A Product Journey

May 243:30 pm – 4:10 pmStage: Main StageFireside

Checking session availability…

Hang tight while we load the latest updates.

Creating multiple startups, getting acquired, working in large corporates and back to the startup world, Feross has done it all. In this fireside we will discuss Feross' career from a product development perspective including:
1. StudyNotes - getting started in high school
2. PeerCDN and the Yahoo acquisition
3. Moving into the Open Source world
5. Socket and the VC approach

A Product Journey

Feross Aboukhadijeh at UXDX USA. Video: https://www.youtube.com/watch?v=ajvS9oKztpE

Readable transcript: edited from the recording's captions for readability (fillers and false starts removed, punctuation and section headings added). Wording is the speaker's own. Timestamps are positions in the video. Names marked [?] could not be verified against the audio.

Going viral in college with YouTube Instant

[00:00:01] Host: This is going to be just a bit of an exploration, because we've just been chatting outside and it's kind of fascinating, the history of your experiences in products, but coming at it from more of a dev side. I'm not sure if the people out there know Feross, but you will over the next 30 minutes or so, learning a bit about his life story. So we're going to start actually when you were back in school and you went viral. Can you just tell me a bit about that?

[00:00:29] Feross: Yeah, sure. It's kind of the first time I realized the power of the internet, really, so it's a kind of cool experience to have had in college. Basically what happened was there was this product announcement from Google. This was back in like 2010. They called it Google Instant, and the idea was, when you are doing your searches on Google, instead of just getting the little autocomplete box that comes down, what if instead you could get the actual search results page, so as you type each letter the search results show up?

[00:01:04] Feross: They hyped this announcement really big, made a really big deal out of it, but it apparently took two years of engineering work for them to improve their backend servers to handle all the additional queries, and they announced it with a lot of fanfare. I saw it and I thought, this is cool, but what if you could do it for videos? So as you type each letter, the top video suggestion comes up. You type J and maybe a Justin Bieber video or something comes up and starts playing, and then you type the next letter and get another video.

[00:01:33] Feross: So I bet my friend I could build that in an hour, and obviously, cocky college student, it took me three hours to get something kind of working. I posted the link and went to sleep. The next day I wake up, I have like 20 missed calls on my phone, and I have emails from NBC and these media outlets that want to talk to me. And apparently what happened was, during the night the YouTube CEO saw the link, somehow it started going viral on Twitter, and then he offered me a job on Twitter while I was asleep.

[00:02:06] Feross: And so then I found myself in this weird situation where the media started writing about, like, this is the future of the resume, this is how people are going to get jobs in the future. And it became part of this media storm, and everyone loved the story of the bet. So I had this wild experience of building something in a few hours and seeing the internet think it's really cool, and especially because it took such a short time, and Google said everything took two years. They didn't understand it was just a hundred lines of JavaScript, it was just calling the YouTube API. I didn't do any work, really.

[00:02:42] Host: Excellent. But you mentioned it wasn't all rosy. Hacker News is kind of infamous for not being kind. So what happened there, and what were people saying?

[00:02:56] Feross: So actually in this instance they were pretty kind. One thing that did happen was a commenter showed up and said, hey, I've actually been building kind of a similar concept and I've been working on it for a few months, and in fact my concept for this has a lot more features, it has filtering options and a whole bunch of preferences you can set in the product. They seemed a little disappointed that their product didn't get the same attention that this couple-hour product that I built got.

[00:03:25] Feross: And so I kind of read the thread there, and one of the commenters replied to that person and said, well, this is the power of shipping. He shipped and you didn't. It's kind of a harsh thing to say, but it's true. I mean, I put it out there, I posted the link, and even though it was a much worse product than this other person's thing, it was out there first. I think that taught me that there's a big difference between the thing being finished and being out there, and being in this kind of indeterminate state where you're just tinkering on it for a long time and you never get it over the finish line and put it out there. That's when all the benefits can come from building something.

[00:04:06] Host: Yeah, I think that's a brilliant illustration of, everybody always wants to wait until it's finished, you always want to add the extra feature or add the extra thing. So it shows you can get benefits of going ahead. You did mention though that while you got this offer from YouTube, where were you working at the time?

[00:04:25] Feross: So I was a sophomore in college and I had a pretty cool internship at Facebook at the time. This was back in 2010, so it was like year five of Facebook, so it was a pretty exciting time to be there.

[00:04:39] Host: I saw a chuckle. What was that?

The Facebook Groups internship, and getting in trouble

[00:04:43] Feross: Yeah, so I got put onto the Facebook Groups team, and at the time I remember thinking, oh, that's a bummer, I don't want to be on this team, because at the time Groups was this pretty silly product where basically people would join groups in order to get a little message to show up on their profile. A lot of the groups were things like, I step on crunchy looking leaves when I see them on the sidewalk. They joined that group just so you could see that. Or they would join, can this pickle get more fans than Justin Bieber? Just these kinds of joke things. So no one was using them for actual communication.

[00:05:21] Feross: I got put on that team and I'm like, oh, this is going to be a bummer. But it turned out that that summer the priority of the company was to make a new version of Groups that people would use to actually talk to each other. It was a team of like five people: a designer, an engineering manager, a PM, and then two or three full-time engineers and two interns, and I was one of the interns. It was actually one of the best experiences, probably the best job I've ever had, and it was an internship.

[00:05:50] Feross: Because it was the priority, the CEO, Mark Zuckerberg, would come into our little office like every day and talk to us, and we'd talk about the product all the time, and I felt like even as an intern I was this member of the team and got to contribute ideas. It was pretty awesome.

[00:06:08] Feross: But I got in a little trouble with the YouTube thing, because I was kind of starstruck by this job offer from Chad Hurley, the YouTube CEO at the time. I said, oh yeah, I'll join, because that's awesome, I can just leave school, it'll be great. And then my manager's manager at Facebook called me into the room and was like, you can't talk to the media, we have this hiring war with Google and you can't be doing this, you're going to lose us the people, they're going to choose to work there, and even though you're an intern you can't be doing this. So I had a bit of a lesson about, when you talk to the media you've got to be a little careful about what's happening.

[00:06:50] Host: Excellent. So you didn't drop out of school though, you ended up changing your mind?

[00:06:56] Feross: Yeah, I said yes and I said no a few days later, and decided that I should probably finish my classes and the job would still be waiting there if I wanted it later.

PeerCDN: building without talking to customers

[00:07:04] Host: And after college, though, you went down the entrepreneurial kind of route and started up. So can you talk about your first company?

[00:07:13] Feross: So after finishing school, I guess the thing that always interests me is looking at how you can combine things in kind of non-obvious ways. I was looking through the list of new features coming to the web platform, so what new APIs are browsers getting in the next few years, and I was trying to look through that to get ideas for what types of apps would you be able to build with these APIs, and what new product experiences would those APIs enable.

[00:07:46] Feross: And I kind of stumbled upon the WebRTC API. For those who don't know, WebRTC is the API that lets you do real-time communications, so you can do video chat, voice chat, and also just generally you can do peer-to-peer browser communications directly between people's browsers.

[00:08:05] Feross: So I had this idea that, what if you could build a content delivery network, so a CDN, but instead of it being based off of hundreds of servers at all these different points of presence all across the world and being very expensive to build, what if we just turned everyone's browser into a point of presence, or into a CDN? So if I watch a YouTube video and my computer's already downloaded that video, why don't I serve that video to the next visitor who's coming along, especially if they're in my city, they're geographically near me, or maybe they're even on my same network at school or at home? It would be a lot faster than getting it, and cheaper than getting it, from the CDN data center. That was the idea.

[00:08:47] Host: So you have the idea, and it sounds good. So how did you approach it from, I guess, a product perspective? What was your angle? Did you go down the customer validation route? What did you do?

[00:08:58] Feross: We didn't know what we were doing. I didn't know anything about how to run a company or how to do anything, just fresh out of college, just going for it and hoping for the best. So we just started building it, dove right into the technology part of it, didn't really do any of the customer conversations or the necessary groundwork to determine if this is actually something that people would want.

[00:09:26] Feross: We spent a bunch of time just building it, and I remember thinking at the time, of the two of us, because there were two of us at the time building it, if anyone's going to talk to customers and validate this idea, or do some sales, or make sure we're building the right thing, it should be me probably, because I was a little bit more the outgoing one. But I didn't want to do it. Every morning I woke up I was just like, I could code and close GitHub issues, or I can go talk to customers and get rejected and have all these awkward conversations. And I just chose to code every day for like the entire year that we were building it. And then, obviously, that didn't go very well.

[00:10:06] Host: So we had a conversation earlier in one of the forums about the role of the product manager, and somebody was saying, what do you do with the developers who just don't want to talk to the customers, they just want to code back-end stuff? So that was awesome. And so, how did it go? Did you get customers though? What happened with that company?

[00:10:26] Feross: So we made a video kind of announcing the product and how it worked, and that was basically just me doing a screencast of how it worked. Posted it to Hacker News, people, developers thought it was a neat idea, so we had, I think, a thousand people put it on their blogs and on their personal sites just to try it out. The thing is that those weren't really the real use cases for it. We needed high traffic, we needed like YouTube or somebody to sign up. And so we just kind of didn't get any paying customers from it.

[00:10:58] Host: Just out of, I know it's probably delving a little bit into the too technical, but in university we were researching peer-to-peer phone networks, and mathematically they said in high congestion areas it can't work because every node gets overwhelmed. Did you have that problem, or you never got enough traffic to validate it?

[00:11:17] Feross: We never really got enough traffic to validate, yeah. And also it worked only in Chrome and Firefox at the time, so it was, I think at the time, less than half, or around half, the browsers. And Chrome and Firefox couldn't talk to each other either, because this was really early days of WebRTC. So yeah, the whole thing was a little too early.

Getting acquired by Yahoo

[00:11:37] Host: So with that and with the current climate, you ended up getting acquired. You didn't have customers, you really had a product. So how did you get acquired?

[00:11:45] Feross: So the timing, it's just luck, honestly. Yahoo at the time had a new CEO, Marissa Mayer. She joined Yahoo to try and help turn it around, and her plan was to try to inject new energy and startup energy into the company, and so she decided to go on this acquisition spree, basically, during that time. We were lucky enough to be one of the, I think she was acquiring a company every week during the first year that she joined. And so we were just three people at the time.

[00:12:20] Host: And it was more that this aligned with the strategy that Yahoo were doing?

[00:12:24] Feross: Yeah, video was one of their big things they wanted to focus on. Which is really unfortunate, by the way, because they had this thing called Yahoo Video before, and the previous CEO actually decided to axe it, and it was the number two video site on the internet after YouTube. They decided that it was user generated content, so how could you ever make a business out of that? So they shut it down, deleted all the content, and then they were like, oh, we need to do video, let's build a new video site. And it's like, anyway.

[00:12:50] Feross: So we were basically interesting to them because we had done a lot of the JavaScript video player stuff with PeerCDN, and they were like, oh, these folks will be able to help us make a really fast video player and modernize it so that it works better on mobile, and that kind of thing. At the time their mobile player took like 19 seconds to just show the play button on 3G. So it needed to be basically rewritten with mobile assumptions in mind, and that was kind of what we were hired to do, basically.

[00:13:27] Host: So you mentioned Facebook was the best job you've ever had, so I'm assuming then this doesn't count as the best one. So how did your time at Yahoo go?

[00:13:37] Feross: So there's actually a lot of talented people at Yahoo, a lot of good people. But I think what happened was some of the benefit of the startup energy that they were trying to get by bringing in these startups got diluted, because the team that we joined was like 20 or 30 people already and we were three people. So we had all these ideas of how to change things and we kept running into kind of organizational resistance.

[00:14:10] Feross: As an example, we wanted to use a new JavaScript tool to build our video player, and the reason why we wanted to use it was because it would let us build a really lightweight player, but they were insisting on using their Yahoo proprietary thing. So there's just this kind of, if you actually want to accomplish the goal of making this player fast, we need to actually change the tooling, that's kind of one of the requirements. And then you run into, basically, we got subsumed by their culture rather than being able to change it as much as we were hoping to, I think.

[00:14:46] Feross: And also we were young, and I'd probably, I don't know, I wish I'd had a little bit of, maybe there's a reason they're doing things the way they're doing them, and who am I to try to change things too much?

The two-button video player

[00:14:59] Feross: There was a lot of interesting product things I observed while there. One really great story was, the video player at the time, right before we joined, had too many buttons on it, it was really complicated, it was very confusing to use. And the kind of mandate that came from Marissa was, let's simplify it. They told the PMs basically, you can put two buttons on the player, that's it. Two buttons. Don't show me anything that has more than two buttons, because it's too confusing and too complicated.

[00:15:36] Feross: So they took that directive and went to the drawing board and they're like, okay, what two buttons can we put on the player? So obviously you need a play button, right in the middle. And then they're like, let's have another button with everything in it, so you hit that button and then it opens up everything and then you get all the buttons under that menu.

[00:15:54] Host: Was there a different product manager for each of the buttons insisting that they got in there?

[00:16:00] Feross: I think there were definitely people fighting to have their button outside, so that people would actually find it. But I think they took that a little too literally, because that's actually the player that they shipped, it was literally two buttons. I remember, I wasn't a PM, I was an engineer, but I care a lot about the product side of things, so I was hassling the PM and saying, can we put the full screen button at least on the outside? Because I know, just without any data, I just know that that's the button that a lot of people are looking to find, especially when it's embedded in a little article and it's a little tiny player. That's the only button you want, is to just make it so you can actually see the video.

[00:16:41] Feross: Finally they instrumented it, and then they found that the full screen button was only being clicked on like one percent of the time, and so they're like, oh, it's fine that it's in there. But I was like, no, it's because it's in there that it's only being clicked on one percent of the time. If you move it to the outside it'll get clicked on more and people won't be frustrated. And it was totally just intuition, I didn't have any data. But then we finally did an A/B test and moved it to the outside and then it got clicked on 14% of the time, and then I was like, yes, obviously.

[00:17:08] Host: And did you cycle through every button?

[00:17:12] Feross: Just the full screen, yeah.

[00:17:14] Host: Cool. So you built your company. What was the time frame from when you set up the company to getting acquired?

[00:17:22] Feross: It was, I think, like eight months from beginning to end. Yeah, it was pretty fast.

[00:17:26] Host: And did you have a functioning product at that point? Were you able to bring your code into Yahoo, or were they saying basically no, you just have to use our tooling?

[00:17:37] Feross: Yeah, at first I thought they were going to use the technology, but then it kind of turned out that they had bigger product problems that they needed to fix first. I mean, our tech would have potentially made the videos faster and reduced CDN costs and stuff like that, but that wasn't even the first problem they were trying to solve. They had a ton of more important problems, such as getting people to even care and visit the site in the first place. So they would have been wrong to focus any engineering effort on an aspect like that.

[00:18:05] Host: Yeah, so it didn't really go anywhere. So how long did you spend at Yahoo then, kind of working on the video?

A hackathon, pop-up video, and leaving Yahoo

[00:18:12] Feross: So I spent a year total. The first six months was basically working on the video player, and then towards the end I was trying to get more into the product side of things, actually. There was a hackathon they did, kind of a company-wide hackathon, and I had an idea for a product and I kind of built it at the hackathon and then presented it to the company.

[00:18:35] Feross: So Yahoo had just acquired the rights to all the Vevo videos, the Vevo music video content. So they were one of two sites on the internet that was allowed to show Vevo content in their own video player. It was YouTube, and then Yahoo had the rights. And they were planning to just kind of put them into a section on their new video site, so there's like a tab for music videos. I remember thinking, well, that is no different than YouTube, and everyone already knows about YouTube, so what's the actual draw here that's going to differentiate it from YouTube?

[00:19:08] Feross: So I had an idea for a kind of music video based music player. So whenever you play a song it plays the video kind of in the background, and when it's full screen it takes up your whole browser and the UI is kind of on top of the video and hovering over it with transparency, so you can see the video behind it, and you can dismiss the UI and see the video if you want to full screen it.

[00:19:35] Feross: And then the other highlight feature of it was, I don't know who here has seen VH1 Pop-Up Video. Does anyone remember that? Yeah, okay. So this is a thing where while you're watching the music video on VH1, they would put these little pop-ups, little factoids that would show up and kind of annotate the song and tell you inside facts about how the music video was made, or mistakes that were made during filming, or just the kind of things that the true diehard fans wanted to know about. So I found a song facts database and then integrated that in and came up with this cool thing and demoed it at the hackathon, and it won the popular vote. So I tried to kind of turn that into a product, but it wasn't too successful getting it out the door while I was there.

[00:20:25] Host: Okay. So after six months of that, I guess you decided that was enough. What was next, or why, I guess?

[00:20:34] Feross: I basically got frustrated with the process of getting a product out the door there, all the reviews, all the different things. I was just fired up and ready to go and didn't understand the process and didn't want to learn the process, and was just too young I think, or too immature, I don't know. Couldn't figure it out. And so yeah, it kind of died before being released, and then that frustration led me to just be like, all right, I'm done working at companies, I just want to go off on my own and do projects that are fun and that I think should exist.

[00:21:12] Host: So back to the PeerCDN kind of approach?

WebTorrent and becoming an open source maintainer

[00:21:14] Feross: Yeah, so I left, and basically what I did was I took the PeerCDN concept and I made an open source project, so that I could, I wanted that idea to see the light of day. So it turned into this thing called WebTorrent, which is basically BitTorrent in your browser, so you can watch videos and do basically a peer-to-peer network meetup of all the browser users.

[00:21:38] Host: And why did you decide to open source it? Why not do another PeerCDN type of thing and turn this into a product?

[00:21:47] Feross: So I guess open source is a product, but a commercial product. I think I just thought it would be more successful as an open source project. Certain things are better executed as open source. For example, most companies and organizations wouldn't want to use a programming language that wasn't open source, if you think about it. There's been no successful commercial programming languages. And there's other examples of this too, like text editors, although maybe that's a bad example because there's some. But with a torrent, or with a peer-to-peer network, it just felt like maybe this should just be a community thing and it would be more successful than doing it as a company. It just felt right to do it that way.

[00:22:31] Host: And did you kind of meet, there's quite a passionate open source community around the Dat project, the Beaker Browser, WebTorrent, all these kinds of things. So was that part of the appeal as well, that kind of philosophy of the code being free?

[00:22:45] Feross: Yeah, I just always thought it would be fun to become part of the open source world and to be one of those magicians that makes the libraries that power all of our software. It always seemed like something that you couldn't do. I always used people's open source libraries but I never thought I could be the person making the libraries, and I always thought that would be something that would be fun to try one day. And yeah, that was the opportunity that I took to do that.

[00:23:20] Host: And you got hooked.

[00:23:22] Feross: Yeah, I got hooked, yeah.

[00:23:23] Host: So were you working at this time, or were you just kind of full time coding on these open source projects?

[00:23:30] Feross: Full-time coding on the open source projects, yeah. I just lived frugally, I had a little bit of savings from having worked at Yahoo. And then I did this thing where I would basically go around, be like, I want to go to Europe, okay, what conferences are there? And then I would go and talk about WebTorrent or whatever open source project at the conference. There was a little community of JavaScript people who were building these libraries at the time. It turns out, if you don't have a job then whenever some conference asks you to come, you always have a completely open calendar, so you can just say yes, and you can have this cool time just going around and finding where you're going to be. So I did that for like a year or two and met a lot of cool people and just became kind of really ingrained in the open source world.

standard: the linter I named as a joke

[00:24:22] Host: And so WebTorrent was one of your big projects. What are some of the other ones?

[00:24:29] Feross: So while building WebTorrent, one of the most annoying aspects as an open source maintainer was getting pull requests from contributors who were well-meaning and trying to help, but they didn't follow the code style standards for the project. They would just come in, and I have a very controversial coding style where I don't put semicolons at the end of my lines in JavaScript. Yeah, it's bold. So basically people would come in and they'd use semicolons, and that was obviously unacceptable, we can't accept that code. They're optional in JavaScript, you should remove your semicolons, delete them all. No, but seriously.

[00:25:10] Feross: But it's important for people to, the code should look like it's written by one person even though it's written by many people. That's the standard of, when you're reading a code base it should appear as if a single mind authored it. If that's the goal, that's the kind of standard, I think. And so anyway, there's linting tools out there for this, so I made a linter configuration and added it to the project, and then that helped a lot because then people could test their code before submitting it.

[00:25:40] Feross: But one problem was that WebTorrent was actually split up into a bunch of separate open source packages, as one does in JavaScript land. There's often thousands of these dependencies, and so anyway we had like a few dozen, and I didn't want to duplicate that configuration across every project. So I wrapped it up into its own package called standard, and made every WebTorrent dependency use standard.

[00:26:05] Feross: And I called it standard as a joke, actually, because it was like my personal coding style, but I was like, what's the most hilarious name I could give this that would be amusing to me, to watch people's reactions? And so I was like, I'll call it JavaScript Standard Style, because it's my style guide, right? So I named it that as a joke. And then people liked it.

[00:26:36] Feross: Here's what ended up happening. I made it so that I wouldn't have to duplicate this configuration, but what ended up happening was, everybody on every team out there has to deal with this process of agreeing on a style for the company to use. If you look at, ESLint is a tool that probably people have heard of, there's like 200 or 300 options you can configure, and what teams had been doing was debating every single point, like what should our style be, and having these protracted discussions.

[00:27:05] Feross: So what ended up happening with the tool was, because I called it standard, and because all the decisions were made and they were mostly reasonable, with the exception of the semicolon rule which a lot of people don't like, people were like, oh, we should just use this, it'll end the debate on our team. And so accidentally, again, I kind of made a thing that people thought was handy, and so people started using standard to end the debate.

[00:27:26] Feross: And the other thing they loved about it was there was no way to configure it, so you either use it or you don't. Once you use it, then there's no developer coming in and sneaking in a change to the configuration while they send in their own pull request, because they don't like that rule so they sneak it in, and then there's these fights where different developers are changing the rules. It was like, that's it, take it or leave it.

[00:27:53] Host: And are you seeing fewer semicolons now since releasing this package?

[00:27:57] Feross: What do you mean, at the end of the line?

[00:28:00] Host: No, no. Yeah. Okay, so how long did this kind of period stretch, that you were just working full time on these open source projects? Is that from like 2015 until 2018 or 2019 kind of time frame? And you were able to self-sustain?

[00:28:19] Feross: Yeah, so I had a couple of websites that I made, just a few websites I made that I threw Google ads on to, that were making me a little bit of money here and there. But yeah, I basically lived really frugally during that time. It's easy to do when you're single and you have low living standards, I don't know.

[00:28:41] Host: You're really setting the stereotype of the developer.

[00:28:44] Feross: No, it was fine. I was living in Mountain View and it wasn't that bad. I'm making it sound worse than it was.

Trying to monetize open source

[00:28:50] Host: But then, like a few years back, I can't remember the exact time, you tried a few experiments around trying to monetize open source. So do you want to chat through those? One of them received a bit more backlash than the others.

[00:29:04] Feross: Yeah. So when you start doing open source, this is a common thing I think a lot of open source maintainers experience, and I experienced it, which is when you start you're so excited. You put your first project out there and usually the initial reaction is no one cares, no one even knows about it. And so then when you get somebody who opens an issue, it's amazing, because you're like, oh my god, even though they found a bug or they're complaining, it's incredible that someone cares. You feel like, I made a thing that someone else is using. And then you start looking at who they are, what company they're at, and oh my gosh, it's so cool that my code is being used by this company. It's this excitement, this phase of excitement.

[00:29:45] Feross: So I felt that for the first few years. It was sort of like, more and more people were using the different libraries I was putting out, the enthusiasm was growing, the number of issues and pull requests were growing, and I felt like this is so cool. And then at some point it reaches a tipping point. For me it reached this tipping point I think around like 2017, where the number of issues that are getting opened is more than you can actually close, more than you can actually keep up with.

[00:30:12] Feross: And so what I ended up feeling like was that this was a to-do list that was globally writable. Anyone can add items to my to-do list by opening an issue on GitHub and saying that this thing doesn't have a feature it should have, or it has a bug, it doesn't work in this certain case. And I would wake up and I'd be like, oh, I guess I have 15 issues I've got to fix today, and I'd just work on it, and then did that again and again and again. And then at some point I realized I'm just working for free for all these companies. And then I look at sometimes where they worked and I'm like, hey, they're making a lot of money, and they're sending me these issues and I'm just sitting there unemployed, just building features for them. And then at some point I was like, maybe I shouldn't do this anymore.

[00:30:56] Feross: I mean, that's what you sign up for when you do open source. I thought it wouldn't be great, it would be great if there was some way to do this as a full-time job, if there was some way to actually make a living doing this. And I also thought it would be great if kids could say one day, when they grow up they want to be an open source maintainer. How could that be? Because the thing that's cool about open source is, when you solve a problem once, you solve it for the whole world. No one has to solve that problem again. You put it out there and it's like you're doing a service for the world, because it's like Wikipedia or something, you're writing an article, you're contributing to the commons. That's how I felt about it.

[00:31:30] Feross: And so I wanted to find a way to do it, but in a way that I didn't feel like I was being taken advantage of, or just overwhelmed by all these inbound requests. So I started thinking, okay, if I could make money from this somehow, if I could do a Patreon, then it would change things for me. There were a few maintainers, I was one of them, and a few others who were experimenting with Patreon around this time. The perks we would provide would be like, I would send people stickers. It was very punk rock. If you pay ten dollars a month you get a little envelope of WebTorrent stickers or standard stickers that I'd send you, and I literally was hand addressing the envelopes and doing all that.

[00:32:09] Feross: It was great for a while, but then what I realized was most of the people paying are actually other developers or other open source maintainers, and who really should be paying is the companies that are using the software that they depend on. And it was so much work to get, ten dollars at a time, to build up a living doing that, that it just didn't scale. It didn't really scale. And it also felt weird because a lot of the people paying were other open source maintainers, and we'd do this thing where we'd support each other, like I would pay them ten dollars a month and they'd pay me ten dollars a month, and then Patreon would just take the ten percent fees from that transaction, and we were just bleeding money to Patreon. And it was like, what are we doing here?

[00:32:50] Feross: So then I realized that the next thing I wanted to try was going directly to companies and saying, you should support this because you use it at your company, first of all. And that wasn't that effective. But then I realized, well, you can actually treat this as a marketing expense. So put your logo on the readme, or put their logo on our website, and then treat that as a marketing expense to recruit developers. And that was actually more effective, because it turns out companies are willing to do that much more than they are willing to, it's hard to justify sending a donation to somebody as a business expense, it just doesn't work, but you can say, oh, it's a marketing expense, and then it works better. So that actually worked.

[00:33:37] Feross: And then I think they also need, you need to learn things like, you need to be able to send them an invoice and you need to be able to do this back and forth process.

[00:33:45] Host: And that's something a lot of maintainers I guess don't want to do, because they just find the idea, it just becomes a distraction as well from what you want to do.

[00:33:54] Feross: Yeah. So I did it for a while, but it was kind of a distraction. And then if you weren't actively getting more deals and trying to find new people to sponsor you, then it would slowly go down to an unlivable amount of money again.

Ads in the terminal

[00:34:09] Feross: But I think you asked about the thing I tried that went really badly.

[00:34:16] Host: Go on.

[00:34:17] Feross: Yeah, so one of the things I realized was that if you try to go to companies, it's a lot of work to convince them, and a lot of maintainers don't want to do that work, because it's not what they signed up for. They just want to code. It's a different skill set. The other problem is a lot of open source projects are behind the scenes, so they're not known by developers.

[00:34:49] Feross: I'll give you an example. A UI component library, so something like Material UI or Chakra UI or whatever people are familiar with, using these design frameworks, these design systems. Most designers and developers have them open in a tab all day long, so they know about this. You might even describe yourself as, I'm a React developer. So they associate with it and they know about it, and so those projects have actually a pretty easy time getting sponsorships, because they have this high profile. But if you're the thing that that library uses, or you're two or three levels deep, you're just some utility library, good luck getting anyone to sponsor that.

[00:35:27] Feross: So I wanted to try to solve that problem, and my idea was to, don't throw tomatoes at me, but it was to show ads in the terminal as you install the package. So basically you would run npm install whatever, and then during the install process a little banner would appear in ASCII, and it would tell you about, this package is brought to you by so-and-so.

[00:36:01] Feross: So I found a couple of companies that wanted to try this experiment out with me, and it was basically a console log. It was very inoffensive, there was no tracking, there was no analytics, they didn't even get numbers on how many people would see their ad. It was just going to put a console log in there. And people hated it. They hated it. Hacker News hated it. People said, this is the one space in my entire life that does not have advertising, can you please not make this a norm? And so they objected. And there's a lot of people who didn't even use the library I added it to, and they were just kind of coming in and trying to just destroy this concept so that it wouldn't take off.

[00:36:48] Feross: And so then what happened was actually really kind of funny. Customers of these two companies that agreed to work with me were contacting the companies and saying, the fact that you even thought this was an experiment worth running makes me want to cancel, so please cancel my service. And so then the CEO of one of the companies sent me this panic text message and it was like, take down the ad, please take down the ad, we're losing customers from this ad. I was like, okay, no problem. So I published a new version of it and I just kind of axed it. So yeah, it yielded negative ROI. Very, very, very bad.

The supply chain attack that led to Socket

[00:37:27] Host: But I guess, was that the spark that led to Socket now? I hope you've seen the talk about supply chain attacks, so updating npm packages and kind of more nefarious things, I guess, that some bad actors are putting into those packages. So was that kind of one of the seeds of the idea?

[00:37:46] Feross: Yeah, I mean, I realized that as a maintainer I have way too much power, actually, that I shouldn't have, in a way, because I could just decide one day to do this change and then everyone who's installing it is getting now ads in their terminal. And for the most part open source maintainers are good people trying to just contribute something good into the world, and they're doing their best, they're burdened with a lot of work and a lot of issues.

[00:38:13] Feross: I definitely really admire the work of all open source maintainers, but there is this sort of risk that comes from using open source that my funding experiment revealed, but also just other things I saw in the ecosystem at the time. There were examples of, a maintainer, a friend of mine, gave access to somebody who volunteered to help with the project that he hadn't been working on for about four years. And he gave access to this person, and for about a month they contributed good changes, but a month in they actually added a big blob of obfuscated code, kind of, you couldn't really tell what it did, it was just really gnarly, to the bottom of one of the files. And no one really noticed, because most people don't read the code, they don't open up the code.

[00:39:06] Feross: And so then a couple of days go by, I think five or six days go by, it gets bundled into a company's product, a bunch of companies' products actually. But the thing that was so nefarious about this code that was added was it actually didn't do anything unless it was running in one particular company's product. So it would look at the name of the project that it was within and it would only activate in that scenario. And it turned out they were targeting a bitcoin wallet project.

[00:39:38] Feross: So what it did is, it would only activate in the wallet, and then it would look at what the balance in the user's account was, and if it was over a million, 39 million dollars of bitcoin[?], then it would just send it all to the attacker. And the thing that's really nefarious about it is, the support people at this company are used to users probably having difficulties with their wallets and saying, oh, my balance is missing or whatever, and so because it only targeted these high roller accounts it was only a handful of people who had their funds stolen. And so it didn't even set off any alarm bells for the company that they got these support queries, because it was a handful, not that out of the norm really. So yeah, it went for quite a while without being caught.

[00:40:24] Feross: And it only got caught by a total accident too. That's the really scary part, is it wasn't like somebody was looking at the code and saw it. It happened as a total accident. They used a feature in Node.js that happened to be deprecated in the next version, and so just totally as an accident, somebody was running the new version of Node and saw this deprecation warning getting printed out, and they traced it back to this blob of code and said, hey, why is this here? And then eventually the mystery was solved. But if that feature hadn't been deprecated, like, who knows how many more weeks? Yeah, so it was really wild. And so yeah, that's kind of the thing that I saw firsthand.

[00:41:01] Host: Well, we're out of time actually, but I've really enjoyed the conversation. It's just been an incredible journey, from creating all the different companies, projects, going viral multiple times. So thank you for sharing it, and I hope you enjoyed it as well.

[00:41:15] Feross: Yeah, thank you. Thank you for having me.