Hacker Newsnew | past | comments | ask | show | jobs | submit | tempaccount3333's commentslogin

I can't wait for my bank to implement fednow. Faster transactions and the social credit are huge plusses IMHO. Hopefully, people will start to take climate change and other crises more seriously (eg covid) and think twice before they spout out disinformation about the vaccine, etc. Fednow has massive potential to ensure this happens.


Basically you are in favor of the government manipulating you. Very democratic what you say. All set for a dystopian society


I'm sure you were one of the ones that made covid last a lot longer than it should have. All I'm saying is that when the next crisis happens (most likely a climate crisis because that isn't resolving on it's own) there are going to be people out there saying it is a government conspiracy. The crisis won't get resolved if 50% of the people don't comply to common sense solutions (in the case of covid it was simply to wear a mask and get vaccinated but the climate crisis will likely mean even deeper sacrifices). Doing it through your wallet is the best way to get people to comply.


> Doing it through your wallet is the best way to get people to comply.

Incompatible with free speech and free society. I am horrified that there is no /s tag at the end of this post.

Do you really think shutting someone’s bank account makes them change their view? Or it’s acceptable to you because it’s only used to nudge toward the “right” views of the period? Do you not see how this destroys the rights of the individual?



Saying they suffer is a bit much. At best they get to collect their fee if there never ends up being a chargeback. If there is a chargeback they don't have to pay the chargeback fee. Sounds like it is an overall win for them to let these slide through.


nope, they get a lot of crap from customers and reputation damage. It's a p0 incident in places where I worked (not stripe, but i can't imagine why they alone would be glad to repel customers for a couple bucks), and everyone absolutely hates it.


It has nothing to do with our website. The card testing happens outside our website.


Aren't you able to disable checkouts from outside your website?


Hopefully their keys did not leak...


it's a public key


Stripe indicated to me they put in a captcha on their end


(Edwin from Stripe here.) I think we _may_ have chatted? (Hard to tell with tempaccount name.) Could you email me at edwin@stripe.com and link to this thread?


> (Edwin from Stripe here.) I think we _may_ have chatted? (Hard to tell with tempaccount name.) Could you email me at edwin@stripe.com and link to this thread?

I am so tired of hearing this. Even worse, you just openly admitted that Stripe has extremely broken processes: "I think we _may_ have chatted?"

Why did that go dark? Did it go dark? Did OP go dark? We'll never know. We just know that Edwin is here for tech support: it's an HN meme. We don't have many of those here.

I'm genuinely disappointed that unless someone complains on [searches Google for your email] channels, they get burned. There are tons of those small companies, entrepreneurs, and others who are getting hosed. I understand there's no incentive to fixing those processes. I couldn't wake up every day and admit to myself that there are certain classes of customers who, despite having equal issues, get preferential treatment because they're loud. This is on the front page right now: https://news.ycombinator.com/item?id=36788274

But as an empath it hurts me.

As someone who has transacted hundreds of millions through Stripe, I'm just floored. It was relatively nuanced before — the support — but this admission just shocks me.


How the hell is the guy supposed to be able to identify the account from this post? It gives no identification.


I have another post they commented on. They can see my historical posts.


"May have" because OP's HN name is "tempaccount3333", and I did ask them to email me once before, but I don't see anything—so I need them to reach out so I can identify their account and see what's going on.

There's no identifying info here (name or business) and we don't see any emails referencing this thread.


I'm just wondering why I have to post here to get your attention on this?


Because here it’s public and they want to save face. When it’s private they dgaf because it doesn’t affect other potential or current clients who might be swayed away from them


I'll check them out.


Does Square do subscription pricing? I don't see that on their website.


They are using my predefined products/subscriptions and aren't creating their own.


They are using my subscriptions. They don't set their own price


Unfortunately, the attacks are happening completely outside of my website. The attacker is generating a Stripe Checkout page using my public key - which I have rotated several times. Implementing a captcha on my end won't work and I have no control over blocking IP addresses.


Now more people know how to do the card testing.

There must be an option to allow stripe script only in specific domains and sub domains. All other domains should be blocked.


Doesn't work as that kind of info is in the http headers sent by the client..


Are you sure this is how it’s being done? My understanding of stripe checkout is that you need the secret key to create a checkout session.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: