HNHacker News
TopNewBestAskShowJobs

PeterisP

22,905 karma · joined September 1, 2011

submissionscomments
PeterisP··on Humans have caused 1.5 °C of long-term global warming according to new estimates
In this context money is just a unit of measurement. If we say that we need more of a particular kind of infrastructure and reduce a particular kind of activity, etc, then the discussion requires being able to say how much of those (many!) things and we can quantify all of those in terms of dollars.
PeterisP··on AI makes tech debt more expensive
I'm definitely assuming that they don't limit their training data to what is open source and crawlable.
PeterisP··on A near impossible literacy test Louisiana used to suppress the black vote
That comes from a time/place where it was issued to 100% adult citizens and it was illegal not to have it - i.e. you have a duty to get one when you come of age or become a citizen or your old one expires, and it's a misdemeanor with some fines if you don't, plus quite a few other legal interactions will be simply refused until you get that sorted out.

Now an ID card is a valid option so some people have only the ID card and not a proper passport; but there is an expectation that everyone (who isn't e.g. actively hiding from the authorities as an outlaw) would have a valid ID and if they don't it's acceptable to require that they get one before they can fully interact with the rest of the society e.g. government, banking, driving, owning real estate or cars, any legal contracts such as rent or credit, etc.

PeterisP··on Thought experiments that fray the fabric of space-time
Sure, timing of the events, but infinity kind of breaks it - if external observers don't see someone falling in, then they didn't fall in yet, and if external observers see that falling in takes an infinite time (as in this case), then that is on some sense just a difference in the timing of events - however, from the observer perspective where that thing takes a finite time, they will also get to observe what happens afterwards.
PeterisP··on Thought experiments that fray the fabric of space-time
You can calculate or 'measure' an arbitrary approximation of that ratio by various methods, but calculating all of it takes infinite time, which I don't have and thus can't do it.
PeterisP··on A near impossible literacy test Louisiana used to suppress the black vote
Some time ago every election or referendum simply put a stamp in the passport when voting, but that was before plastic ID cards. Now they have an online verification process before handing you the ballot papers; this also reports your ID for the invalidation of any pre-election votes (e.g. mail-in ballots) elsewhere.
PeterisP··on A near impossible literacy test Louisiana used to suppress the black vote
The key issue and the whole purpose of that question is that also both a. and b. could be considered wrong.

If the person answers A, then the grader can state that this is correct if they like them, or assert that instead B is correct if they don't, so that the test can always provide the desired outcome.

PeterisP··on Do AI detectors work? Students face false cheating accusations
There's the dichotomy of an irresistible force meeting an immovable object - only one of these is possible.

Either there can be an undefeatable AI detector, or an undetectable AI writer, both can't exist in the same universe. And my assumption is that with sufficient advances there could be a fully human-equivalent AI that is not distinguishable from a human in any way, so in that sense being able to detect it will actually never work.

PeterisP··on Do AI detectors work? Students face false cheating accusations
Such an increase can actually be quite feasible; quadrupling the labor spent on final examination would be perhaps a 10% increase for the total labor spent on preparing and teaching a university course, and at university level (unlike earlier schooling) we don't really have a shortage of educators, quite the opposite.
PeterisP··on Show HN: Dead man's switch without reliance on your infra
I'd argue entirely opposite, that a dead man's switch should 100% rely only on someone else's services and should avoid any dependencies on your stuff, as something happening to you is correlated to something happening to things you run or own, and the whole point of such a switch is that it should function properly when e.g. all your stuff burns down or gets confiscated or whatever.
PeterisP··on Show HN: Dead man's switch without reliance on your infra
Sure, but it would be reasonable to assume that most people in this forum won't die broke.
PeterisP··on Show HN: Dead man's switch without reliance on your infra
It's not about it being impossible to cryptographically prove/validate it, but rather about services choosing to not attempt to try to validate it. They generally don't provide such an option, because it's tricky, somewhat manual, has certain costs and risks, and no benefit to the service provider.

If some law prescribes that after following a certain verification process, the operator is required to delete the account, then that legally mandated process would work, but in the absence of such a law literally no process can be sufficient, because the operators can and will choose to ignore it, no matter how reliable it is.

PeterisP··on Who Pays for the Arts?
The percentage of amount paid->amount received is not the appropriate number as it excludes the (very different!) tax rates on various kinds of consumption, however, it is reasonably straightforward to end up with a single number for the purposes of comparison - metrics like the total of all taxes/tarrifs/fees/etc vs total of all production(GDP).
PeterisP··on EU: Definition of "potential terrorists" opens door to broad information-sharing
Radical parties gaining mass support is an indication that the centrist parties which should be 'more reasonable' are deliberately ignoring some major factor which a lot of the voters care about.

Anyone looking at the rise of AfD should also look at the example of Denmark, which some years earlier had also seen a strong rise of radical alt-right parties, but once the centrists switched their stance against immigration, at the next elections the radicals went back down to their rightful 1% or so of votes. That is also an example which shows that indeed it is possible to compete with hate-based politics with actual actionable and long-term viable policies.

Indeed, SPD should instead examine why they themselves are losing votes and consider it their duty to provide some alternative for German voters so that a person can vote against immigration without getting the full neo-nazi package in addition to that.

PeterisP··on I Am Tired of AI
I think that novel writing and reviews are types of writing where potentially AI should eventually surpass human writers, because they have the potential to replace content skillfully tailored to be liked by many people with content that's tailored (perhaps less skillfully) explicitly for a specific very, very, very narrow niche of exactly you and all the things that happen to work for your particular biases.

There seems to be an upcoming wave of adult content products (once again, being on the bleeding edge users of new abilities) based on this principle, as hitting very specific niches/kinks/fetishes can be quite effective in that business, but it should then move on to romance novels and pulp fiction and then, over time, most other genres.

Similarly, good pedagogy, curriculum design and educational content development is all about accurately modeling which exact bits of the content the target audience will/won't know, and explaining the gaps with analogies and context that will work for them (for example, when adapting a textbook for a different country, translation is not sufficient; you'd also need to adapt the content). In that regard, if AI models can make personalized technical writing, then that can be more effective than the best technical writing the most skilled person can make addressed to a broader audience.

PeterisP··on I Am Tired of AI
They definitely try to replace part of the people this way, starting with the areas where it's the easiest, but obviously it will continue to other people as the capabilities improve. A big example is sports journalism, where lots of venues have game summaries that do not involve any human who actually saw the game, but rather software embellishing some narrative from the detailed referee scoring data. Another example is autotranslation of foreign news or rewriting press releases or summarizing company financial 'news' - most publishers will eagerly skip the labor intensive and thus expensive part where journalists go and talk to people, look into old records, etc, if they can get away with that.
PeterisP··on Binance founder 'CZ' leaves prison on Friday
For the economic impact of monetary systems, the main role of currencies is handling credit - handling direct transactions is intuitively the direct application, but the impact of transaction costs ('costs' in the economic theory sense, not only the direct expenses but also any barriers, difficulties, risks, etc) on the economy, while significant, is not as huge as the impact of availability of credit and supply of money.

For example, when considering dollars, having the possibility to detach the dollar from the gold standard was so extremely valuable to the economy that all the possible transaction costs with handling paper or coins are a rounding error compared to that. Enabling fractional reserve banking is an immense effect on the productive output, due to the big increase in productive investment it enables, so it matters a lot whether a monetary system can support that. Historical changes to what metals were used for coins had a huge impact on economy not because of some decrease in transaction costs but because of changes to money supply. Etc.

At it's core, the primary function of finance is (and arguably has historically always been) handling debt, not handling transfers. So evaluating a currency system on the basis of how good it is for transactions is kind of putting the cart ahead of the horse, if the nature of that currency has, as most cryptocurrencies do, a major impact on the money supply (and thus handling debt).

PeterisP··on Is Tor still safe to use?
If someone would do the thing-to-be-detected (e.g. accessing CSAM) every day, then that 0.14% probability of detection turns out to be 40% for a single year (0.9986^365) or 64% over two years, so even that would deanonymize the majority of such people over time.
PeterisP··on Hezbollah hand-held radios detonate across Lebanon, sources say
The existing conventions do not prohibit attacking militants while they are in the middle of civilians, even if they are not doing that as part of some hostage/human shield operation. It may be considered morally not ok, but doing so does not violate any obligation.
PeterisP··on Why Not Comments
Well, that's a problem.
PeterisP··on Why Not Comments
The concept of "make the new code look like the existing code" still applies - in the example you gave, if you need to add examples148-200, and want to do it in a better way, then it would be wrong to do that new way for the new code; either you are willing and able to refactor the previous 147 cases as well (so that the new code matches the existing code, because the existing code was updated), or you keep the existing structure.
PeterisP··on Nobody Cares About Security
I am a bit confused why shifting liability would be linked to maximizing data theft, and why would that data theft be done by some regulatory agencies - can you elaborate?

The liability shift that I had in mind is mostly about immunity from liability for the impersonated person, like, if some criminal defrauds a company by claiming to be Bob, then shifting the liability for that risk (compared to currently common cases in USA) to that company which had lax processes and was defrauded would be various consumer protection mechanisms for things like credit score, preventing that company from trying to collect that money from Bob, preventing them from reporting that Bob owes them money (as he doesn't) and requiring that company to correct any adverse credit reports if they had already made them, etc, various means to ensure that the fraud stays between the fraudster and the defrauded company and doesn't affect the person whose identity was falsely used; and removing the implication that they are somehow responsible if that information (which they aren't legally required to keep secret) is used by someone else.

PeterisP··on Nobody Cares About Security
This is why "self-signed" is a misleading term, as it means both literally self-signed, as in, "we have added root of trust that we control and our devices trust only certificates signed by ourselves, as cryptographically verified", and also "our devices trust any certificate signed by anyone and ignore errors", and doesn't make a distinction between these two very different cases.

Especially for internal server-to-server connections there shouldn't be any security weaknesses in a fully self-signed architecture where the same scripts that deploy the certificates will also deploy the configuration on other servers specifying that this is the only thing that should be trusted.

PeterisP··on Nobody Cares About Security
We are replacing such things, although USA is a decade or so behind the rest of the world due to various legitimate sociopolitical and historical reasons.

In most places worldwide identifiers equivalent to SSNs and passport numbers aren't really treated as financial secrets; they may not be totally public due to certain privacy aspects, but they generally don't result in financial identity theft, that's a fixable problem of certain regions (like USA and a few others). Similarly, moving to proper credit card authentication (chip&pin or wireless chip when card is present, 3dsecure when not, etc) has made many credit card numbers mostly useless for thieves unless accompanied by a more serious compromise.

But all these things above have been implemented only because (and where, and when) the actual companies became financially liable for the consequences - as long as the losses/fraud/etc hit only the users/consumers, there is no motivation to fix anything. Shift the liability to the company which accepts that fundamentally insecure data as good enough, and they'll figure out some way to implement a secure process.

PeterisP··on Nobody Cares About Security
The author raises two major arguments for why the current low level of care is entirely appropriate -

"the prevailing attitude among business leaders is:

Damage to the company’s reputation SOUNDS bad, but (so the thinking goes) it’s really too amorphous to quantify. Plus, many companies in recent memory were the victims of massive cyber attacks, took a hit to their reputation or stock price, but saw it rebound a week later with no other ill effects. (again, that’s the belief. More on this later)

The fines currently in place appear to be lower than the expected cost to improve the company’s security posture."

But where is the counterargument against that? There is no "more on this" in the article, and if those two things are true, then it would be wrong for companies to start caring more, as it's cheaper/more effective to suffer the not-that-bad-really consequences than bear the substantial effort and expense of trying to prevent them.

PeterisP··on Effects of Gen AI on High Skilled Work: Experiments with Software Developers
> Large enterprises generally have only so many business functions.

Well, no, the difference in quantity of business functions can be enormous due to duplication. A small business will have an accounting business function, but a large business may have 57 separate accounting business functions due to having operations in different countries, having subsidiaries and mergers&acquisitions (possible multiple concurrently ongoing ones) where you will merge accountings (multiple!) from the new acquisition into yours, but it has not yet happened.

PeterisP··on I hate Stripe, so I'm going to build my own payment processor
If they think the response from Stripe for fraud/spam/PBL was too harsh, wait until they see how their banking partners (Deutsche+Fargo) will handle that; if they can't even keep up a level of due diligence that's "clean" enough for Stripe, they'll eventually end up owing the whole company to the banks due to contractual penalties and cost of fraud.

A big reason why companies use an outsourced card payment service instead of going directly for a merchant account with banks is the difficulty of handling fraud & spam well, which is horribly expensive unless you have got a major economy of scale.

As a payment processor, your potential risk is larger than your turnover. And while Stripe might freeze part of your incoming funds, in this business you'll need significant upfront capital as collateral - which you'll lose if you're mediocre at handling fraud.

PeterisP··on Anarchy in Sudan has spawned the world’s worst famine in 40 years
Airdropping "tons of food" wouldn't move the needle.

Airdropping thousands of tons of food per day, every day, for years on end would temporarily reduce famine. It wouldn't prevent famine (armed groupings who would gain control over of the airdrops wouldn't necessarily share), and would destroy local farming, and would be horrendously expensive but it's possible (see e.g. Berlin airlift) if someone major really wanted to dedicate all their airforce (again, see e.g. Berlin airlift for what it takes) to that.

PeterisP··on Did your car witness a crime? Bay Area police may be coming for your Tesla
> Perhaps in the urban setting but the majority of this country is not contained within cities.

83% of USA population live in urban areas, and that proportion is still steadily growing. The same trends apply everywhere else in the world as well.

PeterisP··on Las Vegas police could boycott working NFL games over new facial ID policy
It should be impossible to negotiate this with individual policemen - if the state or municipality has the requirement and authority to provide security for something, then the conditions for that should be handled by the government (and then the officials would execute that as part of their ordinary non-negotiable orders of what duties their service requires), and if the government does not do that thing, then police officers should not be involved at all, this should be handled by private security, in which case even if someone from police participates off-duty, they shouldn't be permitted to have uniforms/badges/official authority, as they are not there as representatives of the state but as civilians.

There shouldn't be any middle ground - either the government sends the police to do whatever the government requires, or it does not - the policemen themselves should not get a choice, they exist to execute and enforce the government decisions, not make them.

← PreviousPage 2 of 34Next →