566 karma · joined September 23, 2008
Email me at dan@manges.com
The "Summer 2011 YC company seeks CoffeeScript drinking frontend engineer" post seems very generic to me. It's nice that they mention the industry they're working in, but otherwise, I didn't pick up on much differentiation in the job description from other companies looking to fill a similar role (and the post nearly admits that itself, at the end).
We mostly work with Ruby/Rails. Our team is talented, our practices are collaborative (pairing, agile), we work on challenging problems (high availability, quality of service, scaling, security), and our devs have 10% time to work on whatever they want. Developers use and love our product. Although we mostly work with Ruby, we also work with Python, Node, Java, .NET, PHP, and Perl. Braintree is profitable, you'll have standard benefits (health/dental/vision), 401k match, ample vacation, an above market salary, and stock options.
More about our people, practices, and software: http://www.braintreepayments.com/inside-braintree/how-we-bui...
Apply at http://www.braintreepayments.com/braintree-careers . If you know somebody who might be a good fit, we'll pay you $10,000 for a hired senior dev referral.
As an example, Heartland includes interchange in their revenue. "Heartland reported $526 million in gross revenues for the quarter... Interchange accounted for $365.2 million of second-quarter revenues."[1]
At Braintree we don't include interchange in our revenue, so our processing volume is higher than Square's, but our revenue is lower.
We mostly work with Ruby/Rails, but we'd be interested in a person without Ruby experience who is skilled with testing, software / web dev in general, and GNU/Linux.
More about our people, practices, and software: http://www.braintreepayments.com/inside-braintree/how-we-bui...
Edit: thanks for the edit.
Braintree ( http://www.braintreepayments.com/braintree-careers )
challenging problems: a payment gateway is mission critical
web scale: we're growing quickly and working on scaling
amazing team: I'm working with 7 of the 10 best devs I've worked with in my career
top compensation: the best devs should have the best compensation
"I have only heard of one application of JS crypto that made sense, but it wasn’t from a security perspective. A web firm processes credit card numbers. For cost reasons, they wanted to avoid PCI audits of their webservers, but PCI required any server that handled plaintext credit card numbers to be audited. So, their webservers send a JS crypto app to the browser client to encrypt the credit card number with an RSA public key. The corresponding private key is accessible only to the backend database. So based on the wording of PCI, only the database server requires an audit."
It's true that if your form is hacked it could be modified to send credit card details to an attacker. But that's also true even if you're redirecting the user to a third party page like Paypal to complete the payment. If hacked, somebody could change the Paypal button to redirect to a malicious page.
Hiring Ruby developers, COO, and customer support
sudo puppet --templatedir $HOME/puppet/templates --factpath $HOME/puppet/facts puppet/puppet.pp
Braintree
We generally recommend collecting at least a five digit postal code - this is the variable you have direct control over that helps a larger percentage of your transactions process at the lower qualified rate. Other information, such as the street address, can be helpful for other reasons, but does not effect your processing rate. Collecting the CVV is usually a good idea, as well, though again - this data does not effect your processing fees.
It's been our experience that for SaaS providers such as yourself, traditional fraud is lower than you would see for merchants shipping physical goods. You'll still want to protect against chargebacks, however, and there are a couple options outside of collecting a large amount of data from your customers.
You'll want to first be sure the descriptor that appears on your customer's statements is obviously tied to the product they've purchased. You'll also want to ensure that the number appearing on their statements is a number that they can call and quickly get information about what the charge relates to.
Once your chargeback rate gets much above 1% of total credit card volume, banks will begin to analyze your processing and conduct various risk reviews. However, unless you're experiencing an obscene chargeback rate out of the gate, the bank will usually work with you to lower this percentage before shutting you down completely. Should you start to see chargebacks approach that 1% figure, you can then look at additional options, like increasing the amount of information you're collecting.
Much of this is just good practice for any business - accurately describe your service, be responsive to customer issues, and provide a great product.