Hacker Newsnew | past | comments | ask | show | jobs | submit | eigenspace's commentslogin

> AfAIK wero needs Google Play Integrity. So you are still stuck with Google.

Wero has no such requirement. The bank that you use to interoperate with Wero might require Google Play Integrity though.


Thanks for the correction

The weights themselves aren't stolen. The claim is that Chinese companies are using VPNs and proxies to buy massive amounts of Claude Pro and Codex subscription accounts, and then selling usage on those subscriptions as cheap white-label LLM API usage.

While selling that LLM API usage, they then capture all the prompts, outputs, and intermediate thinking the LLM does, and then sell those logs to the companies making open-weight models. The open-weight model developers then train on those logs to 'distill' a model.


...good for them?

We used to call that competition.

Imagine making this argument with a straight face in any other industry:

"The claim is that Japanese car companies are buying Ford vehicles, and then leasing them to American consumers at cut-rate prices. In return for the cheap cars, the customers are letting the Japanese observe their driving behavior, studying how they use their F-150 and then the Japanese car companies are applying that data to design new vehicles that will directly replace Ford!"


I wasn't arguing against the practice, I was clarifying that the weights of these models are not being stolen, and explaining what these companies do to create their models.

> observe their driving behavior

That's not what they are observing, it is the behavior of the engines.


:sigh:

fine, s/observing the way the Ford cars work


The parent I replied to said frontier weights were “being stolen” which is not the literal case. I think precision is important here.

I agree. That's why I said that the weights were not being stolen, and then explained what is actually being done.

Fantastic, thank you for the explanation!

For those wondering, the AI Max 395 has around 256GB/s of memory bandwidth, whereas this new 495 has 273GB/s. So a very modest improvement in bandwidth.

It doesn't work that way. AMD said they simply couldn't do it. It wasn't about taking some modest performance hit, it was that they couldn't make the chip function with modular memory due to signal integrity problems.

Then why not pick a CPU that is socketable? There are dozens of them on the market that Framework could have picked for their Desktop product.

None of them have something even close to the memory bandwidth or integrated GPU performance of the Ryzen AI Max processors.

They want a Apple M_ Max like machine.


Why not put a big fat Ryzen 9 chip in it? Most people use their computer for browsing the web, playing some games, doing some spreadsheets. A standard CPU would have been more than powerful enough for that and the Desktop would be more repairable.

There's a million machines that are just as upgradeable as anything Framework could make if you just want a big fat Ryzen 9.

It's not really about performance, it's about signal integrity. AMD said that even with LPCAMM2, you just wouldn't be able to send a clean enough signal from all these different memory channels to the chip, and they insisted on a soldered design because they just couldn't make anything else work.

Technically it's not wrong to say it's about performance in the sense that if you clocked the RAM slow enough you probably could maintain signal integrity, but we're not talking some small hit to performance here, it'd probably be more like a multi-generational drop in memory bandwidth.


KeepassXC is free, open source, and supports passkeys. You can locally store your encrypted password vault wherever you like, and transport it between devices using physical media if you like (or self host your own personal storage synchronization server and sync your passkeys between devices like that).

No need to be a part of an 'ecosystem' to use a password manager or passkeys.


> KeepassXC is free, open source, and supports passkeys.

KeepassXC was threatened to be blocked.[1]

[1] https://github.com/keepassxreboot/keepassxc/issues/10407#iss...


You can sync your vault between devices, but what's the point if the clients on those devices don't support passkeys? As far as I know, no KeePass app on Android has mature passkey support. That's not even mentioning more niche cases, like what if I want to log into a website in a browser on my TV? The cool thing about passwords is that they work on any device.

Also, remember when one of the maintainers of the passkey standard warned that KeePassXC users would get blocked by relying parties [0]? Would you allow tech companies to determine what password manager you are allowed to use?

0: https://news.ycombinator.com/item?id=39698502


KeepassDX has pretty good passkey support I think. At least, it works for me.

I'll give it another go, I found it buggy last time I checked, but that was a while ago.

I love KeepassXC, I use it for all my passwords.

However, I won't give it things which are meant to represent devices.

People who designed the 2FA model designed with the intention that a password is something you know and a device is something you have.

By putting storing both together you're breaking the assumptions of the people who design these systems.

So I store all my passwords on KeepassXC, everything else has to be elsewhere.


Passkeys do *not* do that. I use 1Password to manage my passkeys and they are all synced across all my authenticated devices where I installed 1Password.

You can choose either if your password manager supporte Passkeys

Of course. I was just pointing out that their claim about the lack of portability across devices was untrue.

Perhaps they should’ve said platforms. Because if you wanted to migrate those passkeys off your password manager and into a different platform like Apple Pass or Google how is that accomplished?

There's a protocol, FIDO Credential Exchange Protocol (CXP) which is currently at proposed standard status. It is supported by Apple and Google and some third party password managers (1Password, Bitwarden, and Dashlane). (1Password is kind of annoying though as its CXP export only supports exporting everything. There is no way as far as I can tell to export just a single item yet).

Once 1Password supports proper single export when I make a new passkey I'll store it there and later export it to Apple.

Meanwhile I simply make two passkeys. I've only run into I think two sites that supported passkeys but would not let me make two.

On most sites making a second passkey is as simply as going to your security settings, finding the passkey settings there, hitting the "add another passkey" link, and pointing your phone at the QR code it shows, and then on those phone choosing the password manager that you did not use for the first passkey.



How do you move your passkey from Apple's keychain into the password manager?

in the ios password app you can tap on the button to export data to other app. it will show you the list of installed apps that can import them. works with passwords and passkeys.

I moved all of them from my iphone to a selfhosted bitwarden in two minutes.


Ok, good to know that.

I'm surprised selfhosted services would be allowed in that list. Isn't there the "risk" that you can then extract the raw key from your selfhosted instance?


What's unclear to me here is this: under this new scheme does the USA get access to the biometric data of people not travelling to the USA?

From the analysis linked in TFA:

"The automated query can be based on: * Identity information included in the application or in travel documents, such as name, date of birth, national ID number, and/or * the fingerprint of an individual."

Sounds like they could send requests to that computer system just based on publicly available information on a person like name and date of birth, even if the person never applied for a visa or tried to enter the US.


Well, a national ID number isnt usually publicly available info, even if it can be obtained by the US government through illicit means.

But yeah, it does sound that way, but certainly not clear cut to me what the situation is. I.e. does the agreement involve clauses about what to do if this is abused? Do we have a way to detect if theyre using this on non-travellers? Etc.


> a national ID number isnt usually publicly available info

A couple of counterexamples:

Italy's "fiscal code" is generated with a simple algorithm which can be executed manually:

https://en.wikipedia.org/wiki/Italian_fiscal_code

Sweden's "personal identity number" is public information and can be looked up by anyone:

https://en.wikipedia.org/wiki/Personal_identity_number_(Swed...


Belgian National Number is your birth date, then an increment from 1 to 999 for every baby born that day, then a base-97 checksum.

Not sure if still the case: odd numbers for males and even numbers for females.

This also means a person’s Belgian RRN can change.


Yep, but they do not change on sex change, IIRC.

I wrote a system for a medical lab decades ago and IIRC I did actually have to change some RRN's manually. It's been a while so I'm not 100% sure, but I do think the changes were due to switching gender.

Are there never more than 1k babies born in a day?

With a population of 12M and life expectancy of 80 years (give or take), probably not, as that needs ~400 newborns a day to maintain, and the birth rate is probably well below that, like in most Western countries.

Back-of-the-napkin math supports that, but baby births aren’t uniformly distributed. Well, anyway, I’m sure they thought about it. Thanks for explaining how I got my Belgian ID number!

For the curious, there is a lot more about National Numbers in this pdf: https://www.ibz.rrn.fgov.be/sites/default/files/documents/nl...

This is the leaked draft: https://statewatch.org/wp-content/uploads/2026/05/wk_5183_20...

It's not clear how it is supposed to work in detail. But it sounds like it could be implemented in a way that makes illegitimate queries possible. It doesn't sound like they want to really ensure that you can catch those.


In multiple European countries, national ID numbers are public information that can be searched by name and address (i.e. Sweden)

I played with Estonia’s e-residency and they use asymmetric cryptography for everything so the ID is public but does nothing without the corresponding private key.

Only the people who travel to the US should be included in this farce and vice versa the other way…

It changes the nature of the scheme quite a bit

They probably could, but if done on a large scale, they are likely to be detected.

That would matter if officials on the other side cared and weren't oking it.

In most German cities (and even many villages), district heating is a rather common utility offering. There's pipes everywhere to move around the hot water to people's homes, and the water is typically heated by the waste heat from gas plants and waste heat from factories (though increasingly being supplemented with giant heat pumps).

This isnt some novel thing in Germany, selling excess heat from some energy intensive commercial proccess is pretty standard. The local district heating operator probably took care of almost all the infrastructure for them.


Bonds are not the same thing as stocks.

Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: