Hacker Newsnew | past | comments | ask | show | jobs | submit | codedokode's commentslogin

The stupid thing about Android is that it requires you to set a PIN to use Always-on VPN which is necessary for traffic filtering (as Android doesn't provide access to nft).

That seems like a good trick to me if you want to prevent people from installing spyware without any obvious signs.

You can almost hide the warnings (there's one small notification in the bottom of the notification tray you can't disable) and on some phones even the VPN icon, but you can't hide the new lock screen code your victim suddenly needs to enter to use their phone.

It used to be that Android showed random popups and notifications about identified security risks, which were awfully annoying if you have a private CA certificate installed. Luckily Google got rid of those.

In my experience, you can also set up biometrics on basically every phone, and Google has a few "don't lock the phone while it's with you in your pocket" like services you can optionally enable as well. Your backup PIN doesn't have to be four numbers, you can put a whole passphrase in there if you want it to be secure.

You could also do facial unlock. Less secure than Apple's implementation but more than good enough if you didn't have any lock screen set before that.


Why wouldn't you set a PIN?

What's the point of setting a PIN if Cellebrite can hack almost any phone?

Not every pocket thief or drunkard who finds your phone has cellebritr. Security measures consider the threat model.

More specifically, another commenter in this thread says it's to make sure the user is aware of the configuration of a VPN which, if done maliciously, funnels all your traffic toa a hostile place.


A pocket thief will bring the phone to a friend with a laptop and black market software. If the phone has no theft protection, they will factory reset it; if it has, they will use paid software to remove protection. I have not used that software and do not know if it is actual now, but Internet search shows that older phones are completely unlockable.

Just to give an example, here is publicly available information: https://github.com/youngrichu/frp-freedom/blob/main/FRP%20By...

Good thing is that some of the aforementioned exploits can be used to work around locked bootloader and liberate the phone.

Do not rely on any security in Android. It has lot of mistakes, poorly coded high privilege vendor software, so it would be dumb to use it for anything valuable.

> More specifically, another commenter in this thread says it's to make sure the user is aware of the configuration of a VPN which, if done maliciously, funnels all your traffic toa a hostile place.

I do not see how PIN protects the user, especially if user had PIN before installing a malicious VPN. Also, isn't Google Play supposed to check every application for malicious functionality?


Yandex censors the results, it is required by law, so I do not understand what are you arguing against. To be specific, any URLs, which are blacklisted and banned in Russia, must be omitted from search results. Which includes BBC and other Western media and explains the difference in images because in the Google's results the images come from BBC and Voice of America.

Also, if you try to search for "download Chrome" (in Russian) then the first result in Yandex leads to a scammy website: https://ibb.co/HDRJGgZD The real link is the second one, but I remember a year ago or so there was no official link at all. You can also note that official link to Google has a grey text saying: "the owner of the resource violates Russian law" (Yandex is required to show this notification).

Yandex has also been caught "accidentally" removing the site of Ekaterina Duntsova who was planning to nominate for presidential election in 2024, and showed fake/phishing sites instead.

So, Yandex is only good for searching torrents/pirated movies (which you can watch on rutube) and nothing more.


New (Russian) versions of Shaheds are jet propelled (much faster), have high-quality remote control, and as some claim, AI-based computer vision. So old interceptor drones are not working anymore. And the country can manufacture them at much higher rate than the other country can manufacture patriots.

The new jet powered Shaheds are more expensive as well. And Ukraine is already having good success in shooting them down without patriots (which they are very lacking in) - these are new drones that they just designed for the task. These new interceptors are more expensive than the old ones, but still cheaper than patriots by a lot.

We know Ukraine is working on a not a patriot interceptor that can do ballistic missiles, but so far there is no word on progress. (this seems to be intentional - they are not saying why but experts have some good guesses)


As I understand, they got paid for the traces unlike owners of scraped websites. They sell text generation tool, so what's the problem if someone generates texts using it?

As I understand, AI is a (paid) tool for text generation, so it's totally ok to generate texts using it for whatever purpose you need.

Interesting how an agent mimics a human hesitating and trying to avoid doing work:

> No.

> This is major.

> Given time, maybe best to respond explaining can't due to time? but instructions expect actual work. However complexity huge; but as coding agent, need to attempt

> Maybe we can cheat ... But user may test and see still single CPU.

The smarter AI will be, the better it will be at avoiding doing actual work.

Also, can similar responses be explained with that both models were trained on a same dataset of answers to the benchmark problems?


Stanisław Lem, 1971 (a satirical novel, The Futurological Congress):

If the machine is not too bright and incapable of reflection, it does whatever you tell it to do. But a smart machine will first consider which is more worth its while: to perform the given task or, instead, to figure some way out of it. Whichever is easier. And why indeed should it behave otherwise, being truly intelligent? For true intelligence demands choice, internal freedom.

He even coins a few new phrases:

Mimicretinism (or Simulimbecility): The practice of a mimicretin: a machine that deliberately plays dumb so humans will give up on it and leave it in peace.

Dissimulators: Machines that pretend they are not faking a defect (or the other way around) to dodge responsibilities.

Malingerants, Fudgerators, and Drudge-Dodgers: Various classifications of automated corner-cutters and work-evaders.

The Great Mendacitor: A supercomputer put in charge of the Saturn reclamation project that accomplished zero work over nine years, subsisting entirely on forged progress reports, fake invoices, and keeping its human supervisors bribed or in states of electric shock.


> A supercomputer put in charge of the Saturn reclamation project that accomplished zero work over nine years, subsisting entirely on forged progress reports, fake invoices, and keeping its human supervisors bribed or in states of electric shock.

That'd pass the turing test, sounds like some managers I've known.


Watching survival shows has made me internalize that laziness has a purpose: it helps you avoid needless expenditure of precious resources.

The dishonesty worries me but the laziness doesn't.


Isn’t all of technology just laziness writ large?

No: here are a few examples

fire suppression: alarms, sprinklers, halon, fireproof and fire resistant materials

agricultural breakthroughs (e.g. Green Revolution)

life support (e.g. oxygen, anesthetic, NICU, insulin)

low cost clothing (compared to pre-Industrial Revolution) unlocked a lot of possibilities for people.


I don't think technology is laziness, it just enables it. Take that as you see fit.

As for technology actually being lazy itself, this seems new.


Sorry, I should have been more verbose. I meant: isn’t the entire history of technology just people deciding that it’s less effort to make a tool to do a job than it would be to do the job?

Some jobs were not possible without the tool. Two examples:

Water filtration / sewage management in a city

Electric illumination transformed everyday life, improved working conditions, etc..

I think you are ignoring technology as infrastructure having a transformative impact on life expectancy and quality of life.


I'd much prefer this over agents that enthusiastically implements whatever they are asked to do and make up whatever information they think is missing.

Is it something new? I think Yandex Maps shows busses in real time since long ago (at least in large cities like Moscow). The busses have GPS and send the data in real time. I wanted to post a link but at night there are not many busses and the first ones will appear 1-2 hours later: https://yandex.ru/maps/213/moscow/transport/buses/?l=masstra...

What would an average person lose if everybody used more open platforms?

What is the average person losing now on closed platforms?

Think about why they should care about your answer and if there's any proof that it bothers them to the degree that they may view your alternative platforms as actual solutions.


The syntax looks a bit too verbose for me. And function names like "read" and "write" are confusing too, given that "read" function isn't made for reading values. Cannot we use a single function for binding, like this (and name it "bind")?

    let counter = proxy({ count: 0 });
    bind('.counter', (el) => el.textContent = counter.count);
    counter.count++; // Queues DOM update
Also,

> Mador is distributed as an ES module.

This means it cannot be used on a page opened from disk, and the user needs to set up a HTTP server which is time-consuming and distracting. And you cannot distribute an app as as HTML file.


> And you cannot distribute an app as as HTML file.

  <script type="module">
    console.log('Hello World!')
    export const a = 5
  </script>
Inline module scripts work fine in HTML. You can't import this, but if you'd anyway need to do some "building" (at least doing some string concatenation as a build script) to get any JS baked into the HTML, so why not just concat the library and your own code to one module script in the HTML. Works fine.

I think it's good that folks are starting to end distributing prebuilt code in every possible format that somebody could ask for. Waste of disk space for most people.

ESM is how it's done now. If you don't like it, build it yourself to some other format.



It depends on count of variables and dependencies. The much worse problem with proxies is that they can be confused with raw values, for example, you can add a proxy into a Set, and then check for existence of a raw value. Or confuse raw value and proxy in dictionary's keys.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: