Readit News logoReadit News
garyhtou commented on Show HN: HCB Mobile – financial app built by 17 y/o, processing $6M/month   hackclub.com/fiscal-spons... · Posted by u/mohamad08
cirrus3 · 2 months ago
What is this page of transactions for? https://hcb.hackclub.com/hq/transactions

I get that you want to be "open", but is everyone involved in these transactions ok with them being shared? Even if they are, this doesn't seem like a good idea security wise. I see partial account numbers and other IDs/numbers that I assume you'd prefer not be public, regardless of how insensitive they may seem now.

EXPENSIFY, INC. VALIDATION XXXXXX5987 THE HACK FOUNDATION +$0.89

FRONTING $10,000 TO CHRIS WALKER FOR GITHUB GRANTS MADE FROM PERSONAL ACCOUNT -$10,000.00

CHECK TO LACHLAN CAMPBELL +$800.00

Transfer to Emma's Earnings -$1,923.08

garyhtou · 2 months ago
Hi @cirrus3,

You've found an optional feature called Transparency Mode!

I admit, this is A LOT of information being made accessible. We at Hack Club (the nonprofit organization behind HCB, and the owner of the transactions above) have chosen to make our finances publicly available on the internet. You can read more about it here: https://blog.hcb.hackclub.com/posts/transparent-finances-opt...

That link (https://hcb.hackclub.com/hq/transactions) shows our donations and spending down to the cent since we believe donors deserve to know what their contributions are funding. As a nonprofit, you can talk about what you’re spending money on, but transparency in every transaction builds trust for supporters. This level of transparency is definitely atypical, and I can see why it may raise concerns.

Other organizations using HCB (such as Reboot) can choose to enable this feature too (it's off by default), and they're briefed on the potential risks and level of exposure to decide whether it's right for their organization/team. HCB supports 6.5k nonprofits, and roughly 64% of organizations have chosen to enable this feature.

> I see partial account numbers and other IDs/numbers that I assume you'd prefer not be public, regardless of how insensitive they may seem now.

> EXPENSIFY, INC. VALIDATION XXXXXX5987 THE HACK FOUNDATION +$0.89

Good catch! Thanks for flagging that verification deposit. I've pushed a fix here: https://github.com/hackclub/hcb/pull/12336

As for the account numbers (e.g. XXXXXX5987) visible in some transactions, these are our own defunct operating accounts, and we're aware they're out there on the internet. We have a new way of managing account numbers via Column.com, so these older transactions are less of a concern for me.

I very much appreciate you bringing these to my attention! We're always looking to improve, so I'd love to hear if you find anything else.

garyhtou commented on Ghostty is now non-profit   mitchellh.com/writing/gho... · Posted by u/vrnvu
neural_thing · 2 months ago
Donating in Chrome didn't work, only in Safari.

FullStory namespace conflict. Please set window["_fs_namespace"]. script.pageview-props.tagged-events.js:1 Failed to load resource: net::ERR_BLOCKED_BY_CLIENTUnderstand this error edge.fullstory.com/s/fs.js:1 Failed to load resource: net::ERR_BLOCKED_BY_CLIENTUnderstand this error ghostty:1 Access to XMLHttpRequest at 'https://d3hb14vkzrxvla.cloudfront.net/v1/e3d6bbe1-aa48-43cb-...' from origin 'https://hcb.hackclub.com' has been blocked by CORS policy: Request header field beacon-device-instance-id is not allowed by Access-Control-Allow-Headers in preflight response.Understand this error installHook.js:1 Unable to Load Beacon overrideMethod @ installHook.js:1Understand this error installHook.js:1 $ overrideMethod @ installHook.js:1Understand this error d3hb14vkzrxvla.cloudfront.net/v1/e3d6bbe1-aa48-43cb-8f8b-be1e33945bab:1 Failed to load resource: net::ERR_FAILEDUnderstand this error [Violation] Potential permissions policy violation: payment is not allowed in this document.Understand this error rs.fullstory.com/rec/page:1 Failed to load resource: net::ERR_BLOCKED_BY_CLIENTUnderstand this error 29[Intervention] Unable to preventDefault inside passive event listener due to target being treated as passive. See <URL>

garyhtou · 2 months ago
Hi there! Gary here from HCB (Hack Club's fiscal sponsorship program).

Sorry about that! I've just pushed a fix for one of those errors. Although I wasn't able to reproduce this donation behavior on Chrome, I will continue investigating.

I appreciate you reporting this!

garyhtou commented on Ghostty is now non-profit   mitchellh.com/writing/gho... · Posted by u/vrnvu
simonw · 2 months ago
I wasn't aware of Hack Club before and wow, their fiscal sponsorship program is enormous: https://hackclub.com/fiscal-sponsorship/directory/ - looks like they cover more than 2,500 organizations!

The Python Software Foundation acts as a fiscal sponsor for a much smaller set of orgs (20 listed on https://www.python.org/psf/fiscal-sponsorees/) and it keeps our accounting team pretty busy just looking after those. Hack Club must have this down to a very fine art.

I wrote a bit more about PSF fiscal sponsorship here: https://simonwillison.net/2024/Sep/18/board-of-the-python-so...

garyhtou · 2 months ago
I love seeing PSF support the community with fiscal sponsorship! It makes such a huge difference for these open source projects and meetups, letting them focus on software and community rather than the legal/financial back-office work.

Hack Club's been a fiscal sponsor for about 7 years now (since 2018), and it's evolved quite a bit since the early days. I run engineering & product for the fiscal sponsorship program there and would be happy to chat/share any tips!

oh, and while it's on my mind, the codebase was open-sourced earlier this year (https://news.ycombinator.com/item?id=43519802), and we just launched a mobile app yesterday! https://news.ycombinator.com/item?id=46130402

garyhtou commented on Show HN: HCB – Nonprofit financial app processing $6M/month   hackclub.com/fiscal-spons... · Posted by u/garyhtou
garyhtou · 2 months ago
It's time! Take a look at the new mobile app for HCB. It's built with Expo by a 17-year-old! https://hackclub.com/fiscal-sponsorship/mobile-app/
garyhtou commented on Show HN: We open sourced a $50M neobank   hackclub.com/fiscal-spons... · Posted by u/garyhtou
davidajackson · 10 months ago
That's cool. What's your motivation here? Just to build cool stuff, or is this a business? No agenda just wondering.
garyhtou · 10 months ago
Thanks! We started as a 501(c)(3) nonprofit focused on after-school programming clubs and high school hackathons. We were working with high schoolers across the country and noticed that teenagers lacked the necessary financial infrastructure to run in-person events. For example, receiving money from a sponsor to buy pizza. We built HCB to give them essential tools like a donation page, invoicing system, and debit cards.

Since then, it's grown to a platform that supports not only high school hackathons, but nearly any nonprofit-related mission, including robotic teams and local food banks. We're still an educational nonprofit centered around high school coding clubs, but HCB is a tool we maintain to better empower these high schoolers.

u/garyhtou

KarmaCake day23June 28, 2022
About
Engineering Manager @ Hack Club. Building financial tools to reinvent Nonprofit Fiscal Sponsorship!

https://garytou.com

View Original