Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Admirable, but neither of these are light lifts. Most startups are potentially better off just gambling they won't be in the %0.1 that get shut down due to big company shenanigans.


Any company that doesn't take steps that basically amount to insurance - and insurance is "just in case shit happens" - deserves the pain when the unthinkable happens.

With backups - onsite, offsite, security, code reviews, pen testing, separate environments for testing, etc... all things that take time and aren't "light lifts".

If you skip and don't cover your bases? You're going to fall and you'll deserve the broken leg - or worse - when it happens.


This is a terrible attitude to have, some startups are cobbled together by 1 or 2 people and get off the ground, yet you are expecting them to have a team of at least 12 and additional retainer resource of lawyers and similar otherwise "they deserve to fail"?

In the real world, many businesses aren't created in the Silicon Valley by established founders and friends with VC funds, who can afford the time and cost to have all this.

Edit: To clarify, I am not saying that the things suggested are unimportant or not vital to an established business.. But that the bottom line for a brand new business with very few people involved is to survive and be stable enough to have the change of introduce backing on/off site, distaster recovery plans, paying for pen testing, security consultants, dedicated QA, etc.


Whether you're 1 person or 10,000... if you skimp? you're going to get bit where your weakest.

I didn't say "they deserve to fail"... I said karma will happen. Deserve or not? If you don't have "insurance" then you'll pay eventually.

If you don't have backups? Good luck when the Cyrpo Locker hits. if you don't have redundant hard drives? Good luck when the click of doom hits you.

If you only have one payment processor who is known to randomly lock accounts without recourse? Then it's a matter of time until it happens to you.

I do get that shortcuts have to be made when starting... but those short cuts don't sidestep reality.


Do not take this advice.


Why? Can’t you have a dormant or lightly used gumroad account integrated into your site/app. It’s not trivial, but could be worth it. Most frameworks have these services already integrated.


How would Gumroad prevent this? Hell Gumroad has an entire FAQ devoted to account suspensions so it's clearly an issue for them too.


An alternate processor while stripe figures out the mess - revenue keeps coming in.

Gumroad has their own failures, but if ANY issue with payment processing is intolerable, don’t bother running a business.


In this case, it’s likely that they have set up recurring SEPA debit payments. Changing the payment provider won’t keep the revenue coming in - it would require every customer to sign up for debit again. And when stripe figures out the mess, you need to consolidate the two providers or you’ll end up debiting twice.


I wonder of a health club is preventing account cancelation, playing games, and end users are doing chargebacks.


Isn’t Gumroad runs on top of Stripe itself?


Looks like that might be the case. I might have been confusing Gumroad with Braintree. I was only attempting to give an example, not advocating for one specific processor.


A dormant account that suddenly gets a large influx of new users sounds like a great way to get auto-banned by some stupid automated process as well, just when you most need them to work :-}




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: