Just guessing, Czechia? The Central European software engineering market seems to be softening as well, likely due to second-order effects from the U.S. tech layoffs and decreased demand for remote roles from SV companies.
HN user
tomashertus
Building Cybersecurity Products for Fun & Profit
https://twitter.com/tomashertus
Move fast and break things.
Are they, though? My thinking is that their roadmap is heavily focused on the SDLC and solving problems related to software development, so their model will be optimized for that domain. That leaves room in the market for models that are specialized in other areas of expertise.
These decisions always depend on the lifecycle of the product. I assume that at Basecamp’s level of maturity, where it has reached a certain saturation point and growth and usage are fairly predictable, it makes perfect sense to make a strategic decision like this and commit to a long-term bet.
Regardless, kudos to DHH and team for being so vocal about it, it's a great case study for product teams in similar lifecycle.
This is a bit of a puzzling "announcement". Does anyone have more details on what’s actually changing?
I don’t really use Facebook itself anymore, I’ve mostly kept Messenger for messaging. Curious whether this is an attempt to push users back toward the main feed experience.
The article is surprisingly missing the most important part: a cost comparison. I understand and share the frustration with rising prices and ads creeping into paid plans, but for people who value optionality and broad access, streaming is still meaningfully cheaper than owning content.
In many cases, the price of a single movie is comparable to an entire month of a streaming service, which gives access to thousands of titles. Ownership can make sense if you repeatedly watch a small, fixed catalog over many years, but for most casual or exploratory viewing, the economics still favor streaming.
Can we remove this? While this war is a horrible tragedy, I’m of that opinion that we should not discuss geopolitics on this site unless it’s directly impacting the core topics we are all here for.
Mind sharing a link? That sounds really interesting!
It’s too soon to know, but this could make 3-year H-1B renewals hugely problematic. That would be a major blow to the program. I was fortunate to get mine in 2014 without a single problem. There’s no way I’d expect someone to get through this process today. And realistically, most companies aren’t going to pay such a large premium just for a typical software engineer.
It’s ultimately a numbers game. The more malicious seeds are planted, the higher the likelihood that one of them will be pulled into a real-world build pipeline. Platforms like GitHub, NPM, and other open repositories are ideal staging grounds because very few engineering organizations are willing to block traffic from them. That makes them near-perfect hiding spots for malicious content.
And the asymmetry is stark: attackers only need to succeed once. It takes just a single developer installing a compromised package to trigger a breach with potentially massive downstream consequences. So while I agree that quantifying impact is critical, dismissing large-scale seeding campaigns because “no one might have downloaded it” ignores the risk.
This is a surprisingly common issue. In my day-to-day work, we analyze millions to look for malware, and it’s well-known in the security community that attackers frequently leverage “trusted” websites to host and deliver malware as an evasion tactic.
The technique is so pervasive that I did an extensive research on it. In fact, there are several well-funded and widely used applications, some generating millions in revenue, that unknowingly host malware on their infrastructure. In more concerning cases, these platforms are even repurposed as command-and-control servers for data exfiltration. We're increasingly seeing enterprises take the proactive step of blocking traffic to these high-risk domains entirely to strengthen their security posture (e.g. it's completely common to block all traffic from network to Dropbox or other file hosting services).
Time flies... Thanks for the correction, buddy.
But can you Ghibli? I guess NOT! /s
For a decade, since the intro of NodeJS
Javascript was never build for those use-cases. It should have stayed on the browser.
It would be very positive for the entire startup ecosystem if this deal goes through. It would also be a strong signal from the new administration about support of our current startup ecosystem.
To illustrate this in dollar terms, consider an acquihire exit. At 1% of $10 million, the acquihire nets the Founding Engineer around $100,000, enough to buy a nice Tesla. Meanwhile, the founders net $4.8 million, enough to buy a house in Palo Alto, a small yacht, and two nice Teslas.
I stopped reading after this paragraph. Why to take advice from articles that is presenting delusional scenario about the returns? $100k after tax is good enough for Model 3.
Thank you for the comment! I had no clue that Github has RSS feeds for each repo.
For everyone else, I found this article to be super helpful to understand what kind of RSS functionality is available: https://ronaldsvilcins.com/2020/03/26/rss-feeds-for-your-git...
Wow! I had no clue that this ever existed. I guess it was DOA given its short life-span.
Heh, a couple of years ago, I had an idea for an "Uber for Experts." It would provide a similar experience to Uber, but instead of a ride, you'd get 30 minutes with a domain expert of your choosing. I never got around to working on it, but there might still be an opportunity for something like this.
If the threat actor has played it right, there is a high possibility that this will be the largest data breach in history.
I still remember the number after 20+ years. Crazy.
In my day-to-day work, we analyze millions of files every day, and it's well-known and well-utilized detection evasion techniques to host and serve malware from "trusted" websites. It's so widespread that I did extensive research on that issue. There are well-known apps with $Ms in funding and revenue with a plethora of malware hosted on their servers. Some are even used as C2 servers for data exfiltration. I see an increasing number of companies proactively blocking all traffic to those notorious sites to increase overall network security.
The outcome of my research was the following:
- Disjointed content moderation and cybersecurity departments: Not many companies have content moderation teams equipped to perform malware analysis or make cybersecurity-related decisions (the only company that does an exceptional job in this regard is Meta).
- If hosting malware doesn't impact the company's revenue and reputation, the content moderation team has other priorities.
- Section 230: Companies will refer to Section 230 when asked about hosting malicious content or scanning the content for potential malware.
I use Github's Trends (https://github.com/trending) for discovery, and for all other searches, I use their search and tags. It never failed me to find what I was looking for. The star system already provides you with ratings for open-source projects, and Github's search has powerful filtering. I don't anticipate a general need for such a project.
If you are junior developer interested in learning development or a specific technology, it would be great project to build and open source though.
\_(-_-)_/ good luck with that
These are exciting times in the cybersecurity industry with the recent growth of open-source security tools (osquery, Fleet, Wazuh, etc.). Anyway, I'm skeptical about the detection efficacies, usefulness, and scalability of those products. I do not see them widely adopted either. These are my observations from your pitch:
Your pitch mentions large costs for traditional SOAR products and that you want your solution to be focused on smaller companies that don't have money to pay for expensive SOC tools. Nevertheless, the market reality is that if a company has a SOC team (who is the traditional end-user of SOAR tool), they don't care about $100k for a SOAR because they will spend hundreds of thousands a month for log storage, security tools, and HR. It's much more common for your target audience to use ITSM as a security incidents management tool. Just look at what ServiceNow is doing in this space for example: https://docs.servicenow.com/bundle/washingtondc-security-man.... Based on this one fact, I think that you didn't spend enough time understanding your target customer who are in this case not SOC/Security teams, but IT teams.
Incident management is a critical process for every SOC team and its effectiveness is tracked by measuring the mean-time-to-resolve metric. How do you want to convince SOC teams to use open-source tools for their mission-critical process rather than buying one of the established SOAR tools that are integrated with their security stack? (& there are many options in the SOAR space) How can your product help companies lower the operational costs of case management? (improving the mean-time-to-resolve KPI)
Please, don't get discouraged by my comments. SOAR is an essential part of every security stack and the current offerings have flaws. But the narrative in your pitch is flawed and indicates a lack of understanding of current security buyers and personas.
I admire the level of insight and transparency. Congratulations on an amazing year, and keep swimming!
I understand and agree with your point that you can't just "buy" cybersecurity by throwing money at the problem. It's more like building a well-defended castle, where multiple elements work together to create true security. Cybersecurity is a company-wide process that needs to be powered by specialized tools.
The fact that one of the fastest-growing markets is omitted by YC is shocking to me. The opportunity to build $1B companies, which seems to be one of YC's acceptance criteria, is enormous.
I don't know how far or close you are to the security field, but I do share your sentiment that many tools and so-called security solutions are useless and don't solve the problem. So it's now even more necessary to go and build new solutions. The problem persists and grows.
I apologize, but I don't understand your point. Could you please explain to me what you mean by that or how the fact that you "can't buy cybersecurity" contradicts what I wrote?
The cyber security market was valued at USD 153.65 billion in 2022 and is projected to grow from USD 172.32 billion in 2023 to USD 424.97 billion in 2030, so apparently people are buying cybersecurity solutions.
The fact that YC overlooks the dire need for next-generation cybersecurity solutions is quite shocking. In the coming years, cybersecurity, trust, and safety will be essential needs of every customer and enterprise application. For example, the whole fiasco with the spread of fake Taylor Swift's nude images is just the beginning of the exploitation of internet data on an industrial scale. We can already see attempts to commercialize services similar to ransomware-as-a-service that, for a small amount of money, generate atrocious content about every possible person and spread it online automatically. We are on the edge of a new revolution that will bring malicious tools and services even closer to regular consumers and make them more affordable. I think that our cybersecurity tool chain is far from ready for what is coming.