159 karma · joined August 16, 2013
email: matt@mattarkin.com
[ my public key: https://keybase.io/matthewarkin; my proof: https://keybase.io/matthewarkin/sigs/pgXbGbYwrLUNrV1uF7InbSAPkDV9pqf2Gl1MlPc3NgE ]
The naive interpretation would be that people using stripe with a python codebase in general need less technical support with the integration.
Notes: I'll be graduating in June with a B.S. in Science, Technology, and Society from Stanford (basically a mix of CS and Communication). Looking for a new-grad (though I've worked in industry since I started college) position for once I graduate.
Stack overflow is great for solving individual bugs (which definitely works in some IRC rooms), while IRC is more of a "how to do something" or "why should I do it this way" type of environment
When you send an email to support@stripe.com (or any of the public email addresses they put on blog posts), it goes to Uservoice. Then it gets triaged, depending on the severity of the ticket, if it falls into account or developer related support it gets assigned into a queue (at times it gets put in the wrong queue and then has to get reassigned). But long story short there is a system.
Phone support is also being worked on were told.
That said I do love Stripe but I do agree that support needs to be fixed, though I may have a bias as I see a much higher percentage of upset users than most.
Apple can ensure the latest version of their OS and Apps work on all their supported machines and hardware configurations. This sort of testing and assurance is nearly impossible for Microsoft
With the large companies that have shuttle's the flexibility is because they need to stagger all their busses.
It really depends on the culture and the type of environment though, much more "corporate" positions and cultures would require better on-timeliness, but being told to take the day off for being 6 minutes late seems odd for a developer position.
As opposed to Stripe.js where the credit card inputs in a custom designed form live on the merchant's DOM, Braintree just set it up so that it replaces each field with an iframe (that also allows for custom styling), so that the credit card info gets entered directly to Braintree despite it looking like your own page.
Awesome Braintree!
So if a merchant links to paypal.com/merchant, and I inject js to change it to paypal.com/matthewarkin. The merchant would immediately know something was wrong because they are no longer receiving money. The issue with how Stripe, Braintree, and others have implemented their javascript and iframe implementations is that is pretty easy to replace the iframe with a malicious url (paypal.com/matthewarkin) but still allow the merchant to receive their funds.
A simple fix for this would be the api keys used to instantiate the iframe only be usable from the iframe and could not be used to call the create token api directly.
Their Attestation of Compliance: https://www.dropbox.com/s/xpk1n72n0gtd5o5/Stripe_AOC_2015.pd...
(As part of my blog post, I actually use some malicious js on the merchant site to steal card info from a Braintree iframe (the drop in))