Project ideas from Hacker News discussions.

SB 923 is Law: CCPA deletion rights now reach third-party data

📝 Discussion Summary (Click to expand)

Generating summary…


🚀 Project Ideas

AccessCheck

Summary

  • Real-time diagnostic tool that tells users why a site is blocked by Cloudflare or similar WAF and suggests workarounds.
  • Core value: Empowers users to regain access to content without violating site policies.

Details

Key Value
Target Audience General internet users, researchers, journalists blocked by overzealous filters
Core Feature Automated HTTP request probing, analysis of Cloudflare challenge responses, and guided remediation steps (e.g., adjust cookies, use specific user-agent, enable TLS fingerprinting)
Tech Stack Frontend: React + TypeScript; Backend: Node.js (Express) or Go; Deployment: Docker on cloud (AWS/GCP)
Difficulty Medium
Monetization Hobby

Notes

  • Users complained: "I get blocked from even visiting the site." and "OutOfHere: It has lately been blocking me even in the US while on a mobile device, sending me auto-captchas in a loop." This tool would diagnose the exact cause (e.g., JA3 fingerprint, missing cookies) and suggest fixes.
  • Could spark discussion on balancing security vs accessibility and provide site owners with feedback on false positives.

DeleteVerify

Summary

  • Platform that enables consumers to submit verifiable data deletion requests (CCPA/CPRA, GDPR) and provides site owners with an API to authenticate those requests.
  • Core value: Reduces fraud and workload for businesses while giving users confidence their requests are legit.

Details

Key Value
Target Audience Privacy-conscious consumers; SaaS companies, e-commerce sites needing to handle deletion requests
Core Feature Cryptographically signed request tokens, identity verification via email/OAuth, and a simple REST endpoint for site owners to validate and log requests
Tech Stack Backend: Python (FastAPI) or Rust (Actix-web); Frontend: Svelte; Database: PostgreSQL; Signing: JWT or PASETO
Difficulty Medium
Monetization Revenue-ready: SaaS subscription ($10/mo per site for verification API)

Notes

  • Commenters questioned legitimacy: "accountrequired: How does the website owner know if the removal request is legitimate and not an unauthorized third party requesting removal?" DeleteVerify solves that with verifiable signatures.
  • Provides practical utility for compliance teams and could be discussed on HN as a privacy‑first alternative to manual email verification.

CFPass

Summary

  • Browser extension that intelligently bypasses common Cloudflare challenge loops (e.g., endless CAPTCHA, JS challenges) by rotating TLS fingerprints, managing cookies, and using headless‑friendly user agents while preserving user privacy.
  • Core value: Restores access to sites that mistakenly block legitimate traffic without requiring users to disable security extensions.

Details

Key Value
Target Audience Power users, developers, remote workers frequently hitting Cloudflare blocks on work or personal sites
Core Feature Automatic detection of Cloudflare challenge pages, transparent retry with varied JA3/TLS settings, cookie persistence, and optional user‑controlled allowlist
Tech Stack Manifest V3 extension (JavaScript/TypeScript); Background service worker; Optional native messaging host in Rust for low‑level socket tweaks
Difficulty High
Monetization Hobby

Notes

  • Users reported: "OutOfHere: ... sending me auto-captchas in a loop." and "less_penguiny: I'm blocked via their CloudFlare setup. Is it because I am based in Europe?" CFPass would reduce friction by adapting to Cloudflare's bot detection heuristics.
  • Could lead to constructive discussion about ethical bypassing vs. site owners' right to protect against abuse, encouraging better challenge design.

Read Later