Live data from Hacker News

Don't Talk to Corp Dev (2015)

paulgraham.com

61–70 of 127 posts

Re: Don't Talk to Corp Dev (2015)

#61
post #24

Earlier quoted context omitted.

These words "secure" and "insecure" when used as synonyms for "encrypted" and "plaintext" obscure more than they illuminate and have done a lot of damage to the world of software security. They stop thought. You would not believe how many times I've talked to a company with some complex webapp and asked for their security policy and they respond with some statement about using TLS. It's absurd. Then even in books or…

I'm happy to agree that TLS doesn't guarantee security, but plaintext HTTP does guarantee insecurity.

[deleted]

Re: Don't Talk to Corp Dev (2015)

#62
post #32
post #6

He actually didn't even cover one of the worst parts about the whole process - fake buyers who just want to steal your tech. I was working at a startup with a ground breaking product no one had released before, we had shipped hundreds of prototypes and gotten good reviews and had plenty of orders, but board redesigns and setting up a factory assembly line for the production models was eating into our cash and runway.…

This is a classic. It usually takes an experienced engineer a 15 minutes tour around a building watching the machines to know exactly how you have done anything. It takes years an millions of dollars for your company to iterate on the specific layout, from the infinite possibilities. I have seen so many derivatives of this system, like courting/buying the gatekeeper with expensive gifts (laptops, very cheap vacations…

Sometimes it doesn't even take a 15 minute tour, just some office photos innocently tossed up on the about us page of a company.

Re: Don't Talk to Corp Dev (2015)

#63
post #43
post #35

Earlier quoted context omitted.

In TLS context, “secure” and “insecure” don’t just mean (un)encrypted, but also whether the connection is authenticated, i.e. whether you can be fairly sure you’re looking at the “real” website. This is a far more important property of a site using https. Especially in a world full of disinformation, authenticity and integrity of information are often a much greater good than confidentiality.

I understand what TLS does, but an argument that "we live in a world of disinformation" is not a substitute for having a well defined threat model and for many websites, particularly sites that broadcast information or download binaries which might already be signed or have hashes distributed via alternate means, there does not need to be a threat that requires TLS to address it. Like it or not, it is up to the infor…

Like others have said, I agree that stating that TLS does not garuntee security. But, plain unencrypted HTTP does mean insecure.

For a good discussion into why _all_ websites should use HTTPS, and the many different ways that not having the connection secured is actively harmful and why should not be done in the modern era.

https://www.troyhunt.com/heres-why-your-static-website-needs...

Not having your site as HTTPS puts all of your website visitors at risk. Even US ISPs like that of Comcast use these very same practices to inject warnings into insecure web traffic[0], some of which look more like advertisements than warnings. And like mentioned in the article, promises from ISPs not to use it for advertisements are just that, promises, and those can be broken in an instant. And when you have the power to inject anything without notice, you can do anything and everything with the website experience. You can attempt to force a download, present scam pages that look like antivirus warnings or software updates, one of the easiest ways to have users fall for malware.

We should _never_ expect regular non-technical users to have all of their threat models in mind, nor should they be expected to understand all of these differences. Website owners should be expected to protect all of their visitors as best as possible and one of the easiest ways to start is by protecting their website with modern HTTPS encryption. Otherwise, it would be like a chef leaving the bones in a salmon before serving to a customer. You could do leave them in, but a customer might not know they are there and you have left a choking hazard.

[0]: https://gizmodo.com/comcast-to-customer-who-noticed-it-secre...

Re: Don't Talk to Corp Dev (2015)

#64

I think I've really gotten into the habit of disagreeing with Paul Graham's blogs lately but this one felt different. Felt like a lot of practical, common sense advice that is just barely beyond the horizon that most people consider. Of course, it won't apply in every situation but it felt hard to disagree with the overall sentiment. Note: I say I've been disagreeing with him lately and, of course, this blog wasn't w…

Yep, this one is on the shortlist of YC advice that's useful to founders.

The list:

  - Launch now
  - Build something people want
  - Do things that don't scale
  - Find the 90 / 10 solution
  - Find 10-100 customers who love your product
  - All startups are badly broken at some point
  - Write code - talk to users
  - "It’s not your money"
  - Growth is the result of a great product not the precursor
  - Don’t scale your team/product until you have built something people want
  - Valuation is not equal to success or even probability of success
  - Avoid long negotiated deals with big customers if you can
  - Avoid big company corporate development queries - they will only waste time
  - Avoid conferences unless they are the best way to get customers
  - Pre-product market fit - do things that don’t scale: remain small/nimble
  - Startups can only solve one problem well at any given time
  - Founder relationships matter more than you think
  - Sometimes you need to fire your customers (they might be killing you)
  - Ignore your competitors, you will more likely die of suicide than murder
  - Most companies don't die because they run out of money
  - Be nice! Or at least don’t be a jerk
  - Get sleep and exercise - take care of yourself

Re: Don't Talk to Corp Dev (2015)

