Live data from Hacker News

The toxic side of free – how I lost the love for my side project (part 4)

remysharp.com

141–150 of 185 posts

Re: The toxic side of free – how I lost the love for my side project (part 4)

#141
post #4

Regarding his fraud issue, I found that my website was being used in the same way when I added a credit card payment form. I implemented a system that first does an "Auth". If that passes, then I pass details to MaxMind and get back a response with a "riskScore". If the score is too high, I void the auth and decline the transaction. This has saved me a lot of chargeback fees, though it's still not perfect. I prefer P…

Are the details of Maxmind's algorithm available to you? I'm wondering what factors increase risk.

> The minFraud service determines the likelihood that a transaction is fraudulent based on many factors, including whether an online transaction comes from a high risk IP address, high risk email, high risk device, or anonymizing proxy. One of the key features of the minFraud service is the minFraud Network, which allows MaxMind to establish the reputations of IP addresses, emails, and other parameters.

- https://www.maxmind.com/en/minfraud-services

So not a full list of factors, but some of them...

Re: The toxic side of free – how I lost the love for my side project (part 4)

#143
post #122

Are US businesses obligated to pay VATMOSS? Does the EU have any recourse if you don't?

Yes and no. If you have a physical presence in an EU state, that one will probably get you for tax fraud. If you have sufficiently high transaction volume they might find another way.

I have never heard of it happening, but theoretically any member state in which you sold can start a criminal trial against the responsible persons, making travel to Europe a bit more complicated.

Re: The toxic side of free – how I lost the love for my side project (part 4)

#144

Earlier quoted context omitted.

It's ages since I've seen it used in the UK, although not 10 years. More like three or four. (The redirect sometimes happens, but it's automatically approved.)

I'm in France -- I still see it for almost 100% of the purchases I make online if the merchant is here in France, and a decent number of them when the merchant is in the UK. The last purchase I made with my bank card that got the interstitial page was about half an hour ago. It sends a text to my mobile for me to plug into the form to approve the txn -- thus, not like phishing in this case. But for a while this was a…

in turkey, any purchase online over 300 turkish liras must be 3D-secure. all debit and credit cards issued in turkey are automatically enrolled in the 3D-secure system. all 3D-secure transaction pages are hosted by issuer banks. they send us an SMS including a OTP and we enter it on the page and that's all.

Re: The toxic side of free – how I lost the love for my side project (part 4)

#145
post #97

Earlier quoted context omitted.

Yeah, "Verified by Visa" is exactly like phishing. Good paper. Fortunately here in the USA I haven't been asked for my credentials in at least 10 years. So it seems to have died the death it so richly deserved. Do people encounter this on a daily basis?

Visa and co. are big—really big—so I've never understood why they've not just leaned on the OS manufacturers and browser makers to provide them some form of unique, unforgeable signal to users that they're interacting with a real bank. There could be, say, an HTML5-exposed API capable of triggering "super-modal" forms (like OS UAC does) if-and-only-if the page is being served from a secure origin cross-signed by some…

How about OTP-enabled credit cards? [1]

For every transaction the customer must enter the OTP. It wouldn't serve much for subscriptions, though.

[1] http://web.deepnetsecurity.com/products2/PocketID.asp

Re: The toxic side of free – how I lost the love for my side project (part 4)

#146
post #115

Earlier quoted context omitted.

If you're dedicated enough to follow the bliss, it will pay your bills, and also do the other things. If you have failed personally, please don't discourage others. Programming can be bliss, at least seeing the results. I mean, why else would anybody program? Just for the money?

> I mean, why else would anybody program? Just for the money? Considering the pay, absolutely!

Then, I would recommend, through experiences of doing what I dont love long enough, to reconsider what is more important, money or doing what you love. Of course, sometimes it can be just the money, or the learning, or working with a great team, but to recognize when it turns into a struggle and just drains our energy is something that is important.

Working with software, it is such a toll on the mind and the body, that doing it just for the money seems really pointless at least for me.

But I understand that this realization may come through only going through enough work that is not really fulfilling us inside on a deep level.

On a superficial level programming can be good just to gather resources, but is this really the best we can do? I mean, what if Elon Musk, Nikolai Tesla, Newton or other brightest minds would just worked for money ? Would we have the inventions we have today ? This is my point I want to remind people everyday.

I have worked for 5 years (3 of those fulltime, and so that I have always managed) on a project (http://GeoKone.NET and now http://Geometrify.net) that is the product of my pure love, and at times it has been difficult, yes, eaten a lot of porridge during those days, but the Universe has a way of supporting those who really want to help others, and to provide something to support others in their quest too!

But you have to give back something too in order for it to work. I think this is also a big problem in our society right now, not giving back, but just gathering resources for selfish uses, like many big companies do.

This is why I am reminding to really think about what we are putting our energy into.

Re: The toxic side of free – how I lost the love for my side project (part 4)

#147
post #127
post #97

Earlier quoted context omitted.

Visa and co. are big—really big—so I've never understood why they've not just leaned on the OS manufacturers and browser makers to provide them some form of unique, unforgeable signal to users that they're interacting with a real bank. There could be, say, an HTML5-exposed API capable of triggering "super-modal" forms (like OS UAC does) if-and-only-if the page is being served from a secure origin cross-signed by some…

The better way to do this would be some sort of two-factor thing – e.g. imagine if the physical card had the equivalent of an embedded RSA-style one-time code generator or, better, a U2F USB/NFC device – which would be resistant to UI spoofing or, in the U2F case, phishing. Unfortunately the banks have less motivation to invest in this as long as the costs of fraud are pushed onto merchants and all of the major playe…

Something similar was used in the UK for online banking, using a small reader [1]. It's a feature of EMV (chip) cards.

[1] https://c2.staticflickr.com/2/1218/1438197131_1e0d474266_b.j...

Re: The toxic side of free – how I lost the love for my side project (part 4)

#148

Earlier quoted context omitted.

> I guess they think typical business is like Google or Amazon or something. Exactly. Many in the EU imagine that "business owner" is a synonym for "evil capitalist plutocrat." For them, if you are not someone's employee, you are by definition rich. Questions of scale are ignored.

I don't think, that so many (at least educated) people in the EU believe that ... but the problem is (and I saw evidence for that again and again), that the politicians like to talk about the "Founder culture" or that they want to aid smaller businesses ... but in fact, they do the absolute opposite. I see that, because at least in Germany (where it is very chic in the political class to talk how to aid smaller busin…

I know two people who tried to start a business in Germany and failed, not because of the EU but because of domestic, German rules.

One tried to start some kind of innovative form of pharmacy (the details weren't clear to me), but found himself unable to join the pharmacy guild, and apparently it is illegal to start a business without joining the guild. The other tried to start a bed & breakfast business, but the 'breakfast' part was closed down indefinitely when the food safety inspection found he didn't have the right license for a Sandwichtoaster. Apparently there are different regulations for serving a hot breakfast.

Re: The toxic side of free – how I lost the love for my side project (part 4)

#149
post #11

Okay, say you're a US citizen building some digi service like JS Bin, and VATMOSS starts fling threats at you, for how long can you go about ignoring them? I mean 3.5k GBP and however many weekdays it took isn't exactly affordable for every small business, and if you don't even have many Euro pro-users, I don't see the cost-benefit justification of giving VATMOSS priority unless they can reach across the Atlantic.

Depending on the kind of service, a good solution is to use a third party provider that handles VAT payments for you; FastSpring, for example: http://www.fastspring.com/vat (disclaimer, I am a happy FastSpring customer in the US, but have no other relationship with them)

Does this work if I am in the EU?

Re: The toxic side of free – how I lost the love for my side project (part 4)

#150
post #123

Earlier quoted context omitted.

I have a complex notice written entirely in Spanish that I can't understand, but which with the help of Google translate I have decoded to indicate that some 100 odd euros is being withheld from me as the customer paid for my services and has voluntarily paid some kind of tax on my behalf. I am sure with sufficient effort I can probably find a way to get that 100 euros refunded, but boy, it sure aint worth my time. B…

How do you distinguish between that and some form of scam/fraud?

I suppose that's a good point - it would be a remarkably well executed scam, since it had all the account numbers, and details that I use with that client, as well as the actual amount from the invoice I sent them, printed on it. I didn't hesitate to believe it at the time.
Post reply on HN