9 ms·
Show HN: Firebase, a scalable real-time backend
- gr3g 14y agoSimply Amazing!!
- jpdus 14y agoWow, im excited what people are doing out of this (especially in combination with other new tools like Meteor). Seems there is a huge development ongoing to reflect new development and scaling practices... EDIT: REALLY like the RT-Chat on the site - that is showcasing as it should be (and not just another "Demo" button).
- mayop100 14y agoEveryone has been building their own real-time solutions for the past few years and re-inventing the wheel over and over again. We saw ourselves doing it too, so we thought maybe we should do something about it! We think Meteor is really exciting as well, and should enable faster / better development of the types of apps that Firebase powers.
- geoffschmidt 14y agoMeteor dev here. We're really excited about Firebase -- the time has come for realtime databases. Every Meteor app needs one.
- pkrein 14y agoI used Firebase to build thereelbox.com, and enjoyed it thoroughly. It took 2-3 hours from starting into the documentation to completed/nobugs/pushed to production. Credit for that speed goes entirely to Firebase. TheReelBox uses Firebase as a sort of API caching layer. This protects against rate limiting on the Rotten Tomatoes API, decreases request time by caching queries to the Fandango-via-YQL API, and eliminates an extra request per movie for Youtube trailers. At the beginning, this system made it possible to host TheReelBox on my public dropbox folder, which made for really fast development. Since launch I've moved the static html and js to a micro AWS instance, but Firebase cleanly and transparently handles all the data. Definitely recommend it.
- knewter 14y agoAny reason you don't host those static files on a public 'web enabled' ec2 bucket? We do that for http://www.incubatebang.com http://www.incubatebang.com and it costs us like $1.40/year for hosting
- pkrein 14y agoThat's a cool idea, Dropbox and S3 both seem like good ways to get started with Firebase really fast. The AWS micro is free :) and it gives me a bit more flexibility to do things (in the future) like track outbound clicks to Fandango through a redirect that hits a real server.
- chrishaum 14y agoI love the design of your site! Did you have it done in-house?
- knewter 14y agoYeah, I'm an owner of http://www.isotope11.com http://www.isotope11.com and our designer threw it together in a couple of days. He's awesome, and he's leaving shortly, and we'll miss him :(
- readme 14y agoHey, I like your app! I would use it again if I could expand the map to make it larger. Would be the perfect tool for finding a movie.
- SpiderX 14y agoNice. The Hunger Games is a rickroll? Is that something you did?
- cwb71 14y agoHaha; see nigma's earlier comment about the open admin panel.
- 14y ago
- flav0ur 14y agoGreat!
- IanDrake 14y agoThis is cool. But can someone explain how data is secured in Firebase or Meteor? From the Leader Board sample: // Use setWithPriority to put the name / score in Firebase, and set the priority to be the score. userScoreRef.setWithPriority({ name:name, score:newScore }, newScore); How about I just change newScore to 100,000 in the debug window?
- mayop100 14y agoGood catch : ) We mention this briefly in our FAQ. We actually do have security in place (notice you can't enumerate other people's data for instance in our own tutorial), but the API is far from complete and we have no docs yet. There will be a full-fledged security model coming over the next few months.
- IanDrake 14y agoThanks. It will be interesting to see how you guys do that. Great website BTW.
- r00fus 14y agoHighly interested in what you plan to offer for authentication options and security (both data and transport). This sounds like Model-as-a-service from the MVC pattern.
- saurik 14y agoThat's only true until they launch a public product: at that point you can get access to or modify their data. It is downright irresponsible to launch a service like this that encourages people to use an insecure design for their service: security should be built in from the beginning, not tacked on afterwards, and even at the level of "this is a tutorial" it should be clear to the developer what they need to do to make it secure (not thrown into the advanced level of documentation, for example, like some companies do).
- geoffschmidt 14y agoHey Ian, Meteor dev here. I posted a comment earlier in this thread about how data is secured in Meteor: http://news.ycombinator.com/item?id=3834211 http://news.ycombinator.com/item?id=3834211
- amirnathoo 14y agoIf I understand right: instead of having to worry about calling a REST API for a back-end data store I can just have JS objects persist automatically and synchronize between clients. Dropbox for JS objects. If I've got that right, I think this is totally awesome for front-end web devs and the most exciting backend-as-a-service out there.
- javert 14y agoCan't people find an alternative to the word "real-time" that hasn't already been used for 30 years to mean something entirely different? (As in, real-time systems, real-time operating systems, etc.) I'm not trying to put down Firebase, I imagine it's great.
- IanDrake 14y agoSorry - I think "real-time web" is already in our lexicon. http://en.wikipedia.org/wiki/Real-time_web#Real-time_search http://en.wikipedia.org/wiki/Real-time_web#Real-time_search Just make sure people say web after they say real-time and there should be no confusion.
- javert 14y agoI don't think that it's a lost cause. Mainly because calling these things "real-time" is technically incorrect. Real-time computing is already formally defined and well established. Given the definition of real-time, one could actually create a real-time web or a real-time search. So there is still cause for confusion--or, at least, technical incorrectness--if one uses that terminology.
- IanDrake 14y agoSuggestions?
- zokier 14y agoLow-latency seems kinda descriptive if I have understood the 'real-time web' concept correctly.
- pgroves 14y agoI'd like to see a term that emphasizes that what web developers consider real time is "so fast it looks instant to humans," rather than guaranteed low latency that another system can rely on (or whatever you consider the true definition of "real time" to be). So maybe something like "blink speed." (Then we'd have blink speed apps on retina displays.)
- michaelmartin 14y agoThis looks really good. It seems to be very similar to the Hydna app that was on HN yesterday. For the rest of us, that has to be a win. Can't wait to see how things develop with both companies now! (Absolutely loved the interactive tutorial. Brilliant way to show off the service!)
- haberman 14y agoI'd love to see the host-proof scheme that ZeroBin uses, so users can store sensitive data without having to trust Firebase. http://news.ycombinator.com/item?id=3832269 http://news.ycombinator.com/item?id=3832269
- plusbryan 14y agoThis is the way to do demos - easy enough for a non-coder to use, but it explains and shows the internals for more experienced developers. Nice work!
- mayop100 14y agoThank you! Glad you like it!
- codesuela 14y agoon a sidenote: I wouldn't do business with or trust my data to a company that hides their actual address behind whois protection
- jamest 14y agoGood point. This was on while we were in stealth. I've removed the whois protection.
- deleted 14y ago[deleted]
- Rotor 14y agoI don't think they are trying to hide anything per se, the company grew from envolve.com. Seems to be pretty open here http://www.firebase.com/about.html http://www.firebase.com/about.html They'll probably remove the whois protection once they fully launch.
- jdavid 14y agoFirebase, Burn your servers, you don't need them any more. Firebase is for app developers that don't want to worry about building real time scalable back ends.
- buu700 14y agoRandom aside, but when I first saw this comment (it was originally downvoted, IIRC), it sounded like an incoherent insult directed at Firebase for catering to "noob" developers; I only realised that you meant it as a potential marketing line after reading a bit of your comment history :P. I think a colon in place of a comma at the start would have been more clear.
- jdavid 14y agoI was part of the beta and really enjoyed working with Firebase it was like working only in the browser, i could forget there was a backend. Once you start playing with it you realize that there are so many apps that can be built. the team has a few things to work on, and trust me many of us in the beta flushed a lot of those out. they have their work ahead of them. what's there is polished and ready for use. give it a try. use this as a chance to explore what can be done when you can forget about the backend.
- anandkulkarni 14y agoPhenomenal. I've been waiting to try this for months! It looks terrifically easy.
- asselinpaul 14y agoWhat is the difference between this and let's say 'Meteor'?
- jamest 14y agoGood question. Meteor is an application framework, like Ruby on Rails. Firebase is a database, like MySQL. We both think that application development is going to radically change in the future and we're both building products that promote a new way of developing apps. We're stoked about Meteor and see our products as very complementary.
- tlrobinson 14y agoCould Firebase be used as a database for Meteor? (i.e. replacing Mongo)
- geoffschmidt 14y agoGood answer :) One minor quibble.. I like to think of Meteor as an "application platform" rather than a framework, because we're trying to take on some problems that web frameworks don't always tackle, like packaging and deployment. Also, we don't require you to use a particular strategy for generating HTML. For example, it makes sense to use backbone.js with Meteor, if that's your thing. At the end of the day, Meteor is about how you make all of the pieces fit together in a distributed cloud application. (For better or worse, that's what websites have morphed into, when you think about all of the APIs and services they use.)
- michaeldwan 14y agoThis looks awesome -- a better option than an api-only Rails backend. Realtime pub/sub is also a big plus. Security is a concern with any 3rd party storage, but most uses I can think of wouldn't store missile launch codes in here anyway.. It's also worth pointing out that Firebase grew out of Envolve which supported millions of users, so you know these guys can handle scale.
- arturadib 14y agoAnother great step in the right direction. That being said, I do believe the hardest part of all these attempts to abstract backends is authentication and security models. It seems to me that most of these services launch before figuring out that critical part of the puzzle.
- nicholasreed 14y agoWe're using authentication in our Firebase app and it works wonderfully. Although all data is visible on the Firebase backend, we simply put pointer ids in Firebase, so no identifying data is publicly visible.
- arturadib 14y agoCare to elaborate? Firebase's FAQ seems to suggest that they're still working on a solution.
- nicholasreed 14y agoI believe they are working on a fully documented and stable auth solution; we're running something custom for now. Our whole Firebase namespace is read-only, so all our writing happens with a private key from our server. I think when the Firebase admin panel has more protection we can store more sensitive/identifiable data in there.
- skarayan 14y agoWhat level of control do you have for authentication? I didn't see much info on this on the website.
- nicholasreed 14y agoWrite control was most important for us; all the readable data are simply id's to our internal DB
- geoffschmidt 14y ago
- Rotor 14y agoCongrats on the launch of Firebase and absolutely love the code demo; it hooks you in. At the end of the demo you are asked if you'd like early access. Definitely.
- tomelders 14y agoIt's been a good week for the real-time-web. We might need a snappier name though, because this sort of real time is a lot more real time that the type of real time people are already used to.
- rooshdi 14y agoLive-time?
- trimbo 14y agoI just asked them twice on their chat to describe their infrastructure and they won't do it, at least yet. I realize this is in beta, and it's early, but am I the only one who would not trust my data to a service where I can't get at least some idea of how they're actually functioning behind the curtain?
- lucian1900 14y agoLooks very nice. But just like meteor, doesn't have any authentication or authorisation, which sadly makes them just toys for now. Looking forward to both projects becoming usable.
- wavephorm 14y agoCan someone explain what kind use-cases there are for a database where the client can read and write directly against the database? CouchDB could do this (via CouchApp), but I bet not many people do this because it's bad from security and scaling standpoint and I think there aren't that many types of apps that can be created without a proper back-end.
- webjprgm 14y agoA real-time client-side library that ties in to their database hosting service, basically. Also, if you want to have any non-realtime parts of your web app that do server-side processing of data then it looks like you have to use Node.js to talk to Firebase, as there's no REST API for it that I can see. I guess they don't mind because they're trying to get you to do all data processing in the client anyway. Definitely need security and permissions. How do I make sure only registered users of my site can access chat? How do I make sure only admin users can create new chat threads? From my brief reading it looks like all clients can see everything in the database and modify it all. Am I wrong?
- ibdknox 14y agoThere are ACLs for handling security concerns, but it's fairly early in their conception so they aren't really documented yet. Also, there is a rest API and I believe they're working on clients for other platforms so that nodejs isn't the only player in town.
- jamest 14y agoYou can find our REST API docs here: http://www.firebase.com/docs/rest-api.html http://www.firebase.com/docs/rest-api.html We're definitely working on security full speed. We have some basic security but it's not ready yet. If you'd like to beta test it, please email us: beta@firebase.com You can check out our FAQ for more info: http://www.firebase.com/faq.html http://www.firebase.com/faq.html
- lowglow 14y agoFantastic job. This looks phenomenal, James! I can't wait to find an awesome project to put this to good use. Cheers!
- ique 14y agoI couldn't find any (easily accessible) info about what it actually uses to communicate. Is it long-polling, websockets, something else? What kind of browser compliance is there?
- mayop100 14y agoIt uses a variety of techniques, depending on what is available on the client. When possible we use web sockets in the browser, but have other methods we can use when they're not available.
- MrJagil 14y agoI'm a non-coder. A very simple guide to make a very simple, understandable web-app would be the killer feature for me. There is a tutorial for a chat-app but that's way over my head(I of course get how to put in the code, I just don't understand it (REST, roots, references etc). If I could be shown how to make something insanely simple, and I actually understood how it worked, it'd lead me on to the next thing. A collaboration with codecademy might be the thing. So much potential.
- BryanB55 14y agoI'm the same way and have thought about this concept... I'm not even completely sure exactly what Firebase is but it sounds similar to that idea just requires more coding experience.
- hedgehog 14y agoTools used (from the chat): Mongo for storage backend Node.js client is Faye Scala + Netty backend custom JS client supporting "IE7+, Opera 10+, Safari / Chrome (recent versions), FF3.0+"
- mayop100 14y agoThanks for sharing this! Too busy in chat to keep up with all the HN comments : )
- Yxven 14y agoWhen the multi-player asteroids story was published, people were talking about Firebase, and having never heard of it, I started googling and found this: http://www.cubeia.com/index.php/products/firebase http://www.cubeia.com/index.php/products/firebase A scalable real-time game server with a html5/javascript front end. I still don't know which Firebase that game was built with. You guys have trademark issues.
- ranit8 14y agoMMOasteroids.com links to firebase.com
- deleted 14y ago[deleted]
- felixchan 14y agoThis is going to revolutionize the way apps are built.
- smoody 14y agoHere's my big concern: If my entire app is client-based JavaScript, wouldn't that make cloning my app as simple as copying all of the JavaScript and other asset files and then associating them with another firebase account -- perhaps modifying them some so they dont't get banned? It seems like it lowers the barrier to competition a bit too much for me.
- pron 14y agoYou could say that just about any software development platform. If it makes building software easier, it makes competition easier. And if building apps is easier, it really doesn't matter what stack your app uses - it's going to get easier to "clone", so you may as well use whatever platform gives you the best results. Other than that, you could either make your business, rather than your technology, more competitive, or make your technology ever more sophisticated than what "commodity" development tools allow.
- nick_urban 14y agoIt's not that client-side applications are easier to reverse-engineer. If the application is all client-side, it can literally just be downloaded and reused by a would-be competitor.
- aidenn0 14y agowhich violates your copyright. Microsoft Word is entirely client-side so it too can literally just be downloaded and reused by a would-be competitor.
- _dtw 14y agoReally interesting idea, look forward to giving it a whirl in a moment. Quick question, are you affiliated with firebase.co? They seem to be in a similar field.
- tknew 14y agoFirebase will turn into a chat company :p
- rgbrgb 14y agoWhat are the main differences between this and Meteor? What a strange coincidence that two nearly identical platforms launch within days of each other.
- MatthewB 14y agocongrats, james. i'll whip something up for teamly soon enough:)
- buremba 14y agoI think it's overrated. :/
- drucken 14y agoWhat I like most about Firebase so far compared to Meteor, is that I can actually read about Firebase and its excellent documentation from any machine with any web browser! Well done, thank you.
- oluckyman 14y agoThis should play beautifully with client-side JS web app frameworks like AngularJS where the JSON models are 2-way bound to the views.
- spladow 14y agoFor those interested in this kind of service there are a variety of others, including our own (spire.io), as well as Pusher, PubNub, and others.
- darylteo 14y agoLooks similar to what Meteor was trying to achieve?
- zmmmmm 14y agoSeems slightly misleading with the pitch about "no servers". More like, "proprietary Javascript framework locked to proprietary hosted cloud service, no information about pricing". Not that I begrudge anybody the chance to make some money, but along with Meteor I feel like there's a slightly deceptive nature to this kind of thing where the home page is emblazoned with "look, it's all free!" when in fact there's an unknown price to pay down the line.
- cmelbye 14y agoMeteor is open source, and with one command you can bundle your app into a self-contained node.js app which can, of course, run anywhere you can run node.js.
- ma2rten 14y agoFirebase is not really super complicated. It's just a database with a REST Api. I can not think of much more things they could add to lock you in more. I think if this becomes a thing, someone will make an opensource clone sooner or later. About Meteor: There might be a lot of things wrong with Meteor (insecure by design), but this is not one of them: it's opensource and has a command which makes a self containing tar.gz bundle for you to deploy on your own server.
- davidw 14y ago> it's opensource Under a license that does not permit you to easily use it for commercial projects, unlike, say, Django, Rails, Node.js, etc... etc.... etc....
- ma2rten 14y agoThat is not true. It's released under the GNU GPL, which does not make a difference between commercial and non-commercial projects afaik. It only says if you distribute the binary, you also need to give away the source code and others may redistribute and modify it. That does not mean, however, that you can not run it on your own server and keep the source code for yourself.
- bdunn 14y agoA few weeks ago, I wrote about (and presented at RubyNation) on why I think a "dumb backend" is a really bad idea: http://planscope.io/blog/2012/03/25/rails-is-more-than-an-api/ http://planscope.io/blog/2012/03/25/rails-is-more-than-an-ap...
- deerparkwater 14y agoIf validation rules aren't on the server, how do they ensure that submitted values are valid? Do they have a framework that magically propagates business rules to the server?
- mahmud 14y ago"real-time" has a very specific meaning when it comes to software, don't dillute it please.