Hacker Newsnew | past | comments | ask | show | jobs | submit | fph's commentslogin

It is not unrealistic at all. The Olympics are run by politicians, essentially, since they appoint the committees, make the investments, build the infrastructure.

And the ones pushing for these bans are the sport media tycoons: this fight isn't about Anna's Archive, it is about people watching soccer illegally. Because that is where the real money is.


Yeah correct. I hate this so much in this topic. I hate the disrespect for the law in this topic here but he is right here. The Olympics, soccer and all the other sports (but also other billionaires businesses) have to be put back in their place. How is FIFA able to prevent me from drinking my favourite beer in the city center of my favourite town just because world cup is on town.

Hardware tokens are not allowed in Europe to authorize certain operations such as bank transfers: you need a device that can show the operation you are about to authorize ("enter 123456 to confirm your payment of 99.99 € to Pornhub"). And that essentially means using a phone.

Maybe it’s country-specific, but most banks I know support a card reader or photoTAN device. You don’t need to use a phone.

I don't think card readers can display payment information, can they?

And I have no idea why, but no bank offers photoTAN devices in my country. They seem like an interesting concept, even though I imagine the underlying hardware isn't far from that of a phone, in the end.



The card readers have an LCD display that shows the information.

How do they get this information in the first place, though? Do they have a QR code reader?

Yes, in that case it's often called Photo-TAN or QR-TAN. See https://en.wikipedia.org/wiki/Transaction_authentication_num...

Previously there were also so called "flicker TAN" approaches: https://de.wikipedia.org/wiki/Transaktionsnummer#chipTAN_com...


I'm in Europe, and some of my banks still operate with a token just showing numbers, while others use devices with QR code readers and a colour display which then can show transaction details.

They don't really like you using that and keep annoying you to stop doing that, but I don't think they'll fully get rid of that - those are filling some accessibility niches as well.


I am in europe and my bank issued me a hardware token I still need to use from time to time.

I’ve seen dedicated hardware devices which scan a QR-like code and show this in a little screen of their own. The bank provides them and does not require any app.

I only know of a single bank using this.


>I only know of a single bank using this.

If it's not Crédit Mutuel then you now know of a second bank using this method.


Is this true?

The old, standard RSA number generator token key ring device is not permitted in Europe for authorizing bank actions ?


Precisely. You can use and old-style hardware token that only generates numbers to log in, but not to authorize an operation such as a money transfer.

The requirement is called "dynamic linking" (the 2FA code must be tied to the specific transaction) and the relevant regulation is PSD2.


There are "simple" hardware tokens that allow for that - you have to enter the amount and part of the destination IBAN and they generate a 2FA number based on that + probably the same number generator it uses for logins.

It is very ironic that the solution is using an old, insecure phone full of unpatched holes for all important banking and id business, because that one is vendor-allowed while your state-of-the-art GrapheneOS is not.

If only banks cared about state-of-the-art security.

In reality, banks couldn’t care less. They only care about checking boxes and don’t consider where these boxes come from; every unchecked box is a risk.

Did the latest sham "security audit" say that root is bad? They'll block it.


Why has no one mentioned Clippy yet?

Can you share a few examples?

Well, they're mostly in my native language, but it would be something like "hor-ses jum-ping e-ver-glade" to count to 7 in 2-2-3 grouping

Are you sure? You can post questions even with a completely new blank account. It's comments that require some reputation, maybe you were thinking about those?

Does the Rufus bypass still work after these changes?

No, not yet.

And if there is a prompt engineer, there must be also a prompt scientist, right?

Just don't do food and movie reviews with AI. We really don't need things to go prompt critic-al.

Prompt geneticist?

I suppose this gets useful in applications where you can change the font, but not add syntax highlighting. Besides being a neat trick, of course.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: