I have. It was right at the introduction of the redesigned model year so people that wanted to be one of the first to own the car were paying roughly MSRP. Costco got me to GM Supplier pricing and a $700 Costco cash card with zero negotiation needed from my side. Salesperson honored it with no hesitation. I was also able to stack Manufacturer discounts (GM Cashback and GM Private Offer) so when all said and done I paid just a little under invoice.
HN user
rtanaka
I do stuff at https://poynt.com
It is indeed fixed but updating iOS app alone does not change the permissions. I had to sign out of the app, revoke the permissions on google and then sign back in.
I don't believe there's a single recruiter that's a good fit for anyone / everyone. If you form a good relationship with a well-connected recruiter they can definitely be an invaluable resource for you that help you get interviews that are outside of your network. It's also worth noting that, like most relationships, it something that is fostered over time, not just when you are job hunting.
Quality recruiters are very in-the-know as to who is hiring, what the going salaries are and are able to help you back-channel and get the scoop on people and companies.
The liquid (also comes in spray form) still exists. It's called a Magnetic Developer: https://en.wikipedia.org/wiki/Magnetic_developer
Yup, after you tokenize the card CVC (CVV2, CID, etc) is no longer needed. So even though it will change it won't affect the validity of the card since this sounds like a deal with the networks. Also, you're not allowed to store CVC any way so the system has to work without it. In some cases where fraud is suspected some processors can / may ask you to provide your current CVC before letting the charge go through.
I had no idea these payphones operated at 130 VDC. Seems crazy in this day and age.
An experience like that is inevitable but it likely won't be through this solution. As it stands, LiFi requires a light source to illuminate a product which isn't exactly scalable. What you're describing feels far more likely to happen through image recognition technology.
LiFi is still a neat idea though.
We designed a solution to keep the switching logic between standard touch and PIN entry within PCI scope such that PIN entry is not even visible at the lowest levels of Android (and thus 3rd-party apps). Also, 3rd parties do not get to run on or take control of that screen.
As mentioned, the point at which the dialog for tip is presented (before or after CVM check) is a configuration option for the merchant. Keep in mind we are deploying a US solution first. We are also anticipating that in the US we will have signature as the primary CVM before PIN. From that perspective, our flow will should be a little less odd.
That said, in the true Chip & PIN solution, once you ask for tip after PIN entry you as the merchant are opening yourself up to higher rates (Card Not Present) as well assuming liability for chargebacks. I don't know why a merchant would want to do that but as a platform we have chosen that use-case as an option.
We aren't storing actual card data encrypted or otherwise. As you said, we are a passthrough as far as the payment portion is concerned. We do store a hashed representation of the card for things like refunds (referenced credits).
Our security subsystem is being built to be FIPS 140-2 Level 3. Complete with tampers seals, switches and a security mesh that will destroy sensitive keys when triggered.
No problem. I've been mostly a lurker on HN for a while but this is the first time being put under the microscope. I apologize if I came off as defensive. This is a product that's very close to my heart given the amount of time and effort we've put into the product offering. For the record, none of us here posted the article we are here because of the amount of attention and discussion it has garnered.
Point taken about the errors. There are many things we can improve on all across the board. We made a conscious decision to not let perfect be the enemy of good. The video is done so we won't go back and change that but I will work with the team to fix all of our marketing material to be as accurate as possible. Thank you for pointing out or errors.
With regards to tip entry. Industry standard recommends gratuity be added before PIN but it is not mandatory and is a merchant preference. I can't find all the card network examples easily but I happen to have the AMEX EMV Acceptance Guide open and this is what section 4.2.7 states - "In certain Merchant categories such as restaurants, it is standard practice to enable customers to add a gratuity to the amount of the transaction. There are many different ways in which a gratuity can be added. American Express does not define any specific methods for adding gratuities..." it further goes on to say "American Express recommends that Terminal software enables the Cardmember to add the gratuity amount to the transaction before entering his or her PIN. This enables the transaction to be processed as a normal, “card present” transaction."
In any case, we've all appreciated the various comments on here and it has clearly been the most critical audience of the bunch.
We are in the process of both PA-DSS for our cloud services and PCI approval for the device. This is the primary reason we are not shipping to merchants until next year. We have line of site to certification and we would not (and can not) ship to merchants until this is complete.
I've always felt like it's harder to spy on an LCD screen due to the limited viewing angles as opposed to physical buttons. And the physical layout of the PIN pad should be similar so it should be a smooth transition. The device will also be PCI PTS approved so it will be on par in terms of physical and logical security.
A very valid concern.
To begin with, while our terminal is Android based we have taken numerous steps to lock this device down. Side loading apks is not possible nor is arbitrary access via adb. On top of that, we take great lengths to protect consumer data. In addition to full PCI compliance data is fully encrypted on the device. And if that's not enough, there are several anti-tamper mechanisms that will trigger and lock down the device even further upon physical instrusion.
In terms of physical theft we are actively looking into an option to physically secure the device (think kensington). Our plan is to have a good solution for this before our merchants go live.
Okay, I'll bite. I'm an employee so you'll have to take what I say with a grain of salt.
The video was produced with a cosmetic device and with actors. You're right that the card has to be in the device during PIN entry. The scene you're referring to, however, is depicting tip entry.
The device does not have an ethernet port but we will be shipping with a separate charging dock that will provide wired connectivity.
I can assure you that all of our antennas are not behind LCDs. While compact, the device does have a number of non-LCD surfaces.
The customer facing camera is pointing horizontal. We'll continue to refine the angle (if needed) as we continue testing with our early adopters.
We did in-person demos with over a dozen news agencies. If you have any doubts about the existence of the device, please feel free to reach out to them for confirmation.
poynt employee here. you can open the device and insert a new roll of paper without flipping it over or turning off the device.
Has this happened to anyone? What would happen if you showed up and find that your ticket is invalid. I'm guessing it varies by venue but is there any recourse? I can't imagine they'd just turn you away without at least a little investigation.
It was hard sticking to $25 but other than that one investment I was able to remain patient even though it took me almost 6 weeks to invest my full amount. There was just one person I really felt like I could take the extra risk. Incidentally that person paid off the entire loan in the first payment.
I'm sure they do and I hold no ill will toward them. I still feel bad about it though which takes away from how I feel about lending club.
I started in January of this year. It does seem high for sure. I'd like to think I spent a lot of time finding people that had the most to lose when making a decision (mortgage, relatively high income, stable job, etc) to lower my risk. But who knows.
edit: so i just checked for real. looks like it's been over a year (time flies). for the record, it shows 199 (instead of my stated 200) because i put $50 into one investment instead of the standard $25. http://i.imgur.com/o2DdDLU.png
I went with mostly B/C since they seemed to yield the best return for the risk. Here's the actual breakdown: http://i.imgur.com/egbkFfh.png My charged off one is B and I have an A and a C that are 31-120 days late now.
edit: updated with actual chart and data (i guessed the first time)
I spent a lot of time handpicking my 200 investments and I'm sitting on a 12.23% (adjusted) return right now. I think by most measures, this would qualify as a good experience. For me though, it's not. When someone defaults on me (I've had 1 officially and 2 more that will likely get charged off soon) I feel bad about it. Yes, it's expected and yes, LC makes a reasonable amount of effort to collect but it doesn't help how I feel. Especially when the people filling out the loan application write things like, "I'm a hard worker. I always pay my loans back, etc, etc" As someone, that would never short change someone on money owed I feel very let down when it happens to me and I take it a little too personally. It also doesn't sit right with me that LC takes a cut of every payment but doesn't share the pain of losses in any way. What it boils down to, I suppose, is that LC is just not the right investment vehicle for me.
edit: correcting default stats.
Just in time to go along with their phone that's coming out.
Hmm, it appears you're right. I was coming from a proper P&L perspective: http://en.wikipedia.org/wiki/Profit_and_loss_statement#Usefu...
it's not. revenue is a top line item before expenses. otherwise it would have to be stated as profit.
I'd describe it as an unlimited number of emails that you can send with a limit of 1000 unique email addresses that you can send to.
it doesn't directly affect it because EMV is a card present initiative (online transactions are card not present transactions). that said, these newer cards tend to be more "advanced" in the sense that they have on-display rotating pins or support for two-factor authentication so payment providers will need to be able to support them. these changes will be driven by the card issuers.
Just to add to that - it's $14 million on top of a $2.7 billion project.
I just signed up here: https://gaeforphp.appspot.com/
Updated. It might not be a bad idea to add that to the application process. I'm sure there are people that won't see this message.