Hacker Newsnew | past | comments | ask | show | jobs | submit | itake's commentslogin

> the keys never leave the phones, and the record of who did what can be checked with a script that has no Seal in it.

What happens if someone loses their phone or buys a new phone? What happens if they forget to tell you that they need a new key?


I think that was the plan. But OpenAI hacked the proxy

I don’t understand what this brings to the table beyond what we’re currently doing.

Insurance companies can have a native app and require the device’s camera. Companies already have tools to combat a liveliness check. Even if you’re using a modified app that pulls from the photo album instead of the camera? A video recording with the appropriate liveness verification easily avoids that mess.


As per opening paragraph of link, AI fakes are a thing.

It's been possible to do a live video deepfake for a long time now, but as with all new tech, law and society are taking their sweet time to understand the risks; IMO this is the other side of the same coin as some infamous tech comments on consumer products: https://news.ycombinator.com/item?id=9224 and https://en.wikiquote.org/wiki/Rob_Malda

NVIDIA suggested AI fakes controlled with face tracking input as a compression technique just for reducing video call bandwidth requirements (to ~117 bytes per frame). They did that six years ago: https://www.dpreview.com/news/5756257699/nvidia-research-dev...

As we're now in an AI race, even NVIDIA's specific technique has flaws which all the current tools can detect, there's never any guarantee of this continuing to be the case.

That said, in the case of Apple, they're historically followers not leaders despite the public image they like to present about innovation, and I'd expect this method to be flawed from day one even if we weren't reading a corporate blog post written in a self-congratulatory tone I find almost as off-putting as when AI write.


You don’t even need an AI deepfake to edit a video.

AI deepfake or edit video doesn’t pass liveliness checks without all the c2pa or reference image song and pony show.

Insurance companies can monitor the light reflections from the flash that they control or monitor the accelerometer and compare the accelerometer values with the video that they receive.

They could also just update their app to stop accepting photos from the album.


> Insurance companies can monitor the light reflections from the flash that they control or monitor the accelerometer and compare the accelerometer values with the video that they receive.

All of this data can be spoofed if it's not somehow authenticated.

> They could also just update their app to stop accepting photos from the album.

Doesn't help at all if the spoofed data is arriving via spoofed hardware.


> That said, in the case of Apple, they're historically followers not leaders despite the public image they like to present about innovation

While its true Apple usually isn't the first in a product category--not the first mp3 player, not the first smartphone, not the first tablet) but once they get there, they're quite innovative.

When the iPhone 5s was released in 2013, it was the first smartphone with a 64-bit processor, which caught Qualcomm off guard. Even when Qualcomm released a 64-bit processor the following year, it kinda didn’t matter because Android was still 32-bit.


nobody actually needed that though

Twitter now flashes your screen different colors while watching the camera pointed at your face when you sign up, you know, to "make sure you're a real person"

7 per minute.

I use my high school’s website to test Internet connectivity bc the domain is short and they don’t do a TLS redirect (making it easy to detect WiFi portals).


neverssl.com

Wish the admin never added the SSL redirect, its literally the namesake lol

I just want basically captive.apple.com with a shorter domain and the webserver not even listening on port 443 at all.

Surprised someone hasn't made this yet, it only requires one spare public IP.


I use this too, but my high school url is 8 characters. neverssl.com is 12. :)

PNG is on my list to visit. It’s relatively complex to get to. Most flights either leave from Australia or Jakarta, they don’t run frequently enough to where you will probably spend the night in Jakarta or Australia in order to catch the flight the next day.

I visited Timor Leste earlier this year and what an interesting country


It seems astonishing to me that a "relatively complex" intercontinental trip these days means "have to spend a whole night waiting for the next flight".

the additional complexity is visas and immigration for that country.

I’m American, so I have to pay $35 every time I enter Indonesia and I’m limited to the number times per year I can enter the country.

Australia is easier. Just need to fill out ETA for a $20AUD fee.

The extra night also eats into your limited vacation time. 18 hours in addition to the 20 hours flying means you’re losing almost 4 days of your trip just transiting.

Also, my flights aren’t intercontinental. I did this monkey dance going from tp hcmc to Timor Leste.


That is funny. I am Turkish and my government charges me about 30 usd every time I leave the country

I read about a Japanese flying to Indonesia in 1959 (the president of the country was courting her). She flew from Tokyo to Hong Kong, then to Bangkok, then to Singapore before making the last hop to Jakarta.

That would have been right around the time that airlines were transitioning to jet aircraft. Back before jet travel it could take a whole week to reach the far east.

I tend to fly cheaply with multiple transfers/layovers. What I figured out recently is that it is nice to combine the flights in such a way that one of the layovers is _longer_.

When the airport has a good connection to a major city then 12 hours during the day are enough, but I'm happy to bump it to 2-3 days.

I have managed to visit some Chinese and Canadian cities this way and it was both more interesting and much cheaper than taking a direct flight.


Some travel tools allow you to search for 18+ hour connections.

I visited Japan, Taiwan, Australia, Hawaii, and Turkey at almost no extra dollar cost. If I like the city I go back.


It’s not a place for most visitors to go off-piste, unless you’re like MacAffee or that British lad Mike who does a hitch-hikers YT travel channel. They both were/are quite a-tuned to where they are think on their feet and are adept at escaping tough situations. Most people ate not like them.

Any cool facts to share about Timor Leste? My usual go to - wikipedia - does paint a rather mundane picture of it.

Crypto scammers have long operated in Cambodia, Philippines, Myanmar after being kicked out of China, and were looking to go to Sri Lanka and Timor Leste next - but Timor Leste's politicians and population got together and fought back successfully, it seems:

https://theconversation.com/asias-scamming-gangs-target-timo...

(More on those scam factories: https://theconversation.com/it-seemed-like-a-good-job-at-fir...

And from The Economist - lamentably paywalled: https://www.economist.com/audio/podcasts/scam-inc)


I actually visited abandoned scam centers a couple weeks ago in Bavet, Cambodia. It’s really eery now.

All the units had air conditioning units, which I thought was sweet, considering many Cambodians don’t have that. But the prison bars on the windows and barbed wire surrounding the complex was a bit uncomfortable to see.


Wtf. How come you ended up in such a compound?

I live in Vietnam. Bavet is a popular border for visa runs for expats. Normally, you don’t actually leave the Cambodia border building or you just take a bus all the way to Phnom Penh to wait for a visa was approved.

I was curious about the town, because it’s famous for casinos, scam centers, and Chinese manufacturers.


Interesting, did you take pics? Most living quarters (小区)in China have electrical fences and most windows have been barred. Left over from the 80’s when crime was high. Nowadays the bars prevent pets and children from falling out of the window (plus the cage like construction allows for some extra storage space)

I wrote a quick blog post about my experience and included the photos that I took. I was traveling alone and I knew the area was not safe, so I really didn't take enough photos, but the best one is at the end.

https://www.kcoleman.me/2026/09/08/Cambodia-Scam-Centers.htm...


Thank you so much, what a great write up (did you submit it here?). Surprised you took any pictures to be honest. Some great observations! Those barred windows def look familiar. Correction:on a second look, these do not look like the typical chinese square tubing bars!

There have been big crack downs in Cambodia and Myanmar just recently. Thousands arrested.

That's great. Apparently that's why they're trying to move on to Sri Lanka, Timor Leste, etc.

I wish I could share photos. Food is insanely cheap. I had street fried chicken, rice, and I think two sides for literally one US dollar.

Their primary currency usd.

They have all the child labor problems that other countries in the region have.

Everybody seems to know each other.

Unlike French colonialized countries, Vietnam, Timor Leste is proudly and vibrantly Portuguese. Similar to Macau but not as wealthy.

The public transit system is basically a tiny van that just drives around in loops around the city. You wave the driver down, jump in, and then tap your money against the metal framing when you’re ready to get off (there are no bus stops). I don’t know if you’ve been to Kenya, but it was like very similar to the vans in Kenya, except even smaller.


What's your criteria for mundane? Basically every decent sized island in that part of the world is going to have beautiful beaches, coral reefs, mountains, and jungles.

It sounds like it is easy to get to Port Moresby (which is apparently a bit of a dump and very dangerous), but difficult to get anywhere else.

PNG has changed very rapidly. Parts of the country were in the Stone Age within living memory and are moving over.


ChatGPT advised me to not even leave the Port Moresby airport and to fly immediately to one of the small domestic fishing towns for safety reasons.

People are still debating the liabilities associated with AI development.

If your agent hacks the CIA, people want to blame the AI lab.

but...

If your agent spends $100k on tokens, then thats a user error. If your agent spends $10m on a shopping spree, then that is also a user error?


Yes, of course? Put a spend cap on your card like you would on your API key.

At some point these systems will get certified as fiduciary agents but they sure as hell aren’t claimed to be that now.


I have a home server running vibed applications. VPS host would cost $25/mo or $300/yr.

Mac mini can also build iOS applications. I think if you’re a mobile dev, you can have concurrent builds for your agents instead of everyone waiting on a single machine to finish.


What models are you running on it? I'm also an iOS dev but I find I need more frontier models to get good quality code from it.

I only use frontier models to vibe code iOS apps, as I'm not an iOS developer. I haven't tried the local models post qwen coder 3.5 release for all the reasons.

AFAIK, a limiter for iOS engineers (and AI agents) for concurrent feature development is the xcode environment and hardware limits. BE engineers can easily have 3 agents working on 3 different microservices (or gitwork trees), but iOS devs can basically only manage one version of the code at a time, due to externalized state (like derived data and bundle ids).


Who are they targeting? With SC IP, I’d assume they are targeting SC fans, who probably want more RTS.

If you’re trying to launch a cool new shooter, why use SC IP?


I've played quite a few hours of Blizzard games throughout the years and as much as I loved the starcraft universe RTS is just not approachable for me. So I can vouch as one person who is really excited to get a taste of the universe outside the RTS genre.

That said, whether the game itself will be good is still TBD.


Blizzard released sc2 and people Happily switched over. I think at sc2 peak, maybe 10% still played sc1 and 90% played sc2

I think I have over 5000 hours on SC2, played since day 0 until fewer years ago.

SC1 was full of pathfinding bugs

My $0.02 is when it comes to dating, social media ruined people’s “standards” [0]

People would rather chill and be single than date the wrong guy, even if they aren’t bringing much to the table themselves…

[0] - same energy as the teen girls have low self esteem due to magazine covers and instagram.


Also all the hot people can find each other now because of the dating apps and when people are below a certain level of ugliness they don’t want to date each other anymore.

Nah this is copium.

People who want to do stuff get off the apps. There are plenty of hot folks who never say yes who wind up on those apps for years.

Lots of uggos are also getting off the apps because they actually go on dates.

Personality matters a lot. Saying yes is very important. Everyone has a million excuses to say no.


There’s some truth to it. You can now easily meet people in a 100 mile radius, that wasn’t the case until about 20 years ago. Personality matters when people get to see it, not when you make snap decisions based on an image in half a second when you swipe.

I’ve been married for 15 years. When I found my wife even dating apps were much more slow paced, I just feel for the current generation.


This seems like an excuse/conspiracy theory. Hot people could always find hot people: go to where hot people hang out (clubs, hipster bars, art galleries, yoga, etc). What has definitely increased is access to people complaining about hot people not dating them.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: