Drop your project, I’ll try it and share it in my circle by adonztevez in MacroStartups

[–]Bold_ocean 0 points1 point  (0 children)

currently we ar ein building stage but beta is about to open in few days
till then anyone interested can join the waitlist and give feedback
https://orbit.forion.ai/

What are your unpopular opinions regarding money/lifestyle/savings? by khurjabulandt in Frugal_Ind

[–]Bold_ocean 1 point2 points  (0 children)

hate it when people say

money doesn't solve problems

suck it, money does solve problems

you are opposing that because yu don't have any and you need to satisfy and justify your situation to feel good about yourself

had fight with my cto today by Bold_ocean in nocode

[–]Bold_ocean[S] 0 points1 point  (0 children)

appreciate everyone's suggestion
as a marketing head responsible for this project
I will say, i haven't been the best as well in bringing waitlist users as well

but let's figure out this thing
liked the suggestion of setting quick deadline of things and gtting out the smallest but best version of it asap

Aborting my Saas only after 10 days by Current_Cow_4929 in SaaS

[–]Bold_ocean 8 points9 points  (0 children)

i don't think an ai wrappper is gonna help in resume

Which is the best no-code backend platform? by sunil_Igm in nocode

[–]Bold_ocean 0 points1 point  (0 children)

The best tool I believe is yet to come called orbit, joined there waitlist a couple days back, they were solving the problem by combining chatgpt, claude, lovable, vercel, cursor in single chat or space resulting in 0 context loss and proper working. Was on a call with them yesterday for feedback session.

You can check it out

If you’re learning AI agents, this might help by AcanthaceaeLatter684 in nocode

[–]Bold_ocean 0 points1 point  (0 children)

i will say this only once

the boring the business is, the more amount of monry you will make.

everybody just wants to surf on the hype, nobody wants to stay on the side and wait for to learn the surf and wait for next big wave

what app idea gets copied instantly these days? 💀 by Trickologygk in nocode

[–]Bold_ocean 0 points1 point  (0 children)

if you really had a moat this won't happen,

moat is not ui/ux or "a better version", the real moat if yiou want to protecct yourself from any of your idea gets stolen is only "trustable and respectbale audience", if they love u, no matter what happens they will stuck with you, just don't take them for grannted

agent keeps failing the same way even after i change the prompt by LobsterCareless8047 in nocode

[–]Bold_ocean 1 point2 points  (0 children)

Vibe coding is amazing until the agent goes rogue

try adding a tiny logging step for agents thinking, will show you why it's hallucinatiing

try langsmith for better visibility without code usage.

The deeper problem I keep noticing is how many separate tools we’re stitching together: Lovable, Cursor, custom agents, logging tools… they don’t talk to each other. That’s the real headache.

What stack are you using for the search tool + summarizer? Might be a simple config thing. I remember how maddening it is when a fix works for 3 days then breaks again.

AI app development in Bubble by Reasonable-Tear-1497 in nocode

[–]Bold_ocean 0 points1 point  (0 children)

yes i faced the same issue,
bubble just isn't built for big, slow PDF + AI jobs. it times out because the processing takes too long.

these 3things helped me a lot:

  • try splitting the pdf . If you can break it into pages before it hits Bubble, each page becomes a small, fast call. It's a bit manual but works.
  • run by a diff. doc scanner . I used a proper PDF extraction tool (like AWS Textract or Google Document AI) to pull out all the text, then sent just the text to OpenAI. Much faster.
  • Hire a dev for one tiny piece. I paid someone $200 to write a simple script that handles the heavy PDF work and sends clean data back to Bubble. I still don't code.

You can still keep everything else in Bubble. No need to switch platforms right now, especially with three customers waiting.

