Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
alexblackwell_
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
alexblackwell_
6mo ago
Feel free to try it out and let us know if you have any issues. I was personally skeptical, but it now does about 70% of my "reverse engineering" work. Sometimes needs a bit of guidance on really complex fields, but I think the to
2.
▲
by
alexblackwell_
6mo ago
Web apps like this are few and far between, and piggy-backing on the session/anti-bot tokens from your browser usually works. In really complex cases we do help companies on a white glove case-by-case basis.
3.
▲
by
alexblackwell_
6mo ago
Interesting. We essentially do the same thing, but with MITM. We have a chrome extension internally, but have found it's a bit of a clunky interface. Might be releasing one soon. The approach with executing script in webpage is interes
4.
▲
by
alexblackwell_
6mo ago
You can prompt the mcp to do this. Honestly considering adding this as a skill in the agent chat. Internally we do this all of the time for our white glove integrations.
5.
▲
by
alexblackwell_
6mo ago
The requests still route through your servers/the data still lives with you. Kampala is a powerful tool but I don't see people replacing the actual apps with it. Most of our customers use it for automating repetitive actions in le
6.
▲
by
alexblackwell_
6mo ago
I wouldn't consider what we do evasion really. We are using real tokens that you have received from your browser as a result of browsing the web. Any good anti-bot will have enforcement for abuses of that token.
7.
▲
by
alexblackwell_
6mo ago
My broader point is that these ToS clauses are often so broad and vague that they're essentially unenforceable and not meaningful in practice. For example, "Do not use bots" covers a pretty substantial amount of ground, and i
8.
▲
by
alexblackwell_
6mo ago
sorry a bit confused on your question here. If you're asking about JSON RPC we handle this via parsing. The AI can then handle deducing structure most of the time given enough context
9.
▲
by
alexblackwell_
6mo ago
gRPC obscures the keys not the values. Enums and signed ints are sort of tricky, but the latter is just a mapping problem and the former can be figured out through some logical deduction. gRPC isn't designed to obscure request content,
10.
▲
by
alexblackwell_
6mo ago
Noticed you have two comments here. I think my response to your other comment best answers this ( https://news.ycombinator.com/item?id=47798259 ). Definitely open to discussing this more here. Not sure if I agree on the self-
11.
▲
by
alexblackwell_
6mo ago
The goal is not to scrape sites en-masse, but to allow people to automate their existing workflows and actions that they perform already via a browser. I understand the concerns around this being unethical, and it's something I spent a
12.
▲
by
alexblackwell_
6mo ago
Yep essentially. I would argue that we're probably closer to a MITM proxy like Proxyman than Wireshark. We don't do general packet sniffing (yet), although internally we use our own packet sniffing tools for reverse engineering on
13.
▲
by
alexblackwell_
6mo ago
Definitely get that. Being hammered by scrapers is a massive PITA (especially with latest aggressive AI crawlers). We focus primarily on allowing people to automate their existing workflows. For all hosted workflows we have rate limits to p
14.
▲
by
alexblackwell_
6mo ago
Yep we handle gRPC and websocket. gRPC is a bit sketch/hard to do because of the way the protocol is designed. FWIW not many sites implement gRPC (some google sites and spotify being the only two I can think of), and if they do they us
15.
▲
by
alexblackwell_
6mo ago
Yeah agreed this messaging is a bit confusing. Our focus is on helping people build automations, not do any mass-scale scraping.
16.
▲
by
alexblackwell_
6mo ago
Thanks Ben! For session re-auth we attempt to agentically find the session refresh/login endpoints and make those part of the flow as an auth provider. This can be a bit sketchy though and is the main bottleneck right now. Currently wo
17.
▲
by
alexblackwell_
6mo ago
Unfortunately we can’t do much around SSL pinning yet. Not sure how deep you want to go, but there are several Frida scripts that patch common pinning implementations. I also think mitmproxy (open source) has an option to spin up a virtual
18.
▲
by
alexblackwell_
6mo ago
I’ve probably spent on the order of months of my life in proxyman/charles/burp/powhttp. All are great, but I’ve never been completely satisfied with the UX/features for building automations. As far as differences; we don
19.
▲
by
alexblackwell_
6mo ago
We’ve essentially been using that “recursion” to tune our agent. Having the agent build itself is not something I would have ever thought of though. Curious if you find it genuinely creates specific enough tools for it to be worth the setup
20.
▲
by
alexblackwell_
6mo ago
It was the (generated) name of the Conductor workspace when I started the project. We were going to rename it before launch but the name stuck lol :)
21.
▲
by
alexblackwell_
6mo ago
Super cool. I think this is where most automation is heading . Would be curious if you could one-shot the auth flow using Kampala and completely ditch the browser. Also FWIW you can import HAR into Kampala and we have a few nice tools (like
22.
▲
by
alexblackwell_
6mo ago
Zatanna is a DC comic book character. I’m not sure if either of us have even read comics, so not sure where that came from. For Kampala, when I started this I was trying Conductor for the first time. The generated workspace name was Kampala
23.
▲
by
alexblackwell_
6mo ago
We’re currently running a variety of stuff for TLS/HTTP2. If you download you can see the full trace of the connection. We dump the TLS connection byte for byte with the different structured subsections. With tls.peet.ws and bogdann fi
24.
▲
by
alexblackwell_
6mo ago
Oops now realizing that pattern where we send you to bottom latest download link is definitely confusing. Fixed so that the top button sends you straight to Download now.
25.
▲
Launch HN: Kampala (YC W26) – Reverse-Engineer Apps into APIs
(zatanna.ai)
100 points
by
alexblackwell_
6mo ago
|
84 comments