Hacker Newsnew | past | comments | ask | show | jobs | submit | throwawayian's commentslogin

I look at the egress costs to internet and it doesn’t check out. It’s a premium product dependent on DX, marketed to funded startups.

But if I care about ingress and egress costs, which many stream heavy infrastructure providers do.. This doesn’t add up.

I wish them luck, but I feel they would have had a much better chance from the start by getting some funding and having a loss leader start, then organising and passing on wholesale rates from cloud providers once they’d reached critical mass.

Instead they’re going in at retail which is very spicy. I feel like someone will clone the tech and let you self host, before big players copy it natively.

It’s a commodity space and they’re starting with a moat of a very busy 2 weeks from some Staff engineers at AWS.


(Founder) Thanks for sharing your thoughts. We are early and figuring things out. I agree egress cost is going to be a big concern. We want to do the best we can for users as we unlock some scale. During preview, we are focused on getting feedback so the service is free (we will need to talk if the usage is significant though).


Tencent Music own almost 10%, UMG and Sony own almost 5% together, there are vested interests here.


Security.

Having to pay for SAML and SCIM integration.

MDM and EDR.

Security baseline configuration deployments for different OS.

It’s a farce.


You mean the security in large organizations is a farce?

SAML/ SCIM Integration are often buggy or doesn't work as advertised..

MDM is just a circus in making, EDR can be easily bypassed...

Pentests are barely worth more than script kiddies even from well known and recognized vendors.

I am not even specialized in sec and it drives me crazy the amount of bypass/work around in IT organizations while pretending everything is well managed and design.


Re: IAM cost workarounds in SMBs, SAML / Oauth2/OIDC / LDAP:

From "Show HN: Skip the SSO Tax, access your user data with OSS" https://news.ycombinator.com/item?id=35529042 :

glim: https://github.com/doncicuto/glim

"Proxy LDAP to limit scope of access #60" https://github.com/doncicuto/glim/issues/60

glauth: https://github.com/glauth/glauth

slapd-sql: https://linux.die.net/man/5/slapd-sql

gitlab-ce-ldap-sync (PHP) https://github.com/Adambean/gitlab-ce-ldap-sync

Open Source SSO for SMB


"Launch HN: SSOReady (YC W24) – Making SAML SSO painless and open source" https://news.ycombinator.com/item?id=41110850 :

ssoready: https://github.com/ssoready/ssoready


Don’t promote people who don’t understand building systems. Everything is a system above 100 people, focus on scaling the things that matter below 100.

HR and Finance? Route it all through 1 person and outsource anything that takes significant time.

Tech? Give equity and significant targets to the CTO who should also be CPO until about 80-100 people. Fire them if they aren’t planners.


> CTO who should also be CPO

This is just awful, awful, awful advice. Please do not do this. Your technical leaders should think deeply about how to build a product, but not the product that is to be built. Asking them to do the latter is asking for absolute carnage.


When you’re smaller, the CPO doesn’t matter as much. Your business has an idea, your CEO and CTO knows what it should look like. Polish it later.


Don’t worry, you are.


I don’t think you understand the problem space. Although, this is a great alternative for SMB’s who aren’t being targeted by attackers who are writing tools specifically for their business.

But, also.. A hardcoded “what’s 7\1=“ would also achieve the same outcome.

Barrier to beat is “can the attacker put together a webauthn emulator”. Low, but will work for many organisations for a long time.


How is this any different to auditors or penetration testers doing a crap job? The payment might be in the form of bonuses or more work billed, but it’s just not realistic.


How is it in any way similar?


Because auditors and penetration testers, even incompetent ones, are not government employees violating anyone's 4th amendment rights.


You don’t work in IT.

Unless you’re paying for Okta and Office365 and Workspace, you’re only getting maybe 70% of systems _you know about_.

And don’t get me started on automated provisioning or deprovisioning.


I wonder if you could change your name to “April May” and submitted CCPA/GDPR what the result would be..


Find mentors. This is true of any tech field.

Join Discords related to the stuff you’re working on, you’ll find people much smarter than you and any of your colleagues hanging out, talking about good approaches to designs, structures, infrastructure, etc.

You’ll also find idiots not worth listening to.

Remember you’re 6 months in / just doing the job is enough of a challenge. You’re calling yourself a lead for having full responsibility of the projects you’re working on. This is typically common everywhere except large tech companies.


Having full responsibility for the project, sure, but having the authority to hire for it is rare


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: