Hacker Newsnew | past | comments | ask | show | jobs | submit | ortekk's commentslogin

They will allow registering without phone number as a paid option soon.


> registering without phone number as a paid option soon

Replacing the need to register with a phone number with a requirement to pay is a better option how, exactly ?


Decreases what info Signal needs to collect and retain about a user. When using an SMS verification as a proof, Signal needs to log the phone number, because if they didn't, one spammer could use one phone number to create 10^99 accounts.

When using payment as proof, they can verify that payment occurred, validate the account and then immediately forget about the transaction. One spammer would still have to pay 10^99 times to create that many accounts.


Payment leaves a huge identification trail because of all the know your customer stuff these days.

If they accept monero or something then ok but I doubt they will.


They could make it so all that is known by banks is that you purchased the service. Like how Nym does it or how you can buy Mullvad credits on Amazon.

https://nym.com/zk-nyms

Ideally they accept Monero and do unlinkable payments but I doubt they will accept Monero. Hopefully they accept some crypto.


> you can buy Mullvad credits on Amazon

That is not the same thing.

You buy a Mullvad scratch card on Amazon and you redeem the token string.

Mullvad also offer the option to put your card number into the Mullvad website, and I'm sure many privacy conscious people would be very reluctant to do that.

Card payments these days leave far too big a trail. The bank knows, the intermediary (e.g. Stripe) knows, and the merchant (e.g. Mullvad) has to keep records for accounting/tax requirements.


It’d be pretty disappointing if they started including cryptocurrency features in their stack and didn’t accept it.


They added that BS and then didn't do anything with it.

Molly is going to add a Monero integration while also having various other advantages.

They don't accept crypto donations directly or accept them for their backups so I assume they wont for registration.


Also when they start dealing with payments there might be regulatory requirements like record keeping for a certain period.


It's still often cheaper (and faster) to grab a one-time verification number than to go through payment-based verification. Especially for anything that only needs a single SMS confirmation.

I find convincing that phone numbers or payment is the best way to avoid spams at their scale.


If your concern is "muh phone number", then you can pay and not have to give the phone number to sign up.

It's already the case today (and has been for years) that you don't need to give strangers your phone number to chat on Signal. My username is soatok.45; try to get my phone number if you can.

If you want absolutely no info to be collected, ever, and there to be zero cost on the end user too, be prepared to welcome your new spam overlords. Because the people who will benefit the most from a zero cost signup that only requires a username are spammers.


I'm a bit surprised by this dismissal. Of course some info must be collected, or there must be some cost to enter (probably both I mean phone number is also a cost, but one most people already sunk). But we can still debate the best way, right?

For example:

* Are you absolutely positive signal will never have a bug that let attackers reveal contact phone numbers? I really trust in their secure coding skills, but this class of vulnerabilities (like 2fa leaj) happened to even the biggest players.

* One of the reasons signal collects phone numbers (and asks for a contacts permission) is to check which contracts are already on signal. For some people or in some governments even having a signal account is an opsec problem (to be fair, they have a secure privacy-preserving protocol for this - as you know - and it's possible to avoid this footgun if necessary)


two weeks


[flagged]


> Lol how is that any better at all?

They are [1] implementing unlinkable payments so all that is known by credit card is that you purchased Signal and Signal doesn't know which credit card goes with which account.

>Signal is an obvious honeypot.

Claims without evidence can be dismissed without evidence. You might say they don't do enough to protect metadata privacy but it was never made to be an anonymous messenger, it was made to be a private messenger. You can easily check the end-to-end encryption in the code (reproducible builds on all platforms except iOS BTW!). This person audited Signal recently [2].

>They make no money and have no plans to.

They make money from donations and paid backups and they might make money from paid accounts.

[1] https://github.com/signalapp/Signal-Android/commit/7da3357b5...

[2] https://soatok.blog/2025/02/18/reviewing-the-cryptography-us...


Reminds me of a time when Tailscale cofounder went on a rant about how big bad AWS charges too much for bandwidth, and his solution was to send that money to Tailscale instead


That…isn’t the same thing at all, because your recount is factually incorrect. I’m not even a Tailscale user and I know that this isn’t equivalent.


IIRC tailscale is directly P2P, sidestepping a large part of the infra costs...


And, as far as I'm aware, they don't charge for relay bandwidth even if you do end up needing it (which most users won't).


With deluge of Chinese models popping up recently, I believe there's a few issues one needs to evaluate before deciding to use these models:

- Ethics. As known, ou American frontier AI companies are incredibly ethical. And I have yet to see any interviews or blog posts by Chinese companies where they talk about how they are ethical, or at least credible HN comments about it.

- Safety. Do they covertly sabotage or at least refuse to answer questions that could help cyber- and bioterrorists in their nefarious purposes? What about ML-related questions that could help terrorists create AI models without guardrails?

- Child safety. This is especially important with "free for all" open-weight models, most of which are Chinese (ever think about why that's the case?). How are we going to do age verification and KYC with models that anyone can just download on their computer?

- Intellectual property theft. How can we be sure that no output of our American frontier AI models was used while training these Chinese models?

Frankly, there's a plethora of other issues I don't have time to get into right now. Personally, I believe distribution of Chinese models in the US should be paused until they are required to submit models to the government for review and evaluation, to make sure they are made to Anthropic/OpenAI standards.

We need legal grounds for that.

Write to your congressman, congresswoman or congressperson and urge them to stop proliferation of dangerous non-American intelligence. This is a matter of national security and needs to be acted upon as soon as possible, preferably before IPO.


The funniest thing about this post is not the fact that some people took it as anything but satire, but that it’s likely very close to what the true believers at Antrophic actually think.

Ah, those wacky terrorists and their non-aligned models, trained on copyrighted data to boot. Remember, the only thing that stops a guy with an evil god-in-a-box is a guy with a benevolent god-in-a-box, and only Antrophic can lead us to the second one – but only if we act together as a nation and ban those subversive open weights models!


> Remember, the only thing that stops a guy with an evil god-in-a-box is a guy with a benevolent god-in-a-box, and only Antrophic can lead us to the second one – but only if we act together as a nation and ban those subversive open weights models!

Eliezer Yudkowsky has made this argument explicitly, substituting himself for Anthropic.


Yudkowksy gave up on trying to make a god-in-a-box to stop other gods-in-boxes in 2015. Since then his approach to stopping the gods-in-boxes has been to lobby governments.


And bomb gods in boxes I guess?


So hard to tell what is satire and what isn't these days.


This one's pretty easy dude.


Considering I got into a discussion with someone on this very forum who stated that maybe, yes, only Anthropic are reasonable and restrained enough to have access to these powerful models, it is in fact difficult to tell whats satire and whats not.

I've seen all of the parent's points made seriously over the last few weeks by various folks with AI hysteria.


If that was the only thing in the original message, then yes, but the very last comment about the IPO should have clued you in, among other things. But I get your point, there are a lot of people out there saying crazy ungrounded things.


I used to buy only American Ethics, but Chinese Ethics are becoming pretty good lately for the fraction of the price.


Dario you're logged into the wrong account


This is brilliant, but you should have added some <joke> tag or something. You'll be confusing a lot of people and I really can't blame them. I think I've already seen all of these arguments used here seriously in one way or another.


The solution is tarrifs. Require 3 american tokens for every imported chinese token


Yes, please ban all Chinese models in the US and stick to your US-centric stuff. Good for the rest of the world.


This is great but sails far too close to Poe's Law that I predict downvotes.


I missed it at first. Then reread it, and wow - this is grade A satire of the sort rarely delivered anymore, probably indeed because of exactly what you're saying.


Well, if so it needs a little "touch" I guess


It is not necessary for (good) satire to be easily/immediately recognised as such imo


Before the "preferably before IPO" I honestly couldn't tell.


Fear Uncertainty and Doubt, the terrormongering, is worse than the terrors. Endless denial of society & possibility & progress: begone you demons.


_incredibly ethical_


Closed source, gated access, guzzling up all innovation budget from the country, diverting cities' limited water access, gaming the stock market and convincing leaders to cut jobs across all industries.

Truly we must protect these moral and ethical visionaries.


What is Amodei doing on HN astroturfing instead of trying to get Fable back online smh


Is this a parody of the Chinese-funded anti-datacenter astroturfing?


That you and other readers can't outright identify the comment as parody is actually quite disturbing to me.


It is disturbing, and it is hard to blame them. Given the political climate nowadays, I guess it's really hard to tell what is satire and what is real anymore.

Sometimes I see batshit insane takes on places like X, thought they were just satire. Later it turned out the posters were actually being dead serious.


Chinese models are the closest shining example of their ideological system working for the world than anything else they've ever done

From my perspective


i would call out reduction in extreme poverty or increased healthcare access or something but yeah the models are fine i guess


I don't consider mainland aspects to be "examples of their ideological system working for the world", it works for urban areas in China

and I don't really see their foreign investment to be doing that, I think it complements what the West has done and has high impact in areas that the West ignores or hasn't taken seriously for investment, only a history of pillaging and subsequently aid

their ideological system - usually in name alone - also relies on the whole world eventually being on it for it to work, so the models being so good and available for the people openly instead of as a closed source concoction fits really well

that's what I see and how I got there, what do you see?


If you can't appreciate or understand what a substantial effort it was to reduce poverty in China, then you aren't a serious person worth paying attention to. It's literally the economic question of the century and something we should seriously study because we have the potential to lift the entire world out of poverty too.


Crazy how people make light of this, when you can see the alternative today: India.

Sorry Indians reading this for throwing shade at India, but I just want to point out that making 1 billion of people not poor is freaking hard.


The Chinese government did a terrible job of reducing poverty relative to other East Asian nations like Japan, South Korea, and Taiwan. From a similar starting point the GDP per capita lagged well behind, and even now it still does; it's around $15k, similar to Mexico and less than half of those other East Asian countries. If the argument is "it's harder because the country is bigger", then if the government care about living standards it should have decentralized into lots of smaller countries like Europe, which if didn't do.


Sorry, splitting up does not work for China, politically, geographically and culturally. Peaceful and prosperous times only come when there's a strong central government. If any current government advocates for splitting up, then they'll be toppled in no time and replaced with new guys, maybe even warlords, who strive for a united China. "The land, long divided, must unite. The land, long united, must divide."


> The Chinese government did a terrible job of reducing poverty relative to other East Asian nations like Japan, South Korea, and Taiwan

Your examples ALL had massive help from the US. So not sure if it is a fair comparison.

Japan literally rose to existence back then due to US influence and then has been declining ever since.


It's really not that complicated. The government banned people from trading causing extreme poverty and famine in one of the most fertile areas in the world. Then they reversed the ban and let Chinese people trade again. At the same time western companies setup factories in China causing massive capital inflows.


If it's really as simple as allowing trade with the west then why are many other developing countries either stuck at the middle-income trap or not developing quite as fast as China? You're not gonna tell me Chinese are smarter, are you?


"At the same time western companies setup factories in China causing massive capital inflows." This was an intentional policy to split China off from the Soviet union it's well documented the same thing never happened for other countries.

"You're not gonna tell me Chinese are smarter, are you?" No I'm not, but I will say culture does play a massive role, China was not a bunch of roaming tribes living off the land. Turn the clock back a couple of hundred years and it would be peak civilisation. China was literally thousands and thousands of years ahead of somewhere like North Sentinel island.

Calling China a developing country is actually pretty absurd, it's much more like a rebuilding country. GDP was the only undeveloped part because the communist party was terrible at running the economy. Art, science, poetry, fashion, literature, philosophy, culinary arts it was all present and pretty cutting edge up until the communist party ruined things.

It's the same reason Japan, German and the UK bounced back after WW2 except instead of it being war ( Japanese invasion and Chinese civil war aside ) it was self inflicted.

Also I don't think China has escaped the middle income trap. China to this day has horrible wealth inequality and pretty bad social mobility. I actually think this is an intentional strategy they have an underclass of cheap workers for a reason, the government doesn't force a high minimum wage for a reason. Then they have a rich upper class that gets to study in the west and buy a Porsche something that is completely unreachable for the rest of the country.


> Art, science, poetry, fashion, literature, philosophy, culinary arts it was all present and pretty cutting edge up until the communist party ruined things.

You are really, really overselling the state of the late Qing and the Republican era. My wife's grandparents are older than the PRC, and things pre-communism were not as you describe, to put it lightly.

> I actually think this is an intentional strategy

I think you need to look into why it's the poor rural population and not the elite urbanites that overwhelmingly support the communist party.

You can actually do it. If you don't live in the US, you can probably visit visa free tomorrow and just talk to a bunch of rural elderlies to test your hypotheses.


I think you are having trouble seeing the forest for the trees.

I'm not making the argument China was more advanced than the British Empire. I'm saying there is an ocean of difference between a country with it's own writing system and taxation, and a country that does not. Not everyone has a particle accelerator in there backyard but there is institutional knowledge baked into the society.

https://en.wikipedia.org/wiki/Minggatu

This is a real person that existed, they were not banging rocks together they were doing sophisticated mathematics, I'm overstating anything. It's not my description of China these are historical facts. One the communist party would very like people to forget because it doesn't suit their narrative. They failed with their planned economy and they persecuted their scientists and scholars for being part of the wrong class. They actively caused a regression where millions died from their incompetence. Credit where credit is due they have since corrected course to some extent.

And no I can't find out what the communist party is thinking by talking to old people in rural China. One they don't know, two most Chinese people are extremely Cagey about what they think, you need to know them for years until they trust you enough to talk about it if you are Chinese and even longer if you are not.

If your wife is Chinese it might do you some good to read up on what a primary source is and then go read some Chinese History.


I am Chinese myself, I did learn Chinese history, and I find the idea that China was — in your words, maybe not British Empire advanced, but "redeemably" advanced — and that things would have gone well if only the communists didn't ruin things, to be utterly ridiculous. It sounds like a post hoc rationalization to feed the goal of casting the CPC as bad, while ignoring the hordes of historical evidence and living experiences of people who can testify that the Republican era was pretty horrible and was in no way on track to growth and recovery without the communists. The Republic was a failed state. If those guys were so good then the population wouldn't have overwhelmingly supported the communists. Your dictinction between "the communists" and the population is entire artificial and goal-driven. The population at large were "the communists". They wouldn't have become so if everything else worked so great. Communism was chosen out of desperation in the hopes that it would save China, after everything else failed.

After 100 years of disaster, war and poverty, people needed time to figure out how to govern well, things didn't just happen and kumabaya with "freedom". If you think the Great Famine was uniquely bad, you should compare with at all the famines during late Qing and Republic.

When western allies gave Qindgao to Japan, completely violating any earlier agreements with the Republic, it enraged the population so much that support for the communists spiked. I find things really puzzling... the west helped create the communists' popularity, and when things suited the west geopolitically they would cast the communists as the good guys. Now that the west feels threathened, people happily forget the parts of history that don't suit them, and cherry-pick other parts to create a distorted narrative. Where's the intellectual honesty that they taught me at school and is supposed to be the heart of Enlightened ("western") values? Voltaire would be rolling in his grave.


We’re just not talking about that right now

We are talking about open source ai models working really well for the people of the world


Please. Be serious.


Either that or the only reason they've been releasing the models under permissive licenses is that that the only way they have get any attention in a market dominated by American companies.

(Also, they don't need to make a profit because their system does not prioritize profit potential when making investment decisions: it prioritizes alignment with directives out of Beijing, which include keeping up with the West in strategic technologies.)


Couldn't agree more. Maybe it's because it's a shining example of their ideological system that actually alters /my/ life, in ways that are tangible and which i can grasp, and makes it better.


You get it


Satire, yet terrifyingly real.


Is this comical satire or what? I am surprised to see such a dillusional reply. Come on. Intellectual property theft and openai rings a bell? Ethics? Ever tried uncensored versions of gemma4? LLMs have no bad or good etics. Etics are a thin layer on top. Always. You must be joking.


> You must be joking.

Funny that you came to this conclusion and then posted the comment anyway.


> our American frontier AI companies are incredibly ethical

Ah... sweet summer child.

> Intellectual property theft. How can we be sure that no output of our American frontier AI models was used while training these Chinese models?

The US AI models are already using pirated copyrighted material off the Internet. If Chinese models also do this, they're at least giving it back to the people by releasing their weights as open source.


It's sort of happening already. Members of FIDO threatening to block KeepassXC users [0] from logging in, unless KeepassXC complies with FIDO demands regarding specific implementation

[0] https://github.com/keepassxreboot/keepassxc/issues/10407#iss...


Move fast and break things


Let's not when it comes to human-rated spaceflight, though :-)


Why not? That's exactly what we did when we ventured onto the high seas and across unknown continents. The spirit of adventure and all that. I'm sure you'd have many thousands of volunteers.


Because the risks are different?

Do you have the same attitudes towards helmets whether you're walking on the street or riding a motorcycle? I'm assuming not, because you understand they are different risk profiles.

When risk profiles differ, so do the mitigation strategies. One of the ways spaceflight manages different risk profiles is by implementing a risk-based approach. For example, NASA classifies their software risk based on probability and severity. When risk is high, they leverage more requirements and more oversight as a way of mitigating the risk to an acceptable level.

What you seem to be insinuating is we should be willing to accept more risk. While I agree in principle, the hard part is getting stakeholders (from astronauts to contractors, administrators, politicians, and taxpayers) to agree. They get a say, too.


$0. Their page on Hackerone is a "Vulnerability Disclosure Program", not "Bug Bounty Program".


It is possible they received a reward, it just isn't publicized.

"The decision to pay a reward is entirely at our discretion. You must not violate any law. You are responsible for any tax implications or additional restrictions depending on your country and local law. We reserve the right to cancel this program at any time."

(https://www.cloudflare.com/disclosure/)


Cloudflare, in some ways, still has a startup mindset when it comes to security and operations (both in good and bad ways).


But they're terminating people's TLS?


Their keyboards, while pretty, are made of cheapest ABS plastic. One of my keys became stuck just 2 months after the purchase, because of the crack on the keycap fitting. Corsair also refused to replace it.


Well, I just verified this article's claims with this curl request: curl --head -H "Pragma: akamai-x-get-client-ip" "https://www.disneyplus.com"

It returns different IPs for every request, and these IPs do look like residential ones.


Do an nmap scan on the IP and check for open ports. If there are open ports it's very likely not actually a residence but a business.


Not necessarily. Oxylabs could use UPnP to open ports like other similar services as FluidStack, Honeygain, etc.


> It returns different IPs for every request,

That's the really bizarre thing... I came here to ask about it after getting confused when the article implied this (30 tests, 30 different residential IPs). It seems like this shouldn't work at all if connections to the Disney plus site involve any kind of state.

Is this a content-unblocking exception, and normally everything is routed through the same NordVPN edge server? Assuming that's the case, this seems like a great way to get your account banned at Disney plus the moment they decide to crack down on this. Assuming you have a session ID cookie with the site, no legitimate user is going to be sending that cookie from a different IP address on every page load. This should be very easy for them to catch.


Does it still works if you use DNS over HTTPS ? I'm curious to see if the traffic is redirected because they dectected disneyplus.com DNS request or if it's destination IP based


Interesting. I tried the same thing and it always returns the same IP while I'm connected.

I wonder if this is the client doing something? I've never installed the NordVPN client, I only use their OpenVPN config files.


If it uses a new IP for each new request, that's a way to block this, is it not? Normal traffic will mostly keep the session on the same IP, not have a new one for each new request.


You don't have to worry about cache rules, but what about your bill with Cloudflare?

5$/month plan is kinda open ended, you pay for each request above included in the plan (0.5$ for 1 million requests)

With a high-perfomance language like Golang for example, I could write a script that's making 500req/second to your site. That would cost you 20$/day.

With Github Pages it wouldn't cost you anything (or they might disable your page if it costs too much bandwidth, not sure)


> You don't have to worry about cache rules, but what about your bill with Cloudflare?

> 5$/month plan is kinda open ended, you pay for each request above included in the plan (0.5$ for 1 million requests)

> With a high-perfomance language like Golang for example, I could write a script that's making 500req/second to your site. That would cost you 20$/day.

> With Github Pages it wouldn't cost you anything (or they might disable your page if it costs too much bandwidth, not sure)

500req/s would result in you being ratelimited by the global worker ratelimit though unless you distributed these requests across multiple IPs.


See also Firefox Send - https://send.firefox.com/

Files are encrypted and then uploaded to Mozilla servers. Links automatically expire after some time.


This is not metadata analysis resistant, so Mozilla could still technically see who is sending files to who (unless you use Firefox Send in Tor Browser - not sure how well that works).

That's not to say this service isn't useful, but it's not a drop-in alternative to OnionShare.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: