Hacker Timesnew | past | comments | ask | show | jobs | submit | zaphirplane's commentslogin

How do you ensure the cli can use the auth without knowing how to read it ? It’s potentially a bearer Token

Oldie but a goodie. Why would it matter thou

> 200m knowledge workers in the world, 30m developers

1 in 6 knowledge worker is a developer ! Surely that’s too high thou explains the job market


This sounds targeted, like 2 degrees of separation

It's just opportunistic people calling old people over the phone in hopes of tricking them into handing over some money for "an emergency" by claiming they're a relative. Really low effort scams, I'm not surprised they're using generative AIs to fake voices now, same sort of low-effort operation.

What is the governance and audit trail on offer ?

Like which country allows companies to not follow a legal directive. How weird

Why does it “sound” like a good thing for the company?

Unless it’s a mega establishment product people move on and don’t stick with buggy crashing products

This wouldn’t be acceptable for a car safety, well I could like a whole bunch but you should get the idea


The redirect to a bank is worrying, isn’t it trivial to fake redirecting to a fake bank ?

When I'm redirected to my bank, my bank shows my account name and some details (including a custom per-device avatar). Spoofing that would require gathering these small details.

Some banks have a custom device to scan a QR code, where the device generates a signing token but also shows the transaction details too. Regrettably, these are not too common, despite being the safest variant.


Not really, since in modern 3DS implementations, the redirect pretty much only shows a modal saying "check your phone for a notification and confirm this payment there".

Worst case, you'll be entering a one-time code received out of band, e.g. via SMS, and that message will mention what you are consenting to by entering it anywhere, so even MITM attacks are very hard.

The days of entering a static password in 3DS are long gone.


You'll need to fake much more than just that. Usually the bank website will ask you to confirm the transaction by opening the banking app on your mobile phone.

Trading a dependency on MasterCard and Visa for one on Google and Apple is at best a sidegrade. More likely you end up worse off.

> Trading a dependency on MasterCard and Visa for one on Google and Apple is at best a sidegrade.

That's really not how it works. You as the user are prompted to pick the bank you want to use, and then your bank prompts you to approve the transaction.

The only scenario I can think of that might involve google or apple is if you want to use Android or iPhone for mobile payments with NFC.


Which part of "confirm the transaction by opening the banking app on your mobile phone." does not depend on a banking app installed on a Google/Apple-controlled environment?

not really, the redirect itself is happening at EMV DS level, not by the merchant himself. Merchant has no idea what bank your card belongs to, so he does not know which bank to redirect you to.

I think they are asking about privileged communication


> pass a(n oftrn horrifically thorough) character background check.

Explains why so many let loose afterwards ;) jokes


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: