Thursday, May 01, 2025

How to get the postman collection data of others?

Create a postman collection that is of some interest to other users. 

Invite them to your postman collection. 

Once they accept your invitation, remove them from your team, and while removing, select the option to copy their private workspace to your account.

Voila..  You got full access to their private workspaces, variables and many others. 

At this point, they would lose access to all their workspaces. If you want to appear to be nice, add them back immediately after copying their collections, and grant them access to their workspaces. If they do not pay much attention, they may think that there was some glitch in between and it got resolved automatically. But, in between, you would have got full access to all their collections.

Like the spam mails that are sent, if an invitation mail is sent to all the software engineers, definitely a few of them would click accept and you would get access to all their postman collections.

Typically many people who use postman extensively would keep the passwords, api keys and many other confidential information in their private workspace, assuming nobody could access. If you could tempt them to join your team, you can get all the confidential information. 

However, this would work, only if that person has not yet joined any team. If that person has joined any team, the owner of the first team to which he/she joins, would get the access to that workspace. 

Tuesday, April 29, 2025

Serious Security Issues in Postman

I have been using Postman for many many years.

A couple of years back, I joined a team. 

Yesterday, they removed me from the team. 

They got full access to all my private workspaces that I have created before I joined the team, and I lost access to those workspaces.

It is definitely one of the biggest security issues that I have seen recently. 

Tuesday, July 23, 2024

End of Buy back shares?

Recently, you bought shares of a company for Rs.100. The company is ready to buy it for Rs.120. A random person in the market is ready to buy for Rs.106. Whom do you want to sell to maximize your returns?

You would be more profitable, if you sell for Rs.106 to a random person than selling for Rs.120 to the company. 

Starting with this financial year, the returns in the buy back shares are taxed in the hands of the recipient as Dividend. 

If you are selling the share to the company for Rs.120, and if you are in the highest tax bracket, then you have to pay a tax of Rs.36+Cess. 

Of course, you can claim a capital loss of Rs.100 for the purchase price, which can be offset with other capital gains that you may have. [It cannot be offset with your Salary, Savings/FD interest or any other income other than capital gains.]

Let's assume, you have a short term capital gain somewhere else and you are offsetting that loss with that. The tax benefit that you get by that is Rs.20 [20% is the short term capital gains from 2024-25 FY].

The net tax that you would be paying is Rs.36-Rs.20=Rs.16.

For the profit of Rs.20, you would be paying tax of Rs.16 [In case of short term capital gains].

Let's say, you bought this share more than a year back, and you want to offset with the long term capital gains. The tax benefit that you get from the capital loss is Rs.12.5 [Assuming, your long term capital gains is more than Rs.1.25 Lakh + purchase price of these shares].

The net tax that you would be paying is Rs.36-Rs.12.5 = Rs.23.5

For the profit of Rs.20, you would be paying tax of Rs.23.5

Hats off to Nirmal Sitharaman for bringing such a simplified tax system.

Saturday, February 17, 2024

Electoral Bonds

I am a little disappointed with the judgement of the Supreme Court on the Electoral Bonds.

One of the most important aspects of a democracy is Confidentiality. One should be able to support a political party without disclosing to which party one is supporting. It has two aspects. First one is voting inside a polling booth, and second one is supporting outside the polling booth. Voting inside a polling booth is confidential and others do not have any way of knowing. But, supporting a political party outside the polling booth confidentially has many roadblocks.

Except for the businesses of politicians, no business person would like to align with any political party publicly. They always wanted to be seen as neutral to everyone. They try to tell all the political parties that they are with them. They do not want to disclose any support that they do to any political party. If they are seen as aligned to one political party, they will face many problems when that party is not in power. 

If one does not appreciate the fact that there are few people/companies that want to support the political parties secretly, they need to learn many things in democracy and politics.

Before electoral bonds, if a company wanted to donate to a political party secretly, it was a lot of work for them. They cannot write a cheque in the name of the political party, as that would be reported in the company books, and it would be disclosed. What they used to do was, they manipulate the accounts and take some money out of the company (by not so legal way), and give that cash to the political party. 

Electoral bonds was trying to fix the issue of the anonymousness. A company can buy an electoral bond through the company's money from the bank by paying money either digitally or through a cheque. The electoral bond can be physically given to any political party that the company wishes, and the political party can redeem and get the money in its bank account. 

By this, the company does not need to manipulate the accounts. Manipulating the accounts comes with a cost, as the people who supported with fake bills/accounts/companies would need some percentage of commission for their work. Also, companies won't get any tax benefits from donations to the political parties when they donate that way. With Electoral Bonds, companies would not need to manipulate the accounts and would save money from there. Also, they would get tax exemptions when they donate through Electoral Bonds. 

Even for political parties, it is not so easy to manage a lot of cash. When there is a lot of cash, it is possible that the lower level leaders would siphon some money. It would be hard for the top leaders in the political party to manage huge cash. If the money is in the bank account, then the top leaders in the political parties have control on the money.

Arun Jaitley was a treasurer of BJP for a long time. He faced all the problems, and he wanted to make it simple for both the companies and the political parties, and brought Electoral Bonds. 

Tuesday, February 13, 2024

Next Version of ChatGPT

Previously, people used to comment about me that, if anyone asks me one question, I ask them back 10 questions before answering their question. 

Even if I get a simple question like, "How to go to Guindy Bus stop" from anyone at Guindy Railway Station, I do not answer without asking a question to that person. 

The reason I ask questions for any question is, I would prefer to give an efficient answer or solution for their problem. A question may have multiple solutions, but, we have to pick one good solution based on the circumstances and others. If I know all the related things about that question, then I can pinpoint one accurate solution that is most suited for that situation.

I would like, if ChatGPT can do the same way. If I ask an abstract question, it assumes many things and tries to give some solution. But, it should ask questions about that problem to get the exact situation, and based on the detailed problem, it should give appropriate solution. 

[Guindy is a pretty big area in Chennai. It has three bus stops on three sides of the railway station. If anyone asks "How to go to Guindy Bus stop", one should ask their next destination from Guindy Bus Stop, and redirect to the appropriate bus stop out of the three. If anyone points them to a random bus stop, and if that is not the correct bus stop, one may have to walk half a kilometer to the other bus stop. There were a few times when I got irritated with others, when they interrupted my questions, and gave a random answer to the people.]

[Nowadays, people are not commenting me much, may be due to either Respect or Fear or both. But, my attitude of asking questions did not change.]