HN user

hwatson

118 karma

https://lobi.to/

[ my public key: https://keybase.io/unlobito; my proof: https://keybase.io/unlobito/sigs/Iy8zKJKK7Y6sD-cMEnDqo3RAsQYfgnCMs3yNL40plws ]

Posts10
Comments35
View on HN

It’s a shame these have become more commonplace.

Northern started issuing them instead of cardboard tickets a few years ago and other TOCs followed along after Network Rail/Cubic finished adding barcode readers to ~all ticket barriers.

I understand why: paper barcode-only tickets are significantly cheaper than cardboard tickets (their lack of a magstripe allows any generic thermal printer to be used), but their larger form factor makes them a definite UX downgrade.

I think this is less of a big deal in London because-- and the article entirely glosses over this prospect-- TfL accept contactless (e.g. contactless-enabled debit/credit cards, Apple Pay, Google Pay, Samsung Pay). This means anyone can land in London and immediately ride public transit using their existing bank card.

Judo Payments | Angel, London, United Kingdom | Full-time

Judo makes buying the things we want faster, simpler and more secure. As Europe’s leading secure in app and mobile first payments platform, we’re riding an unstoppable wave as smartphones change the way we engage in commerce.

We sit at the intersection of mobile, SaaS and payments, three of the fastest growing and most interesting sectors of the global economy. Our customers - big brands and innovative Startups - win awards because of our outstanding people.

Founded by serial financial technology entrepreneurs in 2012, Judo is backed by leading VC and hedge fund investors.

We're looking for: - DevOps Help design, build and maintain our IT infrastructure to meet our growing needs. Monitor and maintain our production platform keeping all components in top working order. Automate all the things; help us scale quickly by automating all the daily chores leaving you to focus on infrastructure improvements. Strong Microsoft Active Directory knowledge, including associated functions such as Group Policy, DNS etc. Experience of Microsoft Windows Server 2008 / 2012 & Linux. High level of automation using Octopus/ssh/powershell/bash. Experience of Docker. Experience of PCI.

- Postgres DBA Developer Experience of working on very high transactional load in always on mode. Experience with highly volatile load profiles. At least 2-4 years of administering large PostgreSQL databases. Experience in performance tuning / index maintenance, able to meet and assist the needs of the Development teams using PostgreSQL as its backend database. Designing and Managing PostgreSQL database schemas. Experience in Security access control. Experience with version control. Experience with 24x7 zero downtime database management. Experience with Java and high-available web applications. Knowledge of fault detection and resolution processes. Ability to communicate effectively to different levels of technical and non-technical audiences. Implement Database Change Controls. Experience supporting BI internally and for customers. Experience of, or willing to learn alternative database technologies (NoSQL) such as Mongo, Redis, Cassandra.

Our stack is based on C#/ASP.NET MVC, jQuery/Angular, RabbitMQ, and MS SQL Server/PostgreSQL.

If you're interested, please email lindy.roberts@judopayments.com for more details.

Considering that 100Mbit/s is 12.5MByte/s, the speeds you're seeing aren't horribly distant from your "up to" speed.

[For reference's sake, 8MByte/s is 64Mbit/s and 9MByte/s is 72Mbit/s

Stripe Connect v2 11 years ago

No. Creating the customer will charge the card $0.00 or $1.00 (depends on country/bank) and immediately refund the charge to verify the card itself, the CVC, the address, etc. In most cases, this tiny charge won't be noticed because of the refund.

I wasn't aware of Wells Fargo issuing Chip and PIN cards[0] and I appreciate you pointing that out!

The other USA banks that I've looked at (Bank of America[1], for example) issue signature-only cards. These not working in unattended kiosks is mentioned in the last paragraph of the Wikipedia section we're both referring to.

The main problem with Chip and PIN cards in the USA is PIN management. Since EMV was developed before every ATM was online, the card needs to be aware of its PIN. Not many USA ATMs support reading EMV cards, which makes changing the PIN on the card difficult.

This is why Wells Fargo[0] don't allow you to change your card's PIN and is why many USA banks simply chose to skip PINs altogether. The last sentence of the Wikipedia section we're referring to mentions this.

[0] https://www.wellsfargo.com/credit-cards/features/chip-card/f... [1]: https://www.bankofamerica.com/privacy/faq/emv-chip-card-faq.... under "Using chip credit cards" see "Bank of America doesn't currently offer consumer credit cards that include PIN authorization for purchases." Debit cards can be PIN authorised when running them over the online interbank networks, which makes offline PIN management irrelevant.

As an aside, no USA banks issue chip and PIN cards. The EMV-capable cards being rolled out are chip and sign cards. This usually doesn't matter but can cause issues at fully automated tills (the common example being issues when trying to purchase transit tickets).

Wikipedia's article on EMV has a section explaining the technical differences[0] between the card types.

[0] https://en.wikipedia.org/wiki/EMV#Chip_and_PIN_vs._Chip_and_...

Each message is encrypted individually for each device that will be receiving the message. As a result, unless Apple slip a public key they have control over into the keys reported for the receiver, they cannot read your messages. (This is why abalone mentions that Apple do not have access to your old messages.)

http://blog.quarkslab.com/imessage-privacy.html goes into detail as to how the key exchange process works.

Digital Ocean, for example, won't give you more than 1 IPv4 address per VPS, which means you need a separate VPS for every side project, if you want to go HTTPS.

As long as you're not supporting clients running IE on WinXP or other similarly old web browsers, Server Name Indication (where the hostname is included as a part of the handshake) will work and it'll eliminate your need for more than one IP.

Take a look at me.com, for example. Before Apple bought it, it was owned by SnappVille.com. If SSL certificates didn't expire, SnappVille could have continued using their certificates for me.com.

Yep. You'll normally see this happen if you restore an iPhone backup onto another iPhone then try to launch WhatsApp. Login will fail and you'll be asked to type in the SMS received.

> If you’re in the US, you can’t download updates for your non-US apps due to IP address constraints.

That's odd. I live in the Dominican Republic and I've been using a US iTunes Store account since 2008. Even when the Dominican iTunes Store opened earlier this year I wasn't affected, I'm still able to purchase/update apps like normal. I don't have a DO iTunes Store account so I guess that has something to do with it.

Your 1Password keychain is stored locally and is never uploaded to Agile's servers. The attacker would have to upload the keychain first (or break into your Dropbox, if you have it stored in there)

The blog seems to have gone down. It's just a blog entry that says:

> We are currently experiencing an Denial of Service Attack against DNS1, DNS2 and DNS3 anycast strands.

> We are working on mitigation and will post updates as they become available.