Why so many things cost exactly zero
bloomberg.com
bloomberg.com
Every form of payment, no matter in which direction, needs to provide enough benefit to justify the costs of the complexity added by it.
The purpose of ISRG (the not-for-profit which runs Let's Encrypt) is to drive automated issuance for Web PKI certificates. Nothing about this directly means they should be free - surely a not-for-profit could deliver this as an at-cost service, so why zero cost when that's not a core goal?
Machines don't have wallets. If they charge even 1¢ for a Let's Encrypt certificate (which would certainly cover costs at current issuance rates) now there needs to be a payment flow, which the machine needs help with because it doesn't have money. At zero cost all of that goes away and leaves you only solving engineering problems to achieve your goal of automated issuance.
EDIT: fixed arithmetic, thanks skj
Or more precisely, it's good for the party operating at scale and bad for the individual participant. This is the opposite of how most financial schemes handle unpredictable events: they put the risk on the party that can absorb the risk by letting it be lost in the noise, and take it away from the party that cares deeply about small amounts. Insurance companies will charge everyone the same amount, whether it's a customer that will ultimately bring them a bit of revenue or ultimately cost them a lot of money: the price for the individual customer is fixed. A plane flight costs the same amount of money whether there are strong tailwinds and the plane flew cheaper than expected or whether there was bad enough weather that the flight had to land somewhere for refueling, and the cost of the occasional rare disruption is built into the ticket.
This trick is mathematically nice, but there isn't really a reason for a consumer to prefer it to even paying $.02, unless the consumer is also paying at scale (in which case you can just aggregate the transfer and not use this scheme at all).
This is only needed for micropayments so a buffer of like $5-10 could be fine if you could somehow otherwise otherwise verify the user / monetize the relationship. Best way I can think of that preserves privacy is to serve image only ads through the payment network in an appropriately boxed window every time you add a tip to the randomized micropayment scheme.
Maybe, someday, micropayments will be good.
And if the problem is that even simple payment complicates things, complicated (probabilistic maybe or maybe not) payment isn't going to make it better.
Names meaning mostly DNS names like news.ycombinator.com but also numeric names such as 1.1.1.1
The Baseline Requirements (the rules Certificate Authorities agreed to obey some years back now) currently provide 13 potential ways to verify domain ownership, but these ways are sometimes called the Ten Blessed Methods dating back to when Gervase Markham was alive and worked on the Web PKI.
Although some of the Ten Blessed Methods are specific to the web in practice, such as 3.2.2.4.6 which involves creating a document to be retrieved from a web site, others really aren't such as 3.2.2.4.7 which is just a DNS change. Let's Encrypt offers both these (as challenges http-01 and dns-01 respectively)
Method 3.2.2.4.12 is specifically for domain registrars in the sort of relationship you're talking about, and is used by some registrars which also have a CA business (such as Google) today I believe.
‡ It got this name because the Web is why this PKI exists. SSL was invented by the Netscape Corporation, whose Web browser is the ancestor of today's Firefox. Netscape's successor, the Mozilla Foundation and Mozilla Corporation continues to be the most visible and only public oversight for the Web PKI. Perhaps if instead some other group had secured the Network it would be named, say, the Usenet PKI, or the IRC PKI or the NetBSD PKI, but they didn't and it isn't.
What makes webpki unique (and correct me if I am wrong) is how responsibilities are separated such that domain ownership is established by a 3rd party (like ISRG) as opposed to by the domain registrar. Logically speaking, the party transfering or registering domain ownership (for a fee) would also issue you a certificate at the time of transfer/registration. The different approaches to verify ownership would not be needed if the more sane approach was taken to begin with.
As you know, DNS is a protocol sepatate from TLS or other protocols. As such, domain ownership/control validation should be contained within the domain name system (also, why dnssec,dane and other efforts are under way, but they don't address the root cause of the problem).
For method 3.2.2.4.12 (and thanks for informing me about this), my comment was that it should be mandatory (not optional) for registrars to issue DV certs.
