Hacker Newsnew | past | comments | ask | show | jobs | submit | Nextgrid's commentslogin

Although you can run SIP over TLS (for signalling) and use SRTP for media (key exchange done over the aforementioned signalling channel), in practice most SIP is over unencrypted UDP and media is unencrypted RTP.

If you control both endpoints and they support it you can configure them to use encryption, but even then implementation qualities vary widely (just because you enable SIP over TLS doesn’t mean they’ll actually verify the certificates for example - giving you at best opportunistic encryption), and I bet a lot of the implementations also have bugs/vulnerabilities.

If security is needed, it is often implemented by way of running the whole thing over private links (which can be secured with IPSec or any other VPN technology). In fact that’s presumably what’s happening, but misconfigured equipment making those ENUM lookups would allow the attacker to steer the traffic away from the secure link and towards an endpoint they control over the public internet.


The "/month" is the problem - I just don't read the same paper often enough to justify a recurring subscription even at the intro price, let alone the full price it'll eventually transition to.

I would love it if I could be able to pay _once_ in one-click just like if I was purchasing a physical paper. But until this happens, I'm more than happy not paying (nor reading) paywalled online news.


The problem with paywalled news articles is that the ranking is done on the full article content, yet I am not allowed to see it. This often outranks the results I am allowed to see. Product pages don't have this problem.

Don't they? An ice cream maker might be highly ranked because of positive reviews from people who used it to make good ice cream, yet clicking through to the product page doesn't let me have ice cream unless I buy the machine!

Now imagine clicking through to the product page, and in order to view information about the product, you must pay first.

Product pages don't engage in cloaking or selectively serving a different a different page to the search engine crawler from the one served to the visitor. They are ranked based on the content visible on the page. If that's the best match to my search query, so be it (it probably means I am indeed searching for said product page).

Paywalled news articles rank on their full content (potentially displacing other, free sources) yet do not allow me to see it without paying. That's a bit of a problem because if I don't intend or am unable to pay I would much prefer seeing the other source which is free.

(the ice cream example is disingenuous because clearly we do not yet have the technology for ice-cream-over-HTTP. And when we do get such technology, then absolutely give me the option to block paywalled ice cream).


Google even has/had a rule against cloaking (the practice of serving search engines a different version of the page from the one visitors get).

This started with expertsexchange:

https://news.ycombinator.com/item?id=3182198

but unlike that stack overflow predecessor that attempted to build itself as a paywalled business, newspapers successfully strongarmed Google, at least in the EU, by arguing against Google monopolistic powers so it's unlikely that Google would dare put them in the shitlist.


If you don’t intend to pay anyway, what’s the issue? This option just gives you the choice to hide paywall results.

There is a regex replacement feature. You could build a list of known paywall domains to rewrite them to your desired paywall unblocker service.


You only need to have a business entity (which, to be fair, can be yourself, although liability concerns apply) once you're about to actually enter into a contract with someone.

Merely listing prices (without an associated automated payment form which could imply a contract was en force upon successful payment) doesn't actually force you to do business with anyone. It would however 1) deter requests for unpaid work by giving them an idea of what it would cost to get what they're looking for and 2) give you an idea of the demand for said services and could give you a warm lead which you can then choose to pursue formally by getting the necessary business structure, legal/business advice, etc.


> Merely listing prices (without an associated automated payment form which could imply a contract was en force upon successful payment) doesn't actually force you to do business with anyone.

In some cases it could. If you want to say "we categorically don't do X for ethical reasons", that can sometimes be more easily defensible in a way that "we have a standard price for doing this, but we don't want to do it for you in particular" may be harder to defend. (Even though I think both should always be possible.)


> Stripe is "just" a payments platform

Counterpoint: you can't just go to Visa/Mastercard or a merchant acquirer out there and set up an account on the same terms that Stripe can.

On the other hand, you can sign up to any LLM provider and get API access on terms that are the same or better (since I'm sure they don't appreciate having a middleman and would benefit from incentivizing direct usage) than OpenRouter gets.


To add to this; payment infrastructure requires a lot of heavy lifting. There's a lot of regulations you need to adhere to, different payment systems in different countries, settlement, chargebacks, etc.

There is a reason why not doing your own payment processing is a thing.

OpenRouter may have some interesting things in streamlining the process of switching LLM providers, but it is indeed something easy to replicate in comparison to payment processing.


Yes, you can get better pricing if you do it yourself. But the true advantage of OpenRouter is that, in a space where there's a new model being released every week, you can easily switch to whatever model is best at any given time without having to set up accounts with multiple providers. Or you can just experiment with the latest release. Their product is the convenience. Of course if you decide to only use a specific provider or two, then you don't need OpenRouter.


But it's not really that difficult to make a clone of OpenRouter's service. What they do isn't really that original.

Their only value comes from the fact that the currently have lots of traffic. And I dkn't think that their cumstomers are really bound to theur servuce. They could switch to a competitor without too much hassle.


Yes, but as l9ng as there's no clone, they're good. On the potential clone side, I guess many will be put off by the fact that "there's already OpenRouter". Also, a clone would need to find a way to make existing OpenRouter customers to switch, which isn't easy.


Openrouter is fragile, one good competitor and they are at risk.

Or if one of the provider suddenly decide to forbid openrouter from using their api. Why would they do that tho ?? Well it's not like execs never take dumb decisions.

In my humble opinion, it's extremely overpriced. But then, it's just the standard with AI currently. Divide every ai company valuation by 1000 and you might get it's real value.


Will that necessarily be true in the future? Would we not expect that openrouter will develop the ability to negotiate special pricing?


> I don't understand why there isn't a special USB-C protocol to recover bios over SDU/CC pins

Not enough of these cases happen under warranty for them to bother (and out of warranty cases are either neutral, or even beneficial to them if they drive sales of new hardware).


> after a while the investors start asking where their dividends are at

By then, a new fad will come in and you can just pivot to it.

We went from "engagement" (with no concrete plans to monetize said engagement), through a brief period of "blockchain" and now finally AI.


> engagement" (with no concrete plans to monetize said engagement)

Google and Meta have made billions monetizing said engagement


Eh, this is true prior to an IPO, but listed companies (like every single one doing this shit) are very much beholden to shareholders and quarterly reports.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: