42 karma · joined June 10, 2012
And they handle it so poorly that you have to write them to get a proper invoice in order to recover your VAT.
If your customer buy your application through the app store, they ask "you" an invoice with VAT, and you have to tell them to contact Apple, that's so unprofessional. For a 30% cut, they could clearly put a download link or include a PDF in the sent email.
The tabs shape is repulsing me, I know that's a strong feeling and I can't explain it. The disymetrical back and forward buttons bothers me as well. I can't find how to whitelist domains accepting cookies in Firefox. Switching profiles is much easier with chrome. I'm used to chrome developper tools.
I don't like neither safari neither MS edge.
If it wasn't for the missing onenote extension, maybe I'd be using opera. Again, all about the details.
It is great to improve my focus as I am not disturbed by my waving cpu meter.
Great work, love it.
I used http://www.localfont.com to retrieve the Open Sans font I was previously using from google font. Maybe that's the kind of webapp you are looking for.
It seems allright if you are doing all the duty procedures as well.
Do you verify the given VAT number to be legit and matching through the VIES system : http://ec.europa.eu/taxation_customs/vies/
Do you keep track of the 2 non contradictory proofs of the receiving country end ? Article 24d : http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELE... Do you keep this localisation proofs for the 10 mandated years ? Can you prove this saved data have not been tampered ? Do you have an audit log on this data ? Do you comply with directive 95/46/CE for the protection and treatment of this data ?
Hopefully for you, you are only dealing with VAT registered corporates, so you are on the easy side. Now imagine the nightmare if you are for example selling e-books or saas or traditional software to VAT / non VAT registered corporates and individuals wolrdwide. It's not so easy anymore.
I think, we reached the end of the thread, I can't reply to you. So, sorry for the messed reply.
I'd like to ask more questions. Are your french customers corporates or individuals ? If corporate, do they have a VAT intra-community number, do you have one ? Are you billing VAT in Germany ? As I'm french, could you give me this not stating they are without VAT due to specific french laws.
Beware, I don't know if the situation is the same in germany, but in France you have no recourse if your accountant is wrong, the burden is on you.
I'm afraid many people think "they don't even need to think about it", but are actually wrong. (Not I'm saying it's your case, but here even the tax office is not really sure how to deal with it, the only one who seems to know is the one giving fines, and he's not an adviser, just an inspector ...)
If nothing changed at all, you may be doing it wrong.
Which country are you billing from, which european countries are you selling to ? Are you selling a single product/services, several with each different tax rates ? How do you know which VAT rates you have to apply, are you vatmoss registered ?
It's a difficult subject, I'm really surprised it seems so easy for you (or anybody else)
My comment was supposed to be an addendum but I failed by nitpicking and questioning your interpretation. I'm sorry.
As a security researcher, may I ask you these questions:
Which channel are you using as a first contact ? Would it be enough for me as a saas supplier to monitor security@myservice.com ? I must admit I'm bit afraid by a cleartext channel for this kind of disclosure. Would you have some recommandations for the receiving part of the vulnerability ?
I just read it and it looks like you are misinterpreting it.
> then give them 5 days to respond > they may want to "negotiate" more than 5 days to fix the issue
"5 working days" is not the same at all than "5 days", think of public holidays and week ends ...
So I imagine, given their specifications, they had to give each tenant its own full PG database. I understand they have strong business logics but it does not seem very efficient. Salesforce is known to use a single oracle instance for all its tenants and I don't think their business logics is less demanding.
Giving an administrator or elevated role to the tenant connection looks like a really bad idea from the start, especially if the tenant instance is not sandboxed in a container or virtual server.
But this things are hard and a small mistake can have big consequences.
Maybe you took some notes.
Could you share some more info if you are free to disclose how you poked with the connection pool. I haven't look at OpenERP sources, but I think the database in use is PostgreSQL.
> "for a user of one database to access other database"
Were OpenERP using a database for each tenant or 1 database with multiple schemas ? In case it was the former case, were all databases accessed with the same credentials ? Which connection pool was it ? Pgpool / Pgbouncer ? Where was the vulnerability, code, db, pool, config setup ?
Sorry for all this questions, I'm indeed very interested and involved in this topic.
Are you allowed to run a game server, ftp server, web server, ssh server ?
Words first mean what is written in a dictionary or encyclopedia.
Internet : https://en.wikipedia.org/wiki/Internet
If you are not allowed to run server, they are WSP (Web Service Provider) not ISP.
But if you are OK with ISP not providing internet, I'm sure you are fine with unlimited limited or throttled after x, 24/24 access between 9-5 and secured http page as long as there is a padlock favicon ...
You can ring an intercom in any big apartments block and ask to be opened the door to deliver whatever, most of the time you'll find a resident to open. No reason for it to not work in emails :)
I'm a nitpicker but that's one of the reason why i dislike safari browser. You need the status bar enabled in order to see the links destination url and I don't like the 7 pixels height taken by this bar.
But as I am browsing with javascript enabled, I can't be sure that the url showed by the link is the destination I'll be sent to. That's something quite hard to explain to non technical people (like my parents). I'm not even trying to be honest. I'm not sure what to think about this behavior and generally with link shortener, it's an easy way to phish people in forum, comments, ...
And the shortened link still works for emails.
If your customer is using google domains, microsoft 365 or what else, and the employees do not fall in your phishing attempt and report your mail as spam, you may be heading for some trouble with delivery afterward.
So let me rephrase it for you : France will pretend to be upset ... It's part of the game.
As a french, I just don't give a s US spying our officials, I'm much more worried any foreign secret service achieving it. It just shows how much our defense and digital security is weak. If I'm angry, it's towards our own services which can't prevent this kind of stuff.
I did not know chrome had this setting option, or I view it but did not really realize what it was for. I'm glad you took some time to list the needed steps.