams.com 1mo ago

Making things: interview series on creativity

bobbiechen
1pts0
yegge.ai 1mo ago

N-Tier Services and Systems Complexity

bobbiechen
2pts0
sharedphysics.com 1mo ago

Good Careers at Bad Companies

bobbiechen
4pts0
squeezlabs.github.io 1mo ago

CrankGPT is an offline and off-the-grid AI box

bobbiechen
2pts0
lowtechguys.com 1mo ago

Stop the Apple Music app from launching

bobbiechen
669pts278
digitalseams.com 1mo ago

Interfaces for Representing Uncertainty (2025)

bobbiechen
1pts0
www.marketingbrew.com 2mo ago

Staybl, the browser that adjusts for tremors in real time (2022)

bobbiechen
2pts0
unsung.aresluna.org 2mo ago

"This was a user-friendly computer."

bobbiechen
3pts0
lawsofux.com 2mo ago

Laws of UX

bobbiechen
346pts60
digitalseams.com 3mo ago

The Gypsy document editor: celebrating 50 years

bobbiechen
4pts0
digitalseams.com 3mo ago

Lighter, Not Faster

bobbiechen
2pts3
surfingcomplexity.blog 3mo ago

There is no escape from Ashby's law (2020)

bobbiechen
3pts0
digitalseams.com 3mo ago

Clashes of Tech and the US Government

bobbiechen
3pts0
unsung.aresluna.org 3mo ago

Tools and Toolmaking

bobbiechen
2pts0
postalform.com 3mo ago

PostalForm lets agents place a real print-and-mail order for their owner

bobbiechen
3pts0
dgroshev.com 4mo ago

Okmain: Pick an OK main colour of an image

bobbiechen
1pts0
www.jamesxli.com 4mo ago

Electrical upgrades for our Winnebago Solis camper van

bobbiechen
2pts1
digitalseams.com 4mo ago

Assorted links: clashes of tech and the US government

bobbiechen
1pts0
unsung.aresluna.org 4mo ago

"Just a little detail that wouldn't sell anything"

bobbiechen
127pts24
mihai.page 5mo ago

Testing 80 LLMs on spatial reasoning on grids

bobbiechen
2pts0
Remote Attestation 14 days ago

Oh yeah, just like all cryptography is just a way for bad people to hide their criminal activity.

I'd read the confidential computing post! (used to work in this space myself)

That makes a lot of sense! I recently interviewed several great creators on this exact topic and they all echoed similar ideas - although it's easy to fear that someone else has done it better, oftentimes they really haven't, and they'll never have your own unique perspective.

One challenge is that it takes repetitions to get good enough that you can even bring your ideas to life, and many people don't push through this (Ira Glass "taste gap").

Full interviews here: https://digitalseams.com/blog/making-things-interview-series

A good reminder that signup is a surprisingly rich target.

Every row has the same name: " Dene Hemen! 5K Lira Bonusunu Yakala" — Turkish for "Try it now! Grab the 5,000 Lira bonus." Casino spam.

Each registration fired a verification email. 55K signups = 55K attempted sends to fake addresses — the kind of bounce storm that gets a sending domain blacklisted.

I'd be surprised if the email addresses were entirely fake - it doesn't make sense to advertise to just the website developer. It seems more likely that this spammer is targeting real email addresses from some dump (QQ is especially prone to this, since you can target random QQ ID numbers and get a lot higher of a hit rate).

Hey Omar, do you have any plan to add support for Web Bot Auth? https://datatracker.ietf.org/wg/webbotauth/about/

While I understand that not every business wants automation on their site, I know some businesses are totally open to it. But from a technical perspective, it's very difficult to allow well-behaved browser automation while still blocking abusive bots. Web Bot Auth gives website owners / security vendors a lightweight way to allow providers like Intuned.

(I work on the Web Bot Auth implementation for Stytch, now a part of Twilio: https://stytch.com/blog/stytch-supports-web-bot-auth/ )

I help run a tech/AI meetup in San Francisco - during the initial post-Covid period we often hit capacity limits since there wasn't much else going on.

But since late 2024 into 2025, meetups are extremely back in fashion here. Every day of the calendar has multiple meetups and it's impossible to avoid conflicts, so attendance rate can vary wildly.

The Ballad of TIGIT 2 months ago

It's just like a parallel of tech venture capital, where missing the next big thing is far more costly than making a wrong bet. No wonder we see herding in tech investments as well.

I remember in 2021 or so there was a startup doing 20 minute grocery delivery in SF, $50 off on your first order.

I got some really nice steaks for free and the delivery actually arrived via motorbike in 10 minutes. They must have had delivery drivers waiting with their own inventory or something. Anyways, the VC funding dried up and the company was gone a few months later.

Yeah, I had the same question myself. I think that's what you would want to do to make it airtight (plus some amount of rate limiting or flagging for devices that are part of dedicated device farms).

But even if not, there's still value in raising the barrier to entry. For example, you can buy 1000 reCaptcha solves for $1-2 from various captcha-solver services. And yet that $0.001-per-request fee does discourage mass-scale bot attacks.

This is generally true of every application that handles sensitive data. Unless you explicitly clear that memory, it's likely to hang around forever.

For example, here is a 2019 writeup from KeePassXC with similar notes: https://keepassxc.org/blog/2019-02-21-memory-security/ - even though they explicitly clear sensitive data, there is still a window of opportunity.

During my time working on confidential computing, we had a variety of demos showing similar attacks against lots of different datastores, scripts, etc. That's just how computers work and your options are very limited if this is part of your threat model (imo just confidential computing and, if you can handle the performance hit, fully-homomorphic encryption).

I called this last year: https://digitalseams.com/blog/the-ai-lifestyle-subsidy-is-go... .

I see it as no different from the previous generation of consumer startups burning money - as Derek Thompson wrote,

...if you woke up on a Casper mattress, worked out with a Peloton, Ubered to a WeWork, ordered on DoorDash for lunch, took a Lyft home, and ordered dinner through Postmates only to realize your partner had already started on a Blue Apron meal, your household had, in one day, interacted with eight unprofitable companies that collectively lost about $15 billion in one year.

If I understand correctly, threat model here seems to be to protect against accidental issues that would impact performance, but doesn't cover malicious actor.

For example, Sketchy Provider tells you they are running the latest and greatest, but actually is knowingly running some cheaper (and worse) model and pocketing the difference. These tests wouldn't help since Sketchy Provider could detect when they're being tested and do the right thing (like the Volkswagen emissions scandal). Right?

I love how many interviews Larry Tesler did (he passed away in 2020), he was so influential and it's interesting to see what that looks like from the inside.

Gypsy (that first modeless editor) recently turned 50 years old and I wrote about it here largely from those first-hand accounts: https://digitalseams.com/blog/the-gypsy-document-editor-cele...

And it's not mentioned in this ACM interview but rather this one with the Computer History Museum https://archive.computerhistory.org/resources/access/text/20... that implementing a modeless editor was easier too, since you could use a simple case-switch instead of having a bunch of explicit modules for each mode.

It's interesting how many people I know who jump instantly from hobby to thinking about hustling, Etsy, Patreon, fame, etc. and the thought that they'll never be good enough to go pro is a real barrier. You don't need to monetize your joy.

This article is a great example of "strong + weak = weak".

I only made it to the interesting stuff because of Carreyou's name, otherwise I would have stopped.

The email timing and lack of email metadata were also strong, in my opinion. But all of this nonsense like "Wow, these guys both talk about PGP??" distracts from it.