Hacker News new | past | comments | ask | show | jobs | submit login
At Replit, the toughest people we have to fight are dark web hackers (twitter.com/amasad)
42 points by tosh on March 29, 2022 | hide | past | favorite | 3 comments



> Another user comes back, does the same thing, and another and another -- we are bleeding money.

Isn't this prevented with authorizing features before dispatch? Why are unlimited users allowed access to indefinite resources?

This thread reads "after the rats swarmed in the open front door, here's how we rounded 'em up and got 'em out".


There's always a tradeoff between making it easy for legitimate customers to try out the product, and making it hard to abuse. If you bias for preventing fraud, you have less customers, and vice versa. This was written about a bunch in the context of PayPal in Jimmy Soni's excellent history of PayPal [0], as this is basically why companies like PayPal/Stripe exist: banks optimize for reducing fraud, and not for making it easy to become a customer. So they have very little fraud, but correspondingly few customers (compared to Stripe/PayPal).

[0]: https://www.simonandschuster.com/books/The-Founders/Jimmy-So...


I think that last part is how it reads, but because unlimited users were allowed access to finite resources each. (If you and I independently wanted to try repl.it out, they want you and I to both have a good trial experience.)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: