routing+account numbers are not that sensitive. that's been API for how we transact money since pre-historic times.
plaid gets access to your online account with access personal data, security details, documents, transactions, statements, write-access etc.
Hijacking this comment to complain about fintech apps / saas providers requiring Plaid - please stop.
For example, Coinbase requires logging in with Plaid to... setup auto-pay for their credit card statements. No way to just provide account/routing numbers the good ole way.
There's lots of issues with Plaid but one big one is that banks (e.g big ones like BofA) can lock your account due to suspicious login with Plaid.
I was curious if LLMs are good for this problem. ChatGPT-5.1-Thinking one-shotted a correct Python script without any library use (https://pastecode.io/s/jg6ggxpm).
Claude Opus failed to solve after trying for a while.
In my experience, isolated (repeated) data storage paradigm is even more common at large organizations. They share data via services, ETLs, event buses, etc.
On one hand, the market seems to react to these appropriately. On another hand, the market has a short-term memory and prices go back up.
It's unfortunate Auth0 was acquired by them. Have used it from the beginning and it used to be a great product before the Okta acq. Now it's just constant sales emails, expensive pricing, not much new feature launches, most features are very enterprise focused, bunch of bugs, frequent outages.
Looking for an experienced software engineer to join our strong engineering team. Series B B2B growing startup with about ~100 employees & 30 engineers. We build software products to help some of the largest brands with their supply chains.
- Slack is so easy and fun to use that we use it for things we shouldn't be (fun channels, fun integrations). It creates too much noise and hard to extract signal. It ends up being distracting past 100+ people company.
- Teams is so bad that people try not to use it. It forces you to use it minimally because everything is terrible. It actually ends up being more productive than Slack.
US doesn’t give out a permanent residency based on how long you lived in the country. There’s only a few common paths to immigration: employment sponsored (2-20 years), marriage based (1-3 years), other family based (2-20 years), investor based (1-3 years). Student or tourist years don’t matter.
This seems obvious to the younger generation but “my friends who live in X” works just fine on Facebook. I know the older (my) generation is used to more filters but google/fb/ig/tt handle context-free queries fine by default.
>Consumers, meanwhile, split down the middle between cynics who’re certain it’s worthless and true-believers who think it sets the standard for how security should work.
There are many dependencies in the software supply chain that are maintained by a single person (open source or not),so it seems silly to default assume malicious intent for employees of a software vendor with a good reputation.
There are bad actors that no SOC2 control would catch, and there are good actors (the default) where no SOC2 control affect their behavior.
SOC2 is never part of my decision making, rather, I carefully study the company and product offerings to decide if right fit.
(This is coming from someone who goes thru an annual SOC2 audit)
For me the main and obvious thing about DAU is that the majority of users are readers-only. They don’t tweet or like stuff. Firehose might help with detecting non-bot _tweeters_.
This is definitely a biased post (the author is on the board).
Rippling as a product reminds of Hubspot. It’s cheap/free for small companies, has many checkbox-list of features, looks good conceptually, but doesn’t actually do anything well.
It’s “good enough” initially but most companies end up unbundling Rippling as they get bigger.
Oh support- sometimes it has taken us weeks to hear back.
We probably won’t move away from it but I know there’s a better alternative for every module they provide.
Iirc, they were saved as “drafts”, meaning you could come back to it later or on another device. Youtube was like that before instagram, it’s a popular feature on Snapchat/Tiktok.
My point is that it is feature clearly people appreciated, not a dark UX pattern.
One simple example was that I couldn’t install dependencies from public registries such npmjs (npm) or pypi (pip). It took an approval process for an internal team to review and clone packages onto Google’s internal registry.
On the other hand, things like deployment and monitoring were so trivial and magic.