Hacker Newsnew | past | comments | ask | show | jobs | submit | codedokode's commentslogin

Is it much different from Apple and Google who trick user into agreeing and upload all user's data into a US cloud for convenient LE access?

Also, as I understood, this is a feature to allow server-side indexing of the project. But of course I wouldn't run this, and I generally wouldn't run any IDE or AI tools without a sandbox.

Sadly this plague of silent auto-updates is spreading to Linux. For example, browser plugins in Firefox on Linux can silently auto-update without user consent and without any checks and can be used as backdoors. Furthermore, the auto-updates are not using a package manager; firmware also seem to quietly update and also is not using a package manager.


You should use a sandbox. It is dumb to run any proprietary software without a sandbox, especially LLM-powered.

As I remember, you are also supposed to turn the wheels so that even if a car starts rolling, it won't be able to go staight.

Who are those people having lot of time to re-read their old message history? I assume most people only read last several messages in a chat. This matches the real life conversations which are not stored anywhere. However, police will definitely be happy to discover that your many years messaging history is intact.

I would rather want a feature, like Telegram has, where you can set auto-delete of all messages older than N days.


>Who are those people having lot of time to re-read their old message history?

Everyone who has to, say, prove that they kept paying their rent for a year without interruptions. You sent a photo of your money transfer from the bank app to your landlord, and he sends the "received" screenshot from his bank app.

Moreover, a lot (even most) people make personal notes by sending messages to themselves.


For me searching my old messages is really useful. I don't scroll back through history but I'll search for things like "plumber" to find the number of a plumber a friend texted me a while back.

>police will definitely be happy

Most people trust the police. This might not be justified in your state, but most people still do.


the only people that really trust the police are ones that never actually had to deal with the police (which may be a whole lot of people). however, if you ever have an unfortunate situation to have a run in with the police, there is a good chance you will not be all that trusting any longer. people trust the idea of police more so than anything else

Well, true. But even so, having the history intact is also a way to remove suspicions from yourself.

"Where were you during the event X? I was very far from the place you are interested in, as can be proven by this photo, sent to my grandma, have a look at the history in her phone."


I am ok with Electron if it is needed for Matrix. Also, Telegram has a C++ desktop client.

Also, I would not advise to add proprietary repositories as you grant them root access to your system which is against security practices such as the principle of minimum privileges and defence-in-depth.


> TikTok in August agreed to settle three U.S. lawsuits brought by young people who accuse social media companies of designing their platforms to be addictive and harming their mental health.

I am so happy I do not live in US where an idiot harms themself and non-idiot has to pay them.


> young people

We were all idiots at that point in our lives.


But we didn't sue or blame anyone for this.

What libertarian utopia do you live in?

Because 99% of adult people have other things to do than manually build content filters.

It definitely can be stopped. For example, China sells cars internally at cheaper prices, but they are locked to prevent using them outside the country. However, there are people who can hack and unlock them allowing operating in any country. But maybe it would be illegal in the West, I don't know. Removing the modem is an easier task.

You do not need to compromise anything, you can put any address in the "from" field. Email has no universal verification for sender address.

I would sincerely hope .gov addresses use SPF/DKIM/DMARC. That makes spoofing impossible. In Revolut's case, the sender's email system had been compromised.

And what about the rest of the world?

This is a reminder about what happens to people happily uploading their passport and selfies into the app. Do not do it if you do not want to end up in a Russian underground forums.

What else are you supposed to do? All bank require BYC and will ask you to control your identity. We shouldn’t blame customers for the fintech company mistakes

Some banks, I assume, allow showing the documents in person and without a selfie.

You assume wrong if you’re taking about old-school banks. They’ll still scan your id and it ends up in the same system

Not necesary, it might be an internal system. And no selfie. For example, in Russia it probably would be illegal to send personal and biometric data abroad. But of course in the West the rules might be different and it is ok to send citizens' data to shady foreign companies.

Also I am surprised people do not see the different between isolated internal "old school" systems built on owned servers located at the bank property and modern vibe-coded microservices in kubernetes in a rented cloud with the widest attack surface possible.


Just showing documents? I never saw a bank that will do this. They always make a copy.

Yes, but it might go to an internal system, and internal bank systems are protected relatively well compared to mobile apps. And you don't have to do a selfie.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: