Hacker Newsnew | past | comments | ask | show | jobs | submit | deaton's commentslogin

As much as you're right, the attitude in most software development is not "lets make this as secure as reasonable," it is "lets make this barely functional and then move onto the next thing."

My current phone is definitely flagship for the time, ~$850, and I will be holding onto it as long as I can because flagships, with headphone jacks, available in the US, are something that just does not exist anymore, and I'm not spending $1500+ to import the cheapest Xperia only to have it barely work on my cell network.

Oh, Xperia.

Wonderful hardware but f*k Sony with the update policy.

My last Xperia was I Mk 2. Nominally flagship. Great hardware, great spec, I loved the form factor.

It got one major Android update and total of 18 months of security updates since the release.

Like, WTH?

No more Sony for me.


Even in live sports, Disney fully controls ESPN, so they absolutely have an alternative.

This makes about as much sense to me as AI-powered air traffic control

I think that last thing is key. The authors of these things published them with the express intent that other people would read them. Not that they would be used as training data.

Sign in with a QR code is dangerous though because at that point theres very little stopping QR phishing and forwarding the bluetooth request to your browser. See the most common Discord scam.

> forwarding the bluetooth request to your browser.

This isn't a thing. Discord's QR Code scanning is entirely a feature they made unrelated to passkeys or bluetooth. Passkey auth using a QR code has a step that verifies the proximity of both devices using BLE.


Amazon does benefit from increased account security; they don't have to refund non-fraudulent orders after all. For most people, a passkey is genuinely more secure.

What about availability? The article is precisely about that.

I don't like passkeys either (I use a password manager anyway, and long secure unique passwords), but I understand the need. But yeah it really annoys me when every website wants to give me a passkey, or wants me to use a passkey, instead of just taking me to a page where I can enter my novel-length password.

Uhh yes. If you can't properly cite the sources you ripped off in training, you shouldn't be publishing the model.

What would happen if you asked a human developer to write a chess-playing program?

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: