Live data from Hacker News

I accidentally loaned all my money to the US government

beanlog.vercel.app

191–200 of 512 posts

Re: I accidentally loaned all my money to the US government

#191
post #62

> They require you to enter your password by clicking on a virtual keyboard. This pseudo-security measure actually only slows down humans, not bots, because you can still edit the value of the text field using Javascript. I don't think this is generally worth it as a security measure, but the goal is not to protect against automation. Instead, custom on-screen keyboards are attempts to thwart keyloggers.

Which is ridiculously annoying. I have to edit the HTML every single time to remove "readonly" on that field and paste in my randomly generated password.

> I have to edit the HTML every single time to remove "readonly" on that field

Couldn't you do that with a bookmarklet, so it would just take one click?

Re: I accidentally loaned all my money to the US government

#192

Alternative title: "I purposefully tried to make a transaction that breaks the rules, it didn't end well."

So if someone makes an honest mistake and types and extra number, it's OK to both 1) don't process any amount and 2) hold the money for two months. That doesn't feel right to me. E.g. I buy shares and mistype the ticker or buy extra. It processes but then I notice my mistake and I can either fix it by selling, or decide ir doesn't matter and keep the shares. What doesn't make any sense is the broker keeping the money…

Have you ever paid taxes in the US? The IRS loves creating scenarios that lead to them incorrectly holding big wads of your cash.

Re: I accidentally loaned all my money to the US government

#196
post #62

> They require you to enter your password by clicking on a virtual keyboard. This pseudo-security measure actually only slows down humans, not bots, because you can still edit the value of the text field using Javascript. I don't think this is generally worth it as a security measure, but the goal is not to protect against automation. Instead, custom on-screen keyboards are attempts to thwart keyloggers.

> Instead, custom on-screen keyboards are attempts to thwart keyloggers. Commercial malware doesn't work this way. The term "keylogger" is a misnomer. "Keylogging" without context provides an unintelligible stream of garbage that might have well be from a random number generator. Most malware that I've seen either directly target the browser or the operating system, but in both cases they're looking for an unencrypte…

That's why keyloggers also log the title of an active window.

Re: I accidentally loaned all my money to the US government

#198

Earlier quoted context omitted.

Incidentally, that exact confusion is why he made the third transaction for $9,975. The refund on his second transaction will either be for $25 or $10,000, so his third transaction will either be refunded in full or not at all.

If they refund the entirety of the second transaction, logic follows a third transaction of $9,975 would be correct if you actually wanted to buy $10k. I suspect that's not what's going to happen though. OP will get a refund of $25 + $9,975.

[deleted]

Re: I accidentally loaned all my money to the US government

#199
post #193

Quick question for HN people: Is there a instrument like a I bond that doesnt have a 10k limit?

Nothing exactly like it but TIPS are Treasury Inflation Protected Securities.

Probably best to buy them in a fund due to their complexities. Vanguard and Fidelity both have funds for them.

Re: I accidentally loaned all my money to the US government

#200
post #62

> They require you to enter your password by clicking on a virtual keyboard. This pseudo-security measure actually only slows down humans, not bots, because you can still edit the value of the text field using Javascript. I don't think this is generally worth it as a security measure, but the goal is not to protect against automation. Instead, custom on-screen keyboards are attempts to thwart keyloggers.

> Instead, custom on-screen keyboards are attempts to thwart keyloggers. Commercial malware doesn't work this way. The term "keylogger" is a misnomer. "Keylogging" without context provides an unintelligible stream of garbage that might have well be from a random number generator. Most malware that I've seen either directly target the browser or the operating system, but in both cases they're looking for an unencrypte…

Are you saying you wouldn't be concerned if you found one of these on your computer? https://www.keelog.com/
Post reply on HN