Hacker Newsnew | past | comments | ask | show | jobs | submit | jbstack's commentslogin

There's definitely appeal in key-driven window managers in general. Projects like i3 and Niri are popular. But you can get that with any Linux distro (albeit not many have it set up that way by default). You don't generally choose a distro just for whatever DE/WM it happens to start with.

As someone who uses Signal and WhatsApp, I would be extremely happy if those companies blocked access in my jurisdiction if such laws are implemented. In fact, if they agreed to insert backdoor access I would never trust them again, even if they subsequently reversed it.

We have to be willing to suffer personal inconveniences to stand up to these types of policies.


With all the current concerns about rogue and mis-aligned AI, and about how we've made essentially zero progress on making sure that AI is safe and trustworthy, NOW you want to put backdoors in encryption algorithms? We should be doing everything we possibly can to make our systems more secure, not less.

This type of policy was terrible when they first thought of it. Now it's outright negligent and dangerous.


There are people in the background that are benefiting from all this and it seems to me that its not limited to just one country. Someone knows that weakening all of these systems globally has a lot to gain.

are we sure Ai hasn't escaped long long ago?

I do something similar. I have a base NixOS image in Incus, with whatever tools apply to every project (e.g. Git, OpenCode) already installed. When I work on a project, I spin up a VM instance, use nix shell to add any project-specific tools, then share only the project folder from the host to the guest. This way, the worst the agent can do is destroy my project folder, and I can always restore that from another clone of the repo.

I know a lot of people are using containers for sandboxing, but given how capable the latest models have shown themselves to be for breaking out of sandboxes, I prefer the extra isolation of VMs for this.

I do all this locally - it's an interesting point to able to turn the laptop off but keep the agents running. I might consider running some of these on my homelab server just for that.


My setup is basically, the 'runs harnesses' VM is accessible by ssh (of course) but it also has an xfce4/xorg desktop environment running on it. I can easily form an ssh tunnel to it and then use tigervnc on my workstation laptop.

The VNC session is sized to be exactly pixel 1:1 match of my laptop screen size, so I run it as fullscreen and use the macos hot-corner functionality or multi-desktop session switch hotkeys to toggle between it and my 'real' laptop/bare metal workstation.

Having a GUI on the thing lets me leave all kinds of things running persistently in the background that might be bothersome if interrupted running on my laptop. It also has much higher average speed/reliability 24x7 internet access via my home broadband connection than wherever I might happen to be with my laptop.

The main hassle that I've found is that I have to mentally train myself to remember that a lot of the keyboard shortcuts in a boring stock xfce4 desktop environment (and other applications I can run with gnome and kde libraries installed) are quite different than MacOS, when toggling back and forth between the two.


> Having a GUI on the thing lets me leave all kinds of things running persistently in the background that might be bothersome if interrupted running on my laptop.

Unless you actually need GUIs, you could just use screen/tmux or the newer versions like zellij/etc.


I use screen extensively, the GUI is for leaving things like QGIS running full screen (which is sure not going to work in a TUI). Both CLI environment and GUI get used.

> Permits

Obtained by your AI agent, granted by another AI agent.

> Materials, trucks, equipment etc.

Ordered by your AI agent, delivered by a self-driving truck or drone, loaded/unloaded by robots to/from the warehouse/site.

Most of this stuff can already be done today in some form, so its just about improving the autonomy and integrations along the supply chain.


> Xephyr

Given that X11 is becoming more and more obsolete over time, what's the Wayland option?


Not using Wayland I am not 100% sure, I think Xephyr works in XWayland and I think their is a similar tool to Xephyr for setting up an embedded Wayland session (I would have thought this is even easier and more elegant in wayland but not sure). So could be even better.

I personally use X11 as I am on exwm and exwm does not support wayland and no alternative to it does AFAIK (I think theirs a POC floating around somewhere). Also I know X11 even though it's a bit crap in many ways it's the devil I know.


There's a lot of middle ground between doom-scrolling type content and a 10 hour block of non-stop immersion. It doesn't have to be one or the other.

> I definitely enjoyed more long-form content (like the mentioned games) 10-20 years ago.

On a chat about OpenTIE, and OpenXWA, I was talking to this. I used to be able to dive into several hours of a simulation game.

My kids are able to play Minecraft, Stardew Valley, or other immersive games.

I can't because of many reasons, and I was just saying that I'm looking forward to a time when I'll kick them out the house, tell my boss that I'm done, and strap on a VR headset and finally play through Star Wars Squadrons.


Many factories in China now already have 90% of their work being done by robots. Is it really so hard to imagine that we reach a point where they can be prompted?

You're assuming a handover happens in a single definable moment. More realistically it will be one small decision making power at a time, so that at any given moment it never really feels like control is being given up. Boiled frog.

> in Germany people are reluctant to give their IBAN to others

Are they worried people might send them money without their permission?


My wife recently filled out a SEPA-Lastschriftmandat for an account in my name and all she needed was my name, IBAN address and a signature. Name and Address is semi-public and signatures can be faked. I'm no financial criminal but I would be shocked if there was no attack vector that gets enabled from knowing an IBAN and a name.

The thing is, burden of proof is with the bank. For a lastschrift, you have 8 weeks to reverse it, if you didn't actually sign the Ermächtigung, you have 13 months.

Unless you don't care what transfers happen, that's pretty much always enough time


In Germany you'd be afraid to reverse lastschrift because if by some accident it's legit, the companies like service providers will go berserk at you.

It takes ~2 weeks to resolve and will cost you tens of Euros. The biggest threat is that they won't want to deal with you anymore, at least for a while. Happened to a flatmate of mine 15ish years ago.

I'm certain that it also involves receiving and sending a letter.

Letters are why it takes so long, yes

Pray its not a fax.

I wouldn’t be afraid, but I also wouldn’t reverse a legit one. When you do that, you get sent to collections, which makes sense.

I am not worried about the money staying gone forever and I have ample cash reserves, but I can imagine that someone who might have to worry about a bouncing rent wire or electricity bill would be more worried about their safety cushion potentially being gone until they get it fixed with their bank.

Justified fear. A former flat mate of mine reported an unexpected outgoing transfer to his UK bank and they blocked his account for 3 months. He was essentially unbanked. He had to pay his rent in cash after getting it from an ATM with a credit card (which cost a lot extra and hit limits). Resolving it took months even though we lived right next to a branch of that bank, where he went every day.

I had a situation where my mortgage took money from my account, but used the wrong company/reference name.

I didn't know what it was so I clicked a few buttons in the app and the money was back instantly.

That was on Commerzbank. Dunno if others are the same!


The issue is more "I checked my account yesterday, I have 600€ on there, so I know the 150€ utilities bill due today is not an issue" and then a weird withdrawal happens and all of a sudden the utilities payment bounces. Even if i get the money back instantly once I notice it theres still the issue that now I have to deal with a bounced payment to a utilities provider.

But no company cares about an occasional failed payment? That's part of doing business?

So they send a polite email informing you of it and you pay it a few days late?

No reasonable entity would charge late fees as that's a great way to anger otherwise perfect customers?


But again, I am not talking about myself, im talking about the hyptothetical person who might not be the perfect customer. My in-laws have had their gas cut more than once because of non-payments, or were only allowed to keep the gas running because they told them "we will wire you the last 3 unpaid invoices at once on day x".

For me to personally end up in this situation the bank would need to somehow SEPA out like 2 years worth of mortgages at once in a short timeframe, which is not a realistic scenario.


If you have an app, you'll notice immediately that a payment bounced, via notification. If not, you'll get a letter informing you that it bounced.

Also: it takes A LOT of letters and court orders for them to cut your utilities. I'm not joking, it's more than a couple of Mahnungs, then it goes to debt collection, then it goes to court. The court will then take the money out of your account.

That's all before power gets cut.

It definitely won't be because of a single missed payment.

Even in the situation above: if your in-laws somehow had no balance "at once on day x" because of a fake SEPA, they would be able to reverse via app, or go to the bank and reverse.


Paypal (as an example) only asks for the name and IBAN and they do identity verification themselves, by depositing (!) a small amount of money on your account.

But yeah, it's a very high-trust society. Of course any charge can be reverted via your bank app in seconds. But it's still a nuisance to have to check, so people are wary of giving it away.


It's not high trust society. In Germany service providers have easy and instant access to your bank account. Like TSA to your body on American airports. They absolutely don't trust that someone will voluntarily make monthly bank transfer, so I'd call it zero-trust system.

It depends.

Telecoms, kinda. They will try to force this on you via contract. You can say no, but they will lie to your face that it's impossible. You can always get a pre-paid, too. I witnessed the same situation (forced by contract) in some Gyms as well.

Vatenfall and other electric companies, the government itself, banks, landlords, Hausverwaltung, all are surprisingly chill about which payment method you use.

But then again, Telecoms and Gyms are always trying to cheat and steal from you in every country that I lived, that I'd call this the exception to the rule.


In USA a company that knows your bank account number can withdraw money from it.

They're financially incentivized to behave, but that's it. The ability is there.


The IBAN is also used for paying online by debit note. So somebody who knows your IBAN can theoretically buy stuff using your bank account. You can easily reclaim that money, but still there is hassle involved.

> The IBAN is also used for paying online by debit note

How does that even work?


You open an account somewhere and when you pay they sneak in consent for direct debit with some dark pattern.

there are notifications and approvals in bank apps now, they can't take the money until you accept there too and you can revoke from there as well

i don't want their mobile app

do it on the website then?

or dont do anything and direct debit by default doesnt work


In the early days of eBay I exchanged money exclusively via bank transfer and had no worries, but for me the Internet has changed and these days I use PayPal to send and receive money from strangers. I see it like this: My email address is already public, so I'm not risking anything when I share it with strangers. My IBAN on the other hand is only known to a few respectable companies, so why change that? Seeing all the online platforms store all your PII without hesitation, but keeping your IBAN only as ****** and handing it straight to a trusted payment processor always reminds me that it's not like the others. Yes, I know businesses put their IBAN on their letter head, but they also have accountants watching their transactions.

In some MAJOR banks (not gonna say which one), the last digits of the IBAN are also used as username.

So basically people outside can lock your online account.

I am shocked by how F** dumb this was ever designed.


a user name should not be something that needs to be kept secret. If that is the case, the bank fucked up in my eyes...

An IBAN can be used to take money via SEPA direct debit.

I get notified of all SEPA direct debit requests and need to approve them, only for recurring payments.

Perhaps other banks don't do this and that is the problem.


Which is the problem. Why does something like this even exist?

Because it's a convenient lower tech solution where you don't need to be a merchant with access to the debit card system to get monthly (or one-off) money, and it's easy to take or give back money. As other comments say, it's also trivial to claim back a fraudulent charge, it's exposed directly in every online bank system UI.

In Switzerland the concept of a "Einzugsermächtigung" exists too, but it's a step or two more than just knowing your IBAN.

Basically you do this with your bank and not the other way around with the merchant.

Is it common to check all your banking stuff every month to make sure there is nothing fraudulent? I don't see how this is practical


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: