HNHacker News
TopNewBestAskShowJobs

hwatson

118 karma · joined June 1, 2011

https://lobi.to/

[ my public key: https://keybase.io/unlobito; my proof: https://keybase.io/unlobito/sigs/Iy8zKJKK7Y6sD-cMEnDqo3RAsQYfgnCMs3yNL40plws ]

submissionscomments
hwatson··on MythTV 33 Released – open-source all-in-one DVR
It used to be a legal requirement for American cable providers to offer them, but the FCC dropped CableCARD in 2020 considering streaming apps to be a reasonable equivalent (https://www.techhive.com/article/578820/cable-box-competitio...)

Comcast still offers CableCARDs to new customers at least (https://www.xfinity.com/support/articles/about-cablecards)

hwatson··on MythTV 33 Released – open-source all-in-one DVR
fwiw, Xbox One Digital TV Tuners and some RTL-SDRs (with an extra decoder chip) are able to pick up DVB-T2 and are usually £10~20 on eBay.

https://tvheadend.org/ can be useful for interfacing with the tuners over USB and exposing web streams.

hwatson··on Reversing UK mobile rail tickets
It’s a shame these have become more commonplace.

Northern started issuing them instead of cardboard tickets a few years ago and other TOCs followed along after Network Rail/Cubic finished adding barcode readers to ~all ticket barriers.

I understand why: paper barcode-only tickets are significantly cheaper than cardboard tickets (their lack of a magstripe allows any generic thermal printer to be used), but their larger form factor makes them a definite UX downgrade.

hwatson··on Ham radio is not dying, it's evolving
I think what you're describing is what the RSGB have been attempting to mitigate through the Beyond Exams schemes, wherein they've gamified different activities you could do on your own or with a club to further your knowledge of amateur radio. https://rsgb.org/main/beyond-exams-building-experience/
hwatson··on Why Monzo's bank transfers weren't working on the 30th of May
Faster Payments is managed by Pay.UK who contract the infrastructure to VocaLink (which is 93% owned by MasterCard).

Pay.UK are currently holding a procurement exercise to find a new operator for Faster Payments http://www.fasterpayments.org.uk/infrastructure-renewal

hwatson··on The United States Needs a Universal System to Pay for Public Transit
I think this is less of a big deal in London because-- and the article entirely glosses over this prospect-- TfL accept contactless (e.g. contactless-enabled debit/credit cards, Apple Pay, Google Pay, Samsung Pay). This means anyone can land in London and immediately ride public transit using their existing bank card.
hwatson··on Ask HN: Who is hiring? (June 2016)
Judo Payments | Angel, London, United Kingdom | Full-time

Judo makes buying the things we want faster, simpler and more secure. As Europe’s leading secure in app and mobile first payments platform, we’re riding an unstoppable wave as smartphones change the way we engage in commerce.

We sit at the intersection of mobile, SaaS and payments, three of the fastest growing and most interesting sectors of the global economy. Our customers - big brands and innovative Startups - win awards because of our outstanding people.

Founded by serial financial technology entrepreneurs in 2012, Judo is backed by leading VC and hedge fund investors.

We're looking for: - DevOps Help design, build and maintain our IT infrastructure to meet our growing needs. Monitor and maintain our production platform keeping all components in top working order. Automate all the things; help us scale quickly by automating all the daily chores leaving you to focus on infrastructure improvements. Strong Microsoft Active Directory knowledge, including associated functions such as Group Policy, DNS etc. Experience of Microsoft Windows Server 2008 / 2012 & Linux. High level of automation using Octopus/ssh/powershell/bash. Experience of Docker. Experience of PCI.

- Postgres DBA Developer Experience of working on very high transactional load in always on mode. Experience with highly volatile load profiles. At least 2-4 years of administering large PostgreSQL databases. Experience in performance tuning / index maintenance, able to meet and assist the needs of the Development teams using PostgreSQL as its backend database. Designing and Managing PostgreSQL database schemas. Experience in Security access control. Experience with version control. Experience with 24x7 zero downtime database management. Experience with Java and high-available web applications. Knowledge of fault detection and resolution processes. Ability to communicate effectively to different levels of technical and non-technical audiences. Implement Database Change Controls. Experience supporting BI internally and for customers. Experience of, or willing to learn alternative database technologies (NoSQL) such as Mongo, Redis, Cassandra.

Our stack is based on C#/ASP.NET MVC, jQuery/Angular, RabbitMQ, and MS SQL Server/PostgreSQL.

If you're interested, please email lindy.roberts@judopayments.com for more details.

hwatson··on Google Fiber Is Coming to Salt Lake City
Considering that 100Mbit/s is 12.5MByte/s, the speeds you're seeing aren't horribly distant from your "up to" speed.

[For reference's sake, 8MByte/s is 64Mbit/s and 9MByte/s is 72Mbit/s

hwatson··on Stripe Connect v2
No. Creating the customer will charge the card $0.00 or $1.00 (depends on country/bank) and immediately refund the charge to verify the card itself, the CVC, the address, etc. In most cases, this tiny charge won't be noticed because of the refund.
hwatson··on Stripe Connect v2
If you attach the card to a customer object[0], you can create one off charges whenever you'd like. Stripe will even update the card's details on the customer if the card is reissued[1]. You can then create charges against the card manually through the dashboard (which seems to be what you were looking for based off of your original comment).

[0] https://stripe.com/docs/tutorials/charges#saving-credit-card...

[1] https://stripe.com/blog/smarter-saved-cards

hwatson··on Students Gain Access to Files on Admission to Stanford
You are allowed to keep your FERPA recommendation rights but, as misingnoglic, most universities will not pay much attention to your recommendations if you choose to do so.

https://appsupport.commonapp.org/link/portal/33011/33013/Art...

hwatson··on Apple Pay Data – Faster Purchases, Higher Conversions and Surprises
I wasn't aware of Wells Fargo issuing Chip and PIN cards[0] and I appreciate you pointing that out!

The other USA banks that I've looked at (Bank of America[1], for example) issue signature-only cards. These not working in unattended kiosks is mentioned in the last paragraph of the Wikipedia section we're both referring to.

The main problem with Chip and PIN cards in the USA is PIN management. Since EMV was developed before every ATM was online, the card needs to be aware of its PIN. Not many USA ATMs support reading EMV cards, which makes changing the PIN on the card difficult.

This is why Wells Fargo[0] don't allow you to change your card's PIN and is why many USA banks simply chose to skip PINs altogether. The last sentence of the Wikipedia section we're referring to mentions this.

[0]: https://www.wellsfargo.com/credit-cards/features/chip-card/f... [1]: https://www.bankofamerica.com/privacy/faq/emv-chip-card-faq.... under "Using chip credit cards" see "Bank of America doesn't currently offer consumer credit cards that include PIN authorization for purchases." Debit cards can be PIN authorised when running them over the online interbank networks, which makes offline PIN management irrelevant.

hwatson··on Apple Pay Data – Faster Purchases, Higher Conversions and Surprises
Square Wallet[0] used to implement something similar to what you're describing. It used your phone's GPS to register you as near/inside a store and merchants selected you based on a photo you provided. It was pulled in May[1] in favour of Square Order.

[0]: http://allthingsd.com/20120430/paying-with-squares-new-mobil... [1]: http://www.theverge.com/2014/5/12/5709256/square-kills-squar...

hwatson··on Apple Pay Data – Faster Purchases, Higher Conversions and Surprises
As an aside, no USA banks issue chip and PIN cards. The EMV-capable cards being rolled out are chip and sign cards. This usually doesn't matter but can cause issues at fully automated tills (the common example being issues when trying to purchase transit tickets).

Wikipedia's article on EMV has a section explaining the technical differences[0] between the card types.

[0]: https://en.wikipedia.org/wiki/EMV#Chip_and_PIN_vs._Chip_and_...

hwatson··on Why can't Apple decrypt your iPhone?
Each message is encrypted individually for each device that will be receiving the message. As a result, unless Apple slip a public key they have control over into the keys reported for the receiver, they cannot read your messages. (This is why abalone mentions that Apple do not have access to your old messages.)

http://blog.quarkslab.com/imessage-privacy.html goes into detail as to how the key exchange process works.

hwatson··on A basic guide to when and how to deploy HTTPS
> Digital Ocean, for example, won't give you more than 1 IPv4 address per VPS, which means you need a separate VPS for every side project, if you want to go HTTPS.

As long as you're not supporting clients running IE on WinXP or other similarly old web browsers, Server Name Indication (where the hostname is included as a part of the handshake) will work and it'll eliminate your need for more than one IP.

hwatson··on ICANN bans dotless domains
Wildcard certificates are only valid for the subdomain level directly under it. [1] If I get a wildcard certificate for example.com (the common name is set to *.example.com), foo.bar.example.com will throw an error.

[1] https://en.wikipedia.org/wiki/Wildcard_certificate#Limitatio...

hwatson··on Prism Break
Chrome's sync service also features client side encryption. [1]

[1] https://support.google.com/chrome/answer/1181035?hl=en

hwatson··on Google Abandons Open Standards for Instant Messaging
It's not. As https://developers.facebook.com/docs/chat/ explains, "Facebook Chat should be compatible with every XMPP client, but is not a full XMPP server. It should be thought of as a proxy into the world of Facebook Chat on www.facebook.com.
hwatson··on Windows Azure Storage certificate expired?
Take a look at me.com, for example. Before Apple bought it, it was owned by SnappVille.com. If SSL certificates didn't expire, SnappVille could have continued using their certificates for me.com.
hwatson··on China listening in on Skype - Microsoft assumes you approve
It's P2P on desktop if you forwarded ports or if UPnP works correctly. Skype has documentation on how to check this over here: https://support.skype.com/en/faq/FA1544/is-my-call-being-rel...
hwatson··on WhatsApp is broken, really broken
Yep. You'll normally see this happen if you restore an iPhone backup onto another iPhone then try to launch WhatsApp. Login will fail and you'll be asked to type in the SMS received.
hwatson··on Arch Linux Handbook for Kindle rejected by Amazon
or use @free.kindle.com to force (free) delivery over WiFi.
hwatson··on Steam Linux Beta Build Surfaces In Steam’s Database
Google Cache: http://webcache.googleusercontent.com/search?q=cache%3Ahttp%...
hwatson··on The App Store Nightmare
> If you’re in the US, you can’t download updates for your non-US apps due to IP address constraints.

That's odd. I live in the Dominican Republic and I've been using a US iTunes Store account since 2008. Even when the Dominican iTunes Store opened earlier this year I wasn't affected, I'm still able to purchase/update apps like normal. I don't have a DO iTunes Store account so I guess that has something to do with it.

hwatson··on Introducing Outlook.com - Modern Email for the Next Billion Mailboxes
It is now.
hwatson··on How we spent Friday night coming back online before Instagram and others
Nicer thing to do would be to have the maintenance IP as your last A record. If the client can't reach your regular servers, it will automatically fall back to the maintenance IP.
hwatson··on Seriously? Ads?
It's called 3-D Secure. (http://en.wikipedia.org/wiki/SecureCode)
hwatson··on Pwning a Spammer's Keylogger
Your 1Password keychain is stored locally and is never uploaded to Agile's servers. The attacker would have to upload the keychain first (or break into your Dropbox, if you have it stored in there)
hwatson··on EasyDNS is under DoS attack
The blog seems to have gone down. It's just a blog entry that says:

> We are currently experiencing an Denial of Service Attack against DNS1, DNS2 and DNS3 anycast strands.

> We are working on mitigation and will post updates as they become available.

Page 1 of 2Next →