<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: greysteil</title><link>https://news.ycombinator.com/user?id=greysteil</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 16 Apr 2026 19:06:58 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=greysteil" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by greysteil in "From MCP to shell: MCP auth flaws enable RCE in Claude Code, Gemini CLI and more"]]></title><description><![CDATA[
<p>Is $2,300 the going rate for an RCE with a totally believable attack vector these days?</p>
]]></description><pubDate>Tue, 23 Sep 2025 17:24:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=45350164</link><dc:creator>greysteil</dc:creator><comments>https://news.ycombinator.com/item?id=45350164</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45350164</guid></item><item><title><![CDATA[New comment by greysteil in "From MCP to shell: MCP auth flaws enable RCE in Claude Code, Gemini CLI and more"]]></title><description><![CDATA[
<p>I dunno, I’m still pretty surprised the MCP server auth process could pop a calculator on widely adopted clients. The protocol isn’t perfect but that’s totally unnecessary unsafe. Glad it’s fixed!</p>
]]></description><pubDate>Tue, 23 Sep 2025 16:50:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=45349627</link><dc:creator>greysteil</dc:creator><comments>https://news.ycombinator.com/item?id=45349627</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45349627</guid></item><item><title><![CDATA[New comment by greysteil in "Figma Slides Is a Beautiful Disaster"]]></title><description><![CDATA[
<p>PM at Figma here (for dev tools, not slides).<p>What happened to Allen here sucks. I've messaged the team so we can dig into this specific case. More generally, we know that Slides needs to be bulletproof when presenting, and nothing less than that is acceptable.<p>As an FYI, we _do_ use Figma Slides internally for pretty much everything, from internal meetings to major events. As a PM I use it every week, and our internal feedback channel for Slides is super active with folks like me requesting improvements. Figma is also a pretty unique place, where it's more likely our senior leadership request quality improvements than chase for deadlines - we know how critical the user experience is. We don't always get it right, but when we don't we're committed to fixing it.</p>
]]></description><pubDate>Sun, 01 Jun 2025 16:55:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=44152221</link><dc:creator>greysteil</dc:creator><comments>https://news.ycombinator.com/item?id=44152221</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44152221</guid></item><item><title><![CDATA[New comment by greysteil in "Canoeing on the Danube"]]></title><description><![CDATA[
<p>I did most of this too! It was great.<p>Do you have recommendations for folks who can only do a shorter trip (say, a long weekend, or a week)?</p>
]]></description><pubDate>Tue, 01 Apr 2025 13:34:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=43546624</link><dc:creator>greysteil</dc:creator><comments>https://news.ycombinator.com/item?id=43546624</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43546624</guid></item><item><title><![CDATA[New comment by greysteil in "Ask HN: What are you working on? (March 2025)"]]></title><description><![CDATA[
<p>Thanks! I haven't used Pulsar, but the general answer is that mentions.us is focussed on sending you alerts for notifications, whereas more sophisticated social listening tools provide a lot more analytics (e.g., sentiment analysis).<p>If your company just wants alerts when their keywords are mentioned on social media then mentions.us should work great for them. If you work for Coca Cola then you likely need something very different from your social listening tool!</p>
]]></description><pubDate>Mon, 31 Mar 2025 12:26:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=43534186</link><dc:creator>greysteil</dc:creator><comments>https://news.ycombinator.com/item?id=43534186</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43534186</guid></item><item><title><![CDATA[New comment by greysteil in "Ask HN: What are you working on? (March 2025)"]]></title><description><![CDATA[
<p>For now we use the LinkedIn voyager API's search endpoint</p>
]]></description><pubDate>Mon, 31 Mar 2025 12:20:49 +0000</pubDate><link>https://news.ycombinator.com/item?id=43534125</link><dc:creator>greysteil</dc:creator><comments>https://news.ycombinator.com/item?id=43534125</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43534125</guid></item><item><title><![CDATA[New comment by greysteil in "Ask HN: What are you working on? (March 2025)"]]></title><description><![CDATA[
<p>I put more details in a reply to another comment, but basically I think the number of people willing to pay for email alerts is small, so I’ve made the service free for them. It’s only teams who want Slack notifications who have paid plans.<p>I’m not optimising to extract every possible $ from the market with that pricing strategy. Instead I hope it will maximise the number of users whilst breaking even on costs.</p>
]]></description><pubDate>Mon, 31 Mar 2025 11:49:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=43533854</link><dc:creator>greysteil</dc:creator><comments>https://news.ycombinator.com/item?id=43533854</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43533854</guid></item><item><title><![CDATA[New comment by greysteil in "Ask HN: What are you working on? (March 2025)"]]></title><description><![CDATA[
<p>We’re hooking up to the APIs - the goal is to alert you of mentions as quickly as possible, so waiting for Google to index results would introduce (much) too much lag.<p>Interesting feature request! I’ll have a think on it.</p>
]]></description><pubDate>Mon, 31 Mar 2025 11:44:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=43533818</link><dc:creator>greysteil</dc:creator><comments>https://news.ycombinator.com/item?id=43533818</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43533818</guid></item><item><title><![CDATA[New comment by greysteil in "Ask HN: What are you working on? (March 2025)"]]></title><description><![CDATA[
<p>Thanks for the feedback! For saved terms we show you the number of matches we’ve notified you about, which always starts at zero, whereas during creating we show you how many you would have matched. That’s a confusing UI and I should improve it</p>
]]></description><pubDate>Mon, 31 Mar 2025 11:40:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=43533787</link><dc:creator>greysteil</dc:creator><comments>https://news.ycombinator.com/item?id=43533787</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43533787</guid></item><item><title><![CDATA[New comment by greysteil in "Ask HN: What are you working on? (March 2025)"]]></title><description><![CDATA[
<p>Hey Julien! I’ve seen you advertising KWatch in lots of places, assume you’re connected to it / know the founder?<p>For LinkedIn monitoring we use the voyager APIs. It’s not perfect because it gets posts but not comments, but it’s pretty good.</p>
]]></description><pubDate>Mon, 31 Mar 2025 11:36:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=43533768</link><dc:creator>greysteil</dc:creator><comments>https://news.ycombinator.com/item?id=43533768</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43533768</guid></item><item><title><![CDATA[New comment by greysteil in "Ask HN: What are you working on? (March 2025)"]]></title><description><![CDATA[
<p>I think most of the people who sign up for email alerts would never pay. Lots of them are indie hackers or folks with a side project - I've been there, and know how price sensitive those communities are. I'd rather they use the service for free than not at all - I get valuable feedback from that, a marketing boost if they tell others about it, and the validation of having built something other people use.<p>I do have a paid plan for people who want Slack notifications, and I think those folks ought to be happy to pay. My hope is that I'll eventually get a few paid signups and that those will cover the costs of the service (which are minimal).<p>I know I lose a bit of revenue with the above approach, but it's a tradeoff I'm happy to make.</p>
]]></description><pubDate>Mon, 31 Mar 2025 01:49:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=43529860</link><dc:creator>greysteil</dc:creator><comments>https://news.ycombinator.com/item?id=43529860</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43529860</guid></item><item><title><![CDATA[New comment by greysteil in "Ask HN: What are you working on? (March 2025)"]]></title><description><![CDATA[
<p>:D</p>
]]></description><pubDate>Mon, 31 Mar 2025 00:31:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=43529316</link><dc:creator>greysteil</dc:creator><comments>https://news.ycombinator.com/item?id=43529316</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43529316</guid></item><item><title><![CDATA[New comment by greysteil in "Ask HN: What are you working on? (March 2025)"]]></title><description><![CDATA[
<p>Through the API - in particular the info endpoint[1], combined with the fact that Reddit IDs are base36 encoded sequentially increasing integers[2]. You can get 100 objects at a time, so if you make ~3 requests a second it's enough to get all of the new posts and comments.<p>[1] <a href="https://www.reddit.com/dev/api/#GET_api_info" rel="nofollow">https://www.reddit.com/dev/api/#GET_api_info</a><p>[2] <a href="https://www.reddit.com/dev/api/#fullnames" rel="nofollow">https://www.reddit.com/dev/api/#fullnames</a></p>
]]></description><pubDate>Sun, 30 Mar 2025 22:25:24 +0000</pubDate><link>https://news.ycombinator.com/item?id=43528321</link><dc:creator>greysteil</dc:creator><comments>https://news.ycombinator.com/item?id=43528321</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43528321</guid></item><item><title><![CDATA[New comment by greysteil in "Ask HN: What are you working on? (March 2025)"]]></title><description><![CDATA[
<p>I've been building mentions.us[1] - it sends you alerts when your keywords are mentioned on Hacker News, Reddit, Bluesky, LinkedIn and a few other places. For anyone who uses F5Bot, it's similar but with some extra data sources and a Slack integration.<p>It's been a fun project. Dealing with the scale of Reddit (~300 posts/second) creates some interesting technical challenges. It's also let me polish up my frontend development skills.<p>I don't think it will ever be a money spinner - it has ~70 folks using it buy they're all on the free tier. It's felt really good to build something useful, though.<p>[1]: <a href="https://mentions.us" rel="nofollow">https://mentions.us</a></p>
]]></description><pubDate>Sun, 30 Mar 2025 21:20:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=43527768</link><dc:creator>greysteil</dc:creator><comments>https://news.ycombinator.com/item?id=43527768</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43527768</guid></item><item><title><![CDATA[New comment by greysteil in "Next.js version 15.2.3 has been released to address a security vulnerability"]]></title><description><![CDATA[
<p>Can we take a moment to appreciate how good the disclosure and coordination process on this were?<p>* Reported to the maintainers privately<p>* Patch published and CVE issued before wider disclosure<p>* Automated fix PRs created within minutes of public disclosure (and for folks doing proactive updates, before)<p>The above is _really_ excellent. Compare that to Log4j, which no CVE and no patch at the time it became public knowledge, and it's clear we've come a long way.<p>Supply chain security isn't a solved problem - there's lots we can still improve, and not everything here was perfect. But hats off to @leerob and everyone else involved in handling a tough situation really well.</p>
]]></description><pubDate>Sun, 23 Mar 2025 01:13:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=43450165</link><dc:creator>greysteil</dc:creator><comments>https://news.ycombinator.com/item?id=43450165</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43450165</guid></item><item><title><![CDATA[New comment by greysteil in "Ask HN: Would you use a product to draft contracts for SMBs and solopreneurs?"]]></title><description><![CDATA[
<p>I'm a bootstrapped solopreneur at the moment. I would maybe use this, but I generally DIY everything. For contracts, for example, I'd probably just dust off the YC template, make a few tweaks, and not sweat it. For my T&Cs I took another company's terms and made edits where I thought it was important. Definitely not legally watertight, but good enough for my purposes.<p>Solopreneurs are amongst the most resourceful folks out there, and also the most price sensitive, so we're a tricky market to go after.</p>
]]></description><pubDate>Wed, 19 Mar 2025 01:33:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=43407428</link><dc:creator>greysteil</dc:creator><comments>https://news.ycombinator.com/item?id=43407428</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43407428</guid></item><item><title><![CDATA[New comment by greysteil in "Ask HN: What are you working on (March 2025)?"]]></title><description><![CDATA[
<p>I'm building mentions.us. It's a simple idea - alerts for keyword mentions on Hacker News, Reddit, Bluesky, etc., but has been a fun project. I wanted to build something that had broader coverage than F5Bot (which is excellent) and supported sending notifications to Slack.<p>Right now I'm working on adding LinkedIn support now (trawling through private APIs).</p>
]]></description><pubDate>Wed, 19 Mar 2025 01:28:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=43407402</link><dc:creator>greysteil</dc:creator><comments>https://news.ycombinator.com/item?id=43407402</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43407402</guid></item><item><title><![CDATA[New comment by greysteil in "Ask HN: What are you working on? (February 2025)"]]></title><description><![CDATA[
<p>Yeah, it's on my list. When you're scanning sites with high volume (Reddit has ~300 posts per second, Bluesky has ~100) you have to keep things fast and cheap, so I think keywords still have a role, but I think they can become an implementation detail.<p>My plan over the next couple of months is to build the option for users to enter the kind of things they want to scan for, have AI convert that to keywords, use the keywords for the (fast) scanning, and then apply additional filtering using AI to the small number of posts that match.<p>Not built yet, but I think there's a bunch of promise to using AI to find relevant conversations online.<p>Re: APIs, yep, all APIs. I'm not doing any web scraping at the moment</p>
]]></description><pubDate>Tue, 25 Feb 2025 15:00:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=43172710</link><dc:creator>greysteil</dc:creator><comments>https://news.ycombinator.com/item?id=43172710</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43172710</guid></item><item><title><![CDATA[New comment by greysteil in "Ask HN: What are you working on? (February 2025)"]]></title><description><![CDATA[
<p>I've been building <a href="https://mentions.us" rel="nofollow">https://mentions.us</a> for the last couple of months. It's a little web app that monitors Reddit, Bluesky, Mastodon, Hacker News and a bunch of other sites for keyword mentions. Not an original idea (F5Bot has existed for at least 8 years) but a fun project, and I think it can make a contribution by monitoring more sources and having a free tier that includes sending Slack messages.<p>It has taken a couple of months to go from idea to a product that's polished enough for other people to use, and I've been full time on it. It has a couple of dozen companies using it now, almost all from the last couple of weeks. That's been a big boost!</p>
]]></description><pubDate>Tue, 25 Feb 2025 14:45:44 +0000</pubDate><link>https://news.ycombinator.com/item?id=43172493</link><dc:creator>greysteil</dc:creator><comments>https://news.ycombinator.com/item?id=43172493</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=43172493</guid></item><item><title><![CDATA[New comment by greysteil in "How can I grow as an engineer without good seniors to learn from?"]]></title><description><![CDATA[
<p>I’ve found that everyone learns in different ways, and if having mentors / seniors to absorb knowledge from is how you learn best then I’d agree with the comments suggesting you change roles.<p>However, if you learn well by doing, or by reading, there are loads of other great ways to improve technically. I’ve made big leaps forward in my skills by building (relatively large) side projects, where I can safely experiment with different design decisions and see the consequences over time. I’ve also got a huge amount out of just sitting down and reading the docs for tech I’m interested in - some frameworks (like React) have fantastic resources that can take you from good to great.<p>Good luck!</p>
]]></description><pubDate>Sun, 01 Dec 2024 19:44:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=42290253</link><dc:creator>greysteil</dc:creator><comments>https://news.ycombinator.com/item?id=42290253</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42290253</guid></item></channel></rss>