HN user

webo

441 karma

cto @supplypike

Posts17
Comments171
View on HN

routing+account numbers are not that sensitive. that's been API for how we transact money since pre-historic times. plaid gets access to your online account with access personal data, security details, documents, transactions, statements, write-access etc.

Hijacking this comment to complain about fintech apps / saas providers requiring Plaid - please stop.

For example, Coinbase requires logging in with Plaid to... setup auto-pay for their credit card statements. No way to just provide account/routing numbers the good ole way.

There's lots of issues with Plaid but one big one is that banks (e.g big ones like BofA) can lock your account due to suspicious login with Plaid.

https://x.com/kanateven/status/1973793740331368841

On one hand, the market seems to react to these appropriately. On another hand, the market has a short-term memory and prices go back up.

It's unfortunate Auth0 was acquired by them. Have used it from the beginning and it used to be a great product before the Okta acq. Now it's just constant sales emails, expensive pricing, not much new feature launches, most features are very enterprise focused, bunch of bugs, frequent outages.

Somebody described Slack vs Teams this way:

- Slack is so easy and fun to use that we use it for things we shouldn't be (fun channels, fun integrations). It creates too much noise and hard to extract signal. It ends up being distracting past 100+ people company.

- Teams is so bad that people try not to use it. It forces you to use it minimally because everything is terrible. It actually ends up being more productive than Slack.

US doesn’t give out a permanent residency based on how long you lived in the country. There’s only a few common paths to immigration: employment sponsored (2-20 years), marriage based (1-3 years), other family based (2-20 years), investor based (1-3 years). Student or tourist years don’t matter.

Consumers, meanwhile, split down the middle between cynics who’re certain it’s worthless and true-believers who think it sets the standard for how security should work.

There are many dependencies in the software supply chain that are maintained by a single person (open source or not),so it seems silly to default assume malicious intent for employees of a software vendor with a good reputation.

There are bad actors that no SOC2 control would catch, and there are good actors (the default) where no SOC2 control affect their behavior.

SOC2 is never part of my decision making, rather, I carefully study the company and product offerings to decide if right fit.

(This is coming from someone who goes thru an annual SOC2 audit)

https://xkcd.com/2347/

This is definitely a biased post (the author is on the board).

Rippling as a product reminds of Hubspot. It’s cheap/free for small companies, has many checkbox-list of features, looks good conceptually, but doesn’t actually do anything well.

It’s “good enough” initially but most companies end up unbundling Rippling as they get bigger.

Oh support- sometimes it has taken us weeks to hear back.

We probably won’t move away from it but I know there’s a better alternative for every module they provide.

Iirc, they were saved as “drafts”, meaning you could come back to it later or on another device. Youtube was like that before instagram, it’s a popular feature on Snapchat/Tiktok.

My point is that it is feature clearly people appreciated, not a dark UX pattern.

One simple example was that I couldn’t install dependencies from public registries such npmjs (npm) or pypi (pip). It took an approval process for an internal team to review and clone packages onto Google’s internal registry.

On the other hand, things like deployment and monitoring were so trivial and magic.

This was circa 2015.

SupplyPike | Software Engineer, Sr. Software Engineer | Fayetteville, Arkansas | Remote-ok (US/CA)

SupplyPike (https://www.supplypike.com/) is on a mission to change the lives of retail suppliers by giving them amazing tools to change the way they navigate supply chain problems.

In the past 2 years, we've grown 30->80 people, 1000% in customers, and made $300M+ in direct impact in supplier's businesses. We work with new and upcoming CPG brands as well as some of the world's largest brands.

We're in a hyper-growth mode and would love to have smart, passionate, and ambitious software engineers join the team!

Our tech stack is primarily typescript, nodejs, react, postgres, elasticsearch (5+ TB), mongo. We have an excellent SRE team who builds and maintains devops tools (prometheus, grafana, flux, github actions) and Kubernetes clusters (AWS EKS). We connect with 60+ different external sources which introduces some interesting engineering and organizational challenges.

  * email in bio (mention HN in subject line)
  * https://www.instagram.com/supplypike/
  * https://www.supplypike.com/careers

I’m guessing Discord server hijacking is also a source. There are hundreds of crypto servers that are full of spam (they advertise as pump n dump) and people constantly fall for them.

[dead] 5 years ago

That depends on your company culture. We introduced a tool like that and it’s been helpful for both for management and eng teams to start meaningful discussions — e.g PRs are taking long to review (e.g perceived as not high priority), PR sizes are getting bigger (e.g hard for the reviewer), some people review way more PRs than others (e.g bottlenecks), bug vs chore vs feature PR trends, new code vs refactoring trends, etc.

Need to have the right people who are asking the right questions.

SupplyPike | Software Engineer | Remote | Fayetteville, AR | https://www.supplypike.com/careers

SupplyPike is a fast-growing SaaS company solving challenging problems in retail supply chain such as deductions disputing, retailer compliance, and lost sales prevention using deep domain knowledge and ML.

We're looking for strong software engineers that collaborate with product management, UX designers, other engineers, and stakeholders to define problems, set goals, and engineer amazing products.

We don't look for a specific skillset. Some our of current tech stack include React, JavaScript w/ TypeScript, Node.js, Postgres, Elasticsearch, Kubernetes.

Reach out to email in bio.

Location: This is a remote-friendly role. However, you might change your mind after visiting Northwest Arkansas. Beautiful Fayetteville, nestled in the lush Ozark Mountains, consistently ranks in the Top 5 U.S. News best places to live in the U.S for its quality of life and cost of living and the Top 10 in job growth (Forbes). In addition to being the home to two Fortune 100 and three Fortune 500 companies, Fayetteville also has a strong entrepreneurial community with a growing number of startup companies.

- https://www.supplypike.com/careers

- https://www.greatplacetowork.com/certified-company/7026446

- https://realestate.usnews.com/real-estate/articles/us-news-r...