Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
matthewarkin
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
31.
▲
by
matthewarkin
11y ago
You could take a look at combining ACH and Stripe Connect.
32.
▲
by
matthewarkin
11y ago
a lot of time spent in Stripe's IRC chat room, recommendations from Stripe support to users
33.
▲
by
matthewarkin
11y ago
You can, just not everyone has access or the ability to write server-side code. For instance if you used Wix, Squarespace, some generic website builder you often have no access to the underlying server-side code.
34.
▲
by
matthewarkin
11y ago
the ssl itself was only $10/year, the $20/month heroku charges you to use a custom ssl cert.
35.
▲
by
matthewarkin
11y ago
yeah, but I wanted SSL for the complete trip, free SSL would terminate at Cloudflare leaving the connection from Cloudflare to Heroku not-protected (which would be questionable from a PCI perspective). And then for some reason, I couldn
36.
▲
by
matthewarkin
11y ago
Their SSL endpoint, I plan on just moving to an ec2 instance
37.
▲
by
matthewarkin
11y ago
Commencepayments.com, costs me $40 a month to run (though if I wasn't lazy I could drop it significantly - $20 for heroku + ssl and $20 for cloudflare) launched last February and just hit the $1000 mark!
38.
▲
by
matthewarkin
11y ago
I can say that my last few tickets have been faster than normal, definitely not 3 hours though. And currently I have an issue open since Friday
39.
▲
by
matthewarkin
11y ago
I estimated 1 minute to roughly include research and reproduction time. The week estimation was then based on a 40 work week
40.
▲
by
matthewarkin
11y ago
Yeah, to my recollection I can't recall a single person joining the irc room with a python code base, I can't really say why or why not, but it should be noted that it is popularity in terms of support, not in terms of api request
41.
▲
by
matthewarkin
11y ago
Failures caused by this should have returned an api_error, a card_error (like card declined) would have been returned upstream from Stripe.
42.
▲
by
matthewarkin
11y ago
Woot, a postmortem from Stripe! I've been asking for these for over a year and hopefully we'll see more from them in the future.
43.
▲
by
matthewarkin
11y ago
Location: San Francisco, CA Remote: Yes Willing to relocate: Yes Technologies: Node.js, Elasticsearch, Couchdb, Java, Mongodb, Swift Résumé/CV: https://mattarkin.com/wp-content/uploads/2015/10/Arkin-
44.
▲
by
matthewarkin
11y ago
Its pretty common for Stripe Connect integrations to charge an application fee. With Relay, Stripe would allow some apps that use connect to "move" their products database from their own database to Stripe. Also it allows merchant
45.
▲
by
matthewarkin
11y ago
It depends on the country, Canadian Stripe accounts support USD denominated Canadian bank accounts.
46.
▲
by
matthewarkin
11y ago
You only need a US bank account to open a US Stripe account, other countries don't require a US bank account
47.
▲
by
matthewarkin
11y ago
Pricing for Windows 10 has been announced, $110 for Home and $199 for Pro. You have 1 year to upgrade for free, then you have a license for Windows 10 forever for that machine and you'll be supported for the lifetime of that device (as
48.
▲
by
matthewarkin
11y ago
I've learned quite a bit from IRC (mostly in #stripe). Though the learning has been way more indirect since I spend most of my time helping others. So people would ask "how do I do X?" and the learning comes from researching
49.
▲
by
matthewarkin
11y ago
The issue with AVS is that it only matches numbers (so 123 Main Street and 123 Maple Street could both return true). The other issue is apartment numbers. If the address on file is 123 Main Street #123 but the customer puts #123 on line 2 i
50.
▲
by
matthewarkin
11y ago
They do have a user ticketing system (Uservoice), there is just no user facing view of it. When you send an email to support@stripe.com (or any of the public email addresses they put on blog posts), it goes to Uservoice. Then it gets triage
51.
▲
by
matthewarkin
11y ago
This selling point also causes many of the issues Microsoft and Windows is known for. With choice comes compatibility issues with often leads to crashes and blue screens. Apple can ensure the latest version of their OS and Apps work on all
52.
▲
by
matthewarkin
11y ago
At least in the Valley, hours tend to be flexible, at my current position, people walk in between 8 and 11. My team's stand up is at 11 so the rule is be in the office before them, but even then sending an email saying that traffic was
53.
▲
by
matthewarkin
11y ago
Given the recent PCI Discussion. As opposed to Stripe.js where the credit card inputs in a custom designed form live on the merchant's DOM, Braintree just set it up so that it replaces each field with an iframe (that also allows for cu
54.
▲
Braintree Hosted Fields
(braintreepayments.com)
3 points
by
matthewarkin
11y ago
|
1 comments
55.
▲
by
matthewarkin
11y ago
I think more awesome, was the hosted fields you just launched, so that I can have a custom, stylized form where each credit card input is its own iframe. https://www.braintreepayments.com/features/hosted-fields
56.
▲
by
matthewarkin
11y ago
Last I checked this was also only offered for credit cards, not their debit cards :(
57.
▲
by
matthewarkin
11y ago
Historically, the thought has been that the iframe and a redirect could both be treated as SAQ A (the easiest form of compliance), was because if you changed the iframe that was displayed or the page the customer was linked to it would be e
58.
▲
by
matthewarkin
11y ago
The new Stripe.js does not render an iframe, the credit card information is still entered on your site so $("#credit-card-number").val() would return the card number. The transmission of the card data happens through the iframe. S
59.
▲
by
matthewarkin
11y ago
Stripe got their QSA to renew them but Visa hasn't updated their site was what I was told. Their Attestation of Compliance: https://www.dropbox.com/s/xpk1n72n0gtd5o5/Stripe_AOC_2015.pd...
60.
▲
by
matthewarkin
11y ago
Thats basically the concept, once you have malicious js you can replace the iframe with a malicious one that looks the same. You can even have it still create a legitimate card token, so in theory the website would never know they are hacke
More ›