1,644 karma · joined June 6, 2009
Contact: sdrinf at google's email service
Web: https://sdrinf.com/
In most startup contexts, 1 & 2 is both costly, time-consuming, and non-productive, while 3 is not really desirable. There are structured ways to have founders, and stakeholders stock (or first proxies thereof) of the company in their assets without triggering these. Kindly consult with your accountant to figure out what these might be.
Peter (fictional archetype) might click through on his work computer; then go home, and might want to have another look at the site; however he won't have any recollection of his "personal URL", nor any way to access it. Peter will, at this point, perceive all his time investment going down the drain. He will either re-register (to be wacked on the head when he's back at work again), or refuse the site altogether.
Note this is different in Doodle's case, due to it's inherent sharing nature: people will email the link as part of the main process, so they're able to get back later.
One way to see how this affects user's lifecycle is measuring: 1, username only; 2, username + email; 3, username, email, password variants against eachother, across the entire user funnel: registration, main mechanics, retention (or length of lifecycle).
| Why is Amazon's security for replacement orders so lax?
Amazon values customer satisfiction above their fraud write-off.
| Why would they send a replacement to an address that has never been associated with me, and is in a wholly different state than the one the original item was sent to?
Because the time between ordering an item, and defect can be sufficiently large to cover moves: people shift around all the time. It's entirely concievable you'd like to exercise replacement rights from Texas, even though you've ordered it from NY.
| How did the scammer know about my order in the first place to social engineer the replacement request?
Via: either buying order requests, using third-party honeypots to capture your info, using the domain registrar, or a combination of any of these.
| Why haven't Amazon black-listed the 13820 NE Airport Way; Portland, Oregon address as a destination for replacements? This package drop address shows up again and again when you Google around for people who have been hit by Amazon scams.
I suspect this might be http://reship.com/ (Alexa rank: 166K). This is entirely legit: if you're a UK customer who'd like to buy stuff that are exclusively US-only, reshippers are the cheapest way to do so. Based on their Alexa rank, I suspect Amazon makes quite a money on these customer segments. Blacklisting them also wouldn't help this case: reshipping companies can easily buy up a handful of different addresses in a range of cities, making this a game of whack-a-mole.
| Can I really trust this company to hold multiple credit card numbers of mine in their database, one click away from someone potentially ordering thousands of dollars of merchandise that they can apparently easily redirect to an address that should have been black-listed years ago, if there were any kind of sane security policy in place?
Note that no credit card, or password database has been compromised in executing this attack. This is social engineering corporate goodwill at it's vilest.
I suspect the root cause of this issue to be the friction-less execution of this engineering. A proper solution for this problem might be as simple as sending out an email with clickthrough-link-confirmation before replacement shipping; this would raise the bar from "knowing about an order" to "knowing about an order, and having an active compromise on the mark's inbox".
The second you open that up to application layers, you are facing a wide range of problems. Specifically:
* Common schema: each application considers itself a unique snowflake, and might want to use different columns to mean different sort of things. We've been here before -semantic web, RDF, etc- and the correct solution was letting the apps just manage their own database of stuff.
* Selfish apps: There is nothing stopping apps from overwriting, or manipulating meta-info in ways that are detrimental to user experience. Consider the current case of "Set <x> as default browser", "Set <x> as default media player" at each launch, then multiply it across every schema column
* Interop: Beos attempted to solve this by dumping meta-info into the archives. The problem is, when a file gets outside the original system/OS, these attributes will get truncated. Any workaround on this would require full agreement on changing all of the file transfer protocols, and storage methods on all OS.
Also note, that the 90% of the case (localizing files instantly on multi-terabyte consumer-drives) is handled already via Windows Search & Finder. Personal experience on this shows, that you can safely drop the hierarchical madness in favor of filename-based search for most media/music/document cases; and there are ways you can apply this for development as well.
Incentive boils down to negative externalities:
* In the UK, understanding is attempted by the police; in this case, they probably received a complaint, heard out both sides, and made the judgement call of case having no legal basis. Not hearing the cops out have a potentially significant downside, in them understanding the situation incorrectly.
* In the US, the same level of understanding requires the interplay of a prosecutor, a defense counsel, and a judge (on top of the contestant & defendant), and several man-days of sweat. Talking with the cops can, by law, only weaken your position: anything you say can only be used against you.
The cultural trade-off is a question of variance: the UK system presumes low-variance situations, such that understanding can be built by reasonable individuals; while the US is geared to being tolerant towards people living on the edges, at the cost of longer due process.
The quality of connection between UK citizens, and law enforcement is significantly different, due to actions on both sides: specifically:
* UK police tends to seek full understanding prior to taking any action
* The standard police unit is not armed, and their legal rights are significantly limited
* In general, their strategy aims for avoiding situations to escalate
This allows for the vast majority of situations to be resolved peacefully, and in mutual respect. I leave drawing conclusions, and comparisons to the US armed force to the dear reader.
Regarding built-in media players, not one vendor takes usability of playback seriously. Specifically, when I hit "enter" on a file, that means I'd like to see it played back, like, now. Not "queueing", nor 5 seconds later. When I scroll left & right, that means I'd like it to go +-1 min / hour, like, now; and not 5-10 seconds "seeking". On my quadcore 3.4ghz battlestation, this remains a problem for every single native, and web-based app. MPlayer is, to date, the only one which consistently delivers on sub-second videoplayback, and it does so from cold start. (There are also major problems with how subtitles are handled by players, but I grant you that might be a niche)
Hence my strong requirement above for the app to go with shell.exec, instead of half-baked non-implementation of every single video codec under the sun.
Problem: I've got 2TB of videos, music, and images on my hard drives, and I've found my available tools to be too low-leverage on managing this anymore.
Context: about 2 years ago, I've stopped the directory structure madness, and embraced search as first-order link for media files. As a byproduct of this, I notice I don't have a clear mental structure of what videos/music is downloaded to my computer anymore, and to where (good riddance!). Neither do I want it to; instead, I'd like to have a "youtube for local hard drive":
Basically, I'm looking for a local Media Browser application for windows: specifically, an app which allows:
* thumbnailed preview of all videos & images
* Automagically categorized based on all online, or within-file available meta-information
* With a built-in search
To perform the following operations:
* Preview a thumbnail on video files (similar to file explorer)
* Display categorized lists of all media available locally on my drives
* Channelsurf, similar to youtube: be able to start from one movie file, and have "similar" videos around it
* Double-clicking on the file to start mplayer
* typing the first 2-4 letters of the movie/image to instantly bring up the list of media with that part in it
While specifically not doing:
* Anything that requires me to touch any of the files in any way shape or form whatsoever
* Any upsale (I'm looking at you, windows 8 "personal videos"), advertising, or introduce any friction during interaction
* Bringing up any browsers: solution must be windows-native, and responsive (<20ms results)
Specific things I've tried so far:
* The closest thing I can wave towards "want" is apple's itunes, and JRiver's media center; they both share the same weakness of not being able to use mplayer as playback engine
* Banshee on windows is unable to show video previews, have multiple stability issues, and can't use mplayer for double-click
(I've posted full details of this to http://softwarerecs.stackexchange.com/questions/2646/media-b... a month ago, to no response avail, but getting upvotes, which evidences a market to be had for this )
Long story short: when they call me, I'm generally in REM sleep, and have been for a mere 2 hours. After their interruption, I will not be able to sleep back, but will spend the next 10 hours in zombie mode.
I have found a fantastic new way to use this zombie time: looking up legal, and law services, small courts, corporate databases about their company, facebook of their personal, and any and all leveraged counter-offense methods, that will make these companies, and individuals within not exist ever, ever again.
Please for the love of all that is holy, respect TPS's do-not-call lists.
[1] See https://news.ycombinator.com/item?id=6163051 for more
Tell me operational steps I can take at the 27-28-29th of Dec that will exercise leveraged optimisation pressure against this.
Assuming you're aiming for "pretty productive and can get a well paid job with any of the languages you know", note that skill in programming is, but one dimension in the employability equation. A handful of others include: domain-specific knowledge (both technical, and those specific to the employer's industry), communication skills, ability to juggle tasks, and ability to sell. Strength, or lack in any one, or combination of these skills can be an overriding factor in your pursuit.
You'll often find on these boards, and in software circles people very noisy about language of choice. This has historical, sunken-cost-fallacy, and mid-carrier-crisis backgrounds; none of which are particularly productive to your goal. You'll also find many posts claiming shiny features achieved in one particular language. This has marketing background, and is also not conductive to employment.
In conclusion, given your stated goals, your question is a red herring -it serves to distract you from what you're trying to achieve. It is possible to be very good in multiple languages. You might even aspire, and reach this goal within 3-5 years. Whether the industry will need those skills, and whether you'll be employable in any of these, are separate questions entirely.
* One of the best usage of your business partners might be taking over navigation of the sales cycle -if they're sold on the valueprop, they probably know where it can be sold successfully. If they can't sell it, that's a strong datapoint you need to consider re: viability.
* If the market gap is real, you might want to consider selling consulting solutions to that gap specifically to gain additional understanding to the market.
* As a fallback, you might be able to sell consulting/contracting on other fields until sales gets significantly better
[1] http://businessofsoftware.org/2013/02/gail-goodman-constant-...
* download & open up thunderbird
* Add 2 accounts: your existing gmail account, and your new outlook.com account
* select all email in the inbox of your gmail account, ctrl+c [this will take a while]
* open the inbox (or other folder) of the outlook account, ctrl+v
Personally, the largest migration I've done using this method was ~1GB, but should work for larger accounts as well. Hope this helps!
If that isn't a demonstrative example, what specific devices _would_ be useful to have Internet connectivity, and in what specific ways?
- https://stripe.com/chat VS email
-You usually don't need to "send the docs in" (being hungarian, they asked for my ID, but email was fine), which reduces time to launch
-After having launched with Paymill, production started throwing strange errors. Root cause analysis revealed, that they don't have USD / EUR acceptance enabled by default; and they asked for extra paperwork to have that. This is not a good problem to have when users are hitting the payment wall.
Imagine a new online service, which allows people to rent out their existing accounts at various other SAAS services to tenants, in exchange for a cut (specifically eg. you can share your seomoz account with 2 other people, tossing the $99 + cut inbetween them, each tenant taking one of the slots).
Consumers benefit from radically lowered prices, enabled by "more fine grained transaction in property".
Would you accomodate this sort of usage on your own sites? If not, what specific principle would you suggest, which still allows for AirBNB?
After 2 years of uphill battle, here's how I managed to get off from all recruiters' spamlist & call list:
- For every email coming from an agency: search via the recruiter's domain name for all older emails; scan their websites for contact details; BCC everyone on it (this will make it a subject of coffee conversation)
Subject line: Cease and desist further communication
Body: Dear $RECRUITMENT_COMPANY, and to all whom it might concern,
Pursuant to my rights under the Data Protection Act 1998, I am requesting that you cease and desist communication with me in relation to job offers, or vacancies of any kind.
You are hereby notified that if you do not comply with this request, I will immediately file a complaint with the Information Commissioner's Office. Civil and criminal claims will be pursued.
Sincerely, $FULLNAME
* Send, and mark the original email spam. This will help spamfilters to classify emails of this kind correctly.
* For phone conversations, where the phone number is visible: register for http://www.tpsonline.org.uk/tps/index.html (this is a good idea regardless) ,and file a complaint.
* For phone conversations, where no phone number is available, your mission is to elicit a company name, and while keeping them on the phone, look it up using http://wck2.companieshouse.gov.uk/ . If the company exist, use the above form via email, and inform them the same content verbally.
* If, despite all the above, a company is repeat offender, contact me (email in profile), and we'll take them to small claims.
(Originally from Hungary where it's required; moved to the UK where it's highly discouraged )
The better question is: "How do you decide what to learn?" -for which I strongly suggest taking a strategic portfolio approach: have a few skills that you know in depth, and maintain a consistent flow of learning new things on at least a surface / API level so that given the opportunity you can reach out for them.
Having a few of these under your bells will open your eyes to new opportunities both within your job, and in your life that you can pitch / take advantage of; at which point you can tie it into the "things people pay me for", and start the journey of mastering it in depth without any danger to your livelihood.
A cruicial problem of running marketplaces is any pathway by which stolen CC numbers (readily available by the dozen for pennies) can be turned into cash will be heavily targeted by fraud. See discusson on this here: https://news.ycombinator.com/item?id=5091069 ,and esp the recommendation on getting a Fraud Guy.
http://stackoverflow.com/questions/1050696/the-business-of-a...
However, the business problem raised by mooism2 -specifically, revenue streams, and covering costs - have visible consequences, in that the vast majority of content producers would opt not to pay for distribution of their content.
Also note, that youtube was never built to generate revenue -it was specifically built to flop to one of the big players.
In short, to consider this as an opportunity, you need to radically innovate on extracting alternative revenue streams from viewers, producers, or third parties.
The most viable target market for self-hosted products are still entreprises ; deployment via virtual images might be the most feasable solution for all parties involved.
Second-best option, specifically for eg. PHP, might be compiling the code into executables (via eg. https://github.com/facebook/hiphop-php ), and distributing distro-specific executables.
Re: 3rd option, the specific worry about distributing code in any form isn't piracy (as pointed out by firstprimate, those aren't your customers); rather, blatant ripoffs engaging in marketing-only competition using a rebranded version of your own product.
Reality check: do you have an offer on the table? If no, let them know these details are available once you do. If yes, consider including redtape into your contract days.
Also, and this might sound obvious, but Know Your Customers: specifically perform at least a handful of searches against both the contracting company, the staffing company, all the relevant decision makers, and everyone you know the name of so far. Do they look legit? Are there other contractors on their payroll? Can you contact them, and ask their experiences?