HN user

varunkho

66 karma

I love building stuff. Now focussed on completing stuff that I build :)

<MyHNName> at outlook dot com

Posts18
Comments56
View on HN
aca-obamacare.com 12y ago

Did you notify your employees about Obamacare marketplaces?

varunkho
3pts0
news.ycombinator.com 12y ago

Show HN: I just built this during weekend, does this help?

varunkho
3pts1
aca-obamacare.com 12y ago

Show HN: Just 6 days to go – save your business from obamacare penalties now

varunkho
7pts12
aca-obamacare.com 12y ago

ACA Notice to Employees - Affordable Care Act (Obamacare) Forms and Resources

varunkho
4pts0
news.ycombinator.com 12y ago

Ask HN: How do you handle client that keeps on delaying invoice payment?

varunkho
8pts12
news.ycombinator.com 12y ago

Ask HN: Which tools do you use for invoice (freelancers and small biz)

varunkho
10pts14
www.quicksprout.com 12y ago

7 Simple Yet Effective Social Media Tactics You Should Leverage Today

varunkho
1pts0
news.ycombinator.com 12y ago

Ask HN: what do you use for affiliate tracking?

varunkho
1pts1
news.ycombinator.com 12y ago

Ask HN: Which is your recommended domain registrar for .it/.ly domains?

varunkho
4pts3
phys.org 12y ago

Engineers discover unique fingerprint for cell phones

varunkho
1pts0
aspsecuritykit.com 12y ago

ASP.NET Devs: Mvc security and membership done right

varunkho
3pts0
www.aspsecuritykit.net 13y ago

Show HN: ASP.NET devs, no need to code user management for your site ever again

varunkho
3pts0
unitedwithisrael.org 13y ago

New Israeli Device Helps Blind With Daily Tasks

varunkho
1pts0
www.youtube.com 13y ago

18 Year-Old Girl Invents 20-Second Cell Phone Charger

varunkho
4pts3
github.com 13y ago

Show HN: send to dropbox, an explorer extension

varunkho
1pts2
news.ycombinator.com 13y ago

Ask HN: Your preferred cloud API for voice/SMS and why?

varunkho
9pts8
blogs.office.com 13y ago

Introducing apps for the new Office and SharePoint and the Office Store

varunkho
2pts0
medicalxpress.com 13y ago

Researchers discover gene that permanently stops cancer cell proliferation

varunkho
2pts0

From the outset, I learnt programming by craving to build a thing. It started with tic tac toe that I built in vb6 in school, with computer as a player, sound and lighting effects. Then I built a full-disk media player/ image explorer hybrid. Followed by a multilingual word processor with screen reader and brail keyboard input and ...Finally full-stack web apps.

At the core of my learning was always a desire – that I wanted to build this thing, and rest was the details that I figured out from the internet and MSDN CDs (yes, that used to be my primary and definitive source during initial years of learning.)

In my experience, when I'm passionate about building something, I do not need to motivate myself to learn the details.

Edit: Finally I also did post graduation in CS to cover the gaps of CS fundamentals. Degree is also essential for getting a job at reputed companies which usually have it as the first filter to auto-reject candidates.

I see where you are coming from. It seems that you are already into selling emails business therefore you see others doing a legitimate thing as "harvesting emails to sell for millions." or maybe you are living in your own bubble and has never gone out to try to build something that non-technical can relate to solving their problem. Good luck and next time try to conduct yourself with little humility and that would go a long way in helping you achieve something.

Keep on imposing your line of argument, and of course downvoting. But the truth is I was trying to solve a pain for small businesses most of which have not yet complied by sending the notification. It seems you never tried the website and started with your baseless arguments. Again with this website I have just made electronic delivery of the notification simpler as the same requires that "delivery is tracked". I just take employees email and name (optional) and basic business information necessary to prepare the model notice obtained from DOL website.

Solving somebody pain is a path to a startup, if you have some other definition please feel free to live by that.

Thanks! This is good advice. Btw, if I have a written signed contract in place and if the client does not pay and I'm outside US, is it possible to hand over that case to an entity (like collection agency) in US to take care of?

Edit: Also, is there a standar contract template for a vendor/contractor that lays down these conditions in legit manner. For instance, how much interest you can legitimately charge for each day delayed ETC. Just curious.

In India online banking is awesome:

1) Most (all?) banks have net banking which is a feature to pay money directly from your bank account (and not via credit card) to online merchants those who integrate it (most of them do).

2) Many banks provide utilities payment (electricity/phone/cable ETC) feature which can be set to autopay.

3) there's a three factor authentication system – username and password to login and look around, transaction password to pay to your registered billers and finally for online shopping (net banking), you are asked to input 3 random numbers from the grid printed at the back of your debit card in addition to login and transaction password.

4) For any decent amount of payment received / paid (I think Rs. 5000 or above), you get an sms briefing the transaction.

5) Auto deduct feature – there's an ECS form you can sign and give it to businesses which can then automatically deduct money monthly from your bank account. Good for auto mortgage payments et al.

Checks have almost disappeared from internet savvy people's lives – I have hardly used them in years.

If you make content accessible for screen readers, you are effectively making content more accessible for search engines as well [0].

high accessibility overlaps heavily with effective white hat SEO. The goal of accessibility is to make web content accessible to as many people as possible, including those who experience that content under technical, physical, or other constraints. It may be useful to think of search engines as users with substantial constraints: they can’t read text in images, can’t interpret JavaScript or applets, and can’t “view” many other kinds of multimedia content. These are the types of problems that accessibility is supposed to solve in the first place.

