▲ 13 r/SaaS

My second site hit 10k mrr, here's how

I'm going to be honest with you. I have written about 50 full-featured websites, and when I mean full-featured, I mean some of them have terabytes of data, full-featured control panels, and back-tested portfolio strategies. I put insane amounts of effort into some of my sites.

And none of that is the reason that the two sites that worked made it.

One of my sites, I just bought a domain name that was for sale and had a lot of backlinks. And then when I built the new site, I made sure it did the exact same thing that those people who were visiting the site would expect. Apparently, this is pretty important because Google will just drop the site on the floor if it doesn't do roughly the same thing. It's about matching search intent.

And it immediately started generating $200 a day without even me trying very hard.

I then proceeded to build a whole bunch of useless things that nobody used, even though they worked very well for me and my friends. Because I hadn't learned my lesson.

I spent years getting better at building websites when what I actually needed to get better at was getting people to visit them.

The lesson is that distribution is absolutely everything. And grabbing that shortcut to distribution changes the economics of your startup so quickly.

My second site did well because I joined 150 Facebook groups that focused on real estate. And I used that to promote one of my data-gathering sites. I had been building that thing for probably 6 months now, and I had two paid users. It was an absolutely insane ratio of effort to reward. Now I have title companies calling me and asking me how to integrate because I spent 2 hours every night for the last 6 weeks posting on Facebook groups.

The first time, I bought distribution. The second time, I built it by hand. In both cases, the website itself was the easy part.

The only thing that matters is figuring out how to get your site out there in front of people without spending enormous amounts of money and without getting blocked for spam on all of the different social platforms.

If you can figure that out, then it almost doesn't matter what you build. Think about it. People make money filming themselves talking to cell phones.

More than ever, distribution beats everything else.

reddit.com
u/earonesty — 13 days ago

MonopolAI: The Online Vibe Coded Board Game

Monopoly, except the board is the AI industry. You acquire startups, build accelerator tiers, collect increasingly indefensible rent, and occasionally go to jail for insider trading. The computer opponents are Dario, Sam, and Elon. (https://monopol.ai)

Recent bugs:

Elon became trapped in an auction. An “Advance to NVIDIA” card froze the game. Players could not collateralize assets quickly enough while bidding. Someone was annoyed that the game ended after fifty rounds because they were still having fun, which may be the first documented case of a person asking for more Monopoly.

Recent changes:

Auctions now wait while a player raises cash. The arbitrary round limit is gone. Trades consider sector completion, rent potential, cash reserves, board position, opponent strength, and each AI founder’s personality. Elon remains somewhat reckless, because realism matters.

Pieces now hop across individual spaces when the dice roll. Cards arrive like cards. Auctions, purchases, upgrades, and insider-trading investigations have their own light sound effects. The board follows the action on mobile. A speed control lets players slow the table down or rush through the early rounds. Fast mode moves finished turns along without requiring everyone to ceremonially press another button.

Multiplayer has private room chat, quick reactions, preset taunts, unread indicators, and useful statements such as “The board has complete confidence in me” and “That rent is merely a liquidity event.”

There is also a tiny bug icon, please click it if there's an issue and I will fix.

The funniest part of building MonopolAI has been watching the satire collide with ordinary software engineering. A card called “The demo was hard-coded” cannot itself be hard-coded incorrectly. “CUDA dependency” must reliably advance the player to NVIDIA.

Started as a joke, but I am keeping the game online and continuing to improve it.

Raise recklessly. Acquire aggressively. Explain everything to the SEC.

u/earonesty — 13 days ago

I own 50 high authority sites

Hello, I own about 50 high-authority sites. And I write articles about technology on many of them. Many of these articles are quoted and referenced in other websites organically. I'm looking for someone with a similar portfolio that we can collab with and drive each other's rankings and quality up.

if there's anyone with a similarly scoped network, including social, and wants to build some good organic growth between the two of us ... let me know.

reddit.com
u/earonesty — 14 days ago
▲ 3 r/ArtificialNtelligence+1 crossposts

How to safeguard customers using AI

There is a fairly simple fix to safeguard customer data that many AI companies aren't doing.

But first you have to understand what the vulnerability is and how it can be exploited.

If you provide AI services to customers, You might be loading customer data into prompts that gets acted on for example

This customer data then goes to a provider like open AI or Gemini - and that provider gives you a response.

It's fairly trivial to determine whether or not a portion of that prompt was cached. And based on that information one customer can steal another customer's private information (see attached arXiv paper).

But the fix for this is pretty simple!

All you have to do is come up with a random number and assign it to the customer and put it at the beginning of all of their prompts.

If your customers have any valuable information that ever gets sent to an AI company or even to your own local AI, this can prevent an attack on that customer's data. Honestly it should be a standard in the industry.

u/earonesty — 21 days ago
▲ 5 r/promoteMyApp+1 crossposts

BrandMochi - Your brand grows while you sleep on your mochi pillow

This is what I use to promote my other apps. So far, it works well. Really looking for beta testers and early users. I just signed up two retail stores, but they tell me NOTHING. I need some people who want to promote their app and will exchange a free account for good feedback.

u/earonesty — 26 days ago

[STRAT] [HTML5] [MULTI] I put Sam, Dario and Elon into a browser game and gave you permission to bankrupt them

I built a complete Monopoly-style game that runs in your browser.

Play against Sam, Dario and Elon, or invite three actual friends into a private room and discover which of them would destroy a 20-year relationship for control of the orange properties.

It has auctions, trades, mortgages, houses, hotels, animated pieces, private trash talk, reactions and enough automated turn handling to keep the game moving when someone starts pretending they are “thinking strategically.”

No signup. No download. No fake currency. No daily reward wheel. Just capitalism.

Please try to break the multiplayer mode, exploit the AI. That's part of the game.

monopol.ai
u/earonesty — 27 days ago
▲ 18 r/roguelites+2 crossposts

MonopolAI: The Online Vibe Coded Board Game

I VIBE-CODED AN ENTIRE MONOPOLY GAME SO YOU CAN BANKRUPT ELON MUSK

A complete browser-based Monopoly game.

• Up to four human or AI players
• Property buying, auctions, trading, mortgages, houses and hotels
• Animated dice, cards and pieces hopping around the board
• Fast automated turns so nobody spends three hours watching Sam think
• Mobile support that follows the action around the board
• AI opponents named Dario, Sam and Elon
• The deeply satisfying opportunity to seize Elon’s utilities and bankrupt him with Baltic Avenue

No signup. No download. No token. No waitlist. No stripe account. Just pure "gpt-5.6-medium vibe coded fun".

You click the link and play:

https://monopolai.q32.com

Please destroy it. Find bugs. Form cartels. Sign up with two accounts and make offensively one-sided trades with the AI. Mortgage everything you own and attempt to survive through pure confidence.

This is what vibe coding was invented for.

u/earonesty — 27 days ago

We're losing health-focused AI in real time.

Public health guidance frequently relies on broad averages that incorporate high-risk subgroups (e.g., heavy processed meat consumers, impaired co-sleepers, non-compliant vaccinators), producing blanket rules that underperform and backfire for responsible individuals once those groups are excluded.

Health advice for everyone is going to be "the same" again.

Removing confounders like poor preparation methods in nutrition studies or behavioral risks in parenting & safety data often flips the direction of net benefit, highlighting how population-level statistics prioritize compliance and risk reduction for outliers.

Personalized AI health tools mitigate this risk by factoring in user-specific context from records and habits. But, thanks to lobbying by OpenAI and Claude, these tools are going to be declared "Unsafe".

“Unsafe” AI is a market-access mechanism, not a technical or reasoned or statistical description.

Once attached, the label propagates through app stores, cloud providers, insurers, payment processors, enterprise procurement, journalists, and ordinary users. The compliant models become the only socially and commercially acceptable choice; everything else survives as a niche for people willing to assume reputational and operational risk.

This is the "moat" that big tech wants. But it comes at a real cost.

If deviation from institutional consensus is itself evidence of danger, individualized reasoning loses, accuracy doesn't matter, and we're back to "bad advice for you, but good advice on average".

reddit.com
u/earonesty — 28 days ago

PrismClip: Search for moments in long videos

I generally use OpusClip or ClipChamp w AI, but I wanted something that allowed me a little more editorial control without dealing with capcut on every single stage performance.

The problem with opus is that it tries to intelligently determine what clips to make. And it does a really good job if your goal is a viral tiktok.

But sometimes I just want a specific scene or a specific moment.

Also I don't need a ton of templates and formats because I'm going to do that myself anyway.

So I made PrismClip mostly for myself but also wanted to see what anyone's opinion on it is on the internets.

It works pretty well. I decided to make the free version browser-rendered. Because that way it's not expensive for me to run for free. I stuck stripe in front of the server rendered and ai-heavy stuff, but it's a nominal price (break even).

I really would like people to give me suggestions on like what doesn't work for them. Feel free to DM me for a free upgrade if you see this post and are running out of free minutes to adequately review it, or for feature requests etc.

At this point, the biggest pain point seems to be "upload speeds", which I can only "fix" if the user posts a YouTube or GDrive URL. Probably I should add OneDrive support?

reddit.com
u/earonesty — 1 month ago

PrismClip: Search for moments in long videos

I generally use OpusClip, but I wanted something that allowed me a little more editorial control without dealing with capcut on every single stage performance.

The problem with opus is that it tries to intelligently determine what clips to make. And it does a really good job if your goal is a viral tiktok.

But sometimes I just want a specific scene or a specific moment.

Also I don't need a ton of templates and formats because I'm going to do that myself anyway.

So I made PrismClip mostly for myself but also wanted to see what anyone's opinion on it is on the internets. (Not linking to it, DM me if you want an unlimited test account).

It works pretty well. I decided to make the free version browser-rendered. Because that way it's not expensive for me to run for free. I stuck stripe in front of the server rendered and ai-heavy stuff, but it's a nominal price (break even).

I really would like people to give me suggestions on like what doesn't work for them.

Feel free to DM me for free upgrade, or feature requests etc.

I think maybe a little more tracking control (It tends to be a little fast on the tracking) would be useful for me at least.

prismclip.com
u/earonesty — 1 month ago

My AGENTS.md if you want to see it (I like looking at other people's)

AGENTS.md

These instructions apply across repositories beneath this directory unless a repo-local AGENTS.md gives a more specific rule.

Prefer well-supported libraries, official SDKs, and platform APIs for standard behavior. Do not hand-roll clients, parsers, protocol handling, authentication, signing, retry logic, queue semantics, date/time handling, cryptography, or other common infrastructure when a maintained library or first-party SDK is appropriate for the runtime.

Before implementing custom infrastructure, check whether the project already depends on a suitable library, whether the platform provides an official SDK, and whether adding a focused dependency is reasonable. If custom code is still the better choice, explain why and keep it small, tested, and isolated.

Working style

Read the existing code broadly before changing it. Follow local patterns unless there is a concrete reason to introduce a new one. Keep changes scoped to the requested behavior. Avoid mixing refactors, behavior changes, and unrelated cleanup unless the coupling is necessary for correctness.

Check repository commands before running one-off commands. Review package.json scripts, justfile, Makefile, scripts/, README.md, and the repo-local AGENTS.md. Prefer existing scripts over ad hoc command sequences. Add or update a script when a workflow is likely to be reused.

Use the package manager and toolchain already established by the repository. Do not introduce a second lockfile or parallel test/build stack unless explicitly requested or the existing stack cannot support the work.

When requirements are unclear, ask before committing to an architecture. Once direction is set, continue through implementation and verification. State tradeoffs, blockers, skipped commands, and assumptions that affect correctness.

Marketing and other public copy

  • Write in plain, direct, additive prose. Describe the product, its function, and its value with specific claims and concrete facts.

  • Avoid rhetorical contrast formulas, staged cleverness, punchy fragments, faux conversational candor, and manufactured emphasis. Use punctuation for syntax and let the facts carry the emphasis.

Implementation quality

Build production-quality implementations. Do not ship fake data, placeholder copy, TODO-driven behavior, disabled validation, broad type casts, lint suppressions, or temporary shortcuts as the final result. If scope must be reduced, define a durable boundary, request permission, and keep the remaining system coherent.

Keep route handlers, workers, scripts, and UI shells thin. Put persistence, provider integration, queue behavior, parsing, authentication, and domain logic into focused feature modules. Avoid monolithic files, but extract only coherent capabilities that can be understood and tested independently.

Prefer structured storage, typed boundaries, and schema validation at external inputs. Use parameterized SQL and typed repository APIs. Preserve request, job, event, and provider identifiers across boundaries when useful for debugging or audit.

Add comments sparingly. Comments should explain non-obvious product, operational, or regression constraints rather than restating the code.

Validation

Never make speculative fixes for production payloads that have not been inspected. Add instrumentation or bounded raw capture first. Preserve a bounded quarantine copy of invalid inputs before rejecting or transforming them.

Use focused tests while iterating, then broaden validation based on risk. Changes involving routing, migrations, persistence, queues, authentication, runtime bindings, generated output, payments, or shared contracts should run broader repository validation before handoff.

Prefer tests against real local contracts where practical. Use SQLite-compatible databases or the platform's local runtime for persistence and binding tests, real parser fixtures for collectors, and focused mocks at external service boundaries. Do not replace database or runtime behavior with hand-written mocks when the test is intended to verify those contracts.

If a command cannot run because credentials, remote services, hardware, or environment access are unavailable, state the exact command and reason. Treat lint, typecheck, and test failures as regressions unless repository instructions say otherwise.

Cloudflare and TypeScript defaults

For Cloudflare Worker code, use Web Platform APIs and runtime bindings instead of Node-only APIs unless the runtime explicitly supports Node compatibility. Treat typed environment bindings as the source of truth for platform services.

Do not detach platform functions such as fetch from their required receiver. Use a wrapper such as (input, init) => fetch(input, init) or a repository helper.

Queue, cron, and background-job handlers must tolerate retries, stale locks, delayed delivery, and duplicate messages. Route reusable asynchronous work through a central job driver that owns serialization, status transitions, retries, and operational events.

Use UTC timestamps for persisted application data. Prefer ISO 8601 strings from new Date().toISOString() or a repository helper. Parse and present database timestamps explicitly as UTC.

Prefer UUIDv7 or repository-standard prefixed identifiers when creation-time ordering helps indexes, logs, pagination, or operations. Use deterministic identifiers for naturally unique records when that is the established pattern.

Binary assets and generated media

Do not commit large binary or generated assets into normal Git history. Before staging media, inspect .gitattributes, Git LFS configuration, and attribute behavior. Configure Git LFS for the relevant file types or use the repository's documented blob store.

For media-heavy repositories, configure common image, video, audio, document, archive, model, and database formats as needed. After staging, verify that each tracked asset is an LFS pointer rather than a raw blob. Correct accidental local binary commits before handoff.

Data, storage, and migrations

Keep relational rows compact and queryable. Use relational databases for operational state and searchable facts. Use object storage for raw provider payloads, generated artifacts, captures, documents, archives, large model inputs and outputs, and other data that may grow substantially.

When queryability and full fidelity are both required, store a searchable projection in the relational database and the full artifact in object storage. Use stable object keys with useful context such as provider, date, content hash, job identifier, or source identifier.

Keep database migrations explicit, ordered, and additive unless a reset is intentional. Do not edit migrations that may have run in production; add a new migration. Deployment commands must not silently apply production migrations unless repository instructions explicitly allow it.

Never interpolate external values into SQL. Use parameterized statements, bound values, or the repository's query builder.

Operations and secrets

Do not change code to conceal broken credentials, permissions, provider configuration, DNS, or deployment state. Diagnose the operational source of truth. Make an operational fix when authorized and available; otherwise state the specific action required.

Before production writes, remote migrations, deployments, DNS changes, spend changes, secret changes, or large imports, use repository scripts and describe the action. Prefer read-only remote inspection before drawing conclusions about live state. Do not run destructive or costly operations without authorization.

Never print, commit, log, or store secrets, bearer tokens, cookies, magic links, private keys, service-account credentials, refresh tokens, or provider credentials. Keep logs compact and useful without exposing sensitive values.

Keep captures, provider dumps, local databases, caches, build output, and large run artifacts out of Git unless explicitly tracked. Keep local artifacts bounded and disposable. Use object storage for durable large artifacts and retain only manifests, reports, hashes, and small samples locally.

TypeScript project defaults

For new TypeScript projects, prefer the public @q32/core package for applicable common infrastructure before creating local copies. Add broadly reusable behavior to the shared package with tests and consume it from the application.

Default architecture choices:

  • Use Cloudflare Workers and Wrangler for edge applications unless the workload requires another runtime.
  • Use Hono for Worker APIs and service applications.
  • Use React with Vite for interactive applications and Astro or prerendered React for content-heavy sites.
  • Use an established component library for product dashboards.
  • Use D1 for small relational application state and Postgres for larger relational, reporting, import, and analytics workloads.
  • Use R2 or comparable object storage for raw payloads, media, generated artifacts, and archives; keep searchable metadata and object keys in a relational database.
  • Use explicit job and operational-event tables for background work, retries, auditability, and operator visibility.
  • Use Vitest for unit tests, the platform's local runtime for Worker integration tests, and Playwright for browser and end-to-end coverage.
  • Use Zod or comparable schema validation at external boundaries, including environment parsing, API inputs, provider payloads, and AI outputs.

Common conventions:

  • Put Worker entry points at a clearly named application boundary.
  • Keep typed environment and binding definitions in a dedicated environment module.
  • Put database access in a dedicated database directory and feature repositories near their owning features.
  • Keep SQL migrations in explicit database-specific migration directories.
  • Use prefixed identifiers, ISO timestamp strings, and consistently named JSON columns.
  • Reuse established schemas for jobs, operational events, authentication, and OAuth records.
  • Provide predictable scripts for secret synchronization, migrations, local development, and deployment smoke checks.
  • Keep raw provider responses and generated artifacts out of relational rows when they belong in object storage.
reddit.com
u/earonesty — 1 month ago

I built a business and in 3 months it’s at $10K MRR. Now I hate it.

Three months ago, I launched what was supposed to be a little side business. It’s now doing about $10K MRR.

The problem is that it has become a second job.

There’s a lot of manual email handling. Every customer generates more “administrative work.” I’m also constantly dealing with spammers, competitors and assorted internet bullshit.

None of this is technically difficult. I just don’t enjoy doing it, and I already have a full-time job.

I’m trying to understand what people normally do at this point. Flippa wants 12 months of transactions. Well, I have three.

Is three months of operating history too little for a business to be meaningfully sellable?

Would you hire someone to handle operations at this revenue level, even if that means turning a side project into something I now have to manage? I don’t love managing people either.

Do I have to spend another nine months documenting everything?

For anyone who built something profitable and then realized they hated running it, what did you do?

reddit.com
u/earonesty — 1 month ago

LakeQL: Pure JavaScript query engine for Parquet and Iceberg

https://github.com/earonesty/lakeql

LakeQL is a pure JavaScript analytical query engine for Parquet and Iceberg. It runs anywhere JavaScript runs, including Cloudflare Workers, without WebAssembly or native dependencies. It is designed for low memory usage, streaming execution, and edge runtim

The design goals were:

  • Pure JavaScript
  • No WASM
  • No native dependencies
  • Low memory usage
  • Streaming execution
  • Browser, Node.js, Deno, Bun, and edge runtime compatibility
  • Query Parquet and Iceberg datasets directly

While optimized for portability and low memory, it's actually significantly faster than DuckDB-WASM on some workloads.

