Hacker Newsnew | past | comments | ask | show | jobs | submit | CPLX's commentslogin


I prefer https://en.wikipedia.org/wiki/Cree_syllabics TBH.

They look like something right out of some Sci-Fi.


Amazing "By 1825, the majority of Cherokees could read and write in their newly developed orthography.[5]". It even has a reference so it must be true.

Around the same time, Christian missionaries introduced writing (using an adapted Latin alphabet) to Hawai`i. Within ten years nearly the entire population (I would guess with the exception of older people) was literate. Mark Twain remarked on Hawai`ian literacy a few decades later.

Anyway I put in a request to get a copy at my local library so I will update here in a few months when I have a copy of the book.

Thank you. A big omission from the original article.

> if they are avoiding doing awful things in the name of money, then they are leaving something on the table

That doesn't stand as a reason at all. I think the big contrast isn't as you described. It's more about short-term versus long-term or conflict of interest between principals and shareholders.

But to be specific, Wells Fargo was mentioned, and their downfall was very much driven by doing awful things in the name of money, specifically.


There is a whole table of examples like the one you mentioned in the book. This has been going on a long time: companies being destroyed, all in the name of profit.

Casinos don't have clocks in them.

> Clickable links sent in email are more secure than passwords so I'll stop supporting passwords and instead rely on email delivery of a link for all logins

God, I fucking hate that.

I have a fucking password manager, I have various machines and things open. Just let me fucking log in.

If anyone is reading this who is in charge of the internet please stop doing this.


I seem to spend half my life logging into thing's, confirming 2fa,confirming biometric data. Then when I go back to the first thing it's timed out and I have to sign in again.

The people in charge of the internet are "cybersecurity" "professionals" who can't even follow NIST guidance.

It is with much hesitation that I write this, because I just implemented such a flow.

My reasoning was this: my customers keep forgetting their password and somehow that becomes a trigger to contact me. No passwords, no problem.

I tried convincing them to use password managers but that was pointless.

But I see the pain and frustration so I will add passwords. And I quite liked the passkey idea, have to see how that works. Not that my customers would ever use it, but I would. It literally never occured to me.


To be clear, no shade on actual devs faced with actual problems. My ire is reserved exclusively for the "we must do this because it is on the checklist, no I don't understand what a subnet is" people.

Good to see my take verified. But, where does the buck stop? What if your phone relies on email, but your email needs your phone.

A lot of those same people seemed perfectly capable of insisting on 60 day password rotation back when they could use nist guidance as an authority to appeal to (for about five years after the recommendation changed too).

The "change your password every 6 months" guidance?

That was revoked some years ago.

Specifically the revocation of such guidance. If the field gave even the slightest deference to empiricism we wouldn't be changing our password every 180 days, but here we are.

So agreed. It’s fucking crazy. Password manager is so much easier and more secure. If you do this dumb email or SMS OTP flow, at LEAST support passkeys for my password manager!

It’s wild that they’re like “it’s more secure to not have a password” and then choose two unencrypted delivery mechanisms for the very short OTP.

Sure, people who reuse passwords are not secure. And fair, I guess it’s a tragedy of the commons. But at least continue supporting it and make it dead simple for password managers if you actually care bout security


I thought the same for a long time but now i don't know. If your computer is compromised, they can exfiltrate your password, but with a hardware key they can't, so i think that's legitimately more secure than password+otp. It still needs a pin though to protect against device theft. I bring this up because there's been a ton of compromised developer packages recently and windows itself is being attacked so even if you're pretty good about protecting yourself, you still might get screwed.

If your computer is compromised, the attacker can just as easily read your email.

OTP can be used with a password.


Uh huh? That's why I specifically said hardware key. Like a Yubikey. You can't digitally steal that.

That doesn't address anything. If your device is compromised they do not need your hardware key because they can just read all mails on device or steal login/session cookies for accounts and bypass authentication.

Passkey is still inferior to U2F + password anyways.


There's a landlord/apartment portal where the whole login process has changed to be:

1. Enter username (e.g. an email)

2. Choose from either email or SMS on file

3. Enter the code you got somehow through the respective unencrypted channel

Given that this same site is involved with bank-account details for payment, I am concerned...


It’s really rich when banking/finance apps are fully happy doing 2FA to the phone when using its own browser…

Yeah — loose the phone and it’s pretty much game over.


I don't think it should be the sites' responsibility to guess whether the browser session is the have device will receive an SMS message... The fact that it is SMS is already bad anyway.

Time-code apps or passkeys are a different story.

1. You should be able to make backups.

2. There's nothing to intercept in plaintext.

3. The all can (unlike SMS features) be locked down by default and require a second layer of unlocking, so that they usually aren't accessible to someone who grabs your phone out of your hand.


It absolutely should be the Bank's concern when this is how 99% of their customers will use it. Some even have deliberate integration between the baking and 2FA apps.

I'll heap email and sms based otp into that

I have many ways to generate totp codes. All of them are vastly more convenient than sending me an email or sms


This is exactly my workflow and it’s just incredible. I use aqua and wispr flow depending on which one seems to be returning the best results that day.

Some people really do thrive on this shit though. They know the rules of the game and want to play it. What they’re really thinking is they’ll be better at the game than their opponents.

I mean can you actually imagine the internal monologue of a guy like Sam Altman?


LLMs have more of an internal monologue, and they have none.

Not exactly true:

https://www.anthropic.com/research/tracing-thoughts-language...

They’re even trying to expose some of it as a summary, as part of the anthropomorphization of Claude.


That's not really true on a practical level. For the most part, you can't just buy airline points at the one to two cent price that you effectively get them for in credit card transactions or the even lower price that the credit card companies themselves are likely paying.

Airlines do regular promotions where you can buy miles for less than 2 cents per mile. If you get 2% cash back or pay with cash and get a 3% cash discount and can then buy miles for 1.2 cents/mile during the promotion, you're losing 0.8% or 1.8% respectively by using the card that gives you miles instead.

So do credit card companies run transfer bonuses. There are only a handful of airlines who sell pts < 2 cent per point during promo, like Avianca. Others, including the big three US carriers, seldom do this.

Also the big part of this game is sign up bonuses, like spending $5,000 and get 100,000 points instead of the 2% daily rate.


Cash discounts only really exist for locally owned restaurants and other smaller retailers, not bigger ones like Macy's or Best Buy which have a flat price. So in most cases it is in fact the cash purchasers who are paying the 3% fee implicitly but getting no benefits back in the form of cash back or points.

Of course it's not binary, any more than there are two choices between "cheap" and "expensive"

The question is how much effort and authority is required to gain access through alternative means, not whether it's possible.

It's always a question of how much, insofar as kidnapping Mark Zuckerberg or winning an order from a Federal Judge are two of the possible scenarios.


There's nothing ambiguous about it at all. We had it as our public policy for generations and then bought-off politicians stopped enforcing it.

The information is captured the same way as most policy - via statute and precedent, and guidelines for enforcement agencies.

None of this is confusing, or even hard, except insofar as it's hard to fight against well funded opponents.


What the hell are you talking about? You are absolutely not allowed to bet on whatever you'd like with another individual. Depending on what you're betting on (for example, the price of a stock or the throw of a card), it falls under varying different regimes. This is highly regulated and has been for most of the whole of human history.

Yes, there are de minimis exceptions. Your office NCAA pool, for example, is often legal, but it has nothing to do with what we're talking about and is also irrelevant to a business facilitating it via 18 U.S.C. § 1955.


In Spain in elderly caring homes there was a tradition to bet on Bingo matches for simbolic prices (barely one or two euros, enough for a coffee and that's it). It was legalized on paper recently, but technically everyone turned a blind eye.

https://russpain.com/en/news-3/authorities-consider-legalizi...

>Rarely exceed 25 euros.

Maybe in Christmas, because the weekly play was just about low prizes.


It was, believe it still is, somewhat similar in Australia, where the game Two Up (https://en.wikipedia.org/wiki/Two-up), which was a wartime favorite among soldiers, was implicitly or allowed on Anzac Day despite being gambling.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: