HN user

sleepyhead

1,552 karma

I make https://makeplans.com

Posts42
Comments528
View on HN
techcrunch.com 3y ago

Instagram fined €405M in EU over children’s privacy

sleepyhead
40pts2
blog.makeplans.net 5y ago

Avoid Stripe currency conversion fees using TransferWise

sleepyhead
6pts0
twitter.com 5y ago

Clubhouse uploads all your contacts

sleepyhead
120pts32
blog.makeplans.net 5y ago

A five year dreaded feature request done in 15 minutes

sleepyhead
1pts0
tripmode.ch 5y ago

TripMode 3

sleepyhead
1pts0
blog.chromium.org 6y ago

Rethinking Payment Request for iOS Chrome (Jan 2020)

sleepyhead
2pts0
translate.google.com 6y ago

Instagram censors pro-Iranian statements

sleepyhead
1pts0
mailchimp.com 7y ago

Mailchimp Statement on Shopify Partnership

sleepyhead
15pts2
blog.makeplans.net 7y ago

We are not a platform

sleepyhead
1pts0
hbr.org 8y ago

The Case for Plain-Language Contracts

sleepyhead
2pts0
flexibits.com 8y ago

Cardhop – OS X adress book app from Flexibits

sleepyhead
1pts0
twitter.com 9y ago

Heroku seemingly shuts down third party app Nezumi

sleepyhead
1pts0
github.com 10y ago

A simple and fast JSON API template engine for Ruby on Rails

sleepyhead
4pts0
github.com 10y ago

Rank your GitHub repo's issues by demand

sleepyhead
2pts2
www.youtube.com 10y ago

Piñatas delivered by drones

sleepyhead
2pts4
www.dn.no 10y ago

Inside Popcorn Time – the world's fastest growing piracy site

sleepyhead
337pts336
blogs.opera.com 11y ago

Jon Hicks joins Opera

sleepyhead
2pts0
twitter.com 11y ago

Instagram using expired SSL certificate

sleepyhead
1pts0
sslmate.com 11y ago

SSLMate – Buy SSL certs from the command line

sleepyhead
118pts67
medium.com 11y ago

A computer on every wrist

sleepyhead
1pts0
brianritchie.me 11y ago

Why “Growth Hacking” is a bullshit fad

sleepyhead
3pts0
wake.io 11y ago

Wake

sleepyhead
6pts0
web.whatsapp.com 11y ago

WhatsApp Chrome App

sleepyhead
5pts0
nomadsms.com 11y ago

Nomad SMS

sleepyhead
2pts0
github.com 11y ago

Refile – Ruby file uploads, take 3

sleepyhead
3pts0
www.nationmultimedia.com 11y ago

The Pirate Bay Co-founder Arrested in Nong Khai

sleepyhead
3pts0
talk.sonymobile.com 11y ago

Sony Xperia phones come with Baidu spyware?

sleepyhead
70pts64
2014.javazone.no 11y ago

Game of Codes

sleepyhead
3pts1
blog.arshaw.com 12y ago

FullCalendar 2.0.0 Released

sleepyhead
2pts0
github.com 12y ago

Oj – high performance json parser for Ruby

sleepyhead
2pts0

I flew 747 last month with Lufthansa and asked one of the crew how long they will keep it in operation. «I retire in two years so I don’t care» a very German response but at least they hadn’t made any announcement that he seem to be aware of.

Always fun to be on the second floor despite the seat configuration being a bit dated.

[dead] 8 months ago

Claiming DHH is a fascist is such a dumb take. The article is vile; claiming DHH died. "'DHH has brain worms' is a fact and valid" - grow up.

Heroku Is Down 1 year ago

Their EU region was down for 8 hours last November and it took 2 hours before they were aware of it so submitting a ticket is definitively worth while. I'm suspecting their monitoring is not good enough.

418 I’m a teapot 2 years ago

Sure, but if the server is returning 418 by an error it is likely that it would return some other 4xx error instead of 5xx. 418 is irrelevant here, the server is rogue.

418 I’m a teapot 2 years ago

I don't get it. If the system is so broken it is returning some random http code then I don't see how returning some other random http code is better?

Most data formats used in high performant scenarios, for example in finance, are very basic for a reason. You also get the benefit of being able to start processing the file immediately line by line, instead of having to read and parse the entire file.

Showing duration is helpful but so is the exact end time. Visually as a user I would like to see the exact time when the appointment ends instead of calculating it in my head. While it is not that hard to process when an appointment with a duration of 4:15 ends after starting at 2:30 but still.

As for API it makes a lot of sense to expose end time. If you for example are creating a calendar widget then it has start and end datetime for all events. With only duration available in the API output you know how to calculate the end time. More lines of codes for you.

Fetching from the API you would in most cases limit it to certain dates, for example next week. So now you suddenly do have to deal with start and end time. Not having it otherwise makes no sense.

Never had any developers ask for outputting duration in our scheduling API. It would be useful to include it but since no one have asked about it then I think having end time is more critical. https://developer.makeplans.com/#attributes-1

It’s for the booking site so most visitors come to make a booking thus conversion rate would be high generally. We never had passwords there so can’t compare conversion rates.

For signups to our app (to get an account with a booking site) we require a password.

It is not but CCC is indicating that this provider was only used for 2FA. Sorry I was getting a bit ahead of myself here, this was earlier exposed as a breach of Twilio's vendor (IdentifyMobile). In the case of Twilio they offer an API for 2FA, Twilio Verify. I wanted to clarify that this breach was not only for 2FA, Verify API in the case of Twilio, but for all SMS sent through IdentifyMobile.

We at MakePlans were affected by this breach as we use Twilio. We are not using Twilio Verify (their 2FA api) but rather handle 2FA SMS ourselves in our app using Twilio as one of our providers. So the CCC definition of this being only 2FA-SMS is incorrect, it was all SMS sent through this Twilio third party gateway that was exposed to a limited set of countries (France, Italy, Burkina Faso, Ivory Coast, and Gambia).

GDPR is not necessary applicable here. An SMS gateway is most likely classified as a telecom carrier, and thus any local telco laws would be applicable and not GDPR. That applies only to the transfer of the SMS though, so for example a customer GUI of sent SMS would be out of that scope.

(And before someone tells us that SMS 2FA is insecure I would like to point out that we use this for verification purposes in our booking system when a customer makes a booking. So for end-customers, not for users. It is a chosen strategy for making verification easy as alternatives are too complex for many consumers. All users however authenticate with email and password, and have the option of adding TOTP 2FA).

Yes I received more info as well. Apparently they think that GDPR does not apply to them in this case. Good luck with that.

"To answer your questions:

1. Only France, Italy, Burkina Faso, Ivory Coast, and Gambia were impacted by this incident, only the traffic sent to these countries.

2. To provide you more context, Twilio’s carrier partners are not considered to be Twilio's processors (or Twilio's customers' subprocessors) under the GDPR because carriers transmitting communications content (i.e., Customer Content) are not considered to be processing the personal data contained in the communication. There are a number of reasons behind this positioning: • “Disclosure by transmission” is called out in the GDPR definition for 'processing' rather than transmission without disclosure. • A processor role does not fit the nature of telecoms services and the telecoms value chain; Confidentially (and security) of communications is safeguarded by the ePrivacy framework. • Guidance from the EDPB specifically covers “telecom operators” and does not specify a role for the carrier with respect to the content of the communication. • Communications content merely transits a communications network or service, without significant processing being involved as confidentiality of communications prohibits the carrier from gaining access. • Any other position would be impossible to implement given the complexity of the telecommunications value chain, with many parties involved in the origination, transit, and termination of communications content."

The email is unfortunately lacking in some details. Does this include all messages sent through Twilio or just in the country of this provider?

And why is this carrier storing messages on an S3 bucket? I don't see why they should store messages at all after the message has been processed, storing metadata should be sufficient for their records. It would be definitively be problematic according to GDPR, if IdentifyMobile is a Briths company then similar privacy laws should be in place?

Campfire 2 years ago

Your expectations might have changed. Most users are quite happy with core chatting features. And in the case of Slack those features have become a bit too intrusive and disorganised, so that is one of the selling points of Campfire.

Campfire 2 years ago

Campfire was originally launched way before Slack though.