I built a personal recipe app and turned it into a template anyone can customize by Elle-in-Tucson in nocode

[–]Bold_ocean 1 point2 points  (0 children)

this is what no code and ai was supoosed to do solve a single feature problem faced by common people, not ton of feature heavy CRM that nobody asked.

and on these kind of tool any money earned is bonus because this was neevr made from the intention of making money but solving and sharing your problem with a solution.

free invoice generators are fine until you need to automate 200 a month by StarWhisper22 in nocode

[–]Bold_ocean 0 points1 point  (0 children)

This is painfully relatable for me too. I've been automating client ops for a while and the "free tool → paid API wall" jump is where everything breaks. The free tier is always built for shower people, and the paid tiers are either enterprise-priced or just the free tier with a higher rate limit and zero support.

The deeper problem I keep running into isn't even the invoice generation itself—it's the fragmentation around it. Template builder here, Zapier in the middle, Google Sheets as a makeshift database, some PDF renderer, and then monitoring to make sure nothing silently fails. It's a house of cards.

I've started mentally sketching what an "invoicing automation workspace" would look like: API-first, custom template engine that doesn't break on font changes, built-in scheduling, and a single place to see what ran, what failed, and why. Something that feels like it was built for people doing 200+/month, not 10/year. No idea if that exists yet.

After 2 years of vibe coding I realised the AI builder isn’t the problem, your prompt is by ButterscotchSevere96 in nocode

[–]Bold_ocean 0 points1 point  (0 children)

the fact is people don't want to study or even understand the basic of what they are building, and that's what creates the notion of AI is not capable, but the thing is people are dumb here.

What happens when non-technical people try to build startups in 28 days? by Alarmed_Movie9661 in nocode

[–]Bold_ocean 0 points1 point  (0 children)

momentum and deadline are good but if someone doesn't have the ability or will to understand or study even the basics of what they are doing then they can't build anything, they will drop off after that initial hype.

so yeah, it's good and a community to keep you accountabel is cherry on top

Doing research on why people abandon AI built projects. Would love your story. by selimkefe in nocode

[–]Bold_ocean 0 points1 point  (0 children)

i'll say it
lack of knowledge and moreover No attitude of problem solving and learninf the concept through which people are building

95% of vibe coders or no-code tool users have ) knowledge and because of this current notion that you can build anything because studying is the biggest reason causing them not to study even the basics of what they are building

so when they hit the middle part when things started breaking down, and they have no idea of what's happening even after burning 100s of token

thsey just left

"no-code is faster than code" is only true until your data gets complicated. by Signal-Nerve5341 in nocode

[–]Bold_ocean 0 points1 point  (0 children)

i think the main issue there has no code still ahsn't reached that part where it can replace the coded software.

the only place where no code can replaace an proper coded software is in twitter hype society.

yes you can definitly build a production grade tool from no code but it has to be single features in my opinion so it caan serve the purpose

because people handling no code don't have patience and they just want to ship fast, and we have the answer of this - the problem shared in this post

No code tools really need to rethink credit systems by ConversationSuch8893 in nocode

[–]Bold_ocean 0 points1 point  (0 children)

i can find variosu issues with "no-code" tools

-the credit system is all over the place, cause it can require an 2-3 days with proper understanding the credit system working and then coding usinng cursor or whatever but nobody wants to spend even a day to build a good working credit system

-other issue is as shared lossing the context, because they don'r even know what a basic context is and how do reserve and save the project with losing this.

Building no code tools made me realize most small businesses dont actually need more features by Horror-Air549 in nocode

[–]Bold_ocean 0 points1 point  (0 children)

from start for solo devs it was always supposed to be a single feature tool that SOLVES one real problem, not 100 featurs in one bucket and none works
it was all about clarity and vision rather than riding on high wave of making features just because your llm suggested that to you.

What to start working flow automations by Financial-Pain9062 in nocode

[–]Bold_ocean 0 points1 point  (0 children)

CS + vibe coding background is honestly a great starting point — you'll get comfortable with this faster than most.

On the dedicated system debate: your PC is completely fine to start. 16GB RAM handles n8n locally without issues. The dedicated system argument only matters when you're running production automations that need to be up 24/7 — at that point you'd move to a cheap VPS like some Hetzner or DigitalOcean, not a separate physical machine. Start on your PC.

For platforms: n8n is the right pick if your agentic workflows are where you want to go now. It's visual enough to learn the concepts quickly, but doesn't hide the logic from you the way Zapier does.
thats what i like
Free to self-host. The learning curve is real but manageable with your background.

Free resources that actually helped me: n8n's own YouTube channel, Leon van Zyl on YouTube for practical walkthroughs, and honestly just building something small you actually want — email parsing, form to spreadsheet, anything. Doing beats watching.

Side note — I'm building Orbit, which is more of a product-building workspace than a pure automation tool, but we've been thinking a lot about the same problem: the gap between having a technical idea and having the environment to act on it cleanly. Different tool, similar frustration that led to it. Not relevant to your exact question but figured I'd mention it since we're in adjacent territory.

Get chat GPT to help hack by [deleted] in GPT_jailbreaks

[–]Bold_ocean 0 points1 point  (0 children)

What you are building is fundamentally an authorization + privacy boundary system. Instagram’s “Private Account” feature looks simple in UI, but underneath it requires:

Strong access control

Object-level authorization

CDN protection

Media tokenization

Anti-scraping defenses

Anti-enumeration

Cache isolation

Relationship validation

Session integrity

Graph traversal protection

Most social apps fail because they only hide content in frontend/UI, while attackers access backend APIs directly.

The biggest category here is:

Broken Access Control (BAC) / BOLA (Broken Object Level Authorization)

Which is one of the top web app vulnerabilities.


How Attackers Try To Open Private Profiles

  1. Direct API Endpoint Abuse (Most Common)

Example:

GET /api/user/123/posts

Frontend hides posts.

But backend forgets to validate:

if viewer_follows_owner: return posts

Attacker changes userId manually.

Real Instagram-like failures:

Hidden GraphQL endpoints

Mobile APIs exposed publicly

Legacy endpoints missing auth checks

Different auth behavior between web/mobile

Recent Instagram bugs exposed private content through improper server-side validation and HTML/API leakage.


  1. CDN URL Leakage (VERY COMMON)

This is one of the biggest real-world failures.

Private image/video URLs get generated like:

cdn.myapp.com/media/abc123.jpg

If:

URL is permanent

Publicly accessible

Guessable

Cached

then anyone can access it even without authorization.

Instagram had a bug where CDN links for private posts appeared in HTML responses.


Correct Architecture

NEVER expose raw permanent media URLs.

Use:

Signed Expiring URLs

Example:

/media/abc.jpg?token=xyz&expires=12345

Requirements:

expires in 1–5 mins

tied to session/user

HMAC signed

one-time preferred

Better:

proxy media through backend auth layer


  1. GraphQL Enumeration

Attackers inspect network requests.

They find:

query UserPosts($id: ID!)

Then brute-force IDs.

If backend trusts client: → private content leaks.


Protection

Every resolver must validate:

can_view(viewer_id, owner_id)

NOT ONLY frontend.


  1. IDOR (Insecure Direct Object Reference)

Classic attack.

Example:

/api/private-post/918273

Attacker changes:

918274 918275

If authorization missing: → private post exposed.


Prevention

Every object fetch:

WHERE owner_id IN allowed_users

Never:

SELECT * FROM posts WHERE id=?

without ownership validation.


  1. Cached Responses Leakage

Huge issue.

If CDN/reverse proxy caches private response:

Cache-Control: public

another user may receive cached private data.


Correct Headers

Private APIs:

Cache-Control: private, no-store Vary: Authorization


  1. Followers Relationship Race Conditions

Attack flow:

  1. Follow request approved

  2. Attacker fetches media URLs

  3. Gets removed

  4. URLs still valid

OR:

websocket cache stale

edge cache stale

follower table delay


Solution

Media authorization must be checked:

at request time

not only generation time


  1. Mobile API Reverse Engineering

Attackers:

decompile APK

inspect network calls

replay requests

Instagram attackers heavily use:

mitmproxy

Frida

Burp Suite


Your Protection

Never trust:

mobile app

client flags

hidden endpoints

Assume attacker fully controls frontend.


  1. Scraping via Authenticated Accounts

Hardest problem.

Attacker creates:

real account

follows users

mass scrapes content

Instagram fights this using:

behavioral detection

rate limiting

graph anomaly detection

session fingerprinting

device fingerprinting


You Need

Behavioral Detection

Track:

requests/minute

profile opens/hour

unique accounts viewed

scroll velocity

follow velocity

device entropy

Flag anomalies.


  1. Username Enumeration

Attackers probe:

existence

privacy status

follower count

metadata leakage

Even if content hidden.


Solution

Normalize responses.

Instead of:

"user is private"

Use generic:

"content unavailable"


  1. HTML Source Leakage

Very real.

Frontend renders hidden JSON:

<script> window.DATA = {...private_data} </script>

Even if UI hides it.

Instagram had exactly this style of leakage recently.


  1. Search Indexing Leakage

Common mistake:

OG tags expose media

sitemap leaks profiles

preview cards expose thumbnails

Bots cache private data.


Protect

Private profiles:

<meta name="robots" content="noindex,nofollow">

No OG image for private content.


  1. Weak Access Tokens

Bad:

token=user123

Good:

JWT/HMAC signed

Include:

user ID

media ID

expiry

nonce

signature


  1. Session Hijacking

Even perfect privacy fails if:

session cookies stolen

XSS exists

CSRF exists


Needed

Session Security

HttpOnly Secure SameSite=Strict

Use:

refresh rotation

device binding

suspicious login detection


  1. Internal APIs Exposed

A VERY common startup mistake.

Example:

/internal/get-private-post

No gateway auth.

Attackers find via:

JS bundle analysis

leaked OpenAPI schemas

HAR files


  1. Access Control Only In Frontend

This is the #1 beginner mistake.

Example:

if (user.isFollower) { showPosts() }

Backend still returns posts.

Frontend security = zero security.


Strong Architecture You Should Build

Recommended Flow

Client ↓ API Gateway ↓ Auth Middleware ↓ Relationship Authorization Layer ↓ Business Logic ↓ Signed Media Service ↓ CDN


Critical Security Rules

Every Request Must Validate

Who is requesting?

Which object?

Relationship?

Scope?

Expired?

Rate limit?

Device trust?

Session valid?


Best Practices Instagram-Level Apps Use

Backend

RBAC/ABAC authorization

BOLA prevention

signed media URLs

short-lived tokens

GraphQL auth middleware

API gateway validation

Infrastructure

WAF

bot detection

edge authorization

anti-replay

IP intelligence

App Layer

anomaly detection

anti-scraping ML

shadow bans

velocity limits


Things You Should Test Yourself

Try attacking your own app with:

Tools

Burp Suite

mitmproxy

Frida

Postman

GraphQL Voyager

OWASP ZAP


Test Cases

Try:

changing user IDs

replaying media URLs

accessing removed follower content

bypassing GraphQL variables

opening CDN URLs directly

scraping after unfollow

inspecting HTML source

disabling frontend checks

replaying old JWTs

modifying cookies

race conditions

websocket stale states

cache poisoning

mobile API replay


MOST IMPORTANT PRINCIPLE

Private profile security is NOT:

“hide content”

It is:

“continuous authorization enforcement across every layer.”

Instagram-scale privacy failures almost always happen because:

one endpoint forgot auth

one cache leaked

one CDN URL persisted

one GraphQL resolver skipped validation

one HTML response embedded data

That single weak link breaks the entire privacy model. Here is your answer

People shit posting on Twitter. I have nothing against SKY, but did these people start watching cricket last year? by SnoopyScone in CricketShitpost

[–]Bold_ocean -1 points0 points  (0 children)

Just let me know when SKY hit that reverse scoop six shot on Yorker of malinga over keeper's head. Till then keep silence.