HN user

melody_calling

32 karma
Posts0
Comments18
View on HN
No posts found.

I'd be surprised if this was even noticed at all.

It's a third-party client making authentication and data collection requests, just like the hundreds of other credential stuffing toolkits (OpenBullet et al.) that are smashing the Venmo platform 24/7.

The most likely outcome for anyone using this is their account becoming restricted for unusual access patterns by the existing models already in place.

The Ragged Trousered Philanthropists by Robert Tressell.

Taught me everything I needed to know about being a painter.

Perhaps not the 'best' book ever, but certainly one of the most impactful for me as a common-or-garden 18-year-old realising for the first time that our political and economic systems aren't some sort of almighty edict and could be critiqued.

Love love love this. I recently saw something about Rails 8 (probably Kamal?) and decided to build a toy app using the main git branch parsing and displaying Telegram logs. I haven’t used Rails or done any front-end work since the traumatic 2->3 upgrade over a decade ago.

My two main takeaways were:

1) This is fun

2) Why do we put up with all this garbage in modern development

2a) Okay I guess Tailwind is more useful that I assumed

And it’s legitimately made me think I could build and launch something on my own, which I’ve never had the confidence to try before.

I hadn't realised until reading this, that I use this exact method for Best Buy.

Not intentionally though - I have my password stored in 1Password, so I know it's correct, yet every time I try to purchase something through bestbuy.com I trip some sort of ATO protection that falsely claims my password is invalid.

I'm entirely willing to believe it's something on my side (ad blocker, local DNS blacklisting, etc.) but after a certain number of occurrances, you get bored trying to debug the problem and just follow the path of least resistance.

Great read! I love a pour over, but it's always "...but only if you have time" because I know how much of a pain they are for the staff.

I wonder if the Starbucks story was one of those situations where the CEO had a pet project but the rest of the company silently conspired to kill it? I feel like I'd be the exact target market for this, yet I've never heard of either Clover nor Starbucks Reserve before.

I don’t think I’ve ever had a single interview that left more than about 60 seconds for candidate questions. Maybe you can tease some of this stuff out with the “hiring manager chat” as that tends to be less formal, but in panels?

What level/grade are folks generally talking about here? Or is this a difference between applying for a role vs. being hunted for it?

Every time this topic comes up, people delightedly mention the German Tank Problem, but I have never, not once, seen anyone post an actual example of when a modern business got rekt by a competitor using knowledge gained from monotonic IDs.

At $previous_job (payments provider), the sales engineers would often spot merchants using sequential order IDs and mention it to the account managers.

Rekt? I guess not, but knowing what percentage of their business we processed was extremely valuable information when it came to renegotiate the contract.

If you're just using python as a local scripting language, and not pushing production code, the other option is to simply not bother with any of this.

When there's a new python version I'm interested in, I install it via Homebrew and update my zshrc to clobber everything else via $PATH. All my scripts and tools are broken? Just reinstall the packages globally. Whatever.

Since the big 3.x transition, it's pretty rare for forwards-compatibility to break (IME), and if something does, I can just try running prior python3x binaries until I find the last version that worked.

It's hideous, but honestly the least stressful way I've found to date.

Well, you're halfway there. Each state already runs an immunization information system which holds this data.

In Arizona, it's required that all immunizations given to <=18s are reported (along with "encouragement" for providers to report adult immunizations) and this is the basis for determining if the child may attend a public school, for example.

I think part of the disconnect is communicating what the app actually does vs. what the terms permit it to do in the future.

It sounds like you've put genuine thought into this, and your privacy policy is very readable, but it suffers from the generic "WTFPL" clauses.

For example, you clearly specify who the third-parties are and what data is shared, which again is commendable. But it's combined with "we may use your data for [any] other purposes", "we may sell and may have sold [extremely personal PII]", and so on.

Are you doing this? Doesn't seem like it. Could you? Apparently, and that's part of the concern.

Perhaps obvious in this day and age, but bear in mind the privacy policy given that it has permission to read all of your browsing activity and obviously, all your bookmarks: We will not sell, rent, loan, trade, or the other way disclose your information with third parties unless such disclosure is necessary to: ... (d) promote our commercial interest