26 ms·
New startup sells coffee through SSH
- low_tech_punk 2y ago"Shell company" takes on a new meaning!
- wuj 2y agoCool concept, but quite limiting if you are selling a mass-market product.
- glonq 2y agosure, but can I sudo a sandwich ?
- tithe 2y agoHmm, a CLI interface for consumer purchasing. Can I pipe that order through to a payment processor and delivery method? Script my meals for the week?
- solardev 2y agoEverquest has you beat by a couple decades: https://www.nbcnews.com/id/wbna7020132 https://www.nbcnews.com/id/wbna7020132 In that game you can type /pizza and it'll get ordered and delivered
- tithe 2y agoNice. I was wondering if this had been done somewhere before. "Sony plans to integrate the pizza function more tightly into the game", which every game should do, of course :)
- codetrotter 2y agoGame programmers: it’s a video game, we don’t need the same kind of application security that other programs do Hacker: Hold my beer while I exploit this dude’s game client and makes it order 10,000 pizzas to his door
- ethbr1 2y agoWhy would you order 10,000 pizzas to someone else's door? Unless you don't have 10,000 hungry friends.
- codetrotter 2y agoTo cost them a lot of money for all those pizzas. And to cost the pizza shop money if they can’t collect payment for the pizzas. And to cause general grief and misery, as trolls are wont to do :(
- ethbr1 2y agoBut, you could also not pay the money AND have the pizzas.
- gavindean90 2y agoAnd you left a paper trail
- ethbr1 2y agoThat's why you order them to a neighbor's house who's out of town. Eastern Europe's been having fun with variants of this since the 90s.
- deleted 2y ago[deleted]
- floam 2y agoBy killing the delivery worker? AFAIK the ol’ unlimited free pizza by killing the thread trick no longer works. It sure was nice while it lasted, especially on platforms that easily let you kill a thread id, even kids could do it. Remember how on BeOS there was a GUI for it? Great for unfreezing a crashed app that had state you wanted to try to recover or free leaked pizza. Now worker threads spawned for delivery hold a lock preventing new pizza being placed in the oven for that address, which is not released until the add payment callback is successful. Destroy the only thread holding the lock, and pizza orders just queue up forever. :(
- ethbr1 2y agoThat makes me miss the days when "but in 3D!" was a novel business model... https://duckduckgo.com/?q=everquest+gameplay&t=fpas&iar=images&iax=images&ia=images https://duckduckgo.com/?q=everquest+gameplay&t=fpas&iar=imag... Hard to be formulaic when there's not a formula. "Why not real pizza ingame?"
- solardev 2y agoThe Everquests certainly seem dated today, but for their time, they were pretty neat! The gameplay was simple (especially by today's standards), but it was a pretty unforgiving game that required a lot of teamwork. It was the social aspect that kept most people playing, I think, especially in guilds. I remember a lot of the playerbase kept asking for significant changes to make the game less grindy and hardcore, but the main game designer would always push back and reiterate The Vision™ (in their words) and stick to their plans. Not only did they not ask for feedback, they would actively fight back against it and reinforce their stance. Well, they must've done something right... 25 years later, EQ is still alive, celebrating its anniversary, and making new expansions (after several sets of publisher/developer changes, though). If not for EQ, we wouldn't have had World of Warcraft and all the other MMOs. But today's MMOs have all become basically "massively singleplayer" in that grouping is rare outside of guilds and limited end-game raids, with bots and boosters of various sorts taking the place of what used to require multiple real people (AI really IS ruining everything!) The social aspect has been heavily deemphasized nowadays (Diablo and Destiny don't even have global chats anymore) and you mostly just see the ghosts of people doing their own things with no real need to interact with them anymore. Too bad =/ Showing off /pizza or other fun commands (emotes, music, crafting, etc.) was a big part of the old-school experience. These days there are still some semi-social MMOs (New World has an awesome group music jamming system, where multiple people can get together and jam like Rock Band/Guitar Hero: https://www.youtube.com/watch?v=ggWZJNnaLNU https://www.youtube.com/watch?v=ggWZJNnaLNU)... but sadly no more in-game pizza that I know of. ----------- If anyone's looking for an old-school MMO in the style of EQ, Project Gorgon is an indie MMO made by (I believe) a mom-and-pop dev team: https://store.steampowered.com/app/342940/Project_Gorgon/ https://store.steampowered.com/app/342940/Project_Gorgon/
- 2y ago
- robertlagrant 2y ago> Demonstrating a deep understanding of what its computer-gaming audience, Sony has built the ability to order pizza into its latest online multiplayer game. NBC's command of language might not be good, but it turns out it is consistent.
- hk1337 2y agoPizza Party beat this by a few years, I believe. https://entertainment.slashdot.org/story/04/05/07/138238/pizza-from-the-command-line https://entertainment.slashdot.org/story/04/05/07/138238/piz... https://www.youtube.com/watch?v=J691aLfkWP0 https://www.youtube.com/watch?v=J691aLfkWP0
- gnabgib 2y agoPage title: wip: terminal
- skilled 2y agoThat is objectively a worse title than what is submitted - which explains what the page/product does.
- lxe 2y agoInteresting. I like this. No need for a cookie banner.
- f_devd 2y agoI mean, if they somehow ported google analytics (or some other brokered PII network) I think they technically would need consent and disclosure.
- organsnyder 2y agoThey'd only need a cookie banner if they somehow could put a cookie on your machine using SSH. Depending on how they're using any personal data you provide, they likely wouldn't need consent: for instance, if they use the personal data you provide to ship you your order, they don't need to ask (you supplied your information for the express purpose of placing an order, after all). However, if they want to do more with that data, they'd need consent.
- paxys 2y agoBut what if I want coffee and a cookie?
- joelfried 2y agoCan I interest you in this delicious cup of Java?
- tonymet 2y agothey get your ssh public key which is a unique identifier so that should be disclosed.
- paxys 2y agoIf they aren't logging it then there's nothing to disclose.
- bigstrat2003 2y ago
- Dig1t 2y agoIt's sold out and the only option if you actually connect via ssh is to give them your email address so they can send you updates.
- bradlys 2y agoMakes me wonder if this is just a ploy to email harvest and there never was any coffee being sold.
- aaroninsf 2y agofor backend dev recruiterspam
- fragmede 2y agoThey were mentioned 2 and 1 days ago, and weren't sold out then. https://news.ycombinator.com/item?id=40200701 https://news.ycombinator.com/item?id=40200701 https://news.ycombinator.com/item?id=40208417 https://news.ycombinator.com/item?id=40208417
- ehutch79 2y agoThe Primeagen is behind this, and they had physical samples at react whatever in miami recently for whatever that's worth
- memco 2y agoThere’s always risk exchanging money and information with a merchant regardless of where and how the transaction takes place. And SSH is a fairly unconventional way to run a business so that’s a point in favor of extra caution. That said, tit is pretty unlikely to be a scam. Two of the team members are theprimeagen and teej_dv; both longtime twitch/youtube streamers: with a reasonable following: one of whom is a core neovim maintainer. They streamed the development of most of this live on twitch. They have a reputation to uphold and a track record of other publicly facing work to help support the legitimacy of this venture. Sadly, the VOD requires a subscription and the source isn’t available (though they said they plan to open source it) so there’s not much to fall back on other than hearsay until the orders start arriving or the code gets posted.
- mebazaa 2y agoReminds me of prose.sh. Turns out, there’s a lot you can do if you SSH keys as an authentication mechanism!
- helpfulContrib 2y ago[dead]
- nescioquid 2y agoThis seems obligatory: https://tldp.org/HOWTO/Coffee.html https://tldp.org/HOWTO/Coffee.html
- deleted 2y ago[deleted]
- daft_pink 2y agonow I need a turing complete waffle iron
- nerdjon 2y agoWas kinda hoping this was some place selling made coffee, but I do realize the reach of that would be small. But I do kinda like the idea of something as... niche as this popping up in a highly tech area and then offering the ability to buy and get your coffee without ever seeing someone. Like you just walk into a room with a rotating door (like one you might see at a doctors office for samples) or something like that. Feels very... introvert and would be kinda fun.
- skilled 2y agoKind of disappointed that there is no option for commands like “ls” or “whoami”. I think it would be a nice addition, especially if this inspires other people to launch similar pages for other types of products.
- SequoiaHope 2y agoReminds me of my friend’s zine-via-telnet: https://anewsession.com/ https://anewsession.com/
- FerretFred 2y agoNow /that's/ interesting! Thanks for the link - I must try this myself...
- colesantiago 2y agozero interest rate startups are still in fashion I see.
- jethro_tell 2y agoWhat makes you think any small business like this would need to get VC funding for a website and a simple tui program with a couple features? People make cafes and coffee shops all the time without taking money or at least VC money.
- sm0ol_ 2y agothey're self-funded, there's no interest rates present.
- daft_pink 2y agoonly if they spunoff their ssh based shopping cart with stripe integration to a vc funded startup.
- wrs 2y agoLove the idea! Congratulations (?) on being sold out! My constructive feedback is that the text contrast is so low (in iTerm2 anyway) I can barely read anything. I thought only web pages had that problem, but I guess sufficiently sophisticated TUI apps have designer color problems too! What's next, incredibly tiny terminal fonts? (jk, designers...sort of)
- ethanholt1 2y agoI wasn’t the one who made this, fwiw.
- semessier 2y agoI wanted to ask if they do telnet/finger also, but there is no email listed.
- sva_ 2y agoReally cool interface. Is there any list of such servers publicly available through ssh?
- qudat 2y agohttps://pico.sh https://pico.sh
- tonymet 2y agocreate the next ssh crawler
- deleted 2y ago[deleted]
- efreak 2y agoSome of the older still-available services are listed below SSH: ascii.theater was mentioned here, so was mapscii.me There's a bunch of games at https://overthewire.org/wargames/ https://overthewire.org/wargames/ (and there's likely still dozens of other small muds running over telnet as well) chat.shazow.net is a chat server Non-ssh (the games mostly require registration): `curl wttr.in` for weather `finger help@graph.no` for weather `cat | nc termbin.com 9999` for a pastebin `telnet telehack.com` `telnet freechess.org` `telnet gt.gamingmuseum.com` `telnet fibs.com 4321` to pay backgammon There's used to be Nyan cat through telnet, which I'd hacked into running on ssh but AFAICT there's no longer any servers around (my own server is no longer around either) https://nyancat.dakko.us https://nyancat.dakko.us Unknown how many of these are running still: https://info.cern.ch/hypertext/DataSources/Yanoff.html https://info.cern.ch/hypertext/DataSources/Yanoff.html There's a much more recent list that includes ssh and telnet services here: https://github.com/chubin/awesome-console-services https://github.com/chubin/awesome-console-services --- On a related note, http://shells.red-pill.eu/ http://shells.red-pill.eu/ lists a bunch of free shell services. See also: https://github.com/Swordfish90/cool-retro-term https://github.com/Swordfish90/cool-retro-term
- eddd-ddde 2y agoI remember some blog post that took comments via ssh, that was cool as well.
- tonymet 2y agoI long for an alternate dimension where terminal-based internet like Minitel dominated . Something like hypercard implemented with 80x24 ncurses UI
- mdgrech23 2y agoThe real power of the internet all along in my opinion was networked databases. Everything else is fluff and not a particularly great use of resources.
- tonymet 2y agonetworked spreadsheets would have been ideal
- fouc 2y agoI love TUI (as in text-based user interfaces) so much more than GUI. It always felt like a far more peaceful and productive environment.
- tiptup300 2y agoAs long as I have ctrl+c/v copy and pasting I'm right there with you.
- umbra07 2y agodon't you mean yy and p?
- redundantly 2y agothis comment is based
- tonymet 2y agovim-based
- pahool 2y ago$25 for 12 oz? Yikes!
- tonymet 2y agowhat did you expect when they said "startup" and not "shop"
- jkestner 2y agoFree coffee in exchange for all future rights to my productivity metrics.
- tonymet 2y agoknowing "startups" i'm sure their vision is streaming SSH subscription as a service . They track your keystroke rate and automatically ship new batches of $2/oz coffee when you get below 90 keystrokes/min
- mywittyname 2y agoNo joke, but "startup" can often be code for, "extremely high-quality items that are subsidized by VC money". The quality doesn't last, but if you get in early, you can often buy stuff that's way nicer than it should be for the price.
- tonymet 2y agoi would frame this comment if I could. Early AirBnB, Lyft, Uber, Lime, Bird, Netflix, online-retail were very high quality for low cost and then inverted.
- fabian2k 2y agoWith 70$/kg that's at the upper end of typical prices for specialty coffee (though I'm not familiar with US prices specifically). No idea if they are at a level where they can compete at that price point, a single blend as main product is rather odd for a coffee roaster. At this price point you'd usually get various single origin coffees.
- toddmorey 2y agoThe founders have a great (if conversational and sometimes off topic) podcast about development topics: https://podcasts.apple.com/us/podcast/how-about-tomorrow/id1651741524 https://podcasts.apple.com/us/podcast/how-about-tomorrow/id1...
- 1f60c 2y ago"Universal" podcast link: https://pods.link/i/1651741524 https://pods.link/i/1651741524
- whimsicalism 2y agoThey sold out in 15 minutes? Or this is email/ip addy harvesting?
- mminer237 2y agoFrom their Twitter, they sold out yesterday. OP must have just thought it was interesting regardless, even if it's a suboptimal time for them.
- cat_plus_plus 2y agoScared to order after xz exploit...
- mateusfreira 2y agoSame here, I know Prime tho. I really looks fun, but sound scary
- 1970-01-01 2y agoReminds me of "Before Google, Sergey Brin tried (and failed) to let us order pizza by fax" https://news.ycombinator.com/item?id=5264626 https://news.ycombinator.com/item?id=5264626
- m463 2y agosolaris used to have a pizzatool EDIT: image here: https://blog.adafruit.com/2022/01/31/the-story-of-sun-microsystems-pizzatool-the-first-pizzas-ordered-on-the-internet-vintagecomputing-sun/ https://blog.adafruit.com/2022/01/31/the-story-of-sun-micros...
- Kwpolska 2y agoFull story: https://scribe.rip/the-story-of-sun-microsystems-pizzatool-2a7992b4c797 https://scribe.rip/the-story-of-sun-microsystems-pizzatool-2...
- rvnx 2y agoOne safety tip: disable SSH Agent Forwarding before you connect, otherwise the remote server can theoretically reuse your private key to establish new connections to GitHub.com or prod servers (though this host is unlikely malicious). https://www.clockwork.com/insights/ssh-agent-hijacking/ https://www.clockwork.com/insights/ssh-agent-hijacking/ (SSH Agent Hijacking)
- vrighter 2y agoi usually just disable ssh agent forwarding globally by default, and only enable it selectively via my ~/.ssh/config
- jolmg 2y agoDefault is disabled.
- hnarn 2y agoExactly, this tip only applies if you reconfigured ssh to automatically forward agent to all hosts, which is absolutely insane.
- bananskalhalk 2y ago*disable ssh agent FORWARDING. Which honestly should always be disabled. There are no trusted hosts.
- tichiian 2y agoThat's baby+bathwater. Just use ssh-add -c to have the ssh-agent confirm every use of a key.
- bananskalhalk 2y agoTIL. Thanks! Gonna do wonders when working at places where I can't use a hardware key with physical confirmation of use. My assessment still stands. Use proxyjump (-J) instead of proxy command whenever possible.
- kolinko 2y agoSold out :(
- archgoon 2y agoSince I can't currently order, can someone say how the ordering process works? Do they send back a link to be used with stripe? Or do they try to handle everything within the terminal? The latter seems to invalidate their claim that this is just as secure as using a web browser.
- cozzyd 2y agohopefully using a java implementation of an ssh server
- Shakahs 2y agoI'm curious how they built this. It's SSH but the IP address is Cloudflare's edge network. It could be using CF Tunnel to transparently route all the SSH sessions to some serving infrastructure, but I didn't know you could publicly serve arbitrary TCP ports like that. Building it in serverless fashion on CF Workers would be ideal for scalability, but those don't accept incoming TCP connections.
- deleted 2y ago[deleted]
- Scaevolus 2y agoYup! Cloudflare naturally advertises HTTP most heavily and it has fancier routing controls, but it supports arbitrary TCP protocols. > Cloudflare Tunnel can connect HTTP web servers, SSH servers, remote desktops, and other protocols safely to Cloudflare. https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/ https://developers.cloudflare.com/cloudflare-one/connections... > In addition to HTTP, cloudflared supports protocols like SSH, RDP, arbitrary TCP services, and Unix sockets. https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/configure-tunnels/local-management/configuration-file/#supported-protocols https://developers.cloudflare.com/cloudflare-one/connections...
- londons_explore 2y agoThat requires the client to install custom tunnelling software. If you want the client to not require special software, they provide a web based terminal emulator for ssh, and a web based VNC client.
- KomoD 2y agoCloudflare Tunnels only open HTTP/S to the internet, you'll need their client to reach the other protocols. More likely that this is Cloudflare Spectrum.
- psd1 2y agoI don't think that's correct. I serve matrix on 8443 through a tunnel.
- normsbee 2y agoThis is so cool! Just imagine a world where you can run `getcoffee latte` and have a latte show up at your door 20 minutes later.
- paxys 2y agoMost of these APIs already exist, just that they are hidden behind custom apps and auth walls. For example you can order coffee on starbucks.com or doordash.com right now and see all the network requests which facilitate the delivery.
- objektif 2y agoYour receipt: - latte 5.99 - delivery fees 5.99 - ssh fees 0.99 - internet fees 0.59 - water 0.19 - sewage 0.09 …..
- jethro_tell 2y agoSub total 5.99 Total. 10.80 Wait, what?
- daft_pink 2y agosomeone call the ftc lol
- aftbit 2y agoAh lame, they won't even let you browse since they're sold out.
- krasin 2y agoI believe it's just a stub for collecting emails. Nothing more. Edit: somebody was able to order coffee through them (see below).
- nkcmr 2y agoNope! It is real, I was able to order some coffee a few days ago. Will report back on if it shows up or if it is any good :)
- krasin 2y agoOh, cool! That gives me hope.
- aftbit 2y agoWell I hope they enjoy getting a lot of fake emails, because that's what's gonna happen.
- krasin 2y agoMany people forget that their email is included in the public key that is presented to the ssh server by default. So, the email collection form is actually somewhat redundant. But yes, I added my share of funny email addresses to their list. Tradition is a tradition.
- chuckadams 2y agoAll of my ssh keys are chuck@hostname, which is the default output of ssh-keygen. I’ve never had a valid email in any of my ssh keys.
- aftbit 2y ago
- thisisauserid 2y agoIs it /usr/locally grown and single .'ed? How quickly can they mv it to my ~?
- tiptup300 2y agoas per chatgpt This joke is a clever play on words that merges elements of computer programming and coffee culture. Let's break it down: New startup sells coffee through SSH: SSH stands for Secure Shell, which is a network protocol that allows for secure communication between two computers. In this context, the joke suggests that this new startup is selling coffee through a secure connection, presumably online. Is it /usr/locally grown and single .'ed?: This part of the joke is a play on the directory structure in Unix-like operating systems, where /usr typically contains user-related programs and data. "Locally grown" suggests that the coffee is sourced locally, and "single .'ed" is a wordplay on "single origin," a term used in coffee culture to denote coffee that comes from a single geographic origin. The /usr/locally grown part humorously combines Unix directory structure with the concept of coffee sourcing. How quickly can they mv it to my ~?: Here, "mv" is a command in Unix systems used to move files or directories, and "~" represents the user's home directory. So, "mv it to my ~" is a playful way of asking how quickly they can deliver the coffee to the customer's home. It's also a pun on the idea of moving the coffee to the user's home directory.
- phone8675309 2y agoPretty good
- deleted 2y ago[deleted]
- yegle 2y agoIt would be awesome if I can do something like this: > ssh terminal.shop "register foo $pubkey" > ssh foo@terminal.shop "set shipping address to $addr, credit card info $info, email address $email" > ssh foo@terminal.shop "order one 12oz light roast"
- willcipriano 2y agoLooking forward to reading about this incredible journey
- kobieps 2y agoI would not be upset if the entire internet went back to this.
- orblivion 2y agoSo unless you mean to exclusively sell coffee to users who don't have a white terminal background, you may want to consider your color scheme. I was missing the white text. (I know this is considered an atrocity by some, but I happen to not really care enough about my terminal color to change the default)
- adamdotdev 2y agowe meant to have this fixed before launch, but ran into some snags with charm's `wish` and adaptive colors. shipped an improved light mode today!
- bee_rider 2y agoThe atrocity was committed by whoever set that default, we can work out a plea deal as long as you rat them out.
- Tijdreiziger 2y agoMac OS X’s Terminal.app used to be black-on-white by default, wouldn’t be surprised if that’s still the case.
- int_19h 2y agoXterm is black on white by default.
- gavindean90 2y agoThe whole system wide light/dark stuff came about too late to help our terminal sessions.
- zzo38computer 2y agoIs there an environment variable defined for specifying if you want light or dark colours? If so, then it would help with local programs, and also with remote programs (such as this one) if you add a SendEnv command into the SSH configuration file to specify that SSH should use this environment variable.
- hk1337 2y agoReminds me of the pizza cli app that would order Domino's Pizza. EDIT Pizza Party is what I am thinking about. https://www.youtube.com/watch?v=J691aLfkWP0 https://www.youtube.com/watch?v=J691aLfkWP0
- melodyogonna 2y agoPrime and Teej streamed the development
- raytopia 2y agoThis is really cool. I wonder how they pipe the data to stripe? As an aside kind of funny to see this pop up. I was just talking about if anyone was doing ordering through a cli a while ago: https://news.ycombinator.com/context?id=39817617 https://news.ycombinator.com/context?id=39817617
- abe-101 2y agoWith the stripe api Why would their backend be different then any other website using stripe
- pimlottc 2y ago> # use the command below to order your delicious 12oz bag of Nil Blend coffee > ssh terminal.shop Oops, I thought I was supposed to enter it directly into the prompt on the webpage. The styling makes it look like an interactive console, I figured they included an embedded javascript SSH client for users who might not have one.
- mgfist 2y agoMade the same mistake
- Repulsion9513 2y agoPSA to anyone making a public SSH service: List the fingerprint, not the host key, thanks. (Or better yet list both!)
- robocat 2y agoPlease avoid acronyms on HN or spell them out. We don't all live in your context. duckduckgo just says PSA is Prostate specific antigen. What did you mean?
- snapcaster 2y agopublic service announcement, chatgpt would have got it for you
- deleted 2y ago[deleted]
- eddd-ddde 2y agoIIRC Public service announcement.
- _lvbh 2y agoPublic service announcement. It’s very widely used
- efreak 2y agoI would blame this one on DDG, actually. PSA is an incredibly common acronym for public service announcement. Wherever DDG sources acronyms for might also be assuming people just know it. Try wiktionary or Wikipedia disambiguation pages for acronyms when they don't show up in search, I can often find them there.
- Repulsion9513 2y agoSorry, I meant Secure SHell. Oh wait, that wasn't the widely-known acronym you asked about.
- drekipus 2y ago
- thdxr 2y agohey! i'm one of the people who worked on this, we actually launched a few days ago and sold out quite quickly - we'll remove the email capture so you can poke around we'll be back in a few weeks with proper inventory and fulfillment we'll also be opensourcing the project and i can answer any questions people have about this
- d3m0t3p 2y agoHey, nice work, how to get updates about the open source release ?
- thdxr 2y agoprobably follow the twitter account @terminaldotshop
- Mockapapella 2y agooh shit, you're open sourcing this as well? I'd love to use a similar workflow for some of my projects. Love the idea! Also you guys should post over on Threads -- a bunch of people over there are really into the idea as well: https://www.threads.net/@mockapapella/post/C5_vLdDP0J1 https://www.threads.net/@mockapapella/post/C5_vLdDP0J1
- halfcat 2y agoOh wow. You’re the guy who knows Adam right? His Laravel video was so inspiring.
- dwhly 2y ago
- cbhl 2y agoLooks like they're sold out now. The "enter your email for restock updates" part of the screen showed up as white-on-white on my light-mode-by-default Gnome Terminal on my first try and so I was slightly confused; sshing from `uxterm` worked fine though.
- exabrial 2y agoThe authenticity of host 'terminal.shop (172.65.113.113)' can't be established. ED25519 key fingerprint is SHA256:TMZnO7N8mmR/Pap3urU2P4uBNuhxuWtDUak0g9gyZ8s That's a bit different than the key listed
- zaik 2y agoHave you added the required line to ~/.ssh/known_hosts as described on their website?
- cgriswald 2y agoThat's not actually what they describe. They describe catting known_hosts and seeing terminal.shop with the given key in the output. That won't work if you don't continue to connect because known_hosts won't be updated with their key. Additionally, if hosts are hashed, you won't see terminal.shop anyway.
- zaik 2y agoI think what "cat" here means is that you are supposed to add their key to the known hosts file manually before you connect. Showing the output of "cat file" is a way of saying "this should be in the file".
- cgriswald 2y agoI think it’s fair if they want to assume a certain competence from their audience, and they’re being cute. But these aren’t instructions and if they are, well, the ssh command happens first.
- tichiian 2y agoNo. The key listed is the whole plain ed25519 pubkey (those are relatively short). The message displays the SHA256 digest. You can check that in your local known_hosts file (after having connected at least once) with "ssh-keygen -F terminal.shop -l" and "ssh-keygen -F terminal.shop -lv". (Yes, it is confusing that the command is named "ssh-keygen" but does lots of things that are not about generating any keys) If you want to do it without connecting, try "ssh-keyscan terminal.shop".
- ayman_saleh 2y agoThis is genius! Not sure how the stripe payments intake work but very cool!
- k8svet 2y agoMan, consumerism is a powerful drug. Just one gimmick needed.
- jethro_tell 2y agoI mean, some of us are going to buy and drink coffee anyways.
- nomel 2y agoIn this case, caffeine would be the literal drug.
- PaulDavisThe1st 2y agoA lot of people don't know that before Amazon started, there was a company out of Portland, OR called Bookstacks selling books via a telnet interface. In the early days, Bezos was quite worried about their potential to get "there" first (wherever "there" was going to be). It was a fairly cool interface, at least for 1994. [ EDIT: worried to the point that we actually implemented a telnet version of the store in parallel with the http/html one for a few months before abandoning it ]
- mleo 2y agoThere were a few using telnet before the web gained wider traction. For example, CDNow started out that way in 1994.
- brk 2y agoI remember ordering a CD via CDNow and a very rudimentary SMS interface on my phone around 1996. It took about 10 minutes to go through the entire process, but I did it while at the movies with my wife, waiting for the previews to start and we both thought it was just SO advanced.
- keepamovin 2y agoThat is an epically cool story from the early days of the Internet / web. Thanks for sharing!
- PaulDavisThe1st 2y agoA brief reminder that SMS has nothing to do with the internet (TCP/IP) or the web (HTTP).
- rrr_oh_man 2y agoNetflix also was founded in 2007, not 1997.
- 2y ago
- bee_rider 2y agoAre the beans any good, what kind of roast?
- 9front 2y ago"Dive into the rich taste of Nil, our delicious semi-sweet coffee with notes of chocolate, peanut butter, and a hint of fig" and "medium roast"
- bee_rider 2y agoOh, is that in the email or something? I searched Nil blend coffee but only got results about sports teams. I wonder if it is white-label or something.
- low_tech_punk 2y agoHow does scaling work for SSH? e.g. How many concurrent connections can the server handle?
- pmarreck 2y agoI love TUI's. And now that Sixel exists, we can even have images in the Terminal. The massive simplification this provides over rendering HTML/CSS should be attractive to startups. Now I wish we had a CLI/TUI for things like Amazon...
- arianvanp 2y agoAnother service that is completely controlled through a ssh tui : https://nixbuild.net https://nixbuild.net
- yalok 2y agoI would really like to see a decaf option there.
- miki123211 2y agoI can't test this due to the product being out of stock, but I wonder what their approach to PCI compliance is. Processing credit card data has a high compliance burden if you're unwilling to use a secure widget made by an already-authorized provider like Stripe. That's for a good reason, most web and mobile apps are designed such that their backend servers never see your full credit card number and CVV. You can't do this over SSH. I also wonder whether you could even do this if you had to handle PSD2 2-factor authentication (AKA 3d Secure), which is a requirement for all EU-based companies. This is usually implemented by displaying an embed from your bank inside an iframe. The embed usually asks you to authenticate in your banking app or enter a code that you get via SMS. You can take the easy way out of course and make the payment form a web page and direct the user to it with an URL and/or a Unicode-art rendition of a QR code.
- niutech 2y agoOne esy to solve this is to use a terminal web browser like Carbonyl.
- srinathkrishna 2y agoThey mention in the faq that they use Stripe - https://www.terminal.shop/faq https://www.terminal.shop/faq. Stripe does offer integrations that are not natively using their widgets. Ultimately, the PII data is stored at Stripe. PS: I work at Stripe but I don't really work on the PCI compliant part of the company.
- samwillis 2y agoInterestingly Stripe started life as /dev/payments and I seem to remember the first iteration was an agent on your server that literally processed card payments when you wrote the details to /dev/payments
- niutech 2y agoYou can still find the source code here: https://github.com/benweissmann/dev-payments https://github.com/benweissmann/dev-payments
- mhh__ 2y agoI've been toying around with an ssh based casino recently.
- manicennui 2y agoI really like Fellow Drops: https://fellowproducts.com/pages/fellow-drops https://fellowproducts.com/pages/fellow-drops It is SMS based. Each week they offer a different bean from a different roaster, and you reply with the number of bags you want. I've discovered a number of great roasters this way.
- rrr_oh_man 2y agoI might be horribly out of touch, but... is $25 for a 12oz bag of not-totally-horrible coffee beans really a normal price?
- mywittyname 2y agoNo. 12oz Dunkin is like $9 at Target, same with Starbucks medium roast; Pete's is $12. The most expensive stuff is this mushroom chuga coffee (I have no clue what this is) for $16/12oz. And Target is generally more expensive than most chain supermarkets. So no, not a normal price.
- lee_a 2y agonot normal price for anything you'd find in most grocery stores. but as an anecdote, I get a lot of coffee from the Fellow Drops subscription service, and those bags average around $25 - often for less than 12oz.
- deadmutex 2y ago~$15-$20 for a 12oz to get it fresh from a local roaster in the SFBA.
- SoftTalker 2y agoYou're paying for the convenience.
- technodelic 2y agoThe best local roaster in my town charges about $20 for a 12oz bag of specialty single origin coffee. Their blends are a little cheaper even. The lowest price specialty coffee I could find online is about $12 for a little over 10oz from a place called S&W. So $25 is a very bad value in my opinion.
- poopsmithe 2y agoSo cool! Congrats on selling out! I was curious to see if I could connect using mosh. I could, but I wasn't able to use the hotkeys to browse the different screens like I was when I connected via ssh.
- worker_thread 2y agoI am very curious how this is built, I would like to build similar SSH interactive experiences. Any resources and how to get started would be really appreciated. (I know how to setup a basic TCP server that listens on SSH port, but I really don't know how to implement navigation etc for the SSH experience)
- zedutchgandalf 2y agoI think they use Wish in Go: https://github.com/charmbracelet/wish https://github.com/charmbracelet/wish The company making this, charm.sh, has a whole bunch of cool cli frameworks
- deleted 2y ago[deleted]
- zachlatta 2y agoI love this. If you love this, you might also like a game I built a while ago: $ ssh sshtron.zachlatta.com
- geuis 2y agoIf you're looking for a movie to enjoy with your coffee, https://ascii.theater/ https://ascii.theater/ ssh -a -i /dev/null -o StrictHostKeyChecking=no watch.ascii.theater
- sigio 2y agoI raise you: telnet mapscii.me
- doawoo 2y agoNeat — big fan of TUIs! But I’m an even bigger fan of coffee… so show me where that coffee actually is sourced from… Did you go and source it from farms? Is this sourced from another company? Whose blend? Do you provide the roast date on the bag?
- dingosity 2y agoHappy to see this didn't work scp foo.txt terminal.shop:. I was worried for a second they hadn't thought of that.
- dingosity 2y agoThough obviously, something like scp evil_passwd_file terminal.shop:/etc/passwd or scp evil_authorized_keys terminal.shop:.ssh/authorized_keys is really the kind of thing you don't want. But if you can't copy foo.txt into your home directory, you probably can't copy attacker versions of more sensitive files into sensitive locations.
- nunez 2y agoThis is cool; I wish they had decaf single origin!
- dancemethis 2y agoClaim to be ethical, yet don't deliver in the country the coffee is actually made.
- raggi 2y agoBefore a bunch of you run off and make more of these “because it’s cool”, they’ll likely lose access to stripe once stripes security team pay attention and realize that this can be trivially man in the middled and doesn’t actually offer the equivalent protection to https. I wrote up a little demo and explainer at https://mitm.terminal.shop.rag.pub ssh mitm.terminal.shop.rag.pub
- I_o_IllI__o_I 2y agoHmm, I'm having trouble finding that site. Sick sunset at rag.pub though!
- raggi 2y agoIt’s available via ssh and https That shots from my parents balcony in Bermuda
- lol768 2y ago> I wrote up a little demo and explainer at They give you the ed25519 host key to insert into your known_hosts file on their homepage, which itself is served over TLS with all of the protections you describe in your article. They could go into more detail on being careful with not falling into the tofu trap perhaps, but I don't see that there's an inherent PCI-critical problem here. ssh tells you who, cryptographically, you're connecting to. If I mess with my DNS and point it at your "little demo", this happens: $ ssh foo@terminal.shop @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @ @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY! Anyone ignoring a big scary warning like that probably isn't going to brew the coffee properly anyway. And guess what? My browser lets me bypass HTTPS warnings too! Yes, even when HSTS is enabled I can take steps to bypass the warning.
- raggi 2y agoExcept in their marketing materials they just say `ssh terminal.shop` Users will fall into the TOFU trap, most users who've sent them cash certainly did. Most users won't put their credit card credentials into a page that they've had to bypass a cert warning on.
- I_o_IllI__o_I 2y agoNot to dunk on the coffee which I haven't tried but this seems like a viral ad? I get it's cool that this actually works, but in practice how is it different to selling coffee through an API through a generic web interface served by shopify? In the end in both ways they are selling you coffe beans for money. It's still cool to see it in your terminal though.
- pmx 2y ago> It's still cool to see it in your terminal though This is the whole point, I think. Things can exist just because they're fun :)
- huhuhu111 2y agoThey are missing out.. There are some Tor customers out there...
- deleted 2y ago[deleted]
- matt3210 2y agoSlack preview link shows up weird. It shows as follows > wip: terminal (initial commit)
- deleted 2y ago[deleted]
- 9front 2y agoFrom the FAQ: will Nil make me a better developer? legally we cannot guarantee that it will, but... is it true your coffee contains the sweat of @theprimeagen? we can neither confirm nor deny these rumors. is it true your coffee contains the tears of @thdxr? yes, this is true.
- 9front 2y ago┌──────────┬────────┬─────────┬───────┬────────────────────┐ │ terminal │ s shop │ a about │ f faq │ c checkout $ 0 [0] │ └──────────┴────────┴─────────┴───────┴────────────────────┘ nil blend coffee whole bean | medium roast | 12oz $25 Dive into the rich taste of Nil, our delicious semi-sweet coffee with notes of chocolate, peanut butter, and a hint of fig. Born in the lush expanses of Fazenda Rainha, a 280-hectare coffee kingdom nestled in Brazil's Vale da Grama. This isn't just any land; it's a legendary volcanic valley, perfectly poised on the mystical borders between São Paulo State and Minas Gerais. On the edge of the Mogiana realm, Fazenda Rainha reigns supreme, a true coffee royalty crafting your next unforgettable cup. sold out! ──────────────────────────────────────────────────────────── + add item - remove item c checkout ctrl+c exit
- xyst 2y agothis needs some "charm" to it. it's a bit basic
- 8organicbits 2y agoCharm here is: https://charm.sh/ https://charm.sh/
- archon810 2y agoWow, this is incredible stuff.
- aprilnya 2y agoFAQ: > is ordering via ssh secure? you bet it is. arguably more secure than your browser. ssh incorporates encryption and authentication via a process called public key cryptography. if that doesn’t sound secure we don’t know what does. Doesn’t TLS use public key cryptography too?
- tempaccount420 2y ago"More secure than your browser," while serving the hostkey over HTTPS.
- latentsea 2y agoWho has this problem?
- Linda231 2y ago[dead]
- fagrobot 2y agosuuuuper gay
- langcss 2y agoIs this a reverse-Dropbox play? Make something need ssh, rsync, etc. that didn't need it before.
- bascope24 2y agoThis is really cool. Which tech does it use for ecommerce functions?
- amelius 2y agoDoes ssh have a good payment system built in?
- mynameisnoone 2y agoWhile it's cute, it's a small business not a startup and still a gimmick that doesn't solve the problem that coffee is a commodity and so the business is fundamentally not defensible. It's equivalent to being a meal kit business, which is one notch away from being a restaurant.
- qxfys 2y agonow, I want to sell ketchup over SSH.
- em1sar 2y ago[dead]
- atleastoptimal 2y agook cool gimmick but why? is it special coder coffee?
- lambdaxyzw 2y ago>is ordering via ssh secure?# you bet it is. arguably more secure than your browser. ssh incorporates encryption and authentication via a process called public key cryptography. if that doesn’t sound secure we don’t know what does. Strong disagree. The encryption is the easy part, the hard part is the symmetric key exchange. And PKI used by browsers is much more robust for this usecase then TOFU model of ssh. Of course the proper way to fix this is checking the ssh key fingerprint, but almost nobody does this.
- deleted 2y ago[deleted]
- 1231232131231 2y agoWon't it warn you if you put the public key in your authorized_keys as shown here: https://www.terminal.shop/ https://www.terminal.shop/?
- einpoklum 2y agoHey terminal.shop, Y U No T? :-(
- botsone 2y agoCHROOT
- latexr 2y agoReminded me of Hacker Scripts, specifically `fucking-coffee`: > this one waits exactly 17 seconds (!), then opens a telnet session to our coffee-machine (we had no frikin idea the coffee machine is on the network, runs linux and has a TCP socket up and running) and sends something like `sys brew`. Turns out this thing starts brewing a mid-sized half-caf latte and waits another 24 (!) seconds before pouring it into a cup. The timing is exactly how long it takes to walk to the machine from the dudes desk. https://github.com/NARKOZ/hacker-scripts https://github.com/NARKOZ/hacker-scripts
- dwhly 2y ago"STRONG KEYS, STRONG COFFEE"