HN user

lbschenkel

125 karma
Posts0
Comments77
View on HN
No posts found.

Not sure if by "centralised recording" you are referring to the UK way or how it is implemented in general (civil law) but I can say that in Brazil the registry definitely does not have only the last deed.

In Brazil the books are append-only, they have the whole history of thay piece of land since records began. If it was a bigger plot that was dismembered, it is there too. When ownership changes you have to register the contract/terms of transfer/sale separately in a different process, but that does not change legal ownership and you still must go to the registry and register that registered transfer/sale in the registry, and the paperwork you get is a new certificate of registration which is a new snapshot of the books and includes that whole history from the very beginning. There is no copy or certificate you can can get from the land registry without including that whole history.

It is exactly the same in Sweden: biometrics are stored only until the passport/ID is manufactured, then destroyed. Only copy is on the chip.

At least this is what the law says, and how it is supposed to be. Reality on the ground, though? I am skeptical that the implementation is as perfect as the law requires it to be, especially judging by the quality of the average government IT system...

Another Swedish resident here, using GOS for around 5 years.

So far all the dealbreaker stuff works (BankID, Swish, bank apps, transport apps, etc.) which is great.

That said, I also work in Denmark and need the Danish apps. And the situation in Denmark was the same as Sweden... until one day it wasn't. For example, MitID flipped a switch one day and started enforcing Play Integrity. It became impossible to activate MitID on a GOS phone. And it kinda became the new normal in government or -adjacent apps.

Therefore, I dread the day this might happen in Sweden too. Let us see what will happen with the digital wallet app that the government will launch to compete with BankID. I am afraid there is a good chance that they will tread the same path... I hope I am wrong about that.

This is not true. The airline has the right to ask for it but in practice this is not really done -- or let me rephrase, not consistently done.

I fly intra-Schengen flights at least twice a year. I had to show ID sometimes before COVID but I never had to show ID after that, it actually caught my attention as anybody could have travelled in my place. I do online check-in, drop the bags, go through security, and show the boarding pass. Last time was three months ago, and once again: no ID.

From the top of my mind I can say that I travelled from/to Sweden, Denmark, Germany, Poland, Spain, Portugal in the last few years and I didn't need to present any ID to board the plane.

I have it, it does not. Well, it may. It depends on the firmware you install on the cable. Depending on the firmware, different things will be broken. I tried them all. There's no version that will consistently support 2160p@120 and 4:4:4/RGB and HDR and VRR, and without random handshake issues.

People in general absolutely love this, and are proud that their country is so "modern".

I meant: it is convenient. No doubt. I do use all this because it is convenient. When it works, it is great. The dumb part is to not have a backup plan.

All these things were done for a single reason: cost cutting. They cost less, and the "old-fashioned" flow that could work as a backup no longer makes financial sense so it is retired.

But then again, here we are. Here and now, without a phone, without agreeing with a relationship with a foreign entity and their one-sided T&C, you won't even be able to get service from your own government. And you need to maintain your good standing with that foreign company in perpetuity, because if they ban you as a person then good luck — your are going to be cut off from your own government, your own bank.

So what actually happens in Sweden: there are two officially sanctioned authentication apps: BankID (originally developed by banks) and Freja. Both only run on a mobile phone.

For government services, both will work. But you must use some of them, otherwise no government for you. You can still do some things by paper, but those are getting rarer and rarer nowadays. The general assumption is that everything is done online. Some government services can't be done by paper or physical visit, not without involving this authentication at some point.

For most of everything else, only BankID (the oldest of the two and the most deployed by far). Especially for banking, only this works. Even if you call the bank and try to sort out via phone, they will refuse service until you can prove that you are you by authenticating via BankID.

But Sweden is mostly cashless nowadays (even some bank branches are refusing to deal with cash). For example, you can't take a bus or train and pay with cash. You have to use a vending machine that only exists on train stations, or depending on which kind of transport and the region you live you might be able to do a contactless payment, or you must use the app (the default choice that 99% use). If you use the app, to pay you need to use a "card not present" flow, or Swish (Sweden's mobile payment system), and to complete either you must use BankID. You can't use your card or do any payment without BankID (if the card is not present).

Even if you do use your card, if it gets denied for any reason, for you to sort out the issue you'll need the mobile phone and BankID.

If you go out with friends to a restaurant, most restaurants don't accept cash. If the restaurant doesn't accept charging each one individually then someone needs to pay for the group, and they will expect you to pay them via Swish which requires BankID. People won't take cash either.

As you can see, it's not actually trivial here to live as part of society without a working mobile phone. If you're outside, you better have 100% faith on your card, and/or be prepared that you might need to walk back home as you can't do much now, might not even be able to buy transportation.

Some smaller shops/kiosks only take Swish: no cash, no card. That requires a phone plus BankID.

If (or better said: when) BankID starts requiring the device to pass Play Integrity, then not only you must be carrying the device at all times, but it must be a blessed device from Google or Apple.

In Denmark the situation is very similar, and in their case their app (which is called MitID) already mandates that the device has to pass Play Integrity.

Check how Play Integrity works today (DEVICE and STRONG integrities) and how it uses a non-extractable hardware key fused into the chip or security processor. Or read the GrapheneOS attestation guide and their example code. It's un-spoofable hardware attestation.

The fact that you can make it pass in some cases using Magisk and so on is because it's spoofing an older device (launched before Android 8) without hardware-bound keys and Google is deliberately allowing that in order not to blacklist the genuine users.

However, once Google decides that the collateral damage is tolerable and those devices should no longer pass Play Integrity, then it's game over. You can't spoof any newer stuff, as you can't produce the desired signature -- only the hardware can do it and the hardware won't do it.

The only way would be if the manufacturer screwed up and it's possible to run unsigned code (or signed by a different key) and maintain a pristine bootloader, or if the hardware key leaks somehow. In either case, the key is per device so Google is always free to blacklist that device if it really wants to. (Verification of the signatures is always done off-device, through Google's servers.)

I'm living in Sweden for ~20 years.

I haven't used a banknote in more than 15 years. During this time I can't recall a single time I saw anyone using a banknote either.

Here in Malmö where I live, especially since COVID, you'll be searching more and more to find stores that take cash (besides supermarkets and kiosks and the like). I would say more than half of them don't accept cash any longer. Speaking of restaurants or pubs, my estimation would be that 2/3 have signs that say "no cash". Maybe more.

You can't do simple things as taking public transport if you want to pay by cash. You can't pay in the bus. You can't buy in the machine. It's all card or app only. You'll need to search around for an equivalent of a 7-11 kiosk to be able to buy a ticket using cash. Depending on where exactly you are when you need that, it may take as much walking than you wanted to save by taking public transport.

If you took a daily trip to the Danish side (Copenhagen) and need to come back home, I'm not even sure if it's possible to get back if you need to buy a ticket and only have cash on hand. Only Skånetrafiken sells that particular ticket and only via machines that don't take cash.

Handling cash became more expensive than taking card payments. It's also more complicated in terms of logistics and payments take longer. With this set of incentives, it's understandable why the shift happened.

Not saying I particularly like this development. Just reporting my anecdotal experience.

I'm not an huge fan of BankID either, but a few corrections/clarifications:

1. BankID always allowed to have different settings for login and for signature. I have done that since forever. For example, I configured login to allow biometrics but not signature. If it's forcing me to enter the security code I know it is a signature, which forces me to pause. I cannot sign anything by mistake (like a transfer) because I'm forced to enter my long security code to complete it. And for the much more frequent scenario of pure logins, I can just use my finger.

2. I believe it does use the hardware-backed keychain if the device has one. I cannot prove it as the source code is not available, but I remember being curious and checking this on a rooted device.

Twelve is a quite high ratio of children to carer. In Sweden what is considered a healthy ratio is 5:1, and many places do meet that rate or are very close to it. 10:1 would be considered a very poor daycare, and most people wouldn't want to put their children on it — only if they have no other choice.

Regarding pay being bad this happens over here as well, unfortunately. Teaching in general is not paid as much as it is worth.

No adblocker detected 11 months ago

The problem with this approach is that many "secure" apps nowadays (bank, authenticators, etc.), at least here in the Nordics, are checking (among other things) if the app has been installed from the Play Store. If you install the very same signed APK from Aurora, or another source, it will refuse to work.

I was in a similar situation when I immigrated to Sweden ~20 years ago (I'm Brazilian).

Technically the law says that I'm supposed to carry passport + residence permit (first version was a sticker, then it became a card). However, the hassle of carrying them on a daily basis (and especially losing them!) is too much so I was left them at home. I made a color photocopy of both and put on my wallet instead.

Then later the Swedish tax office started issuing ID cards for non-citizens and I started carrying that (but also the photocopy).

As a foreigner I was not fully complying with letter of the law by doing that but to me the risk of losing my paperwork was far, far higher than being punished for not carrying those. I assumed that in practice if it was something serious they would look me up in the system anyway, or escort me home to produce my paperwork.

Not sure if I that was indeed the reasonable thing to do or if I got lucky, but I never had any problems.

Canyon.mid 1 year ago

As a data point/anecdote, I had a parallel-port Zip drive with a 386 and Windows 3.1. I remember quite clearly that I had to load a SCSI driver in CONFIG.SYS. I didn't understand back then why I had to load a SCSI driver for a parallel port device, years later I found out that the parallel port version was actually the SCSI version but it tunnelled the SCSI protocol via the parallel interface...

Not a joke. When my daughter was younger and we were visiting the daycare (förskola) facilities around us to pick one, in one of them they didn't have a room for children to sleep indoors, they always slept outdoors (even in the winter). This daycare was very highly recommended.

Anecdotally, when my daughter was a baby and had issues falling asleep, all it took was to take her for a walk outside in negative (celsius) temperatures and it was like we gave her sleeping pills. It never failed.

I grew up in a different country, so this whole concept was alien to me and it was diametrically opposite to my instincts, but I have to say that I'm a believer now.

But is true. I am a Brazilian who lives in Sweden and there are multiple banks here that have blank bans on transfers from/to Brazilian banks due to the amount of fraud and money laundering and lax KYC controls. It is simply too much work for the banks here to vet those transactions and they decided just to refrain from doing it.

Now, almost all have come from privileged backgrounds, went to Ivy League institutions, live in gated communities, are completely detached from the reality of what the average American knows about the law, and certainly aren't going to be taken advantage of by the cops. It's no surprise we've seen such an assault on our constitutional rights: they don't understand what life is like outside the ivory tower.

In Brazil we have a problem with the Judiciary too, most of it is completely detached from reality, due to these exact same reasons.

Because in some countries you must run some government sanctioned apps that require a "blessed" device, or you are a de facto non-citizen?

If Americans had anything like BankID or MitID which would refuse to run on their devices and they would be prevented from paying a bill, transferring money, buying tickets, or reading their mail they would go apeshit in 5 seconds.

Some apps are no longer optional in the world we are living in.

And yet if some other country bans US-controlled social media exactly for the same reasons, this works as a data point to label them as "lacking freedom of speech", "axis of evil", "undemocratic", etc.

But I do appreciate the honesty of at least admitting the hypocrisy.

It's not a "stretch", it is exactly that. It's widely known by anyone familiar with the hardware that Gamecube and Wii are basically the same console: it's the exact same architecture but the Wii has upgraded/faster components and (this whas the key:) different peripherals and bet on the motion controls. It's more or less like comparing the Intel 386SX with 20 MHz and the AMD 386DX with 40 MHz.

You could just ask the developers of Dolphin (Gamecube/Wii emulator). There's a reason for why the same emulator can emulate both consoles.

I don't doubt that it's the way you have been taught, but it doesn't make any sense. The whole point of blinkers/indicator lights in cars are to signal your intentions before you do them: if you're going to signal at the same time that you do the action you're signalling, you might as well not bother.

Exactly. The traditional design language is that an arrow besides a button indicates that the button will show a drop-down when pressed (traditionally without a line separating the two), or that clicking on the button will do the default action while clicking on the arrow will show all the actions (traditionally with a thin line separating the two).

Reusing that design language but making the button and the arrow two completely different buttons with their own actions sets wrong expectations for no good reason.

Not exactly. It was heavily inspired by Joda Time, but it also improved the design in a lot of ways. You could think of it as Joda Time if the designer could go back in time and design it again with all the hindsight.

Actually it happens. I live in Sweden and I travel to Brazil to visit family. If I get a SMS on my Swedish number, I get charged the equivalent of a 1-minute phone call. The reason is that the Brazilian telecom I'm roaming in sees a foreign number from Europe as a perfect opportunity to get some easy money, and charges my provider, which passes on to me.

Note that the law in Brazil forbid telecoms from charging to receive phone calls or messages, even when roaming. But I guess the regulations don't extend to foreign users that are on international roaming, or companies do it anyway counting that the person will only find out after returning home and won't know how to fight it. Authorities are not set up as well to receive complaints from non-residents.