Hacker Newsnew | past | comments | ask | show | jobs | submit | bobbiechen's commentslogin

There are lots of people pretending to be Google and friends. They far outnumber the real Googlebot, etc. and most people don't check the reverse DNS/IP list - it's tedious to do this for even well-behaved crawlers that publish how to ID themselves. So much for User Agent.

> So much for User Agent.

User agent has been abused for so long, I forget a time when it wasn't.

Anyone else remember having to fake being a Windows machine so that YouTube/Netflix would serve you content better than standard def, or banking portals that blocked you if your agent didn't say you were Internet Explorer?


I mean forget that, all modern desktop browsers (at least) start with the string 'Mozilla/5.0', still, in a world where Chrome is so dominant.

In the United Stages, RUFADAA provides this legal framework and I think it's quite reasonable.

I wrote about it here: https://digitalseams.com/blog/what-happens-to-your-online-ac...


I got this interesting pair of messages from Schwab recently - not sure if any other companies do this

On login:

Schwab Watch out for scams. DON'T share this security code with anyone, EVEN IF THEY CLAIM to be from Schwab. Your code for online login is XXXXXX

And then on a later phone call with an agent:

Schwab: XXXXXX is your Schwab security code to confirm your identity with the agent.

This is a nice touch, though I'm not sure how much it would help in a real scam situation for say, my grandma.


Not sure for Claude Code specifically, but in the general case, yes - GPT4Free and friends.

I think if you run any kind of freely-accessible LLM, it is inevitable that someone is going to try to exploit it for their own profit. It's usually pretty obvious when they find it because your bill explodes.


I believe this comes from the (browser self-reported) navigator.platform, which is reported as MacIntel on all Chrome for Mac versions including Apple Silicon.


Indeed, bad for consumer AI. But I would expect B2B spending on AI dwarfs consumer spending, I wonder what that comparable B2B revenue would be.


It certainly does but B2B revenue can also be much more "fake", in a sense. i.e. if Microsoft spends $500 million on OpenAI, which makes OpenAI spends $500 million on Azure... where does the profit come from? There have been a few interesting articles (which I unfortunately can't look up right now) recently describing how incestuous a lot of the B2B AI spend is, which is reminiscent of the dot-com bubble.


That makes much more sense, even "a seamless piece of cloth" would have been much less ridiculous.


A more literal one-to-one translation would be "one sheet of cloth", which also would have been better.


I liked the concept! Some thoughts from me:

1. The game was fairly fetch quest-y but I think even the fetch quest format could be interesting with more storytelling around the instruments/people involved.

2. The rhythm game part was fine and straightforward but would get repetitive fast. I have like a million hours on Crypt of the Necrodancer though, which has lots of novelty in it.

3. It could also be interesting to do something like Terry Rileys's "In C" (or perhaps more interactively "In Bb" https://www.inbflat.net/ ), have you considered it? Though I did like hearing some of the parts line up together too.


Thanks for your comment!

Yes this whole thing is tricky because I kind of do want to make the unapologetically difficult version but then I am worried it will be too hard for most people to play, but then the people who do stick with it and make it through might find it even more satisfying. So it's a tricky one!

I hadn't heard of Terry Riley until just then but yes, that is very much in line with what I was going for! There's something just fascinating in itself about hearing individual lines of music come together, it's a reward in itself, and it does feel like someone should be able to make a game around it.


As opposed to username/password, where... An attacker that controls the email address can log right in.

Unless you mean to say I should set up 2FA for my CSS theme variable helper website?

Passkeys and OAuth/social login are great, but everyone has an email. And I don't think any mainstream site supports only passkey as an auth method (and no other way).


"Passkeys and OAuth/social login are great, but everyone has an email"

big tech is only allowing Social login from another big tech anyway, they use whitelist and banning everyone that dont use that because they cant guarantee untrusted "third party"


"Everyone has an email" is like "everyone has a phone number": wrong and bad. At least email addresses aren't difficult to get...


I think this refers to RFID-embedded playing cards, which have apparently been used at the World Series of Poker before: https://www.wsop.com/news/wsop-livestreaming-all-summer-with...

>The card information will be known to the viewers by using RFID (radio-frequency identification) technology for the very first time at the WSOP. Each card has a microchip embedded in it that has no impact on the cards or play, but with a specially-outfitted poker table, can send an encrypted signal to decipher the card’s rank and suit. The WSOP has used this technology during the 2012-13 WSOP Circuit season with success, and it is found throughout European poker events as well.


Update next day, I can't believe it was X-rays... https://news.ycombinator.com/item?id=45693599


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: