4,767 karma · joined June 16, 2018
<first two letters + last four>@twilio.com
Anyone have a use for banana peels?
But people's biometrics really can change over time, and I don't think there's a clean way out. Back to expensive and inconvenient in-person checks?
https://www.gaudi.ch/OpenTheremin/ will run with an Arduino and it's very satisfying to get better at controlling.
>Is it that I want to have done it? Would I be happy if someone else did it? (credit)
>Is it that I want to be doing it? (achievement/process)
>I want to have a mix. I want to do some things for the experience and some things for the accomplishment. I want to do some easy things and some hard things. Some fun things and some unfun things. Some things just for me and some things for others.
Amit Patel, via https://digitalseams.com/blog/amit-patel-on-making-things
And why formalize on HTTP rather than on a similar protocol over websockets?
1. What is the attester (signer) attesting to, exactly?
This URL example is exactly this problem. And if you're really precise about it, they get less and less useful: "I attest that when I accessed this site at XYZ timestamp, it contained ABC content, and I saw ABC happen in person." or maybe alternatively to get away from the URL control, "I attest that these three non-malicious archives of this URL at this timestamp..."
And 2. Why should I trust the attester?
If you give an agent a budget of $500 to buy a flight, and the airline knows this and bumps your price to $499 even though it will offer the same flight at $300 to someone else, is there harm done? I argued it feels unjust. He said it's totally fair, it's within budget so what's the problem?
Naturally this trends towards a sort of principal-agent problem where the airline is incentivized to bribe your agent for up to $198 to max out your budget (which is a problem if you're not running your own agent).
But for general personalized pricing, there is the same dynamic to posture that you have a limited budget so that companies offer you better prices (regardless of whether you really do or not). This is haggling culture at scale.
I worry about a world trending towards this sort of thing and away from clearly universal prices and wrote about this at the beginning of the year: https://digitalseams.com/blog/the-behavioral-cost-of-persona...)
While herding to the majority of latest Chrome makes his life easier, there really is a very long tail of real users who are not there. I get way too many challenges on my personal laptop running Firefox on Ubuntu (including infinite redirect loops).
There's plenty of microbehavioral analysis we can do that is initially effective but will get bypassed (with GANs being the purest way, or something more domain-specific).
You could imagine a livestream that's permanently published somewhere. But the verification of the livestream takes longer than reading the piece itself (and is itself vulnerable to faking).
Personally I think it comes back to something like writing under your real name - staking your reputation - as the most trustworthy indicator. At least people in your circles can trust you.
I wrote about it last year: https://digitalseams.com/blog/what-birdsong-and-backends-can...
https://www.techtimes.com/articles/320266/20260712/anthropic...
I'd read the confidential computing post! (used to work in this space myself)
One challenge is that it takes repetitions to get good enough that you can even bring your ideas to life, and many people don't push through this (Ira Glass "taste gap").
Full interviews here: https://digitalseams.com/blog/making-things-interview-series
>Every row has the same name: " Dene Hemen! 5K Lira Bonusunu Yakala" — Turkish for "Try it now! Grab the 5,000 Lira bonus." Casino spam.
>Each registration fired a verification email. 55K signups = 55K attempted sends to fake addresses — the kind of bounce storm that gets a sending domain blacklisted.
I'd be surprised if the email addresses were entirely fake - it doesn't make sense to advertise to just the website developer. It seems more likely that this spammer is targeting real email addresses from some dump (QQ is especially prone to this, since you can target random QQ ID numbers and get a lot higher of a hit rate).
While I understand that not every business wants automation on their site, I know some businesses are totally open to it. But from a technical perspective, it's very difficult to allow well-behaved browser automation while still blocking abusive bots. Web Bot Auth gives website owners / security vendors a lightweight way to allow providers like Intuned.
(I work on the Web Bot Auth implementation for Stytch, now a part of Twilio: https://stytch.com/blog/stytch-supports-web-bot-auth/ )
But since late 2024 into 2025, meetups are extremely back in fashion here. Every day of the calendar has multiple meetups and it's impossible to avoid conflicts, so attendance rate can vary wildly.
It looks like a straightforward ToS violation to me as well. I guess it's another "ask forgiveness, not permission" move.
I got some really nice steaks for free and the delivery actually arrived via motorbike in 10 minutes. They must have had delivery drivers waiting with their own inventory or something. Anyways, the VC funding dried up and the company was gone a few months later.
But even if not, there's still value in raising the barrier to entry. For example, you can buy 1000 reCaptcha solves for $1-2 from various captcha-solver services. And yet that $0.001-per-request fee does discourage mass-scale bot attacks.