#65

I was courted by corp dev from a big public company. It was quite an experience -- events, dinners, wine, private meetings, large groups of the corp folks hanging on every word. They got pretty pushy, demanding to know trade secrets to keep going with a negotiation. At the end of it I pulled the plug because it was clear they were not working in our interest. (The word "pillage" comes to mind.) The experience was nic…

[deleted]

Re: Don't Talk to Corp Dev (2015)

#66
post #42

>If they can, corp dev people like to turn the tables on you. They like to get you to the point where you're trying to convince them to buy instead of them trying to convince you to sell. I worked for an established company (not a startup) and had a run in with Wal-Mart. Wal-Mart managed to buy some stuff at an ultra low discount because ... someone thought maybe if we get in there we could sell tons to their IT team…

I've worked at a small company constantly chasing large customers. Let's say a middling customer deal was $50k. Pretty much all profit. A large customer deal would be $500k, and need $500k of very specific technical-debt inducing bespoke dev work. I didn't know why they didn't grow the number of $50k deals!

Actually I know why. It was the "If we can get walmart it'll lead to much more" mentality (but not walmart but similarly big clients).

Also the $500k deals took a long time to land. When budgeting, whether the company made a profit or not would depend on a top salesman landing such a deal, or not.

What I notice is with larger deals and tenders the world was more cutthroat, the competition was more fierce etc, a lot of the "value" was from negotiating contracts and arguing over deadlines and shit, not actually delivering a product.

Re: Don't Talk to Corp Dev (2015)

#67
post #42

>If they can, corp dev people like to turn the tables on you. They like to get you to the point where you're trying to convince them to buy instead of them trying to convince you to sell. I worked for an established company (not a startup) and had a run in with Wal-Mart. Wal-Mart managed to buy some stuff at an ultra low discount because ... someone thought maybe if we get in there we could sell tons to their IT team…

Beware of the customer that kills the company...

Re: Don't Talk to Corp Dev (2015)

#68
post #42

>If they can, corp dev people like to turn the tables on you. They like to get you to the point where you're trying to convince them to buy instead of them trying to convince you to sell. I worked for an established company (not a startup) and had a run in with Wal-Mart. Wal-Mart managed to buy some stuff at an ultra low discount because ... someone thought maybe if we get in there we could sell tons to their IT team…

I've worked at a small company constantly chasing large customers. Let's say a middling customer deal was $50k. Pretty much all profit. A large customer deal would be $500k, and need $500k of very specific technical-debt inducing bespoke dev work. I didn't know why they didn't grow the number of $50k deals! Actually I know why. It was the "If we can get walmart it'll lead to much more" mentality (but not walmart but…

Sounds like where I ended up. We had a moderately successful company doing a lot of ~$100K deals and once we became financially sustainable we merged with a supposedly larger company in a complementary field with a view to accelerating our sales and getting access to a larger and more experienced tech team.

It turns out that they didn’t care at all about our regular little deals - the sales lead bragged to me once that he didn’t “get out of bed for less than $1M”. Long story short they spent all their time chasing much larger deals, but landing far fewer of them, and like your experience, the bigger deals are more complex and expensive to service. It was all driven by ego instead of logic, and it ended pretty badly.

Re: Don't Talk to Corp Dev (2015)

#69
post #51
post #49

Earlier quoted context omitted.

Sometimes it isn't about the "big sale" but having the big company on your list of customers. It can give your company a lot of credibility.

I don't doubt it for a start up... but I also wonder what value that is vs. 18 months of work and turn that into a deal that is really a loss, and the customer struggles to use the product ... and now you've got a big dominating customer who is going to continue to eat up time ... I wonder how many profitable customers could be had in that time.

I've lived situation. Large co bought one of our systems, as their internally built systems weren't up to the task. We sold it at effectively break even. This was in part due to my business partner's view that we could turn this into a bigger deal.

Well, no. We couldn't.

The "customer" wanted specifically to see how we did what we did, in order to copy this. It took me a while to figure it out, but I did, and we wound up walking away from it. Partner was angry, but it was absolutely the right business decision to terminate the interaction.

PSA for any small startup firm with real differentiation: BigCo will, absolutely, positively will, try to see if they can replicate your value on their own rather than buy from you. Patents won't stop this. Pretty much nothing will, apart from an architecture and implementation that they don't understand. They will mess with you. Approach with extreme caution, and be prepared to cut bait quickly.

Re: Don't Talk to Corp Dev (2015)

#70

I was courted by corp dev from a big public company. It was quite an experience -- events, dinners, wine, private meetings, large groups of the corp folks hanging on every word. They got pretty pushy, demanding to know trade secrets to keep going with a negotiation. At the end of it I pulled the plug because it was clear they were not working in our interest. (The word "pillage" comes to mind.) The experience was nic…

Yup. Had a similar experience with a BigCo and an investment. Part of the terms they were insisting on was an irrevocable global license to use our tech, name, trademarks, etc. for them and their partners. Our lawyers said they were trying to buy us on the cheap.
Post reply on HN