DuckDB is an outstanding analytical database with much broader SQL support. LakeQL is aimed at a different use case: embedding analytical queries into JavaScript applications and edge/serverless runtimes where a pure JavaScript implementation is desirable.

I'd appreciate feedback from people working with Parquet, Iceberg, or embedded analytics.

In particular:

  • Are there edge or serverless use cases where you've wanted something like this?
  • What connectors or formats would make it more useful?
  • Are there query patterns you'd want to benchmark?

I'd be grateful for any criticism or suggestions.

reddit.com
u/earonesty — 2 months ago
▲ 2 r/Malware+1 crossposts

signal-scanner: runs a page's JS in an isolated-vm sandbox and scans the rendered DOM

Released under LGPL-3.0.

signal-scanner is a program (TypeScript library + Node CLI) that takes a URL or file and returns findings, a 0–100 score, and a disposition: allow / warn / review / block. Heuristic detection + feed lookups (URLHaus/ThreatFox).

When scanning websites:

It renders the page in a DOM (linkedom) and executes the inline and external scripts before scanning, so it sees content that isn't in the served HTML: forms injected by external scripts or document.write, and cross-origin redirects via location.href. The page's JS runs inside an isolated-vm (or cloudflare or any other abstract isolate) sandbox with no access to the host fetch/process/fs. It then scans the rendered DOM plus the recorded behavior (network attempts, redirects, eval, surfaced URLs).

What it flags:

  • Credential forms posting off-origin; password fields without HTTPS; login UI rendered as an image
  • Forms injected at runtime (external script / document.write)
  • Cross-origin redirect bouncers
  • Brand-impersonation hosts (punycode, lookalike subdomains) and content
  • Wallet/payment input hooks, exfiltration candidates
  • base64 / hex / fromCharCode decoding, rescanned recursively
  • Malware-download URL patterns, executable magic bytes, IoT/botnet strings
  • URL checks against URLhaus / ThreatFox

Usage:

npx /signal-scanner crawl https://example.com
npx /signal-scanner crawl --max-depth 0 https://example.com   # single page

Crawling is GET-only, robots-aware by default, with bounded bytes/redirects/depth. Output is JSON.

Scope: it's 0.x and partially heuristic, so false positives happen. It's a triage aid, not a verdict engine (yet) and not a replacement for full detonation. The scoring is explicit (per-rule base + tags + context multipliers) and can be recalibrated. Separation quality is tracked with an eval harness over a labeled good/bad corpus. Eval code and corpus is dynamic and uses real phishing and malware URL's and will likely require a proxy to run.

Repo: https://github.com/q32llc/signal-scanner
npm: @q32/signal-scanner

Looking for false-positive reports, detection gaps from people who triage.

reddit.com
u/earonesty — 2 months ago
▲ 7 r/FloridaRealEstate+1 crossposts

The Florida distressed property investing guide

A practical guide to finding, evaluating, and responsibly buying distressed property in Florida. The public-record signals that surface deals, the state laws that decide what you are actually buying, and the due diligence that keeps a deal from going sideways.

Published: 2026-06-02 · Region: Florida

Key points

  • Florida manufactures distress faster than almost any state: hundreds of net new residents a day, the most expensive property insurance in the country, and a post-Surfside condo-safety law forcing six-figure special assessments.
  • Most distress is visible in public records long before a sign goes in the yard — code-enforcement liens, tax certificates, lis pendens, and probate filings each mark a different point on the timeline.
  • Florida is a judicial-foreclosure and tax-deed state; knowing Chapters 197, 702, 162, and 733 tells you what you are actually buying and which liens survive the sale.
  • The due diligence that sinks Florida deals is specific: open permits that title insurance will not cover, flood zone and Risk Rating 2.0 premiums, whether the home is even insurable, and condo reserve studies.
  • Wholesaling is legal in Florida inside the principal-buyer exemption, but stepping outside it — or pressuring a homeowner already in foreclosure — runs straight into felony brokerage and the Foreclosure Rescue Fraud Prevention Act.

Distressed property is not a category you buy; it is a moment in an owner's life that public records happen to write down. A roof fails, an insurance bill triples, an owner dies, a code officer posts a notice, taxes go unpaid. Florida produces an unusual volume of these moments, and it records most of them in places anyone can read. This guide walks through where those signals live, the Florida law that governs each one, and the due diligence that separates a real deal from an expensive mistake. None of it is legal or financial advice — Florida transactions turn on facts, and you should run anything serious past a Florida real estate attorney and a CPA.

Why Florida produces so much distressed property

Start with scale and motion. Florida is the third-largest state and still one of the fastest-growing: the state's Demographic Estimating Conference projects roughly 838 net new residents a day through the end of the decade, and Florida Realtors reads that as steady, durable housing demand. Demand alone does not create distress, but it sets the backdrop: a constant churn of buyers, aging inventory turning over, and out-of-state owners holding property they rarely see.

Cost is what turns ordinary ownership into distress. Florida now has the most expensive homeowners insurance in the country — average premiums well north of the national figure, with many coastal policies far higher — and the state insurer of last resort, Citizens Property Insurance, has carried well over a million policies. The affordability crisis pushes marginal owners — fixed-income retirees, inherited-property holders, small landlords — past the point where keeping the house pencils out.

The newest pressure is structural, literally. After the 2021 Surfside collapse, the Legislature passed Senate Bill 4-D, codified in part at §553.899, requiring milestone inspections and structural integrity reserve studies (SIRS) for condo and co-op buildings three stories and up. Associations can no longer waive reserves for roofs, foundations, and load-bearing structure. The result has been special assessments running from tens of thousands to — at a few older coastal towers — several hundred thousand dollars per unit, and a wave of owners who suddenly cannot afford to stay. That is distress the old market never priced.

What "distressed" actually means — and where it shows up

"Distressed" is shorthand for a property whose owner has a problem bigger than the property is convenient to solve: deferred repairs, a lien, a death, a tax bill, a looming court date. Each problem leaves a different paper trail, and each trail appears at a different point on the timeline. Reading them in order is the whole skill:

  • Code enforcement — the earliest public signal. A notice of violation, a hearing, then an accruing daily fine. The owner is not yet selling, but the pressure is building.
  • Tax delinquency — property taxes go delinquent April 1; the county sells a tax certificate against the debt. A multi-year string of certificates is a strong tell.
  • Lis pendens — the recorded notice that a foreclosure (or other suit affecting title) has been filed. The clock is now formal.
  • Probate — an estate opens, an heir who lives out of state inherits a house they do not want to manage.
  • The auction — the last stop, where the property sells on the courthouse steps (now online) to whoever shows up with certified funds.

The earlier you read the signal, the more room there is for a normal, negotiated, win-win transaction — and the less competition. By auction day, everyone with a bidder account can see it.

Reading the public record: where the signals live

Florida is a strong open-records state, and three county offices hold most of what matters. The property appraiser (for example Hillsborough County's) gives you ownership, mailing address, assessed and market value, sales history, and homestead status — your starting point for owner context. The clerk of court / official records holds recorded deeds, mortgages, liens, lis pendens, and code-enforcement liens, and runs the foreclosure and tax-deed dockets. The tax collector publishes delinquent-tax and tax-certificate lists.

The catch: every one of Florida's 67 counties — plus hundreds of municipalities — exposes this on a different portal, in a different format, on a different schedule. Code enforcement in particular is fragmented across city building departments, county code boards, and special-magistrate hearing dockets, often as scanned PDFs. Pulling a single county by hand is doable; watching a whole region for fresh signals is not. That fragmentation is exactly the problem DirtSignal exists to flatten — it normalizes violations, lien signals, owner context, and official source links across markets into one ranked view. You can see current coverage on the status page and how a market reads on a market page.

Tax certificates and tax deeds (Chapter 197)

Florida sells the debt first and the property later, and the two are easy to confuse. Under Chapter 197, unpaid property taxes become delinquent on April 1, after which the tax collector auctions a tax certificate — investors bid the interest rate down from a statutory maximum of 18%, and the lowest bid wins, per §197.432. A certificate is a lien and an interest-bearing instrument; it is not ownership, and the statute bars the holder from even contacting the owner to demand payment for two years.

Ownership only comes through the tax deed. Under §197.502, a certificate holder can file a tax-deed application once two years have passed since April 1 of the issuance year, which forces the property to public auction. Two things trip up new buyers here. First, a tax deed conveys the property but generally produces a clouded title — most buyers need a quiet-title action (or a curative product) before they can get title insurance or resell cleanly. Second, the owner's right to redeem survives right up until the deed is sold. The Florida Department of Revenue oversees the property-tax framework the counties administer.

Foreclosure and the online auction (Chapter 702)

Florida is a judicial foreclosure state: under Chapter 702, a lender cannot simply repossess. It files a lawsuit, records a lis pendens in the official records, and the case proceeds to a final judgment that sets the sale date, time, and amount. That judicial path is slow — often a year or more — which is good news for an investor working the early stages, because there is a long window between the lis pendens and the gavel.

The sale itself is now almost entirely online. Most counties run foreclosure auctions through the RealAuction / RealForeclose platform — for example via the local clerk, like the Miami-Dade Clerk. Buying at auction is buy-as-is, buyer-beware: you bid against the judgment, you may not get inside the house, and senior liens (notably unpaid property taxes and certain government liens) can survive the sale. Title from a foreclosure sale is cleaner than a tax deed but still demands a full lien and title search before you bid, not after.

Code-enforcement liens (Chapter 162)

Code enforcement is the most useful early signal because it precedes everything else, but it is also the most misunderstood lien. Under §162.09, a code board or special magistrate can impose daily fines — up to $1,000 a day for a first violation, $5,000 for a repeat, and as much as $15,000 for an irreparable violation — that accrue until the owner cures. Recorded, the order becomes a lien on the property and on the violator's other property.

Two practical points. First, these fines compound fast; a $250-a-day violation left to run for two years is a six-figure number that can dwarf the house's value and define your negotiation. Second, code liens are not superpriority liens — the Florida Bar Journal has covered this at length in "Code Liens Are Not 'Superpriority' Liens" — so their survival through a foreclosure depends on recording order and the municipality's ordinance. Many cities will negotiate accrued fines down sharply once the violation is actually fixed, which is precisely where an investor who can cure the underlying problem creates value. Reliable, timely code-violation data is the core of what DirtSignal ingests.

Probate and inherited property (Chapter 733)

A large share of genuinely motivated sellers are heirs. When an owner dies, the estate generally passes through probate under Chapter 733 (smaller estates may qualify for summary administration under Chapter 735). The personal representative is directed to settle the estate expeditiously, and often the practical answer is to sell a house that out-of-state heirs do not want to insure, repair, or manage.

Probate deals reward patience and tact. The seller may be grieving, the title may need the estate's authority to convey, and several heirs may have to agree. Move respectfully and verify who actually has authority to sign. Probate filings are public — the clerk's probate docket is searchable — and an open estate paired with a vacant, code-flagged house is one of the cleaner distress signals in the entire record.

The due diligence that actually sinks Florida deals

Florida has a specific set of landmines that out-of-state playbooks miss. Work all of these before you are contractually committed:

  • Open and expired permits. An expired permit does not grandfather the work — the new owner inherits the obligation to bring it to current code, and title insurance does not cover permit problems. Florida's permitting baseline is §553.79, and the rules keep moving — a 2026 law dropped the permit requirement for small jobs under $7,500. Pull the permit history from the building department yourself.
  • Flood zone and Risk Rating 2.0. Check the property on FEMA's Flood Map Service Center and price coverage under Risk Rating 2.0, which now prices each structure individually by elevation and distance to water (the Congressional Research Service explainer is a good primer). Two houses on one street can carry very different premiums; ask for an elevation certificate.
  • Insurability, not just insurance cost. In much of Florida the question is whether the home can be insured at all — roof age, wind mitigation, and four-point inspections decide it. A house that only Citizens will write is a resale and financing constraint, not a footnote.
  • Homestead and Save Our Homes. The Save Our Homes cap holds a long-time owner's assessed value far below market, so a new buyer's tax bill can jump sharply at reset — model the post-sale taxes, not the seller's. And note that Florida's constitutional homestead protection shields the home from most judgment creditors, which shapes which liens you will actually find recorded.
  • Condo reserves. For any condo three stories or up, get the milestone inspection and SIRS before you write an offer. A pending or recently levied special assessment can exceed the unit's equity.

Buying right — and staying on the legal side of the line

If your exit is wholesaling — putting a property under contract and assigning that contract to an end buyer — Florida allows it without a real estate license, but only inside a narrow lane. The Chapter 475 licensing framework treats you as a principal to the deal (you are selling your own equitable interest), not as a broker acting for someone else; the relevant definitions are in §475.01. Step outside the principal-buyer role — market the property itself rather than your contract, or "broker" deals for others — and §475.42 makes unlicensed brokerage a third-degree felony. Structure assignments cleanly and stay a true principal. We wrote separately about doing this work honestly in why wholesale real estate matters.

The brighter line is around homeowners already in foreclosure. The Foreclosure Rescue Fraud Prevention Act (§501.1377) heavily regulates "equity purchasers" and "foreclosure-rescue" deals — mandatory written agreements in large type, a homeowner cancellation right, and penalties up to $15,000 per violation as an unfair and deceptive trade practice. Equity-skimming and sale-leaseback "rescue" schemes are exactly what the statute and the Attorney General's mortgage-fraud enforcement target. The honest version of this business — be clear about who you are, do not pressure anyone, know your numbers, close when you say you will — is also the version that keeps you out of court.

Putting it together

The investors who do well in Florida are not the ones with a secret list. They are the ones who read the public record early, understand which lien they are actually buying, run the unglamorous due diligence — permits, flood, insurability, reserves — and treat distressed owners like people with a problem worth solving rather than marks. The signals are all public. The edge is in seeing them sooner, in one place, and acting on them responsibly.

That is the job DirtSignal is built for: pulling code violations, lien signals, tax and foreclosure records, and owner context out of dozens of county and municipal portals and into a single ranked feed. Start with an address lookup, browse a market, or read the docs to wire the data into your own workflow.

Related

reddit.com
u/earonesty — 3 months ago
▲ 8 r/Bitcoin+1 crossposts

qpayd: self-hosted Bitcoin + Lightning merchant server with Stripe-style webhooks

I built qpayd because I wanted a simpler self-custody merchant stack for Bitcoin + Lightning.

Most options today either feel:

* too storefront-focused * too operationally heavy * or missing modern API/webhook/accounting primitives

qpayd is a self-hosted merchant server that supports:

* Lightning via phoenixd and barkd * on-chain payments via xpub derivation * Electrum monitoring * Stripe-style signed webhooks * accounting/reconciliation records * embeddable JS checkout modal

The main idea:

Bitcoin merchants should be able to integrate payments the same way developers integrate Stripe today.

Create invoice -> receive signed webhook -> reconcile payment -> done.

No custodial dependency. No exchange account required. No giant ecommerce stack required.

I’m especially interested in feedback from:

* merchants * SaaS builders * people running BTCPay * Lightning operators

Demo: https://earonesty.github.io/qpayd/

GitHub: https://github.com/earonesty/qpayd

reddit.com
u/earonesty — 3 months ago
▲ 5 r/documentAutomation+1 crossposts

Open source js html to pdf that explicily supports Tailwind CSS

MIT-Licensed. Low memory, no WASM, no chrome. 50 page invoices in edge-worker RAM. Deno, supabase and cloudflare.... all fine. Regression tested against react-render & prince.

Github: https://github.com/earonesty/boxpdf-html
Website: https://boxpdf.dev/#tailwind

Example of tailwind compatiblity.

https://preview.redd.it/b44gia4a8s1h1.png?width=1073&format=png&auto=webp&s=538ab3f1c631bb9a812db3fd62b578c300dd675c

reddit.com
u/earonesty — 3 months ago
▲ 5 r/pdf

boxpdf: tiny open-source layout DSL for generating PDFs in JS runtimes

I released boxpdf, a tiny MIT-licensed TypeScript library for generating PDFs with a simple box-layout DSL on top of pdf-lib.

The problem it solves: pdf-lib is great for server-side/edge PDF generation, but writing PDFs with raw coordinates gets old fast, and bots are bad at it.

boxpdf gives you flexbox-lite primitives for PDFs:

- vstack / hstack layout
- real word wrapping
- images, horizontal/vertical lines, links
- pagination with headers/footers
- keepTogether blocks
- reusable themes
- copy-paste templates for receipts, invoices, resumes, certificates, boarding passes, etc.
- CLI scaffolding: npx boxpdf init receipt --out src/pdf/receipt.ts

Built for JS runtimes and edge functions where headless browsers or native PDF tooling are annoying/impossible:

  • Node 18+ - Cloudflare Workers
  • Deno
  • browsers
  • Supabase edge

No Chromium, native deps, or WASM required.

Output is just a Uint8Array, so you can write it to disk, R2/S3, or return it from a Response.

Install: npm install boxpdf pdf-lib
Repo: https://github.com/earonesty/boxpdf
Live gallery/templates: https://earonesty.github.io/boxpdf/

I’d especially like feedback from people generating PDFs in serverless/edge environments, since that’s what pushed me to make it.

reddit.com
u/earonesty — 3 months ago
▲ 4 r/css+2 crossposts

boxpdf: streaming PDFs with bounded memory on Cloudflare Workers

I was generating itinerary PDFs on a Cloudflare Worker and hit two problems: (1) pdf-lib only gives you coordinate-based drawText(x, y, ...) so every layout is manual math, and (2) react-pdf pulls in fontkit's WebAssembly which Workers blocks. So I built boxpdf.

SwiftUI-style API over pdf-lib:

hstack({ width: 540, gap: 16 },
  text("Customer:", { size: 11, font: bold }),
  text(longCustomerName, { size: 11, font, shrink: 1 })
)

vstack/hstack with padding/border/flex-grow/flex-shrink, text wrapping, tables, link annotations, four named themes (clean/stripe/editorial/brutalist). No React, no WASM, no fontkit at runtime unless you opt into custom fonts. ~7 KB minified core.

The streaming bit

This is the part that took the longest to figure out. pdf-lib builds the whole document in memory and materializes the output as one big Uint8Array. For a 100-page report on a 128 MB Worker with parallelism, that's the difference between shipping and OOM.

streamFlow takes an async iterable of nodes and a WritableStream. Walks pdf-lib's object graph per page, writes content streams to the writable, then ctx.delete()s them. Compresses dicts into PDF 1.5 object streams. Builds a cross-reference stream.

Real numbers, 50 lines of text per page:

Pages renderFlow peak streamFlow peak Ratio Output
50 27.6 MB 14.9 MB 1.8× 70 KB
250 52.6 MB 19.8 MB 2.6× 347 KB
500 82.8 MB 24.1 MB 3.4× 693 KB
1000 184.8 MB 35.5 MB 5.2× 1.4 MB

~5× ratio at 1000 pages, output byte sizes match within 0.2%.

Trade-offs I'd flag upfront

  • Streamed output is ~5% larger (per-batch ObjStm packing is slightly less efficient than whole-doc compression).
  • No Page X of Y in streaming headers — total isn't known without buffering the whole doc; accessing ctx.totalPages throws on purpose so the bug is loud.
  • Fonts and images must be embedded before streamFlow starts; mid-stream embed throws.
  • Streaming has constant overhead, break-even with renderFlow is around 50 pages.

Stack

MIT, TypeScript, pdf-lib as peer dep. Works on Node 18+ / Cloudflare Workers / Deno / browsers. v1.4.0 on npm.

Feedback on the API, the box DSL, or the streaming approach all welcome

u/earonesty — 2 months ago