HN user

michaelbuckbee

13,145 karma

https://expeditedsecurity.com

Twitter: http://twitter.com/mbuckbee

email: mike@expeditedsecurity.com

Posts40
Comments2,553
View on HN
sendcheckit.com 6mo ago

Gemini Nano in Production: 41% Eligibility, 6x Slower, $0 Cost

michaelbuckbee
1pts0
wafris.org 3y ago

Show HN: A better IP Lookup tool I made

michaelbuckbee
8pts4
www.varonis.com 3y ago

The Logging Dead: Two Event Log Vulnerabilities Haunting Windows

michaelbuckbee
3pts0
www.varonis.com 6y ago

Azure Skeleton Key: Exploiting Pass-Through Auth to Steal Credentials

michaelbuckbee
1pts0
www.saastr.com 6y ago

Saastr conference enforcing hand washing and thermal scanning of all attendees

michaelbuckbee
3pts0
expeditedsecurity.com 6y ago

API Security Best Practices

michaelbuckbee
115pts4
blog.varonis.com 8y ago

GDPR in Plain English

michaelbuckbee
45pts7
sendcheckit.com 8y ago

Why You Should Put Your Content on Both Medium and Your Own Domain

michaelbuckbee
9pts2
medium.com 10y ago

How to skip the app review process and update your app instantly

michaelbuckbee
4pts0
www.expeditedssl.com 10y ago

Azure in Plain English

michaelbuckbee
1pts1
medium.com 10y ago

The 3 Axes of Startup Difficulty

michaelbuckbee
2pts0
churnbuster.io 10y ago

Churn Buster Gets Acquired

michaelbuckbee
45pts14
www.varonis.com 10y ago

Learn Web Security Fundamentals

michaelbuckbee
5pts0
news.ycombinator.com 11y ago

How We Grew Our Startup by Providing Awesome Support

michaelbuckbee
1pts0
www.expeditedssl.com 11y ago

How We Grew Our Startup by Providing Awesome Support

michaelbuckbee
8pts0
medium.com 11y ago

An Experiment in Actually Shipping Something

michaelbuckbee
2pts0
www.expeditedssl.com 11y ago

Why Setting Up SSL Is So Hard

michaelbuckbee
5pts1
www.expeditedssl.com 11y ago

Show HN: Heroku Deploy Button and App.Json Schema Maker

michaelbuckbee
14pts1
www.expeditedssl.com 11y ago

Show HN: Simple SSL Scanner

michaelbuckbee
31pts22
www.expeditedssl.com 12y ago

The Hot and Heavy List of Heroku Development Resources

michaelbuckbee
1pts0
www.expeditedssl.com 12y ago

The Hot & Heavy List of Heroku Development Resources

michaelbuckbee
1pts0
www.expeditedssl.com 12y ago

Visual Security: Browser SSL Icons and Design

michaelbuckbee
2pts0
blog.optimizationrobot.com 12y ago

ABold Testing: how to AB Test without much traffic

michaelbuckbee
5pts1
blog.optimizationrobot.com 12y ago

Using Personas for Copywriting and AB Testing

michaelbuckbee
5pts2
blog.optimizationrobot.com 12y ago

Programming as a Marketing Weapon

michaelbuckbee
9pts4
blog.optimizationrobot.com 12y ago

URL as User Interface Design Pattern

michaelbuckbee
12pts2
www.ourownlittleaccelerator.com 12y ago

Our Own Little Accelerator

michaelbuckbee
11pts0
medium.com 12y ago

Act As If

michaelbuckbee
192pts69
www.spaceglasses.com 12y ago

Spaceglasses: Hacking Reality with Javascript

michaelbuckbee
13pts8
www.engadget.com 12y ago

Meta and Steve Mann want to mediate your reality for $667

michaelbuckbee
5pts0

It's a free site, so I was trying to limit both the privacy and risk exposure.

Making the content auto expire after a short period of time greatly decreases the attractiveness of the site to lots of SEO spammers and other types of abuse, and if someone were to get something malicious or vile posted it will clean up after itself without me having to wade into things.

I built a simple (free) eval tool for my own uses (Github Gists + Model Outputs) after not being able to find a suitable one in the market.

The market's being split into

1. Longitudinal LLM observability tooling

Most eval startups have gone down the route of something more like being an observability platform for LLM inference. They want to be in your stack and running the inference to collect data on performance of it.

They collect things like how often a model returns JSON that's out of spec or returns values that aren't expected as well as general timing and cost info.

2. Safety Limiting / Pentesting

Say you're doing something in the medical field or that's sensitive in some way and you want to figure out what model has the best outputs for your task that won't fly off the guardrails.

3. Simple cost + performance + quality swapping

This is what my tool does, basically lets you test if you _really_ need to be running that frontier model in a loop across a million records or if you'd be better with an older model or something else.

https://evvl.ai/

Example eval: https://giyd8stidy.evvl.io

I ran a quick eval to see what this looks like qualitatively vs just calling Opus 4.7 or GPT 5.5 directly.

As expected, Fusion was 7x slower and 4x the cost.

This isn't a knock against it, just that it I think this places Fusion into a "use it only when you need it" category.

https://3fpi5avcqq.evvl.io/

A counterpoint to this is that we have some real different definitions of AI.

If you consider things like the machine learning filters in your smartphone camera and Google's AI Overviews for searches it's entirely plausible that the US is currently at 75%+ of AI usage.

I thought it was more implied, but let me be more explicit:

- This is something I made for myself without a lot of commercial thought, so I still haven't thought through pricing + usage + limits + operational limits. In it's current wildly unoptimized state it's still very cheap to run.

- For the specific concern about API Key leakage there's not a lot I can do about that (that I'm aware of) as the logic of what gets sent is handled by the client AI. It is possible to pull down and audit both the tools + instructions that are published by the MCP server if there are concerns on that side.

This is all very fair criticisms. This thread asked: "What are tools you have made for yourself?" and that's genuinely what this is. I wanted it so I made it and then AI makes it so easy to just throw up a marketing page.

I've a a handful of dev friends that have started to use it as well and give their feedback and it's been slowly growing as I've added sharing/invites.

I would absolutely not recommend putting big production data into it currently.

My vision for it was something more like how the #1 use of spreadsheets is actually people making lists and not actually people doing lots of calculations.

Given the uptake today (thanks everybody!) and your feedback (thanks Mystery-Machine) I'm going to work at addressing your concerns.

The funniest thing I've made is a free utility called "Moniker" that contextually renames files based on their contents.

Uses local AI models and I was able to snag this great domain name.

https://finalfinalreallyfinaluntitleddocumentv3.com/

But hands down the most useful thing I've made is HutchDB, which is a MCP service that you can call from any AI chat or Agent setup to store data for you.

Literally from your AI you just say "save that to Hutch" and then it figures out:

- The schema + fields - Builds nice webviews (Kanban, Timeline, Grid, Calendar) - Lets you share the output with people

So people use it for all kinds of things like time tracking ("every hour save a summary of my activities to Hutch"), for Agent to Human handoff ("Every day check social media for mentions of my company and save them to Hutch").

I use it for things like recording all of our marketing activities and then having my AI compare those to signups for rough attribution, etc.

Dead useful and at https://hutchdb.com

It's not just comparing all the models, it's also comparing all the providers and configurations of those models.

If you're doing any kind of production AI work you'll end up with outages caused by calling a single provider, OpenRouter seamlessly switching between providers is a godsend for uptime.

But even more than that there's meaningful cost+speed differences.

Here's Sonnet 4.6 being served direct, via Amazon and via Google

https://la9q13gg8w.evvl.io/

(spoiler: Google was both fastest and cheapest)

We're already seeing other states struggling with soaring house insurance rates (California and Florida) and a pattern of spikes in rates leading government mandated caps on rates leading to insurers pulling out of the states.

I've no idea what the going rate for insurance is currently in New Orleans but it has to be crazy right?

I was trying to get a better sense of the time cost quality matrix of these, so I threw together a quick eval of Sonnet 4.6, Mistral's dev model, and Opus 4.7 (figuring it's what you'd use if you were on Max).

The results for a function implementation and test of levenshtein distance in js are pretty similar but Mistral is 30x cheaper than Opus 4.7 and 4x faster than Sonnet 4.6.

https://5m6qnuhyde.evvl.io/

I'd be curious to know if you consider a Lego store a "toy store". There's one that opened in my city fairly recently and is in an area of smaller boutique shops (kind of like what you described).

I made a B2C AI app that's fully local (and free) to do AI based contextual file renaming.

So if you give it a bunch of screenshots it will try and intelligently name them based upon what is in the screenshot. Same for videos, PDFs, etc.

But to your point I haven't even tried charging money as it feels like something Apple is just going to bake in as a feature.

https://finalfinalreallyfinaluntitleddocumentv3.com/