While I appreciate the ISRG, there are cases where using letsencrypt is not practical ,that aside, one org controlling so much of the web goes against the very concept of having TLDs that are independent in purpose/function. It would be more architecturally sane if what the ISRG does now was instead done at least at the TLR level. (E.g.: .com's owners should issue certs that says site.com belongs to whoever has this cert)
For the impractical corner cases: let's say I need to run a non-web service like SMTP and I can't spin up a web server to validate the domain. Or let's say I need non-TLS x509 such as ipsec.
> let's say I need to run a non-web service like SMTP and I can't spin up a web server to validate the domain.
You should use Let's Encrypt's implementation of 3.2.2.4.7 which is the dns-01 challenge as I already mentioned. Or use another vendor's own implementation of 3.2.2.4.7 or any of the half a dozen or so non-web methods listed.
> Or let's say I need non-TLS x509 such as ipsec.
The Web PKI can't help you. Leaf certificates in the Web PKI contain an EKU 1.3.6.1.5.5.7.3.1 which says their purpose is TLS server authentication. There is no global public PKI for IPsec. Feel free to try to make your own, but I expect it will be an expensive and thankless task.
The central issue of a PKI is trust and domain name registrars are not on the whole very trustworthy. We're talking about the industry which invented Domain Front Running - the idea of waiting until a customer shows interest in a unique product (a domain name) and then buying it yourself so that they'll have to buy it from you at an inflated price.
I sympathise with the desire to build a parallel PKI baked into the DNS system, but the Web PKI is not that system and there's no practical way to mutate it into that system. If you believe DANE is the only way forward you should go help people make DANE work better, not argue against the Web PKI.
Issuing "a certificate" at time of domain registration greatly misses the point of Internet hierarchical naming by the way. While it would be technically possible for every domain to hold a single wildcard certificate and use flat naming (so news.america.ycombinator.com couldn't exist, it would need to be news-america.ycombinator.com) that's a terrible security choice. Necessarily where a service corresponds to one specific name the certificate and corresponding private key should be for that name only, and not a hierarchy of related names in order to mitigate risk.
To address your concern, clients will have TLD certs in their trust store. TLDs issue intermediate CA certs to registrars. When you get a domain, they issue a cert (not x509 neccesarily) that allows you to issue certificates like an intermediate but restricted to that domain and its subdomains. So news.america and news. Under ycombinator.com will have separate certs,signed by the owner of ycombiator.com which on turn has to have their CA cert signed by a registrar.
This actually can improve security, because you can isolate your intermediate signig key from the rest of your services, and possibly have a dynamic process of issuing extremely short lived certs by your CA box to all of your services. Code signing certs,s/mime,client certs, eap-tls,etc... Can all be more easy to use. For example, if I could use eap-tls to connect to wifi at an airport or starbucks using a cert I issued myself under my domain (or under my work/school domain). Things that have been notoriously hard to adopt like TLS client certs could easier to use because anyone can have a client cert issued to them by any domain owner (likely the domain of their email provider for most) because any site can verify their client cert using this system and anyone with a domain can issue certs. This is the natural and most sensible way.
As for trust, you already trust them with the power to transfer your domain. If someone compromises your registrar account, what stops them from taking over the domain,pointing it at their own servers and getting a new cert from ISRG? Imagine getting a government ID and to verify it's legitimacy,people have to contact 3rd party companies instead of the government, that makes no sense. Things are the way they are because public key crypto was not used widely when DNS and the internet became a thing.
How long does it take to mine 1¢ worth of bitcoin? Or, is there anything else a machine can do in a relatively short timeframe that’s worth 1¢ to someone else?
t2.micro instances on AWS rent for about 1¢/h...
The whole point of profitable mining is to build asics such that the cost of electricity gets lower than the mining rewards.
I don't think you can mine $0.01 worth of bitcoin. Most of the time, you'll lose the race to find the correct hash collision and so you'll end up with nothing. Other times, you'll win and get the reward for the block which is 12.5 BTC at the moment (IIRC). People do join collectives to pool their mining power, but there isn't predictability to when the collective will end up with a coin. If you're looking to set up a web server, you don't want to be waiting days or weeks or whatever while your collective tries to win a block. Theoretically, you could buy a lot of computing power and always get unlucky.
So you can't really get a penny of bitcoin via mining.
But mining once cent worth of bitcoin would cost you multiple dollars on a CPU.
Whether it's actual time spent signing up, putting in my credit card data, updating expired cards, etc. Or linking my account/PayPal/Venmo to receive tiny transactions.
Or just the friction of "do I really want to pay $0.05 for this?" And I just don't want to make a choice, so I close the tab.
I know a lot of people dream about microtransactions changing everything... but even if they work flawlessly technically, I just don't want the mental overhead of making 20 tiny economic decisions every time I use the internet. Ugh.
Decentralization is for clueless idiots who doesn't understand Decentralization or everything is a trade-off concept
LOL, that's so obvious in retrospect: if something costs so little, it's because you probably don't need it. Minor annoyances, even the mere decision, and you won't bother.
But note they mean zero price, not zero cost.
Pretty much all ~consumer services like that are either free or at least $10.
Until payment processing is an inherent feature of the monetary system, rather than through multiple third parties, small transactions like these are just bad for everyone.
Only make the really cheap plans available as annual subscriptions. Charging $3/month isn't very viable, but I bet $36/year is. (Assuming that the costs of providing the service itself permit that.)
Attempting to do both increases the complexity of your pricing scheme, and that translates to abandoned and lost sales. At least, that was my understanding of the reasoning.
I could see creating a tier chart for the different levels of service with "monthly" and "annual" price columns, where the monthly column is crossed out for certain tiers.
But I'm not a marketing person.
Pretty much anything that is remotely considered a barrier to your sign up or checkout process costs you sales; having questions or needing to spend time deciding which position on a chart you want to purchase from is time you are giving people to decide maybe they don't actually want to sign up.
Presumably they think more people would pay a higher amount than walk away because they don’t offer a lower amount? or that people who want to pay for smaller space are more likely to use it, or become less attached to the account and more likely to be less loyal and shop around, or don’t want to support the increased complexity...
Card fees would presumably be more of an issue for flat rate $/gb but I don’t think they they are that zero-margin?
I find it interesting, because EFTPOS (like a debit card in the US) seems to be far-and-away the most popular way to pay for small items and is accepted virtually everywhere.
That's why they offer such great discounts for annual billing. DropBox's cheap plan is $10/month when paid annually, but $12/month if you pay monthly, for example.
There are benefits to cash. And despite the tremendous faults and failures, of a (more-or-less) decentralised payments-processor system. Though one might argue that one in which Visa and Mastercard account for 3/4 of all card-based payments[1], even before accounting for the data "sharing" between payment and credit-scoring entities, fails even harder than even the government-controlled case.
________________________________
Notes:
1. https://wallethub.com/edu/cc/market-share-by-credit-card-net...
Unfortunately, with the costs of transaction fees being put on merchants, there's essentially no incentive for customers to get anything other than what is commonly accepted, and so no way for any new entrant to the system that uses a different (or no) processing fee structure. The closest thing to new has been Stripe, and that too has essentially the same structure as the rest.
It is interesting to me that you mention the Post Office- a government run organization that effectively operates independently and probably has less data on you than your phone company. In fact, I suspect an organization set up in a similar manner probably would have the same level of insight and (in theory, if not practice) the same level of privacy for you as Visa or MasterCard.
Then again, if I had a magical fiat wand, I would also allow FedEx and UPS to deliver packages into my mailbox rather than leaving them in the rain and snow, so I can't say that I've worked through all the details of where the right balance between "public good demands a monopoly" and "public control is unwarranted and not likely to be more beneficial".
The problem's a difficult one. More usually, the answer seems to be a mix of bundling and subscriptions.
With technology and all that it entails (protocols, data, interchange, hardware, various forms of IP), that itself is problematic in ways simple print content subscriptions generally weren't.
If you keep the existing rate structure, payment processing represents a ~3% sales tax that yields a huge margin for all players, a tantalizing revenue stream to nationalize.
Id you use the state resources to subsidize the price down to zero, you have a great "pro-business"/"pro-inclusive-economy" plank for political points.
Either way, you get a huge amount of data and a massive lever you can use for political ends. Think of the deplatforming debates of a year or two ago, but magnified by "this is basically the only payment platform used in the country."
The so called Faster Payments System (Система Быстрых Платежей), launched last year, offers instant money transfers in Russia for 0.05-6 rubles (≈$0.01-0.1). Your bank can charge you on top of that, but i.e. in my bank it totally free (subsidized by other services).
Now (since autumn) they are slowly launching payments system (it's not gained traction yet, but it's just started). Tariff for payment system is 0.4-0.7 for retailers, split between your and retailer's bank.
Afaik, China also has something like that for for years.
I think that USA don't have something like that because political tradition forbids government to compete with established private services. I have read that Americans have to buy commercial software for filing taxes. :-) In Russia, it would be unbelievable — you just using government provided tax filing software free of charge.
Personally, I would much prefer that our legislators simplified the tax code to the point that specialist preparers and software wasn't necessary, but all of the incentives around elections pretty much guarantee that won't happen.
Outside the U.S. there are differences in payment system. Here in Germany we have working wire transfers for most things working fine. However that system lacks online authorization ... only in 2015 German banks started their PayPal copy PayDirekt, which however fails to attract vendors and users, to a degree due to hen and egg issues and to some degree due to competition law issues (such a cooperation between banks might for a cartell, thus they've built a complicated structure)
Government can't really regulate this much, unless they want to rule prices completely.
Edit: yup, tips: https://www.ecb.europa.eu/paym/target/tips/html/index.en.htm...
Alas, the 90s hit and these banks, along with the energy companies, the cable companies and the postal company, were privatized. Innovation ground to a halt and service quality plummeted. In the end, they had to be bailed out during the 2008 financial crisis.
Low level managers and staff are allowed to purchase stuff directly below some sum, typically below $2000, sometimes higher. If somebody needs something below that sum they just buy it online or with few emails if they have money in the budget.
If you go above that limit, suddenly it's more complicated. There may be purchasing department. They compare prices, may select bidders etc. Purchase may even become a procurement. You often have to send a person to sell and negotiate. If you send someone, you may as well add $20,000 to the price to cover the cost of travel and time. Product you sell for $5000 online costs now tens of thousands.
https://www.joelonsoftware.com/2004/12/15/camels-and-rubber-...
Is this something you made up?
I don't know about a single name, but a google search for that phrase got me these:
https://www.today.com/money/how-much-can-you-spend-checking-...
https://couplemoney.com/family-and-finances/couples-spending... (writer used to have an exactly $100 threshold, fits your memory)
https://www.fool.com/the-ascent/credit-cards/articles/study-...
Just think about the traffic you can easily generate when you have some work projects sitting on Dropbox folder. All the builds, downloading libraries, getting node modules etc, people working on large documents etc. The cost to provide 100GB of space vs 1TB of space might be actually pretty close for Dropbox (considering also that very few people actually use all that space).
Other providers may have different cost structures. Maybe the services they are providing are bit different (for example less focus on sync speed), or maybe the customers are using the storage in very different way (I guess most of the content in iCloud is photos and videos).
Maybe they just want people to be used to getting a monthly invoice from them. Or to used to paying for cloud storage (and so willing to increase the limit if needed). But then the $1 tier is pretty generous so maybe they want you to store a load of data in their cloud so you’ll continue to buy their products.
That then allows for impulse purchases (movies, apps, etc), and validates that the user is not fake. One whale can pay for a lot of users.
Selling to individuals is expensive, not just because of credit card fees, but also because of accounting costs, VAT MOSS in Europe, and support. In my case, a single support inquiry from a customer could negate income from that customer for an entire year.
At the same time, you can sell to companies, which pay 8-48x more, and will bother you with fewer support requests because they have things to do.
I think pulling of a consumer SaaS is extremely difficult in general.
As a very rough comparison for SaaS companies, sales and marketing can consume a solid 50% of your revenue, overhead like accounting, insurance, support, and office space should be 20%, and actual product development is just 30%. This obviously varies greatly by industry and product, but if you're solely thinking about the final product and not how you get it to your customer, you're not thinking broadly enough.
Do you have a free tier?
Perhaps Dropbox is better as a feature after all.
I did that with Evernote a long time ago. I pay $35 / year and it keeps auto-renewing at that price.
I would imagine that it does lower chun. Commit to $10 and you're likeky to stay. Less, and it's no commitment at all. I don't think the seller - sans chun - has a tbing for $10. It the market setting that.
This already doesn't make sense. This wrong logic could be extended to every paid service which doesn't rely on an external service, especially SaaS, on the internet. If this reasoning was correct, everything from Zendesk to Superhuman to GitHub (pre-Microsoft pricing) should be free. Development costs money, and hosting overall costs a fair bit of money (because every user doesn't just post one picture, or have one email, and it compounds).
The real reason it is free is because they want users, and make more money from ads than they would charging a reasonable price (which would massively cut adoption anyway).
This article seems to be written by someone who doesn't understand the engineering side of things. At scale, the extremely low cost of serving an individual request ends up being potentially costly in aggregate, which is why the larger a web service gets, the more important performance becomes.
This is such a good way to describe the current state of blockchain.
It's a cult. And mostly spread around by people who are trying to increase the price so they can sell and profit off other people. It's a giant ponzi scheme, and wealth redistribution.
But I think the technology has promise. We just haven't bothered explore real applications of it, because we're too busy trying to use it to make a quick buck at someone else's expense.
All that billing infrastructure costs money as well. Think of how much of the phone and TV cable networks is consumed by nothing but managing tollbooths?
The post from Stratechery yesterday made this point differently: when credit cards were introduced merchants liked them because they no longer needed the (pre-computerized in those days) infrastructure and headcount of billing customers, checking credit, etc.
It's not just the mental overhead here. I specifically avoid toll roads because I think their concept is fundamentally wrong. I pay taxes to pay for roads and their maintenance. I shouldn't have to pay more taxes ("tolls") to pay to use those roads.
If it's a private road then it should be marked as such. The public shouldn't be permitted to drive on private roads marked as if they're a interstate or state highway or anything like that. It's deceptive and profiteering off of what the government already provides: transportation infrastructure. And it absolutely should not be permitted for a private entity to purchase an existing road and turn it into a tollway.
Anything +/- 0 by a little bit will be zero because there's huge friction costs in transferring money:
+ UI complexity, sign up + Transaction costs (VISA, fraud protection) + Financial accounting + Hosting the relevant financial data + Legal issues
If people were really on board with micropayments, I suspect they could be made to work technically/financially.
'Paying money' is not like the old days when you'd flip literally a few cents out of your pocket for some candy.
Money transfer in tech comes with huge headaches across the board.
Privacy, compliance, international taxation, VAT, risk, etc. etc..
In particular, under legal issues: taxes.
Sell something online to a person in city/state/country X, and you might be required by X to collect sales tax or VAT on the sale.
At least not in Germany. Every household has to pay a monthly fee even if they dont want to. No opt outs possible.
And for music licenses there is GEMA which is also financed by additional charges on empty media like SDcards or Hard disks. Also no opt out possible. Google/youtube was fighting it and they finally lost the battle.
So in principle the IP Providers could be forced to pay a monthly fee for internet searches and social media. For mobile networks this is already discussed.
It seems that the EU doesnt like the free services from the SV giants and will fight them in the time to come. The GDPR was only the beginning. The next one will be more about the money.
Yes, but you can simply not pay that. I've been doing that for decades now. They send you scary reminders and say things like "Hurr durr, we are going to impount your wage!" but that's where it already ends. Just send them GDPR requests which they can't/won't reply to on a regular schedule and they are actually the ones that have to deliver/comply first before anything else.
Side note: My household and car are broadcast/radio free and I don't consume these on the internet either.
The assumption is that everybody owns a media receiver (since computer+internet counts as well, as there is streaming) and since running the infrastructure is seen as a public service.
If you have a legal obligation to pay a fee the government is obviously allowed to process your data for that purpose.
Even if you don't own any screen or audio devices they still make you pay for it. I always fail to see how this isn't pure theft.
> Even if you don't own any screen or audio devices they still make you pay for it. I always fail to see how this isn't pure theft.
The rationales is that you are benefiting from that service (public information) indirectly (other citizens make more informed decisions) even though you don't use it directly.
And, realistically, which household does not own a device that is able to receive a video via a web site?
BTW, you don't need to pay the Rundfunkbeitrag if, among others:
«* you receive BAföG and do not live with your parents, * for recipients of unemployment benefit II or social allowance benefits, * for recipients of social welfare benefits or basic subsistence benefits ("Grundsicherung"), * for recipients of assistance to blind people according to § 72 German Code of Social Law XII.»
Source: https://www.studentenwerk-hannover.de/en/en-social/en-reduct...
That said, it is high time that these kind of levies get converted into normal taxes and progressively taxed like everything else. Why should the €30k/year household contribute as much to the public information as the €200k/year household?
It's like if you received a letter asking you 10 euros a month for building schools, another 15 euros for building new public buses, another 15 for a new train line. All these things are taken from your salary before it even reaches your bank account so why is this tv/radio thing any other way? We're already paying insane amount of tax in gerrmany, asking for 17 euros per months for thing like this on the side is an insult.
I'm sure there's a million issues I haven't thought of, but I like the idea.
It doesn't always require the service have 100% market dominance either, just that it be popular enough people hear others use it and commonly used in exclusivity by the user.
No one says they're going to "Kleenex their nose" or "aspirin their headache" so why would they "gmail their friend"?
You've at least heard someone say "let me Google that" or "that's photoshopped" right?
I think one is complements[1] (if the price of jelly goes down, peanut butter sales increase)
Apps are complementary to iPhones, so if Apple drives the cost of apps to zero, they sell more iphones.
For Google, if data sales are complementary to services, making the services free makes data sales rise.
Only thing I've noticed though is that free is associated with lots of unintended consequences. Free electric car charging means it's hard to reliably charge your car. Free web services means nobody gets good customer service. Even a modest co-pay leads to significant cost savings for insureres because free visits can easily tie up all health-care resources.
[1] https://www.joelonsoftware.com/2002/06/12/strategy-letter-v/
Amazon had a service that was built mainly with micropayments in mind. It never took off.
"Amazon FPS’s aggregation feature lets developers track and aggregate micro-payments into a single payment transaction, saving on transaction processing costs and avoiding having to build complex ledger functionality into their own applications. Using the aggregation functionality coupled with the lower Amazon FPS fees, developers can now pursue micro-payments businesses that previously have been cost-prohibitive."
Edit: Better Source and a quote
In theory a regular shareholder could earn this money too, but it's not worthwhile except at scale.
But I doubt anyone other than Vanguard would do this at scale.
I believe the real reason is that Google isn't exactly a commodity. People are used to the brand, the user interface, the web url, and maybe the occasional quality or exact flavor of the search results.
Because it's not a commodity, people don't just instantly change to whichever site pays the most, and because of that there would have to be a large pay difference for customers to make a switch. Users are basically willing to "forfeight" the money they would get using Swagbucks to use Google.
That's not why. They don't charge because it's not lucrative to do so. Charging - however small - would change expectations on SLA, privacy, security, etc.
Most importantly, as everyone on HN knows, they can't charge for access to their platform because the platform isn't the product. You and I are the product.
Finally, Bloomberg should be more careful with their word choice. They are prestigious enough to know that __nothing__ is free. There is always a cost(s) involved. The transaction might not call for an exchange of financial wampum but that does not make it free.
I read the article. It is a synopsis of a paper. The word "free" does not appear in the article, and to my reading the author does not imply "free".
My point is, free or cost zero...neither exits. There is no free. There is no zero cost. Those are myths.
There is always a cost. It might not be tangible (i.e., money) but there is always a cost.
Maybe I'm just overly sensitive as Quora initially got on my bad side when they used to put everything behind a login wall and required accounts with real names.