Hacker Newsnew | past | comments | ask | show | jobs | submit | gorgmah's commentslogin

Slightly unrelated: is it relatively safe to root android phones nowadays or should I stick to the unrooted standard android? The reason I'm asking is that I'm stuck with authy as a MFA code app, and would like to move to something that has both desktop and phone support, and my conclusion is I'd need to root my phone to get access to the actual MFA seeds (they don't allow exports to keep you stuck in their app).

The main issue is that many apps will block rooted phones (banks, state apps and the like). Usually more trouble than it's worth.

* some apps.

Both of my banking apps work fine with a rooted GrapheneOS phone. If you want to have full control over your phone like you would a Linux laptop, to customize it to your own preferences and maximize privacy, there is nothing else gives you the same amount of control over the device that you bought and paid for.

The fact that people pay $1000 for a device and then not be able to fully uninstall pre-installed crapware nor fully block it from the internet is depressing.


GOS is not rooted by default - in fact, rooting breaks the GrapheneOS security model and is unsupported.

I don't care. It's my phone and I care more about my privacy and the ability to sandbox apps (useful every day) than I do about a border patrol agents trying to clone my phone. (Will statistically never happen to me)

Some apps such as Aegis allow exporting the MFA secrets.

I think they allow importing from Authy but only on rooted phones. I missed the train to move away from Authy in 2024 and now the only non-root option is to regenerate the seed from every provider one by one. As other commenters said, rooting my main phone would lock me out of banking apps. I suppose I could find an old phone, sync from authy cloud, root it, and then migrate, but then generating new seeds is probably both safer and faster at that point.

Importing is usually not an issue, as you can always enter the secret manually. It is the exporting that is the problem.

The secret looks something like this:

JBSW Y3DPF QQHO ....

(usually fairly short unless its google)


It's not quick, but you can submit a GDPR/Subject Access Request to Twilio and after a month or two they will send you all your Authy TOTP seeds.

Then you can import them into Aegis or some other FLOSS solution: https://github.com/uiltondutra/authy-migrate


That is alarming. They have access to the plaintext? And they will hand auth secrets out? That seems extremely wrong to me.

>...data arrives as a CSV in which every token is encrypted with your backup password...

Fair enough. That seems reasonable.

They always had access to the plaintext, they could do better to hand them out

So there is a real solution to that problem! Thanks a lot for sharing it

You can extract keys out of Authy using mitm-proxy. I have done it and switched to Bitwarden.

Good point, sadly ios only, I'm on android: https://ente.com/help/auth/migration/authy/ Or do you mean it also works on android but not documented?

It was never particularly safe to root the phone - both because it drills a hole into the security model and because you don't have any good ways of verifying what apps asking for root actually do.

Moreover, most of root tools and ROMs are rather poorly written and glued together with other forum scripts which you have no way of checking if they're not malware. (There are exceptions.)

So no, "safe" it's not and never has been. The tradeoff might be worth it for you as a user though.

> The reason I'm asking is that I'm stuck with authy as a MFA code app, and would like to move to something that has both desktop and phone support, and my conclusion is I'd need to root my phone to get access to the actual MFA seeds (they don't allow exports to keep you stuck in their app).

The way to do that is to take the hit and recreate your 2FA codes in an opensource app like Aegis or Stratum.


Thanks for the summary. I agree with you about 2FA, but it's still annoying, I was hoping I would find a lazier solution.

Not sure why this is downvoted. It's accurate. A major problem is that when you root you loose assurance of the integrity of your /system partition. That means malware can now persist undetected.

The answer really depends. Root by what means? And to what end? Permanent or only temporarily?

Personally I reject with extreme prejudice the android security model (it's my &#^@ device not the vendor's). But I don't generally want to grant any apps root. Lineage strikes a nice balance by providing root adb.


I want the ability to grant specific apps root through Magisk. Tasker for example for tasks that change system level settings and adaway for system level adblocking, material files for accessing to root filesystem for pulling config files from apps, Swift Backups for backing up all my apps and their data.

AFAIK rooting an Android phone necessitates a factory reset of the phone beforehand, so I don't think you'd be able to dump the MFA seeds before Authy is uninstalled (unless that's a hardware thing)

That was never the case back when I was rooting phones. Sometimes the phone would reboot immediately after getting root so that you could do something useful like installing recovery, but maybe something has changed.

I was also thinking that this is almost too good to be true

Yeah, apparently


You made me irrationally laugh reading this


It's partly true: this only applies to consumer cards. That's why many EU banks still offer corporate credit cards with huge cashback etc. For example, revolut offers no cashback in France on their metal cards if you have a consumer account, but up to 1% cashback on the same card if you have a "freelance" account. https://www.revolut.com/fr-FR/metal/

Second thing: interchange fees are not the only fees that your typical store has to pay, the total fees are much higher. I think the EU essentially capped Visa/Mastercard profit in the EU, more than they capped small business fees for card payment.


> That's why many EU banks still offer corporate credit cards with huge cashback etc. For example, revolut offers no cashback in France on their metal cards if you have a consumer account, but up to 1% cashback on the same card if you have a "freelance" account.

If 1% is huge, that's a lot better. 2% cashback is my baseline for normal in the US and I currently use a 4% on everything card (no longer available for new customers).

I don't like the cashback system, but the economics insist I use it while it's available.


> That's why many EU banks still offer corporate credit cards with huge cashback et

We're a business in the UK and the charges for accepting Business credit cards is much higher.

I don't have current charges to hand, but in 2023 Personal Credit Cards were 1.97% whilst for Business Credit Cards we were charged 3.43%. That's probably how they afford such high cashback/loyalty schemes.

I think we're paying about half those rates now. I know Amex is somewhere between Personal and Business charges.


Never heard about this before but it sounds crazy. Are you able to control this somehow, like reject business cards?


I don't think we can selectively reject them, it's not anything I've looked into though so not certain about that.

Although we are a B2B business, most of our card transactions are from business owners personal cards so it's not really an issue. We occasionally monitor the split and if it became significant we'd need to look at addressing it, probably by increasing prices for those customers.


In Denmark many retailers pass on the charge for business cards. For example it's often printed on the bottom of a restaurant menu.


For those who had access, how does it compare IRL with GLM 5.3 ? iirc both models are similar in terms of benchmarks ?


From a cost perspective Mythos is too expensive right now. With the right Harness and a few layers of models you can get close or better in some circumstances. Kimi / GLM, Qwen etc. And that's before ablation / Abliteration...

For those in Mythos.. if you ask how much it cost to assess their repos, your jaw would drop. We're talking the price of buying a couple machines to run Kimi / GLM full weight outright.. for one Scan.

Right now I wouldn't say GLM 5.3 is the same, but it's not far off. For the cost benefit it's the better of the two.


I’ve been working on a decompilation project that fable was choking on and GLM 5.3 has been chunking away at it for 72 hours now? I think it’s my favorite agentic/implementer model right now.


My big fear is that they are busy nerfing the weights for "safety" before releasing them. In fact, they've more-or-less said as much.

I have a feeling what we are about to see on HuggingFace is not the GLM 5.3 that you're using now.


You mean when they said they are doing safety evaluation and hardening? I'm having the same fear as you.


Yes, exactly.


Oh? Can you share any details on the decompilation project?


The GLM series is GOATed.


> Models Are Getting Dumber on Purpose

I know is editorialized, but a more accurate title to this content would be either :

Models Are Getting Ignorant on Purpose

or

Models Are Getting Less Knowledgeable on Purpose


We are already seeing math problems being solved by AI on a weekly basis now. Maybe at some point a breakthrough in math will cause a breakthrough in physics?

It makes me wonder if the model is the limit here or if it's the harness: e.g. give GPT 5.6 or Fable a team of 20 people that can easily interact with the real world and let it do whatever in order to "make a breakthrough" in physics; do you think it would manage to?


good find! This sounds a bit like what Meta was doing with the earlier Llama models?

There is also this paragraph in their licence that is smart marketing-wise:

> 3. If the Software (or any derivative works thereof) is used for any of the Licensee's commercial products or services that have more than 100 million monthly active users, or more than 20 million US dollars (or equivalent in other currencies) in monthly revenue, "Kimi K3" must be prominently displayed on the user interface of such product or service.


Meta had much higher limits and not restricted merely to token resellers


Is that even enforceable?


I think it is as enforceable as other licenses are.


Before figuring that out, could Facebook take you to court in order to argue their case that it is enforceable, and thereby forcing you to get lawyers and be distracted by the preparation and all that comes with this?


Nothing stops anybody from suing anybody else (and maybe even winning) though. What Napster was doing in isolate was just a technology yet RIAA and others sued and the lawsuit had led to the conclusion that the tech could be held reliable and if what users were doing were an intentional known to the tech-creators.

So the mere knowing of it led them to lose it and Napster died because of that but also the actual nail in the coffin was that they couldn't significantly do anything to the problem about that given its P2P nature, Ipods were around the same time and RIAA was a bit afraid of that too but Steve jobs assured them that because of the walled garden they could better control the piracy issue and have proper ways of countering it.

Now aside from the interesting details of that time I showed, coming to my main point, Lawsuits can sometimes happen for lesser reasons than or just limited to plain and simple license violations and if a company is earning 20 Million dollars supposing so, then they might also have a really good lawyer insurance package and could lawyer up just as well.

The core argument lies on proving if AI weights are copyrightable or not from my understanding because the licenses could be best applied under copyright material not public domain materials and the other discussion[0] by @cosmojg shows the most likely cases of AI not being copyrightable?, so you would have to prove if AI is copyrightable or not.

Now that would be a fun lawsuit to watch though.

[0]: https://news.ycombinator.com/item?id=49074087


What's wrong with it? Licenses like the MIT license already requires you to attribute, the only difference is the "prominent" part.


IANAL, but probably not, at least not in the United States. Under U.S. copyright law, the weights of machine learning models are excluded from copyright as they are the product of an automated optimization process (e.g., stochastic gradient descent, expectation maximization, genetic algorithms) rather than human authorship. Granted, this has yet to be fully tested in court and going to court is expensive, so it's likely that your employer would prefer to err on the side of caution and respect such attempts at model licensing anyway. Nonetheless, this was partially tested last year in Thaler v. Perlmutter which affirmed that copyright requires human authorship, reading the Copyright Act's provisions on ownership, duration, and transferability as presupposing a human author[1].

If you want to assess the position of the U.S. Copyright Office for yourself, the relevant text can be found in the Compendium of U.S. Copyright Office Practices § 313.2, "Works That Lack Human Authorship"[2], which states:

> […] the Copyright Act protects “original works of authorship.” 17 U.S.C. § 102(a) (emphasis added). To qualify as a work of “authorship” a work must be created by a human being. See Burrow-Giles Lithographic Co., 111 U.S. at 58. Works that do not satisfy this requirement are not copyrightable.

> […] the Office will not register works produced by a machine or mere mechanical process that operates randomly or automatically without any creative input or intervention from a human author. The crucial question is “whether the ‘work’ is basically one of human authorship, with the computer [or other device] merely being an assisting instrument, or whether the traditional elements of authorship in the work (literary, artistic, or musical expression or elements of selection, arrangement, etc.) were actually conceived and executed not by man but by a machine.” U.S. COPYRIGHT OFFICE, REPORT TO THE LIBRARIAN OF CONGRESS BY THE REGISTER OF COPYRIGHTS 5 (1965).

Oh, and there's also a bit in the following Section 313.3, "Works That Do Not Constitute Copyrightable Subject Matter"[2], which explicitly excludes mathematical principles, formulas, algorithms, and equations, along with DNA sequences and other genetic or chemical compounds, regardless of whether they are produced by humans or by nature. If one takes the perspective that machine learning models are algorithms, the conclusions on copyrightability are pretty clear.

[1] https://media.cadc.uscourts.gov/opinions/docs/2025/03/23-523...

[2] https://www.copyright.gov/comp3/chap300/ch300-copyrightable-...


If your argument is true, what would make LLM weights not copyrightable, but compiled code copyrightable?


(IANAL), but the argument would be the same because how compiled code (binary data) is copyrightable but the code (binary data) of an image of a painting created by say a monkey itself with no human involvement isn't.

As such as they have mentioned in the argument, their argument is sound in terms of the level of human involvement in creation of the artifact.


We already know that competition brought GLM 5.2 prices down roughly 45% since its release on June 16th (1.5 months ago), and the price downward slope is probably still going (I've been checking regularly and new providers keep fighting on price, I don't think prices have settled yet). For reference : https://openrouter.ai/z-ai/glm-5.2#providers

I saw arguments like "Providers cannot price less than their costs" in other comments. In economics, it's generally admitted that they shouldn't price less than their marginal costs, i.e. in their case roughly the cost of electricity, since a lot of these datacenters are not at capacity in terms of graphics cards usage (speculation since it's very easy to rent a GC for a couple hours on some providers). My guess is that someone will be selling tokens at less than electricity + depreciation of GCs soon, since there's a lot of competition and "smaller" data centers have overcapacity? This is speculation, correct me if I'm wrong


> My guess is that someone will be selling tokens at less than electricity + depreciation of GCs soon, since there's a lot of competition and "smaller" data centers have overcapacity? This is speculation, correct me if I'm wrong

My guess is they are selling you the tokens, then selling your tokens (data) onto someone else.


I see these conspiratorial arguments all the time and I think people massively overestimate the value of the average users tokens.

The problems with frontier models (design taste, ability to solve novel/difficult problems, etc) cannot be solved by throwing more slop from the average user at it.

Actually, most of the main deficiencies in current models stem from the fact that their data sets aren’t curated and specialized enough.


I don't think the goal of this data is necessarily model improvement.

I think it's marketing, advertising, and product refinement.

Ex: all the things Google wants your search data for.

It's somewhat silly to think the value of that data has changed much. Advertisers want to know what's popular and getting clicks and attention. Competitors want to know what features are getting used in their markets.

In the simplest case, think of this data as improving the harness, not the model.


I wonder how much less useful it is if I use those models for open code or similar. What are you really learning about me, other than the fact that I am a technical person, which you could know by the fact that I signed up for open router to start with.


Do you run your coding harness in a completely segregated sandbox? Even folder names of what projects you have, what projects you actually work on, etc are very useful for targeted advertising.


The prompts contain sensitive personal data.

That would be valuable to advertizers for example.


Press x to doubt on the 45% number. The cheaper providers on open router are fp4 vs fp8 for official zai. There are some cheap fp8 ones (like novita) but the ui makes it seem like it's a temporary promotion, with their normal prices being almost equal to official zai (idk much about open router so not really sure what's going on with these discounts)


If you click the provider it shows the precision, 45% off at AkashML shows FP8. The drawback is the small context window, at 96k.

Then there's 43% off at StreamLake with FP8 precision and 1M context window.


Yes it's true that it's not super clear whether these prices are permanent or short term promotions. On the other hand, there are so many providers making promotional offerings that you could probably easily switch from one to another should their prices go up?


There is nothing to doubt, the cheapest price on openrouter is ~45% lower than when GLM5.2 was released.


Seminanlysis is estimating sub $1 cost per MT for ~2Trillion models. The numbers change based on throughput and quant, but it is conceivable that provider costs at scale are low enough that even $2.42 per MT on GLM 5.2 (current best price) is margin positive by a wide margin.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: