Facebook's Novi wallet hits trouble as two top engineers depart
financefeeds.com
financefeeds.com
I got to know Riyaz more after we graduated and was impressed not just by his technical chops but also by how humble and grounded he is. I can't think of a better pick to serve as CTO, a role which requires not just technical acumen and mental agility, but also the ability to work with a wide variety of stakeholders.
I've always been bearish on crypto/blockchain but seeing Riyaz make the jump is making me think twice. A16Z made a great hire here.
Plenty of scams and irrationality too of course.
Things like their on-chain language not being Turing complete so they can scale it better than the Ethereum disaster.
Most of the new blockchains constantly being spun up are little more than schemes to make the founders rich. Even if the stacks are technically cleaner and nicer to work with, it's really hard to imagine any new blockchain bringing anything significant enough to the table to overcome network effects of established leaders. Specifically be wary of coins like Solana, Cardano, and maybe even Ethereum, which Gary Gensler of the SEC has indicated are probably all unregistered securities and he looks to be gearing up to come after them.
I'm in the bitcoin only, simple, rock solid foundation with complexity built in higher layers camp, so I'll mention a couple of interesting things going on.
The taproot softfork was recently approved by the network and will go live on mainnet next month. Read up here, https://blog.keys.casa/what-is-taproot-bitcoin-upgrade/.
The lightning network is starting to get some real momentum after years of development. People are using it in unexpected ways, like building an e2e encrypted chat network (https://sphinx.chat/) that piggybacks on the network, or the LNURL-auth protocol (https://xn--57h.bigsun.xyz/lnurl-auth.html) that allows websites to provide persistent user accounts that are authenticated with a user's lightning wallet and require no other personal information. There's recently been some proposals (e.g. https://github.com/JohnLaw2/btc-iids/blob/main/iids14.pdf) to do some magic to stuff a truly massive amount of scaling within the limited bitcoin blocksize.
Protocol changes needed for trustless drivechains/sidechains seems to be gaining traction, https://github.com/bitcoin/bips/blob/master/bip-0300.mediawi.... The Rootstock sidechain will potentially bring the ethereum virtual machine to bitcoin as a sidechain.
I know Ethereum also has some interesting layer 2 work, but I'm not as familiar with what's happening since I don't personally buy into the fat, complex base layer approach, the much more centralized nature of the network and development, nor the planned transition to proof of stake.
Some of those students were absurdly talented.
I've never met a higher density of talented individuals in my life.
Money is an economics and societal problem (it's about trust, isn't it, trust that pieces of paper with numbers on them are worth something), not a tech problem, so software engineering expertise alone isn't enough. IMO.
Gimme a break
--> solve the problem
/
see a problem
\
--> exploit the problemCrypto is more like a honeypot for the incompetent, ideologically delusional and/or pathologically greedy. (Which explains why certain FB executives are still running this doomed Libra/Diem/whatever project. They might do more harm somewhere else.)
All you really need to secure a blockchain is a number of parties who are not likely to collude. The original idea was huge numbers of miners using spare CPU time. There's a famous picture of the top 5 Bitcoin mine owners in China, who together had well over 51% of the hash power, all on the same stage, talking about what they, as a group, intended to do. That was not the plan.
The "smart contract" system was botched. Smart contracts should have been something like decision tables, which can be checked exhaustively. But no, they had to put in a bytecode interpreter, become Turing complete, and dig themselves into an expensively bug-ridden hole.
Incidentally, I suspect that the SEC's hammer is about to come down on the "metaverse" NFT people. Back in 2018, the SEC brought the hammer down on the ICO people, by prosecuting the worst of the worst and sending the rest of them letters saying "please explain to them why this isn't a security offering". Suddenly most of the ICOs disappeared.
What we're seeing now are schemes where people are selling NFTs which represent virtual land in virtual worlds not yet built. I've seen three of those in the last week. That's a security offering under the Howey test. If you sell an NFT for something that already exists, that's one thing. If you use NFT sales to fund the creation of something, you're selling shares in a common enterprise run by someone else. That's a security.
This metaverse stuff irks me because I'm into virtual world technology, and the make-money-fast crowd is giving metaverses a bad name by not actually building good virtual worlds. (Go visit Decentraland, which, by the way, only has 200-300 concurrent users. It makes Facebook Horizon look good.) Or, in too many case, building anything at all beyond the money-collection NFT system.
Well, possible, I guess. It could be exciting!
Or just believe that technology is inevitable, and you might as well be the one building it.
You might think that way, and consciousness about the greater effects of technology on the world are coming into focus, but there are still plenty of people who don't see it that way at all. Or they don't care so much and just want a paycheck.
It's harder to get young liberals in oil, finance and defense, yet those industries still have plenty of talented people working for them.
A pile of Libra/Diem/Novi people have left. I think it's less fear of being hauled up in front of the Senate, and just being sick of spending their lives in development hell. Even the original instigator of Libra, Morgan Beller, left in late 2020.
The last attempt to get permission to do Diem was earlier this year, when they wanted to do a US dollar stablecoin with an actual bank (Silvergate) holding the backing. But a consumer stablecoin that's meant to serve as money in society was still too much to allow, particularly from Facebook. So Novi is now scouting around for other stablecoins to use in its wallet software.
This is assuming a significant number of users of Facebook-owned apps want to use Facebook for payments, which is unclear. Messenger Pay/Facebook Pay has existed since 2015 and still has negligible volume as a percentage of the FB userbase.
Or also if the project has 10 engineers, and the first is the lead who knows everything and the second one is the one who knows deeply about some real important dependency it could suck - losing 20% of your engineers on a project is bad enough, but the two most important ones comprising that 20% could derail a project.
I mean my private data is already passed around when I use Visa/MasterCard. I am already raped by forced conversion fees when using PayPal (basically additional 3% penalty for anyone not based in USA). The customer support and merchant protection is already non-existent with those options and security can only be described as a complete joke (the whole "carding industry" merchants are forced to pay for due to biased charge back process).
I trust Facebook to get those things much better. I think their track record on privacy is way better as well. I hope they can keep the project running and compete with dinosaurs of today payment processing/credit card industry.
“Wait no, big companies should have redundant employees!”
> only two of them actually do any work
"These two were clearly non-evil developers, and frankly we are looking forward to returning to alignment with our core values of insularity, dark patterns, and subjective ethics."
I'm not saying you owe $BigCo better, but rather that HN threads are good when they're specific and unpredictable, and bad when they're generic and predictable. Here are a couple of heuristics that I like to go by:
https://hn.algolia.com/?dateRange=all&page=0&prefix=false&so...
https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sor...
https://news.ycombinator.com/newsguidelines.html
We detached this subthread from https://news.ycombinator.com/item?id=28846699.
I almost wonder if FB might litigate to stop the move.
One famous argument about why SV was special is that its because California judges utterly despise non-competes and non-competes-alike. I believe they're at least, in some form, unenforcable.
> One famous argument about why SV was special is that its because California judges utterly despise non-competes and non-competes-alike. I believe they're at least, in some form, unenforcable.
They absolutely can; it just doesn't have to involve non-competes. It wouldn't surprise me if they trump up an accusation of IP theft, or more effectively, if they happen to hit the lottery and find an audit trail suggesting exfiltration of data prior to the departure.
I'm not saying they did this, but I am saying it wouldn't surprise me if Facebook tried to build a case around it, if only to slow a16z down a bit while Facebook recovers.
The California Business and Professions Code section 16600 states that “every contract by which anyone is restrained from engaging in a lawful profession, trade, or business of any kind is to that extent void.”
What you're saying might be true about the personal opinion of judges; I have no knowledge of that either way. But the fact of the matter is that state law makes non-competes void in employment contracts.
That doesn't mean you can take your company's IP with you, however, as we've seen happen in other high-profile cases, like the engineer who went to Uber with a bunch of tech stolen from his previous self-driving car company: https://www.nytimes.com/2017/05/30/technology/uber-anthony-l... "Uber Fires Former Google Engineer at Heart of Self-Driving Dispute".
But general knowledge of cryptography and blockchain primitives is not that sort of IP, unless the company has some truly novel cryptographic construction, or the engineers in question are trying to take code with them – I'm sure they're smarter than that. Besides, blockchain code for one project wouldn't necessarily be useful for an entirely different project unless it was an almost exact duplicate. Lastly, for blockchains to succeed they likely need to be open source or at least shared-source; no one will trust a closed-source, single-party controlled blockchain. There's no point in using the technology that way: you might as well just have a ledger in a database. So any successful blockchain tech will end up being open source, and there would be strong indications of copying unless the people working on it make a massive effort to obfuscate and rewrite.
Let me put it a different way: if you had the source code for AWS's S3 or DynamoDB, they wouldn't be of any use to you. They're so complex and proprietary that if you wanted to form a company to offer competing services, you'd be better off and would get a product to market faster by building the functionality from the ground up (unless you could somehow take the entire team that has expertise with the existing software with you). The source would probably have value for bug-bounty hunters and blackhat hackers, but someone wanting to build similar services would be better off starting from scratch with the latest platforms (e.g. Rust) and programming/validation techniques.
Very specialized cutting-edge areas like self-driving cars and computer vision that have advanced algorithms and machine learning are exceptions. I think blockchain tech is well enough understood that it's past that stage, except perhaps for complex smart contracts, especially ones that involve multiple blockchains, and maybe advances to speed up network transaction speed.
I have no blockchain expertise whatsoever, but I'm pretty sure I could build a cryptocurrency from scratch from first principles given my existing knowledge of cryptographic primitives, and having skimmed Satoshi's original whitepaper and read casually on the topic. There's probably some fine-tuning magic in getting a few parameters right (like block size, difficulty, whether to be deflationary, etc.) but the basic structure of blockchain tech is pretty well understood by this point by people interested in the technology, even casually interested folks like myself. You submit a transaction for publication onto the blockchain and offer a fee for a miner to include it in their block. (How the network propagates these requests effectively peer-to-peer I'm not entirely sure, but I imagine that the wallet clients have hardcoded seed servers that they use to discover others for broadcast, after which candidate blocks move peer to peer across the network. There may be discovery techniques similar to other P2P networks.) So-called full nodes probably discover and maintain connections to a suite of other full nodes, which they use to broadcast transactions and candidate blocks across the network.
A miner successfully cracks the hash for the next block, based on the current difficulty level (set by time since last block), and includes all the pending transactions they know about that fit into the block (limited by block size). The pending transactions are cryptographically validated by their respective wallet public key signatures. You'll need to get that signature validation just right to make sure it's validating every input. Pending transactions include an operation code instructing what operation should be performed: transfer funds to another wallet, transfer funds to another wallet given N out of M signatures from other identities, and so on. More advanced blockchains than BTC have sophisticated programming models with many operations to make "smart contracts"possible involving multiple actors, but you don't need that complexity for a basic working network that can move blockchain currency. Bitcoin has basic operations and multi-signature transactions; Ethereum has a fully Turing-complete programming model, to enable its smart contracts and sophisticated constructs like the DAO. To prevent abuse and infinite loops you have to "pay" for the amount of computational power your transaction/contract uses based on its complexity, and also set a maximum number of operations it will perform before stopping (and you still have to pay for its execution if that happens).
If I was truly going to implement a cryptocurrency from scratch I'd probably start either with Satoshi's original code as a reference minimal implementation, and compare it with the current mainstream BTC clients (which have fixed bugs etc. since then). That's all open source, then adjust as necessary to meet your goals.