GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Jess👾 (jesstheunstill@infosec.exchange)'s status on Saturday, 13-Sep-2025 04:32:14 JST Jess👾 Jess👾

    Periodic reminder to anyone who builds applications:

    People's names and email addresses can change over time. And not just women's last names. Any part of any person's name. Build a fucking workflow that won't break everything when they do change names.

    In conversation about 2 months ago from infosec.exchange permalink
    • Embed this notice
      ✧✦Catherine✦✧ (whitequark@mastodon.social)'s status on Saturday, 13-Sep-2025 04:32:12 JST ✧✦Catherine✦✧ ✧✦Catherine✦✧
      in reply to
      • artemist

      @artemist @JessTheUnstill these websites exist lolsob

      In conversation about 2 months ago permalink
    • Embed this notice
      artemist (artemist@social.mildlyfunctional.gay)'s status on Saturday, 13-Sep-2025 04:32:13 JST artemist artemist
      in reply to

      @JessTheUnstill i'm also begging everyone to stop using "first name" and "last name", not everyone has both of those and in several countries the family name is first and the personal name is second.

      it's like if you asked everyone to put in their patronymic in a field on your website

      In conversation about 2 months ago permalink

      Attachments

      1. http://second.it/
    • Embed this notice
      Ryan Castellucci :nonbinary_flag: (ryanc@infosec.exchange)'s status on Saturday, 13-Sep-2025 06:21:00 JST Ryan Castellucci :nonbinary_flag: Ryan Castellucci :nonbinary_flag:
      in reply to

      @JessTheUnstill gender should be an ASN.1 BER structure to discourage storing it

      In conversation about 2 months ago permalink
    • Embed this notice
      Jess👾 (jesstheunstill@infosec.exchange)'s status on Saturday, 13-Sep-2025 06:21:01 JST Jess👾 Jess👾
      in reply to

      Obviously gender markers can change too (but unless you're legally required, why the fuck are you storing gender anyway you fucking creeps)

      In conversation about 2 months ago permalink
    • Embed this notice
      Erin 💽✨ (erincandescent@akko.erincandescent.net)'s status on Saturday, 13-Sep-2025 06:43:53 JST Erin 💽✨ Erin 💽✨
      in reply to
      • Firstyear
      • Erin 💽✨
      • xyhhx 🔻
      • yaleman

      @xyhhx @JessTheUnstill @firstyear @yaleman sending full names and full addresses in the general case would be hopeless, these networks work in Latin-1* so there’s no way it could ever work for even half of europe never mind asia

      (*Technically EBCDIC 037 or EBCDIC 1047 butt both of these are 1:1 permutations of ISO 8859-1 so…)

      In conversation about 2 months ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Erin 💽✨ (erincandescent@akko.erincandescent.net)'s status on Saturday, 13-Sep-2025 06:43:55 JST Erin 💽✨ Erin 💽✨
      in reply to
      • Firstyear
      • xyhhx 🔻
      • yaleman

      @xyhhx @JessTheUnstill @firstyear @yaleman for mastercard & visa it basically boils down to card number, expiration date, cvc2/cvv2 digits of address, post/zip code.

      as an issuer we don’t decline based upon address mismatches we just tell the merchant how the address digits + postcode digits matched and they decide whether to reverse the transaction or not. typically they ignore the address digits result entirely and just check the postcode result because addresses get mangled in unholy ways and that check fails all the time for stupid reasons

      In conversation about 2 months ago permalink

      Attachments


    • Embed this notice
      xyhhx 🔻 (xyhhx@nso.group)'s status on Saturday, 13-Sep-2025 06:43:56 JST xyhhx 🔻 xyhhx 🔻
      in reply to
      • Firstyear
      • Erin 💽✨
      • yaleman

      @JessTheUnstill i'm fairly sure it depends on the card issuer and the merchant. i've had mine be declined for erroneous name and/or postal code before

      @erincandescent @firstyear @yaleman

      In conversation about 2 months ago permalink
    • Embed this notice
      Jess👾 (jesstheunstill@infosec.exchange)'s status on Saturday, 13-Sep-2025 06:43:57 JST Jess👾 Jess👾
      in reply to
      • Firstyear
      • Erin 💽✨
      • xyhhx 🔻
      • yaleman

      Hunh, I thought they were picky about that. Is it really just card number, code, and zip?
      @erincandescent @firstyear @yaleman @xyhhx

      In conversation about 2 months ago permalink
    • Embed this notice
      Erin 💽✨ (erincandescent@akko.erincandescent.net)'s status on Saturday, 13-Sep-2025 06:43:58 JST Erin 💽✨ Erin 💽✨
      in reply to
      • Firstyear
      • Erin 💽✨
      • xyhhx 🔻
      • yaleman

      @JessTheUnstill @firstyear @xyhhx @yaleman (asterisk asterisk we might get them if the merchant decides to do 3DSecure v2 and we might even look at them then but if they’re wrong the transaction isn’t getting declined we’re just making you authenticate)

      In conversation about 2 months ago permalink
    • Embed this notice
      Jess👾 (jesstheunstill@infosec.exchange)'s status on Saturday, 13-Sep-2025 06:43:59 JST Jess👾 Jess👾
      in reply to
      • Firstyear
      • xyhhx 🔻
      • yaleman

      I mean, I really don't need someone specifically saying "Dear Jessica" just because that's the first name on my credit card. I'll tell you my name is Jess, you can use Jess anywhere in your application, and you can store "Jessica $Lastname" in the same data as my credit card number. Which is nobody's fucking business beyond processing a credit card transaction and shouldn't be visible in anywhere else in the application.

      @xyhhx @firstyear @yaleman

      In conversation about 2 months ago permalink
    • Embed this notice
      Erin 💽✨ (erincandescent@akko.erincandescent.net)'s status on Saturday, 13-Sep-2025 06:43:59 JST Erin 💽✨ Erin 💽✨
      in reply to
      • Firstyear
      • xyhhx 🔻
      • yaleman

      @JessTheUnstill @xyhhx @firstyear @yaleman as someone who works at a card issuer feel free to tell the merchant your name is “mr fucking blobby” for all i care they don’t send us the name and as for the address we probably only get all of the digits mashed together.

      In conversation about 2 months ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      xyhhx 🔻 (xyhhx@nso.group)'s status on Saturday, 13-Sep-2025 06:44:00 JST xyhhx 🔻 xyhhx 🔻
      in reply to
      • Firstyear
      • yaleman

      @JessTheUnstill shout out to kanidm (thanks @firstyear and @yaleman!):

      https://kanidm.github.io/kanidm/stable/developers/developer_ethics.html#self-name-change

      https://kanidm.github.io/kanidm/stable/developers/#humans-first

      #kanidm

      In conversation about 2 months ago permalink
    • Embed this notice
      Wolf480pl (wolf480pl@mstdn.io)'s status on Saturday, 13-Sep-2025 15:54:31 JST Wolf480pl Wolf480pl
      in reply to
      • Wilfried Klaebe

      @wonka @JessTheUnstill
      hot take:

      instead / in addition to fines, require deletion of data in the presence of a court-appointed expert witness

      In conversation about 2 months ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Jess👾 (jesstheunstill@infosec.exchange)'s status on Saturday, 13-Sep-2025 15:54:32 JST Jess👾 Jess👾
      in reply to
      • Wilfried Klaebe

      @wonka I mean, usually they want it for targeted advertising and demographics profiles for market surveys. But yeah, unless they're needing it for matching to government ID or health insurance or some other system that requires giving a gender marker, it's pointless.

      In conversation about 2 months ago permalink
    • Embed this notice
      Wilfried Klaebe (wonka@chaos.social)'s status on Saturday, 13-Sep-2025 15:54:32 JST Wilfried Klaebe Wilfried Klaebe
      in reply to

      @JessTheUnstill Collecting data that is ONLY useful for profiling and advertising should be only allowed with an explicit opt-in, with stiff fines for transgressions.

      In conversation about 2 months ago permalink
    • Embed this notice
      Wilfried Klaebe (wonka@chaos.social)'s status on Saturday, 13-Sep-2025 15:54:34 JST Wilfried Klaebe Wilfried Klaebe
      in reply to

      @JessTheUnstill Apart from stuff around medical topics and probably dating apps, what would anyone need that for?

      In conversation about 2 months ago permalink
    • Embed this notice
      artemist (artemist@social.mildlyfunctional.gay)'s status on Saturday, 13-Sep-2025 15:58:06 JST artemist artemist
      in reply to

      @JessTheUnstill if you want to ask for "name in passport" don't complain if there's no first name, e.g. Malaysian passports put the entire name in the surname field

      see the sample on PRADO: https://www.consilium.europa.eu/prado/en/MYS-AO-03001/image-315879.html

      (in the MRZ a < character represents a space in a name, the string << separates the surname and forename)

      In conversation about 2 months ago permalink

      Attachments


      Haelwenn /элвэн/ :triskell: likes this.

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.