Andrew Escobar (Andres)

@andrewe
76 Followers
152 Following
104 Posts
fintech exec, open banking persister • board leadership & good governance • former open finance director mx.com & corporate director
cira.ca
websiteandrewe.ca
defaults write com[.]apple.Preview com[.]apple.SwiftUI.DisableSolarium -boolean YES

“In a time of misinformation, in a time of suppression, having this place where people can come and bring knowledge and share knowledge, that is a statement.”

How Wikipedia survives while the rest of the internet breaks: https://www.theverge.com/cs/features/717322/wikipedia-attacks-neutrality-history-jimmy-wales

Claude needs temporary chats. ⌘ ⇧ N

I pay $100 for Max and yet I still use ChatGPT all. the. time. for mundane prompts.

Google will begin redirecting traffic to google‍.com stating that country-code top-level domains are “no longer necessary” for search.

A hit to the .CA brand, sure, but Canada’s domain name has never been more relevant.

While twitter is down, I’m noticing the thoughtful details available to Mastodon apps via API.

Author credit in preview cards: https://docs.joinmastodon.org/entities/PreviewCardAuthor/

PreviewCardAuthor - Mastodon documentation

Represents an author in a rich preview card.

A password manager can ideally suggest the right account(s) at the right time. This saves time but also avoids the user attaching verification codes to the wrong account. The most direct way to identify those accounts is to match a domain name.

1. Not every browser or platform shares the domain name or other heuristics during a handoff on the same device.

2. QR codes in particular need the domain name included in the URL (and encoded in the image) for handoff.

Always include a domain name!

Apple and Google have similar recommendations for this handoff, but one difference can improve the user experience (or it hold back) by allowing a password manager to suggest the right account (or none at all) to add a verification code to.

QR codes are most common way to set up a verification code today. Users are often prompted to scan one with an “authenticator app.” These QR codes are just an encoded URL like this example:

otpauth://totp/Example:username?secret=key&issuer=example‍.com

The internet needs a standard for setting up one-time verification codes. Apple should draft one.

SMS codes are effortless, but less secure.

One-time verification codes offer a more secure alternative, but require a password manager — and an initial handoff that lacks an internet standard.

Try this demo of an ideal handoff and verification codes in general: https://otpauth.dev

otpauth demo

otpauth demo B

Great annual report from Defector — a cooperatively owned and operated media business: https://defector.com/defector-annual-report-year-four

Appreciate the overall transparency, but (as a payments nerd) particularly enjoy these insights into Stripe and subscriptions: “a new annual subscription projects to be worth ~20% more to us during its first year than a new monthly subscription.”

Defector Annual Report, September 2023 – August 2024 | Defector

Published on October 16, 2024 Purpose of this report This is the fourth year that Defector’s business team is publishing an annual report. Let us be frank: We sort of regret backing ourselves into this corner of having to produce one of these every year. We’re not sure we will continue to have all that […]