Hacker Newsnew | past | comments | ask | show | jobs | submit | NJRBailey's commentslogin

This extension has an auto-save option to back up pages you visit to the Wayback Machine automatically, which I think is pretty handy for preserving content.


I get this due to a browser extension I have (in my case it is the extension FreeTree, but chances are you aren't using that). Maybe try disabling all extensions and try the captcha again?


> someone actually had £1000 taken. They actually only had £250 worth of points in their account – however, because the Nectar points balance doesn’t refresh immediately, the fraudsters hit their account 4 times in quick succession. Leaving them with a debit of £750 in their Nectar account balance.

It's astonishing that of all the software engineers involved in programming and reviewing this system, not one of them thought to lock the DB records to prevent this (or worse, someone ordered them not to for some reason). It's so simple to do and should be top consideration when dealing with financial transactions.


I'm sure all of them thought about it. But were then told the terminals used for scan & shop or the self-scan kiosks needs a bit of slop in them to make them appear more reliable, meaning to work "offline" for a short span of time. It is a trade-off between serving real customers (meaning the majority) well but with the downside of benefiting fraudsters.

All systems have trade-offs like these. It reminds me of the phase: "Anyone can build a bridge, but it takes an engineer to build a bridge that barely stands." That applies here. Any student can build a system with locking database records, but then when thousands of people's cards don't work for minute-long lockout periods, you aren't the one doing the CS calls or getting yelled at.


The system originally worked on an overnight batch processing basis.

Each store would have a local copy of the card balances - but only for cards that had been used in that store in the past 12 months.

The first day you scanned your card in a store, you could only collect points (not redeem them).

By the next morning, your card would be included in the local database and you could redeem points - with the vulnerability that each store had its own database, and therefore you could redeem the points in multiple stores.

I thought this had been improved in recent years, but maybe not.


Everything that normal people don't like about the user experience of large computer systems can be attributed to the batch nature of how these systems were designed and often still operate. A lot of systems that feel real-time are really just batched more often.


Is there any actual identity connected to these? A way to find the person and get the money back?


You can register a Nectar card (giving name/postal address/email address/phone number/date of birth), but I'm not sure how much verification of these things they do.

I am not sure, but I think you might need to register to redeem points.


There would be CCTV and maybe more if they used a payment card for the purchase. Whether Sainsburys would lift a finger to investigate a small loss is another matter.


What does negative Nectar points even mean? That you have to keep shopping at Sainsburys until you've accumulated enough points to "pay back" the "debt"?


Or there is a batch update in there somewhere - which given that Nectar is over 20 years old and probably based on older systems I suspect would be a distinct possibility.


Do you have average figures for how much each platform pays per stream? My colleague has his music on both and has said YouTube pays 2x as much per stream compared to Spotify.


My colleague has his music on both Spotify and YouTube Music, and he has said in the past that one YouTube listen is worth 2x as much as one Spotify listen.


What music does he produce?, Can you share his profile



How come you think YouTube Premium would be the same cost as Spotify or Netflix? Spotify in particular only has to store and stream audio, and Netflix has far far less video and audio to store than YouTube - they also both only allow somewhat official content on their platforms (you have to register as an artist to upload to Spotify, and you have to be a registered studio to get onto Netflix). YouTube allows unlimited length, 8K, HDR, 60fps video from anyone who signs up with an email and password. I don't have any actual numbers, but I find it difficult to imagine that YouTube Music (storing one cover image and some audio tracks for a whole album) costs them anything in comparison to the main YouTube service.


Well, I guess I'm really talking about the price of the service rather than the cost to run it really (i.e. what would be a competitive price for the service considering other offerings), but appreciate that the price has to be less than their costs.

Although my assumption (which could be incorrect) is that storage is not the main driver for cost. For Netflix and Spotify I assume their major cost would be licencing, which YouTube mostly gets to forgo. For YouTube, I would assume bandwidth / data transfer is the biggest factor.


Checked on iPhone, it shows the following:

Enter a phone number or email

Or just tap submit

[text input]

Submit


I got that and clicked submit, and it was just the date on an otherwise empty page.

I wasn't expecting much, yet I'm still underwhelmed.


Click the times, each one links to a list of stories. Presumably the idea is the home page is going to be a list of dates and times.


It's due to a broken dark mode I think. Try changing to light mode and try again. I saw a list of times next to the date which are clickable.


New InfluenceMap research finds that corporate net zero or similar targets are rarely matched by support for government climate policy, with 58% of almost 300 companies from the Forbes 2,000 found to be at risk of “net zero greenwash” due to their policy engagement.


I agree - I mostly get ads for things I'm actually interested in (e.g. furniture), and I don't usually buy anything from them, but it at least makes me aware that there may be a new style of products available for when I next need to make a purchase. Also on occasion there will be an advert for something which I wasn't aware existed, or which shows me a new idea to consider. I'm also happy to see ads as an alternative to having to pay for access to a site.


I am hoping for an eye-tracking mouse solution in the meantime, where looking at a portion of the screen and pressing a key on the keyboard will click rather than having to move a hand away from the keyboard to use a mouse, or wait for the analog stick mouse to reach the right point of the screen. Seems to be getting more plausible but still fairly expensive for a few years yet.


You've unlocked a memory. Probably 10-15 years ago, I tried a bunch of eye tracking apps and found one that somehow worked really well with my cheap USB webcam. I'm sure it needed to be calibrated first. It was classic developer software, snappy with bare-bones UI. Freeware, ran on Windows 2000, not sure if open source.

I wonder if I have it backed up or could track down what it was again. I was not much of a developer then, but these days it would be simple to wire up simulated mouse events.


I've built something similar along these lines. It's an app that uses your camera to track hand movement. As you move your hand through the air your cursor moves as well and to click you need to show a simple hand gesture.

My experience with eye trackers was similar. The clicking thing is partially solvable with eye tracker + foot pedal combination, but the biggest turn off with eye tracker was poor support for wider monitors or multiple monitor setup. Eye trackers also require you to be in a certain distance from it which was affecting my posture.

These were some of the reasons why I've built Cursorly https://cursorly.app/ It's still in the early stage but I'd love to hear some feedback. There is a free trial for a few days, but let me know if you want to extended it, I'd be happy to do so.


Talon has an eye tracking mouse, the necessary hardware runs around $250.


I would say that an eye tracking mouse is what OptiKey has, and for Talon it's more of an eye tracking+head pointing+voice clicking mouse. If you have tmj/vocal cords/neck problems you won't be able to use eye tracker as a mouse replacement.


> for Talon it's more of an eye tracking+head pointing+voice clicking mouse

> If you have tmj/vocal cords/neck problems you won't be able to use eye tracker as a mouse replacement.

I disagree with these assertions. There are several options in Talon for eye tracking. Optikey is a nice suite of functionality, but it's Windows-only, while Talon is cross platform. I also have a few users who use the Optikey UI but prefer to use Talon's eye tracking to control it. I've certainly recommended Optikey to users.

The updated direct control mouse mode in Talon 0.3 can be used without any head tracking at all as long as your targets aren't too small.

The zoom mode explicitly uses no head tracking as well.

To click or trigger the zoom mouse, you can make a pop noise, use voice commands, or a physical mouse button, or keyboard, or any keyboard emulating input device (such as a foot pedal), or use one of the dwell options.


Exactly. I hate focus-follows-mouse, but would love focus-follows-gaze.


There's an open issue for me to implement that: https://github.com/talonvoice/talon/issues/487


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: