2,525 karma · joined August 5, 2011
https://www.eff.org/deeplinks/2013/08/letter?utm_source=twit...
In any situation involving money, every loophole or mechanism for scamming people will eventually be discovered and then exploited to an extent you never believed possible. Just as the Internet has massively changed the basic economics of almost every industry, it has greatly reduced the risk and costs of widespread fraud to a level that would make Charles Ponzi cry with joy into his spaghetti.
There are teams of extremely intelligent and motivated people who spend their entire working careers figuring out ways to rip off Paypal (and Amazon, eBay, Google, Baidu, Bitcoin merchants, etc...) If a top tier company that deals with money on the Internet is problematic for a certain transaction, then you can be sure that is due to a real problem in the past that resembles that transaction.
Pydanny believes that Paypal's actions are without basis, so he has clearly identified a market inefficiency that is ripe for "disruption".
I think pydanny should take this opportunity to pitch his payments startup, PyPal, to pg and several other top-tier angels/VCs. Make sure to include a slide on fraud and loss prevention, and clearly outline the policy that will differentiate you from Paypal:
"The developer community is critical for the success of PyPal. In a situation where a PyPal account identified only by a Yahoo email address and with limited transaction history receives hundreds of thousands of dollars in deposits for a service that will not be delivered for months, we will not freeze that account under any circumstances. Especially if they self-identify as a Python developer."
Let me know how the pitch meetings go.
That'll make you appreciate the Shinkansen or ICE networks.
As priced, it's a no-brainer for the executive set who like to be seen with their iPads but get real work done on 5 pound, AD-joined, IT provisioned Dells. They already have volume licensed Office, and IT teams are going to make this a standard option for road-warriors and execs.
I think the Hacker News set doesn't understand what it's like to work at a non-tech Fortune 500 company. Microsoft's goal isn't to replace the iPad on teenagers' Christmas lists, it's to protect the highly lucrative corporate market from further iPad (and eventually Mac) penetration. On that measure, the Surface Pro is going to crush it.
I should point out this is about more than TLS, and more than the web. We have a short window during which we can create an Internet category that is both clear to the user in it's goals and specific in its requirements for hosts. Our hope is to create an extensible protocol with DPF, one that can be extended to give domain registries and registrants the ability to choose higher privacy protections, limit risk to CA compromise, and secure other protocols like SMTP.
I think we agree about UX. One of the big picture goals of .secure is to invert the current security experience. These days you go to a site and then have to interpret the UI to see if you are safe. In our vision, when you type bank.secure you are telling your browser, OS and the server on the other side that you want to navigate there as safely as possible.
I'm going to post about the tech details more tomorrow and hopefully that clears some things up.