HN user

yokto

205 karma
Posts7
Comments70
View on HN

However, not paying does not mean that you necessarily become "the product".

Offering loss-leading products is a common business strategy and I'm perfectly okay taking advantage of this for hosting needs that fit a vendor's free tier.

Static hosting is very cheap to offer and gathering free tier users will gain developer mind-share, which helps the vendor can sell their truly money-making products. To pick a clear-cut example: AWS Lambda does not collect any additional data on free tier usage compared to paid usage.

Location: Geneva, Switzerland (CET)

Remote: Yes, within Europe; on-site around Geneva

Willing to relocate: No, but happy to travel

Technologies: TypeScript, Node.js, Nest.js, React, Python, PostgreSQL, AWS (CDK / IaC), WebRTC, real-time streaming, GPU autoscaling, LLM inference & voice agents, Swift, Kotlin, Unreal Engine, Unity3D, Firebase, CI/CD

Résumé/CV: https://www.linkedin.com/in/nathanlucavogel/ (full CV on request)

Email: [firstname] [at] nathanvogel [dot] com

Hands-on engineering leader with 14 years building products, infrastructure, and teams, from indie apps with 10M+ users to a production real-time GenAI platform.

Most recently Director of Engineering at Journee, where I scaled the team to 25 and ran a multi-cloud, multi-geo GPU platform (3,000+ concurrent nodes behind a custom cost-aware autoscaler), a low-level WebRTC backend for interactive 1080p/60fps streaming that beat Unreal's PixelStreaming on latency and bandwidth, and the web apps and APIs on top. I also owned cloud FinOps (six-figure annual savings), enterprise security and GRC for automotive and public-sector clients, and represented the tech org in investor relations.

I'm useful when product goals, infrastructure, and team structure are out of sync: getting a real-time or AI system to hold up in production, cutting cloud spend, tightening developer experience, and helping a team ship without piling on process. I trained as a designer (ECAL) before going deep on engineering, so I care as much about the UI/UX as the GPU autoscaler, and I bridge product, design, and infra without overengineering.

Looking for: fractional or full-time CTO / Head of Engineering, or technical advisory work.

Best fit: startups and scale-ups building AI-powered or real-time products that need one senior person to set technical direction and stay hands-on in the code.

It's most likely two or more separate attackers operating. The first malware, Shai Hulud 2, exfiltrates credentials from the infected dev machine to new public GitHub repositories. As the repositories are public and searchable via GitHub's interfaces, any malicious attacker aware of the attack can easily grab the credentials and launch any attack, whether it's a noisy destructive script or some sophisticated ransomware.

That's my bad, apologies. This job post will be published next week and I somehow removed this mention from my comment while editing it. I've put it back now. In the meantime, feel free to apply through the Platform Engineer role while stating your targeted role and I will re-categorize your application later. Thank you!

Whenever an LLM struggles with a particular library version, I use Cursor Rules to auto-include migration information and that generally worked well enough in my cases.

This reminds me of this quote I love:

"[They] placed too much weight on the introspections that they generated at that moment in time, and thus lost sight of their more enduring attitudes.” [1]

The quote refers to this study [2] in which subjects had to chose a poster to take home. The group who was instructed to think about their reasons for their initial choice, and had the option to change it, were less satisfied with it three weeks later. As the abstract says:

When people think about reasons, they appear to focus on attributes of the stimulus that are easy to verbalize and seem like plausible reasons but may not be important causes of their initial evaluations.

This suggests that satisfaction is more correlated with initial gut feeling than reasoning, at least for aesthetic choices, but I think in many other cases as well.

[1] https://sci-hub.st/10.1016/S0065-2601(08)00401-2

[2] https://journals.sagepub.com/doi/abs/10.1177/014616729319301...

I'm not sure how relevant that threat model is (OS level security would probably be enabled for people susceptible to be targeted in such a way. Support could advise to do it before toggling the flag, etc.), but anyway the hypothetical flag would only be about making sure the automation doesn't happen and the ticket goes to support. Support can then manually handle the rare edge case and place more burden on the person attempting to deactivate the account.

What is the abuse your referring to?

With your suggested approach, the attacker is free to use the account to impersonate the victim until they get a new SIM card, which could easily take days or weeks.

This seems like a degredation compared to the current abuse potential which is mostly limited to logging you out.

As YetAnotherNick said, logout might be the better word to describe the impact here (plus, a fairly aggressive inactivity deletion period).

I agree with you in principle, but I still don’t understand how else to mitigate this: WhatsApp must get a lot of cases of stolen unprotected phones. The victim can ask their operator to lock the SIM card, but their WhatsApp account would still be out in the open.

With the continuous improvements in mobile OS security defaults, I’d expect this scenario to become less and less of a problem, but it must still be accounted for.

The process still goes through support ticketing, so I’d expect a spike to be noticed and stopped.

Isn't this flow what more ore less what you would expect? Could someone suggest what would be the appropriate alternative here?

- The inconvenience to the deactivated account is minor: one SMS verification code and the account is back, queued messages get received, etc.

- Persons who lost their phones probably don't have a good fast way of proving their identity, as their identity is tied to their phone number in WhatsApp's model.

- Needing to quickly lock out spammers, thiefs or hackers is probably far more frequent than abuse of this feature.

- If abuse of this feature becomes a recurring problem, I'd expect WhatsApp to react and adjust the flow to place more burden on its user.

The auto-delete part is slightly more worrying, but if you don't use WhatsApp during 30 days, your account and group membership probably isn't very precious. Backups are automated and separate. You can still easily re-create an account with the same number then.

The story might be "Apps should stop using SMS and phones numbers as the source of identity", and while I generally agree, most comments don't seem to be about this and WhatsApp is maybe _the_ one app whose success was based on this very idea.

To offer a counter datapoint: I moved from engineer to manager while tracking my hours fairly accurately. I can pull off 50 hours of development, including late night emergencies, some client pressure, etc., and still feel energized the weekend, while after 40 hours of management, meetings and firefighting, I become mostly useless and have to take some serious breaks. I enjoy both.

However, there are so many parameters affecting this result that I wouldn't dare to make a call on which role is more tiring in general at a regular company.

- I'm less experienced as a manager, I have to continuously learn a lot and grow fast.

- This is in a young start-up context.

- This is with a very broad scope of responsibilities.

- I'm me.

- etc.

YMMV

The largest fatigue factor to me seems the amount of context switch I have to do as a manager.

The text chat experience is something that has been so refined over the last 10 years that to meet today's expectations towards it, you need a very surprising amount of engineering.

It's something I didn't realized until I started coding it: every detail that you omit from your chat UX is a tragically noticable pain to the user used to WhatsApp and Slack 100 times a day.

Dall-E 2 4 years ago

Hands are notoriously hard to even photograph. You very quickly get weird unnatural results with a camera in front of hands, so in a way I'm not surprised AI models struggle to produce satisfying imagery there too.

My ZSA Moonlander keyboard [1].

When I bought it, I was just looking for a sleeker and more ergonomic keyboard with a split design, but the ability to easily reconfigure every key on the layout brought a new meaning to the word "ergonomic" for me.

It means that when a particular motion or shortcut that I frequently use is puts too much strain on my hands, I can simply change the layout to make the keys more natural too use. And it's just an overall incredibly well made product.

[1] https://www.zsa.io/moonlander/