Hacker Newsnew | past | comments | ask | show | jobs | submit | codedokode's commentslogin

As I remember, you are also supposed to turn the wheels so that even if a car starts rolling, it won't be able to go staight.

Who are those people having lot of time to re-read their old message history? I assume most people only read last several messages in a chat. This matches the real life conversations which are not stored anywhere. However, police will definitely be happy to discover that your many years messaging history is intact.

I would rather want a feature, like Telegram has, where you can set auto-delete of all messages older than N days.


>Who are those people having lot of time to re-read their old message history?

Everyone who has to, say, prove that they kept paying their rent for a year without interruptions. You sent a photo of your money transfer from the bank app to your landlord, and he sends the "received" screenshot from his bank app.

Moreover, a lot (even most) people make personal notes by sending messages to themselves.


For me searching my old messages is really useful. I don't scroll back through history but I'll search for things like "plumber" to find the number of a plumber a friend texted me a while back.

>police will definitely be happy

Most people trust the police. This might not be justified in your state, but most people still do.


the only people that really trust the police are ones that never actually had to deal with the police (which may be a whole lot of people). however, if you ever have an unfortunate situation to have a run in with the police, there is a good chance you will not be all that trusting any longer. people trust the idea of police more so than anything else

Well, true. But even so, having the history intact is also a way to remove suspicions from yourself.

"Where were you during the event X? I was very far from the place you are interested in, as can be proven by this photo, sent to my grandma, have a look at the history in her phone."


I am ok with Electron if it is needed for Matrix. Also, Telegram has a C++ desktop client.

Also, I would not advise to add proprietary repositories as you grant them root access to your system which is against security practices such as the principle of minimum privileges and defence-in-depth.


> TikTok in August agreed to settle three U.S. lawsuits brought by young people who accuse social media companies of designing their platforms to be addictive and harming their mental health.

I am so happy I do not live in US where an idiot harms themself and non-idiot has to pay them.


> young people

We were all idiots at that point in our lives.


But we didn't sue or blame anyone for this.

What libertarian utopia do you live in?

Because 99% of adult people have other things to do than manually build content filters.

It definitely can be stopped. For example, China sells cars internally at cheaper prices, but they are locked to prevent using them outside the country. However, there are people who can hack and unlock them allowing operating in any country. But maybe it would be illegal in the West, I don't know. Removing the modem is an easier task.

You do not need to compromise anything, you can put any address in the "from" field. Email has no universal verification for sender address.

I would sincerely hope .gov addresses use SPF/DKIM/DMARC. That makes spoofing impossible. In Revolut's case, the sender's email system had been compromised.

And what about the rest of the world?

This is a reminder about what happens to people happily uploading their passport and selfies into the app. Do not do it if you do not want to end up in a Russian underground forums.

What else are you supposed to do? All bank require BYC and will ask you to control your identity. We shouldn’t blame customers for the fintech company mistakes

Some banks, I assume, allow showing the documents in person and without a selfie.

You assume wrong if you’re taking about old-school banks. They’ll still scan your id and it ends up in the same system

Not necesary, it might be an internal system. And no selfie. For example, in Russia it probably would be illegal to send personal and biometric data abroad. But of course in the West the rules might be different and it is ok to send citizens' data to shady foreign companies.

Also I am surprised people do not see the different between isolated internal "old school" systems built on owned servers located at the bank property and modern vibe-coded microservices in kubernetes in a rented cloud with the widest attack surface possible.


Just showing documents? I never saw a bank that will do this. They always make a copy.

Yes, but it might go to an internal system, and internal bank systems are protected relatively well compared to mobile apps. And you don't have to do a selfie.

The stupid thing about Android is that it requires you to set a PIN to use Always-on VPN which is necessary for traffic filtering (as Android doesn't provide access to nft).

That seems like a good trick to me if you want to prevent people from installing spyware without any obvious signs.

You can almost hide the warnings (there's one small notification in the bottom of the notification tray you can't disable) and on some phones even the VPN icon, but you can't hide the new lock screen code your victim suddenly needs to enter to use their phone.

It used to be that Android showed random popups and notifications about identified security risks, which were awfully annoying if you have a private CA certificate installed. Luckily Google got rid of those.

In my experience, you can also set up biometrics on basically every phone, and Google has a few "don't lock the phone while it's with you in your pocket" like services you can optionally enable as well. Your backup PIN doesn't have to be four numbers, you can put a whole passphrase in there if you want it to be secure.

You could also do facial unlock. Less secure than Apple's implementation but more than good enough if you didn't have any lock screen set before that.


The issue with many people like me like to use tailscale, so they should probably think about giving too many warning.

Why wouldn't you set a PIN?

I already have a very long password. I object to unnecessary extra layers -- you can rely on secure hardware via the system if you must authenticate me again, but do not pretend to become your own steward.

Most of my apps that decide to ask for their own PIN (e.g. Klarna, Privacy.com, myFICO) have some deterministic garbage that's easy to guess because they provide no real security. I refuse to entertain security theater with real secrets. (real secrets = ones I don't remember)


What's the point of setting a PIN if Cellebrite can hack almost any phone?

Not every pocket thief or drunkard who finds your phone has cellebritr. Security measures consider the threat model.

More specifically, another commenter in this thread says it's to make sure the user is aware of the configuration of a VPN which, if done maliciously, funnels all your traffic toa a hostile place.


A pocket thief will bring the phone to a friend with a laptop and black market software. If the phone has no theft protection, they will factory reset it; if it has, they will use paid software to remove protection. I have not used that software and do not know if it is actual now, but Internet search shows that older phones are completely unlockable.

Just to give an example, here is publicly available information: https://github.com/youngrichu/frp-freedom/blob/main/FRP%20By...

Good thing is that some of the aforementioned exploits can be used to work around locked bootloader and liberate the phone.

Do not rely on any security in Android. It has lot of mistakes, poorly coded high privilege vendor software, so it would be dumb to use it for anything valuable.

> More specifically, another commenter in this thread says it's to make sure the user is aware of the configuration of a VPN which, if done maliciously, funnels all your traffic toa a hostile place.

I do not see how PIN protects the user, especially if user had PIN before installing a malicious VPN. Also, isn't Google Play supposed to check every application for malicious functionality?


Non-malicious VPN software can be used by malicious actors to route packets through servers they control.

How does PIN help against this? Also, my packets are already routed through malicious actors - ISPs, luckily most of them are encrypted.

Yandex censors the results, it is required by law, so I do not understand what are you arguing against. To be specific, any URLs, which are blacklisted and banned in Russia, must be omitted from search results. Which includes BBC and other Western media and explains the difference in images because in the Google's results the images come from BBC and Voice of America.

Also, if you try to search for "download Chrome" (in Russian) then the first result in Yandex leads to a scammy website: https://ibb.co/HDRJGgZD The real link is the second one, but I remember a year ago or so there was no official link at all. You can also note that official link to Google has a grey text saying: "the owner of the resource violates Russian law" (Yandex is required to show this notification).

Yandex has also been caught "accidentally" removing the site of Ekaterina Duntsova who was planning to nominate for presidential election in 2024, and showed fake/phishing sites instead.

So, Yandex is only good for searching torrents/pirated movies (which you can watch on rutube) and nothing more.


> I do not understand what are you arguing against.

Re-read the comment you replied to, and the one above


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: