Hacker Newsnew | past | comments | ask | show | jobs | submit | quesomaster9000's commentslogin

TL;DR Tamil Nadu should ... be its own country?


It doesn't sound like a particularly large leap to think that polities as large as the Indian federal states could work as countries.


> In what situation were you as a foreign traveler where you needed to pay UPI?

If you live in a tiny bubble and only take an Uber to the Work Campus, Uber to the small number of marts you've found that accept card, Uber to the small number of restaurants that accept card... you have to find them first of course.

Want to buy some cigarettes while you take a stroll in the evening? Good luck. Want a tuktuk to take you a mile across the beautifully walkable road infrastructure? Good luck. Want to get lunch with friends? Good luck.

90% of life doesn't exist inside the corpo "work hotel sleep" bubble, I described it to somebody as akin to trying to pay with bank transfer in the UK, technically you can do it... the manager will come out and spend 20 mins futzing, taxi drivers may be able to do it if you ask nicely, your shopping options will be very limited and far between because you're trying to transact in the non-predominant medium.

Yes, loads of places accept card, larger stores accept card, want coffee? Blue Tokai accepts card. Want Blinkit or Zomato? You need an Indian number first. Want a Hotel? Booking.com is predominantly "pay at the hotel" across most of India, which means it's a dice roll as to whether they'll accept card. You'd be surprised at how many hotels completely forget that not all customers are Indian+Aadhaar+UPI, except by the time you've got there and realized they accept neither C-form nor Card despite telling you explicitly they do - you've already spent the time, money and effort getting there only to find out that no... it's not practical in reality for you to book a hotel and pay for whatever reason. Repeat ad-nauseum everywhere daily


> Want to buy some cigarettes while you take a stroll in the evening

Why would you go buy a beedi from the local paan-wala?

> Want a tuktuk to take you a mile across the beautifully walkable road infrastructure

Why would you call an auto or e-rickshaw when you could call and pay for via Uber (which also does autorickshaw pairing)

> 90% of life doesn't exist inside the corpo "work hotel sleep" bubble

OP was talking about "business travel".

> You'd be surprised at how many hotels completely forget that not all customers are Indian+Aadhaar+UPI

They aren't forgetting. They just don't care about a foreign traveler. It's the same when I travelled to China outside of the foreigner bubble on multiple occasions

----

At the end of the day, foreigner who can afford India1 but is consuming like India3 is a waste. Doesn't matter if it's a backpacker or a kanjusi NRI.


> Why would you call an auto or e-rickshaw when you could call and pay for via Uber (which also does autorickshaw pairing)

I don't know when the last time was when you were in India, but using Uber to hail auto rickshaws requires direct payment to the driver at the end of the ride. Uber does not handle payments. Your credit cards are of no use for this. The driver will either take cash (without having change) or probably UPI.


Why would you go for a masala dosa with filter kaapi with your colleagues when you could order a hamburger from room service? Why would you hail an auto when you could just charter a helicopter instead?


Why visit India when you can book an entire floor of the JW Marriott Aerocity in Delhi...


Yearly I spend, on swiggy alone, more lakh than most bengaluru techs get paid.


> the system is now available in some form for payments in 11 countries outside India.

I see this often cited, but in reality it's a farce. "UPI is international" the staunch defender says, so I rebut "Yes, in one place at the Eiffel Tower... everywhere else? The French have no idea what UPI is, and your bank will charge you stupid FX fees for card payments".

Meanwhile if I'm in India, people look at me weirdly for paying with UPI yet most won't take card payments outside of tourist areas or it will get declined because foreign cards are blocked - and if you try to pay cash suddenly nobody has any change, will refuse to take the 20 rupee note they gave you yesterday, or have concerns about whether the notes you literally just withdrew from an ATM are legitimate - meaning you can end up with notes that are defacto unspendable despite being perfectly legal tender and in acceptable condition.

And as a tourist... you want UPI? There are a few ways but they're byzantine, apps locked to the Indian App Store (for tourists?), in-person KYC upon landing, very low first-payment limit, topup/signup and idle fees that push the net fee % easily into the 5-10% range.

Lets look at a perfect example... you pre-KYC on an app ahead of your trip on the one app that allows remote KYC, but you can't load money onto - first you must provide your visa, but the eVisa doesn't count they want the actual visa stamped in your passport. You land, immediately after customs you submit the picture of your visa stamp and wait an indeterminate amount of time, it could be 8 hours, or 24 or 48 or it could get rejected and you could be required to do in-person KYC (either you go to them, or they come to you within a ~5hr window... but only in the major cities).

So day 1 it's impossible to use UPI. It gets approved on day 2, you take a taxi somewhere maybe a nice restaurant, your UPI is now loaded with INR and you try to pay the driver... Your driver has a personal UPI account, you can't pay him! You only have cash... Large denomination INR notes because that's what the ATM provides, he doesn't take card and refused to admit he has change. You eat the already inflated cost and swear to only use app-based services (assuming the Taxi Mafia hasn't had them banned in your city).

You get to the resto and enjoy a meal with your friends, it's a nice place and somewhat expensive, you come to pay, the bill is reasonable and you think "I will pay with UPI", you try paying, it's a business account so should be OK! NO.... You have exceeded your first-day limit! Waiter tells you there is no card machine, and they have no change for cash...

Eventually you leave India, there's a non-trivial amount left in your tourist UPI account, you look for somewhere to withdraw it back to your card - no physical counters open at the airport, you request a withdrawal via the app... it never comes, the next month you get hit with a 500 INR inactivity fee, your visa expires and the app shuts down, next month 500 INR inactivity fee - can't make support requests through the app any more because your visa is no longer valid... Your balance slowly goes to 0 because you didn't think to spend every last rupee on your way out so it gets eaten by the system.

I say a small sub-1% fee on UPI is fine, it's great infrastructure when it works, but more needs to be done with global UPI integration. I have QR enabled payments available across maybe 10 different countries and India sticks out as being the one that's consistently an absolute pain and actively works against you.


Incredibly, WeChat Pay in China is now easy for foreigners: submit a copy of passport, link a debit account, and you can use WeChat Pay with no problems. No physical presence in China required, and the only restriction is that you can't use it abroad (i.e., at WeChat Pay stores outside of China). I've had a fully working WeChat Pay account for a couple years now, and I've never once had to do anything in-person or anything except upload my passport and Tencent made it happen.


Wexin diaspora ftw


> I have QR enabled payments available across maybe 10 different countries

Any experience or rec's for Thailand?


Unfortunately Moreta disabled Thai PromptPay QR payments recently except for US KYC'd people due to some compliance dispute. There's also lbank.com but I can't confirm if they currently work in Thailand (lbank has an... interesting reputation, I can only use it via TestFlight, but works for my daily food spend needs)

Otherwise you're stuck with AliPay+ merchants (easy via Wise) or TAGTHAi which should still work but is expensive and sucks.

--

I forgot about https://p2p.me - they're taking the regulatory arbitrage 'personal travel payment concierge service' approach, basically "work around the problem, not with it" as the founders realized the people making the regulations neither know nor care about on-the-ground practicalities.


This is the reality.


POSIWID. Purpose of system is what it does.


If you're going to post this, please elaborate on it at least a little bit. At least to show whether you actually understand the point of the phrase.


Well in GP's posting the system is universally used by Indians, but ends up costing foreigners quite a bit. That's seemingly not a problem that Indians would want to solve.


Counterpoint: These are temporary growing pains that will be resolved in 10-ish years.


Currently hacking away at https://github.com/lockboot

Using UEFI SecureBoot + vTPM for cloud root-of-trust, a stack to prove what's released on github/gitlab is what's actually running on GCP/EC2 (and soon Azure & AliYun).

I was annoyed that so many companies in the Web3 space would do the on-chain theater of verified contracts and "audits" then 99% of their infra would be deployed on EC2 (or god forbid Vercel) in full un-ironic "Trust Me Bro" mode.

It's a different trust model from SGX/TDX, more pragmatic and hopefully easier/cheaper. Currently polishing off "Docker to verifiable cloud VM" stuff, and then gVisor support next.


Great, by "remain ahead" this implicitly means "put everybody else behind". These are the same people that are pushing for "think of the children" internet and VPN KYC.

Let me translate this for you:

> - Secure-by-design and secure-by-default must become standard practice – not an aspiration.

This means we will enforce censorship of many many topics, often broadly, even egregiously, and at the whims of whichever policy wig is trying to climb the ladder.

> - Resilience cannot depend on a single solution or technology. Defence in depth remains essential.

This means it will be wide sweeping policy applied to anything tangentially related to "AI" - pushing the compliance burden down onto everybody, luckily a small number of firms will profit massively from this due to regulatory capture.

> - As AI systems evolve, new and previously unknown vulnerabilities will emerge, including zero‑day vulnerabilities.

This means we're realizing that so much software is utter shite, instead of letting people fix it we will bury our heads in the sands and only allow approved government contractors access to models which can fix vulnerabilities (fixing them requires finding them too)

> The rapid pace of frontier AI development means cyber risk assumptions can become outdated in months, not years. We must act before and be prepared to adapt and withstand evolving threats.

This means "We're fucked, and we know it, this will be rushed through parliament and congress, basically the "AI Patriot Act" on steroids as a "temporary measure", to try and keep ahead of the curve.


Amazon Nitro Enclave does pretty much this, the guest has one method of communication, via vsock, and it's up to you to build the pipes on either side.

It's a huge PITA in practice because whatever you want to run inside some enclave usually ends up being a 'normal program' that needs to talk TCP/IP over sockets... so your vsock I/O becomes a weird mix between a TUN proxy or a SOCKS5 local listener inside the VM that tunnels through vsock.

For example, I have the Windows NT 3.50 kernel compiling from scratch with virtio-net drivers, it's fairly straightforward for me to add a bus driver that runs over vsock inside Nitro Enclave that exposes itself (o,o) as a NIC then handle the tunneling logic in a usermode process in the host - but I don't uderstand the point of why you would do that when you already have sufficient attestation methods that don't require you to do vsock isolation.


Yes, you can do this on real metal, EFI is EFI and as such you can make it do essentially whatever you want. For example recently I had to make a stage0[1] HTTP EFI bootloader, it pulls the URL and hash or pubkey from the cloud metadata service, downloads the EFI binary and chainloads it after verification.

On metal you would simply embed the URL and pubkey into the EFI loader binary (or a file on disk), put it into your ESP partition and reboot the machine. Typically the certificate DB of the machine would be reset with a single certificate that signed stage0 then switched into 'Deployed mode' so no new certificates can be added.

This separates the 'provision machine' phase from the 'machine boots and runs your latest release' phase. Although at this point we're booting UKIs so a Linux kernel + uefi stub + initramfs all in a single file.

[1]: https://wavebend.org/blog/2026-06-13-stage0-http-netboot/


One of the best flights I've ever taken was Spirit and had 8 passengers on it, 5 of which were transferring staff/pilots. The second worst flight I've ever had the pleasure of enduring was also Spirit - the worst was Easyjet (simply because their seat dimensions are somehow smaller than the average human and generally incompatible with human physiology), and third worst was Ryanair because a mass of orange colored Brits are with near a unlimited supply of duty free gin is... amusing enough to move it up a few notches.


> a mass of orange colored Brits are with near a unlimited supply of duty free gin

I fly direct from London to Vegas occasionally. The upside is that going through immigration is trivial -- of 270 people on a flight, 265 go to the "foreign passports" line. The downside is the 15 minute wait after getting to the gate for the police to come and arrest the people who were fist fighting in the aisle.


I've flown on Spirit exactly once, thanks to an ex-wife who fit the "needlessly frugal" type talked about yesterday to a tee. Grew up in foster care and couldn't acknowledge we weren't poor. We flew into Miami during some bad weather and it's the only time ever in decades of flying I've seen the flight attendants visibly scared. If you've ever gotten speed wobbles on a skateboard, it was just like that. I'm still amazed the plane didn't fall apart in the air. They also charged for water.


Spirit Airlines has had a perfect safety record with no passenger fatalities and every plane that ever took off from its 34 year history landed safely. I'd trust them more than other airlines.


Most flight attendants know very little about the actual flying part.


Do you think the weather would have been better if you had flown with another carrier?


It's quite possible other carriers would have gone around the worst and that the economy airline saved fuel.


I'm very much from the same era, "stfu and fork it", "PoC or GTFO".

And as I got older, I realized "I am not the customer, there is no money in responding to me, I am a net negative cost to your business".

And uhh... I'll shuffle the F out now then? And try and catch-up on 200 years of math.

I don't think anything has changed IRL, aside from my knees hurting


"Self-service doacracy" rather than "look at me and fix my 'world-ending' problem for me for free right now". While I applaud creating patches and submitting them upstream, there's zero obligation to review or accept them... just throw them out there and let whatever happens happen in its own time.

It's my tailbone and an old torn back injury; I can't sit or stand for longer than 2 hours and I think I need to swap my Aeron classic size B for a C.


Some people get so precious about code bases and want everything to be 100 line digestable units that working with them is becomes near impossible when they dig their heels in.

It's like dealing an angry grandpa throwing mud over your newly cleaned car, "You gotta start at the wheels lad, not the windows, do it again".

Great, now you've broken the flow, I have to re-do everything, figure out which tests to introduce in which order and unravel them all, ironically this is where I've found more bugs creeping in, because you're no longer diligent - you're appeasing performatively.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: