Project ideas from Hacker News discussions.

I could've accessed 17T Microsoft records

📝 Discussion Summary (Click to expand)

1. AI‑generated writing style draws criticism
Many commenters noted the tell‑tale “AI” phrasing in the blog post and expressed fatigue with LLM‑slop.

“Prefixing saying something with 'Two quick notes first' is extremely common AI meta commentary.” – ltbarcly3

“I stopped reading immediately at the quoted sentence. If it's not nauseating to you, perhaps you have had the good fortune to not have seen that exact pattern a hundred times in LLM‑generated articles already.” – applfanboysbgon

2. Microsoft’s bug‑bounty payout is seen as stingy
The $5,000 award for a potentially high‑impact flaw provoked disbelief, especially given Microsoft’s size and typical payouts for similar bugs.

“It's a little perplexing… awarded $5000 … Why would it be only $5000?” – sdfhbdf

“$5k is a literal penny for Microsoft. Give the kid $100k.” – bix6

3. The JWT “none” algorithm highlights broader security concerns
Discussion repeatedly pointed to the JWT spec’s dangerous “none” option as a root cause of the flaw, reflecting wider worries about Microsoft’s security posture.

“They did verify the signature, and it was correct according to the 'none' algorithm.” – meindnoch

“wow I am so surprised to hear once again how JWTs are terrible” – er0k (link: https://www.howmanydayssinceajwtalgnonevuln.com/)


🚀 Project Ideas

Generating project ideas…

AI Slop Detector

Summary

  • Highlights likely AI‑generated phrases (e.g., “Two quick notes first”, over‑use of bullet points) in web articles and blog posts to help readers avoid low‑quality AI slop.
  • Core value proposition: gives readers a quick, trustworthy signal of AI‑written style so they can decide whether to invest time in the content.

Details

Key Value
Target Audience Regular Hacker News readers, tech journalists, anyone who consumes online tech writing
Core Feature Real‑time text analysis that flags characteristic LLM patterns and provides a confidence score
Tech Stack JavaScript/TypeScript, WebAssembly (for lightweight ML model), Chrome/Firefox extension framework, optional backend API (Python/FastAPI)
Difficulty Medium
Monetization Revenue-ready: Freemium (free detection, $9/mo Pro for unlimited scans and history)

Notes

  • HN users complained: “I stopped reading immediately at the quoted sentence… it’s obviously AI and bad style” (applfanboysbgon) and “Do people not read what the AI produces before putting their name on it?” (ltbarcly3).
  • Provides a concrete tool to surface the very patterns commenters are tired of, sparking discussion about AI transparency in writing.

JWT None Algorithm Scanner

Summary

  • Scans codebases and configuration files for the dangerous JWT “alg”: “none” usage and suggests secure replacements.
  • Core value proposition: prevents a class of critical authentication bypasses before they reach production, aligning with Microsoft’s own MISE guidance.

Details

Key Value
Target Audience Backend developers, DevSecOps teams, security auditors working with JWT libraries
Core Feature Static analysis rule (AST‑based) that detects alg:none in JWT header strings, library calls, or config files, with auto‑fix suggestions
Tech Stack Go or Rust for CLI, GitHub Action wrapper, VS Code extension (TypeScript), optional SBOM integration
Difficulty Medium
Monetization Revenue-ready: SaaS tiered pricing ($20/mo per private repo, free for public/open source)

Notes

  • Commenters warned: “The existence of that option is extremely dumb and it shouldn't be possible to use that” (fabian2k) and noted Microsoft’s internal MISE library to avoid such issues (verst).
  • A scanner directly addresses the frustration that “JWT is complicated… Complexity is a spec failure in security issues” (buckle8017), giving teams an automated safety net.

Bounty Fairness Estimator

Summary

  • Helps security researchers estimate the fair market value of a vulnerability based on impact, exploitability, and comparable payouts, then compares it to the offered bounty.
  • Core value proposition: empowers researchers to negotiate better rewards or decide whether to pursue private disclosure, addressing perceived undervaluation by big vendors.

Details

Key Value
Target Audience Independent bug bounty hunters, security consultants, vulnerability researchers
Core Feature Input form (vuln type, affected asset, impact, exploit difficulty) → ML‑backed market value estimate → side‑by‑side with vendor bounty program payout
Tech Stack Python (FastAPI) backend, scikit‑learn model trained on public bounty data, React frontend, optional MongoDB for history
Difficulty High
Monetization Hobby

Notes

  • Users lamented: “$5k is a literal penny for Microsoft… Give the kid $100k.” (bix6) and discussed how bounties are “unilaterally set… far lower than true market value” (yieldcrv).
  • This tool would give researchers data‑backed leverage, likely sparking HN debate about bounty fairness and encouraging more responsible disclosure practices.

Read Later