1
13 Comments

No 3rd party included products

What do you think about our idea of coolLabs?

Its a bootstrapped side-project which aims to build products that are independent of large companies or any 3rd parties, privacy focused & community-driven. (Even our servers are not connected to any large corporations)

Do you think a simple idea like this will be succeed on long term?

on January 15, 2020
  1. 2

    My I recommend watching this Ted talk?
    https://m.youtube.com/watch?v=5ODzO7Lz_pw

    I think "not using any 3rd party except a payment processor" is an oversell that either is at least partially untrue or you'd run yourselfs crazy and underperform vs the market.
    If you want to be privacy and whatever aware and avoid specific things, cool...

    1. 1

      Wow, thanks for the video. I watched it & it was hilarious. :-)

      I would reinvent the toaster as well. He probably learnt a lot & enjoyed doing it.

  2. 1

    It's simply not feasible.

    Take the servers for example, how do you plan to handle routing, load balancing, redundancy, fail-overs, ect. These are all problems that things like AWS solve for you, and they're not easy problems by any means. You also take on the full cost of supporting a server which is going to be significantly higher than renting what you need on a cloud host.

    You're going to run into similar problems for almost everything you do; how are you going to handle emails, what about 3rd party development libraries? Something as core as React is technically a 3rd party dependency. How about storing data, are you planning on writing a custom DB engine?

    There's certainly some merit to trying to limit 3rd party dependencies, but to completely do away with them is reinventing the wheel for no reason.

    1. 1

      Thanks for your feedback!

      Oops, looks like I was not clear enough. 'No 3rd party included' means that our web based applications are not connected to any 3rd party services, so your data does not flow out in the background, like it does for a lot of applications.

      Yes, doing the scalable infrastructure in AWS/Google/etc, is far easier than in traditional hosting, but as I was a system administrator / infrastructure architect for years, I love to do it. :-)
      If there will be a point in the future when this could be out of my/our hand(s), ofcourse we will search for a cloud provider who fits our needs, but currently we are not in that stage.

      We are using nodejs, vuejs & mongodb. The 3rd party dependencies are OK. We would not like to reinvent the wheel in this scale. :-)

      We just would like to build a place where people will sure that their data is in safe hands and not transferred to anyone else in the background.

      1. 2

        You know the average person would rather have his data in the big guys than with you, right?
        Who are you? How do I know you won't sell me for a 1$ without any reprecuasions? Would you secure your systems against your 3rd employee that should not access customer data?..
        If I'd try to complain about you to authorities or file a lawsuit would anyone care? Would I be able to get composition?...
        I know that privacy niche gets a lot of headlines like crazy in some very small mostly tech circles..

        1. 1

          Also I like my Gmail auth over creating yet another user with you for example
          Which for most people would be a bigger security risk since they don't use a password manager, so they do reuse passwords and come up with easy ones, so more copies with more small unknown companies that might have a security issue at some point...

          If you very privacy aware Dev focused or even serurity focused clients they would love what your selling in a way after you get all the certs and get to size..

          1. 1

            So you mean, that every smaller company than the big ones, who tells you that they won't sell you data, potentially lying?

            Of course, you cannot be sure that we don't do it either. Even if we show all of our source code, you still cannot be sure.

            But, providing these applications as transparent as possible, could be one step further, than the 'big guys', where you do not know anything.
            All you know that their revenue is from selling your data & you are totally okay with it, as you are forced to use their products.

            We would to prevent this coercion, by making these applications.

            Btw, you can use Google / Github authentication in our apps. You do not need another account/password pair.

            1. 1

              You might be too defensive to follow up, but
              If you face 2 people one has 0$ and one has 1,000,000 and is a publicly know figure
              In you mind is the chance one would lie to you on something big the same between them?
              Assuming both lied to you on something big and caused the same amount of damage to you, let's say 10,000$ worth, what is your chance to get at least some of this damage paid back?

              ---

              Unrelated, as a small business, to your first customers you might have way more subjective trust regardless.

              --

              If your up for higher trust IMHO your worst enemy would always be overselling, which I personally currently fell you do a bit, probably by error only

            2. 1

              If you allow 3rd party auth then again this title seems broken to say no 3rd party products

              1. 2

                Thank you very much for your feedback. I really appreciate it! :)

                You pointed out 2 weak points which has to be improved.

                1. We need to be clear with our 3rd party statement, as it could be missunderstood easily.

                2. We need to prioritize the 'magic email' authentication method, which is already on our table.

                1. 1

                  Just updated our main site. Hopefully it is clearer now!

              2. 1

                The magic email login is also implemented! :-)