4 ms·
This represents over 1 year of work. Why am I open sourcing this? I don't see any other RBI / CBII vendor open sourcing their platform and in the security ind
by slowenough 7y ago
This represents over 1 year of work.
Why am I open sourcing this?
I don't see any other RBI / CBII vendor open sourcing their platform and in the security industry "closed source" can create issues.
But what about business defensibility?
I agree. Open sourcing removes the trade secret aspect that could make a defensible business.
At the same time, a determined hacker would already have my source code. A hacked "free wifi" connection here, a bit of social engineering there, and my so-called "competitive advantage" could be easily removed. Access to GitHub, Gitlab, other accounts would prove no obstacle for someone motivated, and open sourcing is a way to remove the advantage any small group of parties has by keeping it secret.
How do I self-host it?
There's instructions on the repository page.
- jusob 7y agoUnable to connect to https://free.cloudbrowser.xyz/ https://free.cloudbrowser.xyz/
- slowenough 7y agoSorry, I need to restart it. I resized the instance, then forgot. Hold on a couple minutes while the queue of browsers rebuilds on restart. Thanks for letting me know :) Edit: It's getting kind of slammed, right now. I might need to resize it up again in a while. Edit2: Alright, I have to resize it, it needs more power. Hold on while it comes back up. Queue is rebuilding @23:13 ET. Edit3: Okay, back up @23:20 ET. Please enjoy!
- mirimir 7y agoThat's an admirable move. Nobody sane relies on anything that's closed-source. Edit: OK, nobody prudent.
- krzkaczor 7y agoAre you familiar with https://mightyapp.com/ https://mightyapp.com/ it looks like there are people working on something very similar but closed source & VC backed. Thoughts?
- slowenough 7y agoYes! I requested an invite and reached out to Suhail on Twitter (I actually interviewed at Mixpanel ~ 18 months ago before I knew anything about MP or MA) about a technical question about MA that I got to thinking about from my experience building BG but didn't hear back from them. Mixpanel was a cool interview. I remember the question was about data structure for a rank system (it was a heap). The office in SF is beautiful, and the lunchtime catered food, was great. I guess I'd have more to say about MA if I knew more about it! I did not try it yet and I don't know how they make Chrome faster in the cloud and deliver a seamless broadcast of the screen to the user, but with enough smart people, I'm sure it's possible. As I said in a previous comment, I definitely think the future is mreo 'app virtualization' in the cloud, in some sense perhaps MA is starting at the beginning of that curve.
- Erlich_Bachman 7y ago> I definitely think the future is mreo 'app virtualization' Why would you think that? Where do you see this trend? Their app looks incredibly stupid to me and it is hard to imagine any large number of people that would use it. Your project aims to provide security, which is an interesting goal, that I think security-conscious people would want to use. But to virtualize a browser... for performance? For browser apps (which are already "virtualized" desktop apps, of sorts), trading off enormous amounts of bandwidth, for what, cheap RAM sticks that are getting cheaper by the month and faster SSDs for quick swap? For what usage case? That one guy who happens to have a chromebook but needs to run 100 tabs actively? You could just run "unload tab" extension already... Or like just have a desktop that you VNC into... Which all of the people that need this have been doing for decades...
- slowenough 7y agoI'm sorry to give you a link but I addressed this here[0]. The TL;DR is computing advances will allocate disproportionately to the big cloud providers, consolidating centralized/server compute which, coupled with 5G and AI, will lead to high-bandwidth experiences streamed to comparatively "thin" devices. For that being said, I agree that virtualizing apps "right now" is stupid outside a niche unless you have some secret sauce (like Mighty must, otherwise why?), because it's too much overhead. Preserving resources is why I run headless, and that's why I avoided WebRTC/VNC/video instead of judiciously sent screenshots only on change. [0]: https://news.ycombinator.com/item?id=21562899 https://news.ycombinator.com/item?id=21562899
- FreeHugs 7y agoWhen you say over one year of work, do you mean one year of manpower (aka ~2000 hours) or that you started it about a year ago?
- slowenough 7y agoThanks for the thoughtful question. For the CE release, I deleted the Git history (it became too difficult to deal with branch rewrites trying to remove all the cruft and deployment secret keys etc). But the actual current working repo for the non-free version has ~ 2400 commits[0]. And the repo that I forked that from (~ 7 months ago), I'd closed 238 issues, and the repo I forked that project from I closed 200 issues. Those previous repos are all my work built from the ground up within this last ~12 months as well. The current working repo has closed 124 issues. My Gitlab contribs for the last year are at: https://gitlab.com/dosycorp https://gitlab.com/dosycorp And it's actually a little bit over 1 year, and if I count the Gitlab contribs show there, it's over 5500. So, yeah it's been about 2000 hours I think. Working full time every week day and most weekends, and often longer than regular hours (but also dividing the work up in the day into sprints because that's how I manage myself to work best). It's definitely been a year. [0]: https://imgur.com/gallery/wpNhxS0 https://imgur.com/gallery/wpNhxS0
- FreeHugs 7y agoAwesome. Thanks for the detailed answer. I dig your dedication! You well earned to be on the front page! Who do you see as the main target audience? And do you have a business model in mind?
- slowenough 7y agoThank you for this! Main audience is people and organizations who are having problems with malware and cyber attacks. Business model I am still working on, but it's a mishmash of licensing (+ maintenance, for hybrid / on-prem) and pay per seat (for cloud-based). Could be other ways to provide value. What's your background? I'm open to new ideas.
- westi 7y agoThis is pretty cool. It might be work stopping the browser 'loading' itself inception style with some kind of blacklisting of loadable urls - I assume you already have something to protect against SSRF type attacks on the platform itself.
- slowenough 7y agoIt sounds like it might be work to stop the browser loading itself inception style. I like it can load itself. What's the biggest problem you've had with that ability?