Hacker Newsnew | past | comments | ask | show | jobs | submit | dahcryn's commentslogin

it's common, they reserve an amount, and then update towards the final payment. These are not payments as such, and almost always take 48 hours to clear. Same at hotel rooms usually etc..

Many banks only show payments (so only after cleared) and not reserved funds. They will just show that you don't have the full credit available


The update with the final amount happens within minutes after you’re done pumping, not only at batch clearing time.

This was introduced to not unnecessarily block debit card funds for days but it works like that for credit cards as well now.


wait, people can just do that? How does that even work? Does Visa not supposedly protect both the seller and the buyer?

In Western Europe, a chargeback is not that unheard of, but it still requires you to make your case and follow a procedure and review. It's not that lengthy or difficult, but you cant just buy something online and then do a chargeback, unless you can clearly show that the download is not working and tried the helpdesk or you were mislead or something


It’s supposed to be the same in the US, but due to heavy automation on both sides, the “evidence” presented on either side is essentially pages of rasterized TIFF slop propping up a handful of bits of ground truth data.

I suspect most decisions are now made based on ambient factors such as “does this customer file above average chargebacks; if not, believe whatever they entered in our multiple choice questionnaire” or “if we have any undisputed payment on the same card by the same account, push back, otherwise eat the loss”. Part of this is even getting codified by newer network dispute evidence rules as well.

Since nobody ever seems to hold cardholders accountable for misrepresentation, and since it’s psychologically much easier to lie on a whimsical multiple choice form you fill on your bank app when bored on the bathroom than to sign a printed document containing a short summary of the legal consequences of willful deception, the situation is what it is.

Sometimes, whether a society is actually “high trust” depends on the transaction amount, and whether that amount warrants legal expenses on either side.


Yaah I feel the same way. Gemini is great at and Django and AI backends, OpenAI better at making something visually pleasing in React and Claude for everything else or across frontend and backend.

At least, that's my heuristic that tends to work for my workflow. I use a combination of Gemini-CLI, Claude Code, and Github Copilot, but across those, the underlying model choice works best according to which part of the applicaiton I am messing with


yeah I thought that was the USP of Legora and Harvey, so this is not the same thing at all, just surfing the brand recognition


Harvey made it a point to FT ChatGPT models for a year or so but they were struggling to keep up with the pace of new model deployments and quit. They never went as far as Cursor AFAIK which produced its own routers/"composer" models.


Harvey doesn't have finetuned model anymore do they?


I think it was a lot less restrictive, as far as I understood, the only limit was Microsoft not being allowed to launch competing Microsoft-developed LLMs.


the M line of macbook pro's are beautiful, well crafted, long lasting machines.

MacOS might not be your preferred way of working, and you might prefer cheaper options or USB-A ports, but there is really nothing you could arguably call bad craftmanship in those machines.


>> nothing you could arguably call bad craftmanship in those machines

my 2 bad craftsmanship cents:

laptop keyboard leaves marks on screen. laptop's sharp edges leaves marks on wrists.


> laptop keyboard leaves marks on screen.

I don't think this has been a thing in years.

Sharp edges on wrists is true.


It definitely is a thing on my M2. Unsure if it is something that was fixed in the later models.

My wrists, conversely, are fine, but I suppose I rarely use it in a 'classic' desk position that would cause that.


My 2023 MBP's keyboard leaves marks on the screen while closed.


..from the company that brought you "You're holding it wrong", not just bad but dumb


In addition to the sibling comment, I would point out the touch bar was poor craftsmanship and the butterfly keyboard was also poor craftsmanship. They both are addressed now, but there were several years where we had to live with them.

Their software craftsmanship has really suffered in the last 10 years.


I thought the touchbar was pretty neat, it was just a mistake to replace the function row with them. It also was hard to get adoption because it wasn’t available on desktop Macs or their cheaper laptops so developers had no incentive to really do anything interesting with them.

I think a better implementation might have been to have it be an alternate mode for the trackpad and sell external trackpads that also had it so it could be used everywhere. But I get why that didn’t happen, the touchbar was basically being run with a mini Apple Watch SOC built into the MacBook Pro, and it’s primary use was to have the Secure Enclave on it. The touchbar itself was a deal where they could find a use for having an otherwise idle smartwatch’s worth of computing power in there, but that wouldn’t be doable if it’s sold as an external device.


they're very well designed and built products, craftmanship is something else.


What is it?


They are mass produced in factories, not made by craftsmen.


I mean, they're not bad, but they have spicy chargers, the corners are uncomfortably sharp, the keyboard often doesn't register, the LCD is prone to vertical bars and other issues even without physical damage and is extremely sensitive to bumps and other minor damage elsewhere on the laptop (not even the display itself), and so on.


Some of these are consequences of what makes them feel "premium" or even "solid". Aluminum is a terrible material for bumps and drops because it dents, and that often damages the internal components.


weird how its 0 to 15, and no in between.

I went in hoping to set it to 5 minutes. I don't see that as a problem. However, suddenly losing 15 minutes, yeah that's an issue


thank you, I had this debate at work so many times.

Sure it's not a security measure as such, but it's still a worthwile component to the overall defense system.


The problem with this is, you spend a lot of effort for low benefit. You should spend it on actual security instead.


Changing a port and enabling aslr are not "a lot of effort".


Changing the port is not the kind of security measure that will consume a lot of the attacker resources


Sure, it'll do nothing to stop a determined attacker, but it does wonders to stop the noise from passive scanners.

Are you familiar with the Swiss cheese model of risk management[0]? Obscurity is just another slice of Swiss cheese. It's not your only security measure. You still use all the other measures.

[0] https://en.wikipedia.org/wiki/Swiss_cheese_model


It will conserve a lot of defender resources, it will completely bypass all mass scans, and it will make "determined attackers" much more visible as they will have to find the port first which will show up in logs and potentially land them in a tarpit.


What would be "actual security" in this context?

This isn't about security of the same kind as authentication/encryption etc where security by obscurity is a bad idea. This is an effort where obscurity is almost the only idea there is, and where even a marginal increase in difficulty for tampering/inspecting/exploiting is well worth it.


The one not described as "security through obscurity".


My point is: the "security through obscurity is bad" and "security through obscurity isn't real security" are both incorrect.

They apply to different threats and different contexts. When you have code running in the attackers' system, in normal privilege so they can pick it apart, then obscurity is basically all you have. So the only question to answer is: do you want a quick form of security through obscurity, or do you not? If it delivers tangible benefits that outweigh the costs, then why would you not?

What one is aiming for here is just slowing an annoying down an attacker. Because it's the best you can do.


Somehow your approach was not chosen by Intel ME or AMD PSP, and they remain unbreakable.


That's orthogonal to this. That requires special hardware and using those doesn't really rule this out as an additional measure.


I love the irony on seeing the contribution counter at 0

Who'd have thought, the audience who doesn't want to give back to the opensource community, giving 0 contributions...


It reads attribution really?


also, let's not conflate easy to repair with cheap to repair.

The macbook is quite easy to repair, it's just insanely expensive because they made the choice that, for user experience, they attach the keyboard to the machines body.

You can have ease of repair and build quality, but then you give up portability I guess (bulky and heavy). And also cost goes up


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: