Live data from Hacker News

Klarna users are being signed in to random accounts

twitter.com

381–390 of 517 posts

Re: Klarna users are being signed in to random accounts

#381

Earlier quoted context omitted.

tangential thought, but related: I am, in general, a proponent of nuclear energy as a green alternative to whatever the hell we are doing today. But when I see such stories that humans manage to fuck up simple payment processing apps, still make errors while maintaining bridges, still manage to do hugely negligent screw-ups (most likely corrupt) in *cable cars maintenance*, I immediately think that it is imminent, th…

The Italian cable car was really messed up. The emergency brakes of that cart were intermittently triggering, so the operator jammed a piece of metal to stop that from happening. His assumption is surely, "Relax, what's going to happen, the cable won't break!".

> The emergency brakes of that cart were intermittently triggering

My guess: each time a strand within the cable broke the cable stretched a little and the brake triggered.

Five years ago a company was hired to maintain the cable car. They took one look at the state of it, wrote to the operator (the town council) saying it needed to be shut down and exited the contract. It was an accident waiting to happen long before the brake fiasco.

Re: Klarna users are being signed in to random accounts

#382
post #311
post #288

Earlier quoted context omitted.

I'm afraid you don't decide what comes across as hostile. Things can be discussed in many ways, yours is one of assuming to hold all the answers in a conversation with a stranger you know very little about. I would reconsider this. You don't know what I was buying, for what reason, or if there was a realistic alternative. You just say "you weren't born with it", and "it's the truth". An unconvincing way to argue what…

If you find truthful and accurate statements of fact to be hostile, I don't know what to tell you, other than perhaps clarifying that I wasn't intending to be convincing or persuasive. Those that care about the truth will be persuaded sufficiently by facts, and everyone outside of those that care about the truth I am not interested in spending any effort persuading.

Does that mean you do not care about the truth, as you seem unpersuaded by the fact your missives are found to be hostile?

Re: Klarna users are being signed in to random accounts

#383
post #257

Having at least authenticated sections of your site use HTTPS was standard well before 2011.

Not sure why you are being downvoted but this is exactly correct. We had, as an industry, been so focused on PCI during this time and TLS was and continues to be the most important aspect of the protective technology. SSL/TLS had already made e-commerce viable in the 90s and its power was well known and being applied for the decade following. Being in 2011 without full ssl for authenticated access was quite bad behavior indeed. Maybe excusable for some low rent bulletin board, but perhaps that is what the commenter was operating. I have no clue.

Re: Klarna users are being signed in to random accounts

#384

Their German counterpart, Sofortüberweisung, didn't properly blacklist test credentials given out by banks e.g. to developers in the beginning, so people could simply use those and pay for goods and services with fake accounts. For me there are so many red flags with all these services, as they basically "steal" your credentials to log into your online banking. And while they claim that they only use the credentials…

Sofortüberweisung specifically got caught looking at 30 days of transaction data.

> how banks can allow this

A court decided that blocking this "business model" would be anticompetitive.

Re: Klarna users are being signed in to random accounts

#385
post #341

Earlier quoted context omitted.

True, but it's still always possible to get an answer to a question—you just have to ask. However, we might not see it unless you ask at hn@ycombinator.com.

I don't want to appear ungrateful - let me take this opportunity to thank you sincerely for all that you do. Your set up appears to work, and I'm probably in a minority with my demands. We wouldn't have to ask if you had a public mod log (and banned sites list etc) and a public explanation of the algos that power HN. Your comment reminds me of hotels - "X is available, just ask". A scheme clearly designed to reduce u…

I've actually written about that a lot over the years. Here are some links I dug up (mostly via https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...). If you take a look at the previous explanations and still have a question I haven't addressed, I'd be interested in knowing what it is.

https://news.ycombinator.com/item?id=23837866

https://news.ycombinator.com/item?id=23807944

https://news.ycombinator.com/item?id=23286685

https://news.ycombinator.com/item?id=23227833

https://news.ycombinator.com/item?id=23127622

https://news.ycombinator.com/item?id=22939878

https://news.ycombinator.com/item?id=22711604

https://news.ycombinator.com/item?id=22648990

https://news.ycombinator.com/item?id=22547697

https://news.ycombinator.com/item?id=21546486

https://news.ycombinator.com/item?id=13036179

Re: Klarna users are being signed in to random accounts

#386
post #303

Earlier quoted context omitted.

A recruiter contacted me aswell and I asked about their salary. They pay 50k euro for juniors in berlin with afaik no stock vesting. How they even manage to get qualified personnel is beyond me, I would expect much more for a fintech with over 3B evaluation

50k in euro's is pretty ok for European developers, no?

Stripe, another payment company, has salaries starting at 130k euros in EU

Re: Klarna users are being signed in to random accounts

#387
post #291
post #257

Having at least authenticated sections of your site use HTTPS was standard well before 2011.

Let's Encrypt started in 2014 to address HTTP overuse. In 2011, I (in-house corp app dev) was still stuck with HTTP services (behind a firewall, accessible only via VPN). In 2014, public facing mobile apps using HTTP was prevalent enough to prompt name and shame campaigns. [1] My fuzzy memory suggests some banks were still using HTTP. [1] https://arstechnica.com/information-technology/2014/08/new-w...

Let’s encrypt came way way late to the party. We had been banging the drum for 20 years by then.

Re: Klarna users are being signed in to random accounts

#389
post #377

Earlier quoted context omitted.

The moderator comments are a kind of public mod log and a thing worth looking at regularly if you're interested in how and why HN is moderated.

Are you being serious?

It's true - I use those comments to provide detailed explanations, which I often link back to. They're sort of the case law of HN moderation. It's my intention to someday compile them into some sort of compendium of moderation heuristics or something...not sure yet what that should look like.

Re: Klarna users are being signed in to random accounts

#390
post #144

Earlier quoted context omitted.

In Sweden there is a current cultural view that the only reason someone would not sign up for an account with any kind of banking service is because they are too old to navigate the registration process, in which case all they need is help going through it. Any other explanation for why someone does not have an account at X is perceived as perplexing or straight alien. Non-coffee drinkers will have an easier time cul…

Regarding Swish I would agree, regarding Klarna I could not disagree more.

Same here. Swish is a must. Klarna an annoyance.
Post reply on HN