[0] http://alistapart.com/article/accessibilityseo

At least in 2013, you can cancel it (my client did) and Azure has a default spending limit for trial accounts which, unless you remove, never gets you charged if you consume the trial usage and simply suspends your account. On the other hand, AWS doesn't have a spending limit concept for even free, one-year micro instance trial last I checked.

Never heard of instamojo so I just checked it out. According to its FAQ [0],

5. When do I get paid. .... For offers selling in INR, the amount would be remitted to your Indian bank account if it has crossed minimum payment threshold of ₹500. For offers selling in USD, the amount would be remitted to your Paypal account

Since most of your customers will be paying in USD (I guess),, Instamojo will anyway be paying as per above to your Paypal account. So, IMO, you should sort out Paypal account. (Or talk to Instamojo if they have this option to directly convert USD payments to INR and remit them to your bank account.)

[0] https://www.instamojo.com/faq/

"a consultant hired to build an in-house CRM wouldn't pitch "Our CRM is going to be easy to use", they'd pitch "Your sales team will close more deals in less time when using our tool."

Sadly, we product people often get hung up on the feature set of our product. No matter how many times we repeat "Features do not sell software. Benefits sell software.", we often revert to implementation details when pressed for why customers should care about our apps. And when we start thinking in terms of benefits, we pick bad, non-specific, frilly benefits, like "Easy to use" and "Sleekly designed." Does anyone ever try to sell software as being hard to use and clunky?" "

- patio11

These are full of actionable advice if you are planning to do or doing consultancy/product business.

Anecdote: reading [0] in Patrick's last Friday email was a light bulb moment for me. The timing was perfect as I was about to throw pre-launch page for http://www.ASPSecurityKit.net . Though the product’s target market is primarily software developers, still the copy should address what kind of systems they can build with the product I’m proposing rather than listing the raw technical features “activity-based, resource-aware authorization … Blah blah” and expect them to think what they can build with it.

[0]: a consultant hired to build an in-house CRM wouldn't pitch "Our CRM is going to be easy to use", they'd pitch "Your sales team will close more deals in less time when using our tool."

Edit: As a consequence, made it to HN home page, and collected a lot of interested folks' emails (in 3 digits).

No Problem – the power of ASP Security Kit hlies in its flexibility and extensibility. You can provide your own implementation for most things including hashing routines if you don't find existing implementation suited for your particular needs. Till now, it is either not possible (in some cases) or difficult (in other cases) in the default ASP.NET implementation for membership management.

Glad you asked this. That is just a pre-launch page so it does not go into detail in length. Nothing built in-house – it uses Salted password hashing with PBKDF2-SHA1 and key stretching as mentioned on [0]. Password hashing is too delicate to write a custom algorithm.

[0] http://crackstation.net/hashing-security.htm

"Salt ensures that attackers can't use specialized attacks like lookup tables and rainbow tables to crack large collections of hashes quickly, but it doesn't prevent them from running dictionary or brute-force attacks on each hash individually. High-end graphics cards (GPUs) and custom hardware can compute billions of hashes per second, so these attacks are still very effective. To make these attacks less effective, we can use a technique known as key stretching. The idea is to make the hash function very slow, so that even with a fast GPU or custom hardware, dictionary and brute-force attacks are too slow to be worthwhile. The goal is to make the hash function slow enough to impede attacks, but still fast enough to not cause a noticeable delay for the user."

Most of it is installed as source files in your mvc project so you are free to change and inspect things. This is where protection against XSS/XSRF/over-posting attacks is handled as in Mvc. Only the core module is delivered as closed library. But that is more of a business layer than the security layer. The best thing about the core module is that every piece is swappable (including salted password hashing with key stretching piece) as everything is based on service pattern (interfaces and contracts).

Hi author here! if you have any feedback or suggestion, do let me know. you can also drop me a mail – varun@ASPSecurityKit.net

ASP Security Kit is my humble attempt to solve membership management problem for applications built on ASP.NET Mvc platform. I have periodically observed that There are many common but essential requirements for most real-world web applications that aren't served well. Like action-based and resource (entity record) aware authorization. ASK handles all such must-to-have requirements pretty transparently and is highly flexible. This is because it's been developped and actively improved as a basis of many consultancy projects I have undertaken over the years.

It has also many nice-to-have things and many more things planned. I'm pretty excited about it and looking at the trafic I have received, many other feel the same way. So thanks everyone for logging on to the site and special thanks to those who have shown interest and provided their email! I'll soon get in touch with you all personally sharing the progress and launch date.

Your words are always inspiring! I'm building #1 with features more than authentication for a particular platform. I have found those features minimum for every web application I have built for clients, and decided to package them to first assist me and now to many more soon!

Whole premise of making inroads in service providers servers is that information stored there is human readable. Store it encrypted.

Nobody is inroading, government has access to the data by law or by policy. Service providers, that operate under the jurisdiction of a state, cannot perform actions that do not adhere to the laws and policies of that state. It's as simple as that.

Come up with stronger algorithms and security schemes and this problem is affectively solved.

Algorithms and schemes are already there, but there's no legal and/or policy framework to force their use. In fact, the current framework is designed to force the opposite.