Hacker News new | past | comments | ask | show | jobs | submit | lukebennett's comments login

Firefox offers this in the dropdown when typing a URL, there's a "Switch to Tab" option to take you straight to the existing tab instead of creating a duplicate.


Or, if you already know it is already opened, you can use % prefix in the url bar to only suggest switching to already opened tabs.


> I think we need to force all financial companies to have a modern API and OAuth available for everyone via legislation.

That already exists[0] in the UK

[0] https://www.openbanking.org.uk/


It's been a little while since I've looked into the Open Banking API stuff - how easy is it to use this API as a consumer? Or do I have to create a business and apply for a license in order to use it?


Open Banking is in some ways misnamed - you can't as an end-user just do OAuth and get a data feed out of your account, you'll have to go via a third party who've jumped through all the hoops.


Got it! That's what I thought (feared). I wonder if there are ever plans to open it up to general use, or if it would be easy as an end user to jump said hoops.

I wonder if there are any open source third parties?


I don't know about open source ones, but I did find Enable Banking (https://old.reddit.com/r/eupersonalfinance/comments/k4ny3j/f...) offering free access to your own accounts. I don't know if "offer" still stands, the FAQ is not very explicit on it (it only talks about testing, https://enablebanking.com/docs/faq/#can-i-test-the-api-befor... & https://enablebanking.com/docs/api/linked-accounts/).

I tried it, but I couldn't get things working sandbox environment so I ended up giving up and just do manual exports.


GoCardless has an API that’s connected to 2.3k banks in Europe and UK.

Free to use (up to a limit). Not open source though.

Link: https://gocardless.com/bank-account-data/

[I work at GoCardless]


Europe has a shot too but what i’ve found is that the API’s are often so clunky and bad that they might as well not exist


This is explicitly accounted for, as per the README:

> Many Postgres clients also inspect the pg_catalog to determine system information so Postlite mirrors this catalog by using an attached in-memory database with virtual tables.


What if you are logging into something on a device that doesn't have your email on it? So called magic links are an absolute nightmare.


Whilst there is an element of lab measurement involved, they do use field measurement, so metrics are collated from users rather than their own connection. This means that your data could just as easily be skewed by a browser/OS update that rolls out to a ton of devices at once, as much as anything at your end.

Do agree that the proliferation of acronyms doesn't help with wrapping your head around it all!


Yep, that's exactly what Splunk have done - scroll down the release notes linked to by the grandparent and the faulty regex is shown.

What's super daft is the proposed fix is only a further sticking plaster, adding support for the 16... range (and the 2020s decade) rather than all future dates. So in a couple of years a further patch will be needed...


To fix the fire this is probably the best solution because the risk of unintended side effects is very low. I would just hope it is then followed by a proper fix.


Wow ... I'm ... I'm sure there's a better way to handle this.


Yep that's right, the liability shifts from the merchant to the bank.


Not for long, it will be mandatory in the EU from the end of the year under the PSD2 regulations (though the deadline has moved back into 2021 for some countries, including the UK which is adopting them despite Brexit).

Issuers will start to decline card transactions for any merchants that submit payments that haven't gone through 3DS.


Hell yeah! Now we just need to get banks to stop using SMS 2FA and embrace an open 2FA standard like TOTP and our money (!!) will finally be almost as secure as our Facebook accounts have been for 5 years...


TOTP can be phished (there is even ready to use proof of concept software for building a TOTP phishing site), so it's a pretty poor choice.

https://breakdev.org/evilginx-2-next-generation-of-phishing-...

Instead banks should use WebAuthn. WebAuthn's credentials are directly bound to the DNS name. So anything that involves fooling the human like a phishing site can't work. The only site your authenticator can give the real-bank.example credentials to is... real-bank.example.


SMS 2FA can also be phished, so TOTP would still be better and WebAuthn is such a complete paradigm shift that it would take many years for banks to implement it. TOTP is so stupidly simple they could roll it out in a month, audits and all.

Not to mention that in order to have a decent WebAuthn experience, you need a Yubikey with NFC, which go for 30-60$ if I remember correctly. Cost of authenticators is why everyone switched away from RSA SecurID.


WebAuthn for relying parties (what the bank is in this scenario) just isn't very hard. And you don't end up with any long term secrets at all, so that makes the security story easier. But I sadly do not expect banks to adopt it anyway.

I don't see what a Yubikey with NFC is getting you here. For a laptop/desktop user any of the Security Key products in an appropriate USB form factor (USB C for some newer laptops otherwise USB A) would be suitable.

The high end phones are or in the case of the iPhone very shortly will be WebAuthn platform authenticators, there's nothing extra to buy. Apple released a video of the pleasant UX journey they want to promote, obviously being Apple it doesn't actually say this would work on non-Apple devices but I use it already so I know it does.


My bank never used SMS as 2FA. They supported mobile signature for… I do not even remember how long, at least 11 years now. TOTP was supported even before that and is phased out in favour of https://www.smart-id.com/


My bank once gave me a one time pad :)


Was it Symantec? You can import that into Authy/Google Authenticator/1Password if you want. It's good at least for backup.

https://github.com/dlenski/python-vipaccess


> Claudia's theme from Once Upon A Time in The West is as good as it gets.

Hear hear, one of the most evocative pieces ever written, sends shivers down my spine every time. A real masterpiece.


So very sad :( One of my all time favourite composers. Such emotive music that bring back so many memories, not least my wife walking down the aisle to me to Gabriel's Oboe. RIP.


That piece gives me gooseflesh every time I hear it.


Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: