We are currently maintaining a very old client-server architecture. The server collects real-time data from a large number of sensors and controllers, transmitting it to a legacy database under continuous, massive load (writes every few seconds).The problem is the client side. It’s ancient, strictly requires Internet Explorer, and heavily relies on ActiveX. If a standard domain user launches the browser, the data fails to load and the browser completely hangs. It only functions correctly if run with local administrator privileges.Giving users local admin rights is a massive security risk we can't take. Currently, I have a workaround running in production using Task Scheduler to elevate just this specific application without giving the user the actual admin password. I documented the specific approach we are using here: https://www.hiddenobelisk.com/how-to-let-a-standard-domain-user-run-one-program-as-administrator-without-giving-admin-rights/#:~:text=least%20privilege.-,Approach%202%20%E2%80%94%20Running%20Applications%20with%20Administrative%20Privileges%20Using%20Task%20Scheduler,users%20can%20simply%20double%2Dclick%20the%20shortcut%20to%20launch%20the%20application.,-Changing%20the%20ShortcutI recently started a thread over on r/sysadmin trying to find a cleaner solution: https://www.reddit.com/r/sysadmin/comments/1rm6uv4/how_do_you_let_a_standard_domain_user_run_one/The general consensus there was to either buy an expensive enterprise PAM (Privileged Access Management) solution, or deep-dive with Procmon. I am currently analyzing the software with Procmon based on that advice, but so far, I haven't been able to make the client work without the Task Scheduler workaround.My questions for the HN community:1) Are there any reliable open-source PAM alternatives or privilege elevation tools for Windows that handle this "per-app" scenario effectively?2) When dealing with hostile Activ
FL score
out of 100
Verdict
medium confidence
Competition
5
competitors found, emerging market, funded players
Trend
No signal yet
A simple, secure 'per-application' privilege elevation tool for Windows to run legacy IE/ActiveX clients without local admin rights.
The pain
The gap
Build angle
Strengths
Questions about this idea?
FlyBot reads the scoring and gives you a second opinion on “Running legacy IE/ActiveX clients without local admin rights?”.
Risks
Next steps
Fly Labs Method
Is the pain real, is there a gap, is it the right time, can one person build it.
This idea addresses a clear and painful problem for IT professionals dealing with legacy systems. There's a gap for a focused, affordable solution between complex VDI/PAM and risky local admin rights. The build difficulty for a truly robust solution is higher than average for a solo builder, but an initial MVP targeting the specific workaround is feasible.
Value Equation
Dream outcome and how likely it feels, against the time and effort it costs.
This idea has strong market viability and a clear value proposition, targeting a persistent pain point with good pricing potential, but faces moderate build complexity.
One-Person Business
Curiosity pull, identity fit, and a path from free value to paid for a solo creator.
A highly specific problem with strong creator fit and clear monetization, targeting a reachable niche, though the technical solution requires deep expertise.
Viral Frameworks
Hook strength, shareability, and how cheaply it can be tested.
This micro-SaaS has a specific, reachable audience and a compelling, measurable value proposition for a critical business need, with good validation signals.
Builder Lens
Evidence the problem exists, timing, defensibility, and a model that fits on a napkin.
This idea addresses a critical, desperate need for specific users with clear, expensive, or risky existing solutions, and a viable narrow wedge to start building.
Why this verdict
Five lenses, one composite. How scoring works
The angle
This weekend
Who is already there, emerging market
Cameyo is a secure and cost-effective virtual app delivery service that delivers Windows applications to any device from the browser without the complexity of VDI or DaaS.
Pricing: Starting from $12.00/month (older information, contact for current pricing).
GO-Global provides an intuitive and lightweight platform for delivering Windows applications without the need for complex client installations.
Pricing: 25 - 99 concurrent users: $4.20/month ($41.40 paid annually per user); 100 - 499 concurrent users: $3.85/month ($38.40 annually per user).
RunAsSpc allows standard users to run programs with administrator rights by reading application and account login information from an encrypted file.
Pricing: Free for personal use; companies and organizations need a licensed version, with prices ranging between 20 and 200 Euros depending on the number of computers.
RunAsRob provides multiple options to run specific applications with elevated administrator permissions, including temporarily elevating a user's account to an administrator.
Pricing: Price for each additional license is 1.50 EUR / 1.65 USD, including RunAsSpc; licenses are valid for 5 years within one organization.
Spoon.net (now Turbo.net) allows you to run applications, including old browsers, without installing them, by creating virtualized application layers.
Pricing: Individual access was free with up to 1GB storage and synchronization between two machines; a $12/month upgrade offered 100GB and synchronization between 12 machines (older information).
What they charge
Recent news
Hacker News, March 26 2026
GO-Global - Graphon, February 18 2026
iTnews, October 14 2025
eSecurity Planet, October 14 2025
Market signals
The market for running legacy IE/ActiveX clients without local admin rights is a niche but persistent one, driven by the continued existence of older business applications and industrial systems. While Microsoft has officially disabled standalone Internet Explorer, IE mode in Edge provides a compatibility solution, though it introduces security concerns. The acquisition of Cameyo by Google suggests growing interest in virtual application delivery solutions for legacy applications.
What frustrates people
Last summer we faced a conundrum at my company, Tiger Data, a Postgres cloud vendor whose main business is in timeseries data. We were trying to grow our business towards emerging AI-centric workloads and wanted to provide a state-of-the-art hybrid search stack in Postgres. We'd already built pgvectorscale in house with the goal of scaling semantic search beyond pgvector's main memory limitations. We just needed a scalable ranked keyword search solution too.The problem: core Postgres doesn't provide this; the leading Postgres BM25 extension, ParadeDB, is guarded behind AGPL; developing our own extension appeared daunting. We'd need a small team of sharp engineers and 6-12 months, I figured. And we'd probably still fall short of the performance of a mature system like Parade/Tantivy.Or would we? I'd be experimenting long enough with AI-boosted development at that point to realize that with the latest tools (Claude Code + Opus) and an experienced hand (I've been working in database systems internals for 25 years now), the old time estimates pretty much go out the window.I told our CTO I thought I could solo the project in one quarter. This raised some eyebrows.It did take a little more time than that (two quarters), and we got some real help from the community (amazing!) after open-sourcing the pre-release. But I'm thrilled/exhausted today to share that pg_textsearch v1.0 is freely available via open source (Postgres license), on Tiger Data cloud, and hopefully soon, a hyperscalar near you:https://github.com/timescale/pg_textsearchIn the blog post accompanying the release, I overview the architecture and present benchmark results using MS-MARCO. To my surprise, we were not only able to meet Parade/Tantivy's query performance, but exceed it substantially, measuring a 4.7x advantage on query throughput at scale:https://www.tigerdata.com/blog/pg-textsearch-bm25-fu
AI
Hi HN!I recently switched from a Fedora/GNOME laptop to a MacBook Air. My old setup served me well as a portable workstation, but I’ve started traveling more while working remotely and needed something with similar performance but better battery life. The main thing I missed was a simple taskbar that shows the windows in the current workspace instead of a Dock that mixes everything together.I built boringBar so I would not have to use the Dock. It shows only the windows in the current Space, lets you switch Spaces by scrolling on the bar, and adds a desktop switcher so you can jump directly to any Space. You can also hide the system Dock, pin apps, preview windows with thumbnails, and launch apps from a searchable menu (I keep Spotlight disabled because for some reason it uses a lot of system resources on my machine).I’ve been dogfooding it for a few months now, and it finally felt polished enough to share.It’s for people who like macOS but want window management to feel a bit more like GNOME, Windows, or a traditional taskbar. It’s also for people like me who wanted an easier transition to macOS, especially now that Windows feels increasingly user-hostile.I’d love feedback on the UX, bugs, and whether this solves the same Dock/Spaces pain for anyone else.P.S. It might also appeal to people who feel nostalgic for the GNOME 2 desktop of yore. I started my Linux journey with it, and boringBar brings back some of that feeling for me.
AI
### Describe the project you are working on Godot C# bindings ### Describe the problem or limitation you are having in your project For the past weeks, I've been discussing with several Unity users intending to move to Godot C# regarding dealing with the C# garbage collector. The most common complaint I hear from users is that, in Unity, allocations can trigger unexpected GC spikes into the game. In Godot, we target to make all of the high performance APIs (those that intended to be called every frame) not allocate any memory, so theoretically the GC should not be a problem. Additionally, Godot starting from 4.0, uses the Microsoft CoreCLR version of .net, which also supposedly has a better garbage collector than Unity. But in all, after several discussions with Unity users, neither is enough reassurance for them, and they would really feel safer if Godot exposed a zero allocation API. ### Describe the feature / enhancement and how it helps to overcome the problem or limitation The idea of this proposal is that Godot exposes zero allocation versions of many functions in the C# API, that users can use if they desire. Technically, this could be done from the binding generator itself, without breaking compatibility, and without doing any modification to Godot itself. ### Describe how your proposal will work, with code, pseudo-code, mock-ups, and/or diagrams **WARNING** I am not familiar with C#, so take this as pseudocode. Imagine you have two functions exposed as to C#: ```C# void MyClass.SetArray( Vector2[] array); Vector2[] MyClass.GetArray(); ``` This works and is pretty and intuitive. However, it has two problems: * GC is allocated on return * Memory is copied to Godot native formats every time there is a call. The idea is to add NoAlloc versions, which can be generated directly by the binder automatically when required: ```C# void MyClass.SetArrayNoAlloc( Godot.Collections.PackedVector2Array array); void MyCl
AI