HNHacker News
TopNewBestAskShowJobs

Kalium

11,257 karma · joined February 24, 2011

[ my public key: https://keybase.io/kalium; my proof: https://keybase.io/kalium/sigs/DsdmC8-Y50DPulIeuAi3rH4cPh075xGNt3whzETU-PI ]
submissionscomments
Kalium··on Delta Dental says data breach exposed info of 7M people
For a long time, payment processors in the US would charge more to offer tokenization services. Cost-conscious companies with an eye on their unit economics reacted in predictable ways.
Kalium··on Fast Fashion Casino
Pockets are one of those niches where expressed and revealed preferences collide in ways that defy memeification.

The popular imagination holds the idea that basically any garment can have good, functional, high-quality pockets added to it without consequence. Unfortunately, that's not true. For a common example, you can't just slap good pockets on close-fitting women's jeans. Good pockets need lining and room in the cut to expand. These in turn mean extra cloth. a looser fit, and lots of extra stitching, likely coupled with a higher price. Some of this can be mitigated by using more elastic-heavy material, which comes with a major drop in durability.

How many women are looking to pay a higher price for a baggy butt in exchange for pockets? For those that are, the products exist today. Carhartt happily offers such items for $50-$70. Meanwhile, Shein sells their pieces for $10-$15. Bear in mind the Carhartts will almost certainly last longer than four or five Shein pieces.

I can think of several very high quality denim brands that do work more fashionable than Carhartt. Of course, they charge more than $50 a pair.

In its simplest DIY expression, you can sew a patch pocket on a dress. If you're not very careful in both dress cut and pocket location, the first time you put your phone in your new pocket you will completely wreck the lines of the dress.

Of course, when you're paying $15 a piece you don't expect it to last long. So you buy several. This, I suspect, is where a lot of the pink tax in clothing lies.

Kalium··on Language and Poverty
I suspect this is why "post-scarcity" is generally used to describe a state of affairs that does not currently exist, such as the idyllic Federation in Star Trek. In this context it was used to describe a society fundamentally different in significant ways from any past or present human one.

I don't know if I agree that post-scarcity cannot exist. I know that imagining a way to get there is very challenging. Knowing that scarcity is real certainly informs my politics, though.

Kalium··on Language and Poverty
I believe you may be using a vernacular definition where others are using a technical definition from economics.

In this context "scarcity" does not mean "There is not enough stuff", though that can be implied. It means there is a fundamentally limited amount of stuff and the aggregate demand is greater than the aggregate supply.

Given that the demand for resources is functionally infinite, I think this is basically accurate. Your objection to the existence of rich people is an objection to part of the aggregate demand, rather than to the description of resources as scarce.

Kalium··on Google Drive misplaces months' worth of customer data
That's an excellent description of a basic diffing tool.
Kalium··on Cisco aids Ukraine defense with modified switches to counter Russian attacks
High security development practices will, as you wisely say, go a very long way. That is not quite the same as some kind of zero-vulnerability "secure" system, however.

No system involving humans is, or ever can be, perfectly secure. At best you can make it uneconomic to attack the computerized parts of the system through networks. You've touched on a number of ways to do this, which are known and understood in the commercial world as both feasible and expensive. This is why Common Criteria has a spectrum of evaluation levels... and even EAL7 does not offer any kind of guarantee of zero vulnerabilities.

Meanwhile, adversaries can and will investigate if their goals can be achieved through human attacks or disruption. There's no need to devote extensive resources to breaking into a system if a carefully placed bomb can produce the same goal, after all.

As you say, this task is by no means impossible. How to go about it is well understood. It's merely very expensive.

Kalium··on Cisco aids Ukraine defense with modified switches to counter Russian attacks
It's a good idea! I like where your head is at.

Apollo and other historic moonshot programs were fundamentally striving to match some set of fixed natural forces with human ingenuity. The conditions to be met and overcome were measurable and knowable. They were natural-world challenges, bristling with natural-world problems. Vacuum, radiation, lunar regolith. The sound barrier, the Polio virus, and more.

Unfortunately, this is in sharp contrast to the challenges of security. Information security is an adversarial, human-centered enterprise. The forces with which we contend, armed with human ingenuity, are themselves armed with the same. It becomes a question of resources and economics. Even the cryptography on which so much relies is ultimately a question of how much breaking it is worth. If we are willing to spend enough, we can probably make it too expensive to successfully attack a system.

Plus, we know that the weakest leak in any system is generally the humans involved.

With all this in mind, we cannot possibly expect to build systems with zero vulnerabilities. It's not a moonshotable goal. What we can do - and what a mature security program will help you do - is plan for detecting, containing, mitigating, and recovering from attacks.

Kalium··on Nothing's iMessage app was a security catastrophe, taken down in 24 hours
One of the counterintuitive things I've learned is that "security is everyone's job" is one of the worst possible scenarios.

First, the vast majority of people are not equipped to find or address major security issues well. Unless you have specialists integrated in the right places this means everyone's likely to be bad at the security part of their job and ill-equipped to notice.

Second, this means conflicts of interest everywhere. When you have a dedicated security org, you have people whose job it is to catch issues, hold things up, and generally make sure things get fixed. Without that, you have a bunch of people who have to choose between the possibility of a security event they don't understand and the certainty of blowing a deadline.

Third, security being everyone's job almost certainly means accountability is broken. Consequences will likely fall on some junior employee who might be directly accountable for an issue, but the huge org around them that did not enable them to succeed go unaffected.

You need specialists, an org to enable them, and an enterprise-wide apparatus to support a strong security process.

Kalium··on Nothing's iMessage app was a security catastrophe, taken down in 24 hours
This has the overall feeling of something developed by a team where leadership sincerely believes that security is everyone's job. Because it's everyone's job and they hire good people, they don't need specialists.

When there are deadlines to hit, average quality non-specialist management will generally prioritize keeping promises to leadership over meeting security requirements. It takes a rare manager with a strong grasp of the importance of security to stand up and tell their VP "We're not shipping, the security isn't there".

So how do these managers get there? They cut the corners that don't matter and hit the ship date. It gets them the promotion.

Kalium··on Meta disbanded its Responsible AI team
One key question is if the teams are being effective referees or just people titled "referee".

If it's the latter, then getting rid of them does not seem like a loss.

Kalium··on Google sues two men who weaponized DMCA notices to crush competition
Counter-notice and it goes to court, I believe.
Kalium··on Beg Bounties (2021)
The issue here is that these people aren't providing value. Further, engaging with them as serious and sincere costs in time and energy. That's expensive when there's no payoff. From my own experiences, beg bounties reliably do not have findings of a useful quality and the begging approach is a very strong signal that the juice will not be worth the squeeze.

The piece is gatekeeping in the same way the spam filters we all use are gatekeeping. There's always stuff we want to keep on the far side of our filters. Beg bounties are among them for many.

Kalium··on We're sorry we created the Torment Nexus
It's been my experience that spending a lot of time with cautionary tales spun mostly out of imagination teaches people that the consequences of things can be predicted in the same way one might predict the course of a story. This is demonstrably an inaccurate assessment of human ability to consistently predict the future. Stories tend to adhere to specific patterns that make them comprehensible. Reality is under no such obligations.

The issue arises when people try to shape the future and one another in ways that depend on these faulty predictions. Before long, you wind up with people who essentially believe that Cambridge Analytica was easily predictable from the invention of TCP/IP and thus that they (or we) are responsible for averting it. That false assurance is cringe, and it seems to come about in no small part from confusing the conformity of narrative fiction for messy reality.

Kalium··on We're sorry we created the Torment Nexus
On the contrary, they generally teach people to be an entirely different kind of cringe.
Kalium··on Banning E2EE is stupid
One thing to bear in mind is that any technical lawful intercept capability is also a technical intercept capability for a hostile intelligence agency. Note that "hostile" and "foreign" are not always the same thing.

With this in mind, I think making the tools resistant to abuse is a highly desirable design goal, up there with making the detection of abuse very easy.

Kalium··on Banning E2EE is stupid
Are we sure it's complex? Or is it portrayed as complex for political reasons?

So far we've seen a lot of assertions that encryption is a major hazard to public safety, mostly from groups with a long history of abusing access to wiretaps. We've seen precious little evidence to support this. The other group claims that encryption enhances privacy and pushed back against abuse. There's plenty of evidence to support this.

More than once in my life, I've seen people attempt to advance an unsupported position by claiming it's very complex. Sometimes this is true and they just need time to support their points. Sometimes it's completely untrue, and the idea is to leave uninformed onlookers with the impression of complexity that needs to be negotiated.

How sure are we that this issue is genuinely very complex, versus the real possibility of false complexity in an effort to confuse you and me?

Kalium··on Banning E2EE is stupid
Basically, I need law enforcement to prove they're not full of shit. Law enforcement and intelligence systems have a long and ugly history of abusing easy access to private information. They also have a long history of working around technical privacy protections at need, in pasts both distant and very recent.

Until then, I think we should give their claims all the weight of all the evidence they have provided. Or failed to provide.

Kalium··on Banning E2EE is stupid
At the risk of being very directly contrarian: is it?

Is it actually getting harder for law enforcement? Do we have evidence of E2EE harming cases, hurting conviction rates, or similar? At this point in time law enforcement has been routinely dealing with and lawfully overcoming encryption for several decades. Encryption is no longer a novelty law enforcement has no idea how to deal with.

I understand that law enforcement officers may sincerely believe that encryption makes their jobs more difficult and thus the public less secure. Since they are public officials, I am happy to accept their claims as truth. I just need to see supporting evidence. At that point we can begin to weight public safety against privacy. Until then, I can only consider a demonstrable loss of privacy against a purely hypothetical impairment of law enforcement functionality.

Speaking only and solely for myself, I in no way expect people with governing responsibility to ignore end to end encryption. I do expect them to ask questions when people with a demonstrated capacity to function in the presence of E2EE claim it is making their jobs too difficult.

Kalium··on Seeing like a bank
Trial and error takes time. Potentially a great deal of time. A motivated fraudster will likely get caught and stopped several times along the way if they're attacking a particular bank.

It's worth bearing in mind that most financially motivated criminals are after easy marks. If you're too hard or expensive to hit, they'll find another target. If you're seeing like a bank, that's a victory and the protocols are doing their job by reducing fraud.

Kalium··on Seeing like a bank
Pick any two small businesses in the same niche. Grow them for three or four decades. How identical do you think their evolved business practices will be?

My very very naive take is that they will have had to solve similar problems over time and will have practices and systems that work analogously. I would bet they will probably not use identical software packages or data structures and will have had little reason to structure their internal operations around someone else's standards. This is especially likely to be true of standards that came along well after the companies already solved the problems the standards are aimed at.

Kalium··on Seeing like a bank
All the bank knows is that they tried to get to know someone as required and that person gave them bad info. This is either intentional or unintentional.

Now, they could go in for a high-touch customer care process, but that has drawbacks. It's expensive. Every person intentionally providing incorrect information is going to claim it's unintentional, meaning that this high-touch customer care process is going to have to double as a strong anti-fraud screening. From the bank's perspective, this is failure-prone and needlessly risky.

If we're seeing like a customer, this is a shitty experience that they can't understand, negotiate, or do anything about. They're being punished and don't know why. If we're seeing like a bank, it's a way to control a risk for a known price.

Kalium··on Why banks are suddenly closing down customer accounts
> “And in this scenario, you can’t really negotiate,” he said. “You aren’t talking with a person who has the power to tell you what went wrong and what didn’t go wrong.”

I find this one of the most telling bits of this entire article. It says the quiet part out loud - people are often not looking purely to understand. People want information so they can negotiate, reason, or argue with the decisions.

Kalium··on In 1886, the US commissioned watercolor paintings of every known fruit (2019)
This project wasn't undertaken for artistic reasons. It was done so that the US government had records and depictions of domestic produce that could be used in efforts to promote trade. Watercolors were almost certainly the best available option at the time.

Today it would be a waste of money. We have digital cameras and pretty good records of what produce American farmers grow without hiring several dozen artists to traipse around for years.

Kalium··on How America moves homeless people around the country
I don't know if you're aware of this, but the United States Postal Service is self-funding. My understanding is that they are required to be. They do not receive a yearly budget from Congress.

This means questions like "How will this be paid for?" are not idle distractions to derail good ideas with impossible perfection. They are key obstacles to be overcome. To have USPS run a bank as a non-self-funding public service would mean they would have to go to Congress to raise prices to subsidize it. This is always a political process, and I imagine the cost of things like stamps falls more on the poor than on the rich.

Alternatively, you could find a way to rework the entire legal and financial infrastructure of the USPS so that it does run on direct federal funding. This is, to put it mildly, a lot of work.

Whether or not it's a good idea depends in no small part on what your precise goals are and how you expect to achieve them. If your goal is for poor people to have access to basic banking services, then the Bank On program and local credit unions might be better options for many people. If your goal is for poor people to have access to credit, then a postal bank is probably not a good choice unless you want lots of poor people having their credit wrecked by a public service.

Generally the idea is to have a public bank with the postal system being a convenient vehicle for that, rather than some deep and fundamental ties between post offices and banks in the modern world. The postal service in the US might not be as ideal a vehicle as it is in some other places.

In summary, a postal bank that can pay for itself is far more likely to get set up and deployed widely. This is an important point because of how USPS is regulated.

Kalium··on Cloudflare API Down
Isn't that Fossil?

https://fossil-scm.org/home SCM, bug tracker, wiki...

Kalium··on How America moves homeless people around the country
It cost money to run and the customer base pulled its funds in favor of better choices.

The goal of a postal bank is often framed in terms of a source of revenue for the USPS. Examples include in this very thread. If there's no expectation of net-positive revenue, then there needs to be a different justification for why the post office should spend money to offer everyone banking service inevitably inferior to the private sector. Plus, now you have all the politics that come with a subsidized service and paying for it. If it can pay for itself, it's much simpler.

Postal banking is often advanced as an idea for a public service that will eat Wall Street's lunch to the benefit of all. We should be at least a bit skeptical of the unvarnished optimism of that. Further, I think that if we're going to seriously discuss the topic we need to grapple seriously with why the US doesn't have one anymore.

Kalium··on How America moves homeless people around the country
Example 3: The USA.

It was subsequently shut down because it couldn't compete with private banks.

Kalium··on How America moves homeless people around the country
Can you help me understand how distributed financial systems enable people in dire need of housing and supportive social services, who often with poor to zero access to legal infrastructure, get back on their feet when they are often struggling with mental health or substance abuse problems? Bonus points for an explanation that helps in the context of high housing costs, housing supply shortages, and the people in question experiencing low incomes.
Kalium··on Sodium batteries offer an alternative to tricky lithium
Yes. You are correct.

Thankfully kitchen sodium is in compound form, and thus not likely to react violently with water. In this context, the properties of pure metallic sodium are relevant because it would need to be handled in manufacturing. Kitchen salt is more commonly mined or extracted, requiring minimal to no handling of pure metallic sodium.

I hope this helps clarify any misunderstandings.

Kalium··on Ask HN: What happened to hackerspaces?
Speaking only for myself, it's very hard to find people who treat community, sharing, and collective action as things to engage with regularly rather than as a way to get access to tools for cheap. It can be exceptionally stressful and anxiety-inducing to manage shared resources under those conditions.

It should not be a surprise that some people prefer to not deal with the idea of hackerspace-as-community and seek their community elsewhere.

← PreviousPage 4 of 34Next →