Hacker Newsnew | past | comments | ask | show | jobs | submit | cassianoleal's commentslogin

In this case it's not fraud though, since the person running the software is the same person whose signature ended in the document.

> So for example, i have a conversation in Proactive Messaging asking claude to follow the lowest price of something and let me now if it goes below a certain value. Then a few weeks down the line, i get a popup from claude about this if it happens. There should also be a menu in this case with what tasks like this have been defined.

I've been looking for a new cooker. I have a Hermes agent running on VM that does this. I told it to keep an eye on prices. It created a cron job that triggers the scrapes and messages me if anything interesting happened since the last time it checked.


> The model draws on ratings from 60 people

So, not representative of "human preference" at all, probably.


Yes, the result is for entertainment purposes only and does not represent a serious scientific path.

> This is also why they do Windows on Linux emulation.

They don't. They use WINE, which as the name says, Is Not an Emulator. :D

(I'll let my pedantic self out now)


despite the funny backronym, Wine actually IS a WINdows Emulator. Someone apparently told them that it's only called an emulator if it's emulating a CPU architecture, but that's not true.

I thought it was an implementation of the Win32 API as a compatibility layer.

What is it emulating exactly?


DOS interrupts, for starters.

Windows.

Does Windows NT have a Windows 9x API emulator?

Windows NT predates Windows 95 for two years.

And yes it did had emulators for Windows 16, and DOS

https://en.wikipedia.org/wiki/Virtual_DOS_machine

https://en.wikipedia.org/wiki/Windows_on_Windows


If you squint a bit (well, a lot really), Win32S on 3.1 and Windows 95’s Win32 implementation are Windows NT emulators running on top of 16 bit Windows.

Windows NT doesn't emulated Windows, it is Windows. Wine is not Windows and emulates Windows.

It is windows today, but in the beginning the two were incompatible different products.

Wine Is Not (an) Emulator

Yet, it emulates windows and is a windows emulator.

No, it's a Win32 implementation for Unix.

its closer to a translator than an emulator

What do you think an emulator is?

“Emulator” is a term of art in this area which refers to emulation of a hardware (and usually machine instruction) environment. Ironically, “translation” (as in instruction translation), as proposed by a sibling comment, is an even more connoted-with-hardware-emulation term.

WINE is … well, most directly it’s just an implementation of an API (the Windows APIs). In webdev parlance it might be called a “polyfill”. Perhaps a “compatibility shim”?


I think in common usage, people expect an "emulator" to be a more sandboxed translation layer than Wine, for example, provides.

e.g. it's probably a security vuln if loading a Game Boy ROM reads arbitrary paths on your local filesystem determined by the ROM's code, not so much with Wine.

Someone made a cute demonstration that I think usefully encapsulates this a while ago. [1]

[1] - https://gpfault.net/posts/drunk-exe.html


Mostly because the Gameboy doesn't have any IO register to reformat your hard disk. If the emulator interpreted some instruction as reformatting your hard disk, that would be a bug because it's not interpreting it as whatever it actually does on a real Gameboy.

A translater is a more accurate description of WINE. WINE literally translates API calls from the client program to the host OS.

What do you think an emulator is?

For me an emulator works to simulate the hardware which is very different from translating API calls. THe result may appear to be same, but the approach is very different.

Why is hardware the only thing that can be emulated?

an traditional emulator emulates all the hardware of the target machine. WINE does nothing of that.

Yeah this could open up a whole new category of lightweight gaming PCs.

Fried chunks of potato with chilli sauce.

> The data may have also included verification selfies

Why do they even keep those?


I am almost sure they don't and instead they query selfies and documents on-demand from their KYC provider.

Yep, the KYC provider keeps them.

Could they be put in what bitcoin people call "cold storage"? I can't imagine they're used every day.

They're used pretty often, so not really. The KYC providers anyway wouldn't code anything like that.

Around banking it's usually because they have to

Other banks do not require selfies, so there are other options

But they are verifying customers in person with account creation, this is an online bank

> But they are verifying customers in person with account creation, this is an online bank

Revolut could do the same as they do with ATMs: make a partnership with local banks for the verification step.


Sure, but that would be like insanely stupid on pretty much every level though, so why would they do that?

Trying to find a way to tip toe around KYC, whilst keeping their customers safe, has also turned out to only use insanely stupid methods, though. So why did they already do that?

FYI it turns out that humans are pretty bad at comparing faces to ID documents. Like, really quite bad.

Automated methods, like the ones Revolut use, are significantly more effective at KYC than a Jane Doe working a 9-5 at a bank. In no way is it “tip-toeing around KYC”, and while really unfortunate leaking a selfie is pretty low down on the list of “bad stuff a bank could leak”.

The implication that the solution to this is to somehow convince your direct competitors to do inferior in-person KYC for you is the most ridiculous thing.


>The implication that the solution to this is to somehow convince your direct competitors to do inferior in-person KYC for you is the most ridiculous thing.

People work with their competitors all the time (see Netfix vs Amazon). Whats ridiculuous is the claim that a scammer would prefer to show up physically at a bank and risk being exposed instead of operating remotely.

>leaking a selfie is pretty low down on the list of “bad stuff a bank could leak”.

don't some of them require a selfie while holding legible official documentation?


No, it’s most certainly patently ridiculous.

> Whats ridiculuous is the claim that a scammer would prefer to show up physically at a bank and risk being exposed instead of operating remotely.

Of course they wouldn’t prefer to show physically. What does that mean though? Are you saying no scammers showed up physically to banks, therefore banking fraud rates are less? Do you have a source for that?

> don't some of them require a selfie while holding legible official documentation?

You can of course do KYC as stupidly as you like (zoom calls anyone?) - Revolut (and their providers) obviously separate document presentation from the liveness check (and fyi this is a short video, not a selfie. The selfie they are talking about is just a capture from the video)


>No, it’s most certainly patently ridiculous

Is your argument supposed to be more convincing because you added the word "patently"?

>What does that mean though?

It means that when you find a way to bypass purely online identity verification checks executing fraud at scale is easier than the physical alternative. As you would say, this is patently obvious.


For security reasons, obviously! That way they wouldn't leak selfies because they wouldn't have any.

Sending your new/potential customers to your competitor doesn't sound very sensible.

Seems like a thing you should be able to do at the post office.

What does post office have to do with identity verification?

In the USA they already take passport photos. Being able to receive mail addressed to a name is the closest thing to a national ID the USA has. They're already depended on for identity verification quite a lot.

You can receive mail to any name at your address.

I didn't say it was a good national ID system, I said it's the closest thing the US has to one.

Some post offices in the US also function as a so called notary public. Basically, they can verify your identity and attest that it's you who sent/did something.

This is used quite often for important things that don't have offices themselves.


This is a 100% online bank account you typically open from an app. The typical clientele will just use the "selfie" auth.

The issue is that there is no alternative to the "selfie" auth in case of Revolut.

Most banks now require selfies, try shopping around. KYC requirements get tightened all the time.

I have accounts with 2 other banks. They never asked for a selfie.

Same, they never asked for a selfie back then.

Try opening one now. Today it's hard to get a hire purchase contract as an existing custoner (already known and verified) without photos of the ID and selfie.


Likewise, opened a couple in the past few years and never saw this. That said, bank lobbies have tons of ambient cameras anyway, so they don't really need a selfie.

At least one traditional UK bank requires a selfie and a passport scan.

CYA in case of litigation.

You can't have implicit opt-out either. Opting is an explicit act.

I almost fell for one. Actually I did, but uBO blocked it.

I searched for "Homebrew install". Clicked the first link. It looked exactly the same as the legit brew.sh. I was tired and didn't even think twice. Google wouldn't have put the scam clone website ahead of the real one, right?

When I clicked to copy the install command (which read exactly correct), I got the uBO message saying it blocked a ClickFix attack. Users who do that without protection would have the wrong URL on their clipboard, and likely install malware thinking they were getting upstream Homebrew.


I haven't seen it spelled out, either here or in TFA: Is uBlock Origin, and thus Firefox, required? Or is uBlock Origin Lite, and therefore a Chromium-based browser, sufficient?

Which one blocked the homebrew attack you mentioned? Because while I have a suspicion, knowing, and having it stated explicitly, is still good information to have


https://github.com/uBlockOrigin/uAssets/discussions/34325#di...

I think that implies mv3 does support it. Seeing as it can inject scripts, I don't see why it wouldn't be able to.


In my case, it was uBO on Firefox. I don't use Chrom(e|ium) so I couldn't tell.

In any case, "We don't record continuously" is still recording. They should not be recording at all!

Enough with the knee jerk reactions. They have to record in some cases. You don't have to like those features, but plenty of people want those features.

- The television has voice control.

- The television has a manually triggered speech-to-text feature so you don't have to type with tv remote.


You simply do not say something like “we don’t record continuously” if the reality is that you only record when voice control or speech to text is active. Given the entire industry’s track record, the only sane thing to do when confronted with weasel wording is to assume the truth is the worst possible interpretation that isn’t a blatant lie, and even then, sometimes it is just a blatant lie.

Here’s some examples:

- We don’t record continuously -> We record nearly all the time, only stopping to upload the recording.

- We do not sell your data -> But we do “share” it.

- All your data is protected from unauthorized LLM scraping -> But we define all the big tech companies as authorized scraping.


> We do not sell your data -> But we do “share” it.

Likely true that it's not sold. They want to retain ownership. Like all modern items, they LICENSE your data to others.


You'd think if that was all they recorded for, they would be saying it very loudly to end the speculation that weasel-wording leads to.

But they did say that? "LG TVs process voice data only when the voice button on the remote control is pressed and held, or when a wake word such as 'Hi LG' is recognized after the user has activated the Far-Field voice recognition feature."

Find one person who when asked if you they want the useful feature of LG always recording everything they watch on their TVs and selling that data to third parties without giving anything in return would answer yes.

I get the voice commands but it shouldn't be possible for them to always record everything anyone in the vicinity says without explicitly activating the command (and it should be impossible to hack it, i.e. it should be implemented in hardware not buggy software)


None of that requires recording and has been done with embedded hw with local software for years.

> Enough with the knee jerk reactions.

No. Stop minimizing their abuse.


Recording is not the same as listening

Enough with the corporate shilling. Go back to your manufacturer for a factory reset

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: