HNHacker News
TopNewBestAskShowJobs

clearf

69 karma · joined March 31, 2010

[ my public key: https://keybase.io/clearf; my proof: https://keybase.io/clearf/sigs/wCKHJQh2nnVCG59TKMrzTEBX2_ieGFp9BZWf3fU8I2s ]
submissionscomments
clearf··on Attack campaign involving stolen OAuth tokens issued to third-party integrators
How _lucky_ that github itself was the subject of the attack in npm.

Unless I'm missing something, this attack could have gone unnoticed for a long time (it would be hard for someone to connect a random breach in their infrastructure to an oauth intrusion affecting two of their service providers).

clearf··on We Shouldn’t Be Surprised at the Theranos Fraud
An interesting side note about this story is the homogeneity and lack of relevant background among Theranos's board of directors. All the outside directors were white, prestigious (former generals, senators, cabinet secretaries, etc) and relatively old. Research shows that homogenous groups are less likely to challenge each other.

My coauthor and I wrote about this in our book Meltdown (Published by Penguin Press in in March). We drew on Carreyrou's excellent reporting and some pretty interesting research about how team diversity affects decision making.

clearf··on DeepMind and Blizzard to release StarCraft II as an AI research environment
I'm not sure that accuracy/HP are the right things to tweak. I've always wanted to be "surprised," in an unscripted way, by AI enemies in FPS and RTS games.
clearf··on Startup Playbook
It's an interesting point, but I'm wondering how to unpack it.

"If Twitter was open... a dozen people innovating on it..."

Though not 100% independent of their funding model (loss-aversion bias might lead us to conclude that big companies take less risk), presumably Twitter has at least a dozen people trying to innovate on it?

They may not be doing what [parts of] the community wants, but that's not quite the same thing as not innovating.

clearf··on Major Flaw in Android Phones Would Let Hackers in with Just a Text
> Someone could probably also create a video with a payload to hot patch libstagefright.

This is brilliant. Assuming that it doesn't cause further problems.

clearf··on Major Flaw in Android Phones Would Let Hackers in with Just a Text
Independent of the question if "everyone" is owned is the interesting (and scary) possibility that specific people have been (or will be) targeted.
clearf··on How to Read in College
The comments here remind me a little of Pierre Bayard's delightful(ly) postmodern monograph, _How to Talk about Books You Haven't Read_ [0].

It's an entertaining read.

[0] http://www.amazon.com/Talk-About-Books-Havent-Read-ebook/dp/...

clearf··on YC Backs Portable Coffee Stand Called Wheelys (YC S15) to Take on Starbucks
One thought is that we could reframe the question (as e.g., Sweden has done) and work to increasing gender equality.

If the starting point is recognizing that people have kids and it takes time to care for them, and both parents have that right and obligation.

From there, one could devise policies that encourage BOTH men and women to take parental leave and invest in high-quality childcare for when that parental leave is over.

clearf··on YC Backs Portable Coffee Stand Called Wheelys (YC S15) to Take on Starbucks
I believe it's a licensing arrangement. Those locations often buy and license Starbucks coffee (though often not their baked goods), but are not run by Starbucks. e.g., Barnes and Nobel, Safeway.
clearf··on Philae comet could be home to alien life
The rebuttal: http://www.theguardian.com/science/across-the-universe/2015/...
clearf··on Goldman Sachs' $38MM options trading error [pdf]
It's a pretty interesting sequence of events that turned on configuration errors and humans overriding automated pauses (what the Order calls circuit breakers) without really understanding what was going on.
clearf··on How Is Critical Life or Death Software Tested?
Make sure they're well separated! c.f. http://www.wsj.com/articles/SB100014240527487033765045754919...
clearf··on Why the Flash Crash Really Matters
What a great question. I do think that, generally speaking, confidence that the markets are stable is good for an economy, and these sorts of events undermine that confidence.

It's important not to understate the cost of failure in these markets. A firm might go bankrupt and have to lay off real people if caught on the wrong side of such an event.

I also think that there is a direct connection between events like the Flash Crash and things like Nasdaq's mishandling of the Facebook IPO, which, again, had real costs in terms of time and money. Both emerge, I would argue, from a similar flavor of complexity.

I'm struggling for an analogy to show that it matters. Maybe it's a little like Target's website going down. It's not Quality, in a Zen and the Art of Motorcycle Maintenance way, even if it's only down for a short time, and the consequences were "only lost orders." Compelling?

clearf··on Why the Flash Crash Really Matters
I have heard Gregg Berman speak, though I hadn't read this speech until skimming it just now. I do think that there is, generally speaking, a heartfelt desire to develop the tools and data needed to gain insights that Berman is talking about.

I think there are two challenges to unpack. One, though I wasn't insinuating it, I could have been. I do believe that regulators are more lawyers than physicists. Berman is the exception rather than the rule.

Two, Berman, in particular, makes a fundamental error that I think is very easy to make. There's a difference between "complex" in the sense that something has a lot of parts, and interactively complex in the sense that parts of a system are fundamentally unknowable and it can experience wild and unexpected dynamics. I think Berman doesn't distinguish between those two types of systems (repeated analogies to cell phones give some indication of his thinking), and more generally, regulators don't understand the aggregate cost of complexity.

In my view, things like Midas are orthogonal to some deeper issues facing the markets. Regulators have created a quasi-competitive market that breeds this sort of interactive complexity. Then, when something goes wrong, they rely on punishment and enforcement actions [1] to target individual firms that have made "mistakes." This not only does not address root causes, it creates a culture of silence around technology risk issues within firms and across the industry. I've written more about this here: http://harvardkennedyschoolreview.com/preventing-crashes-les...

[1] See, e.g., http://www.sec.gov/litigation/admin/2013/34-70694.pdf and http://www.sec.gov/litigation/admin/2013/34-69655.pdf

clearf··on Why the Flash Crash Really Matters
One of the authors here. I think that's a pretty good summary. And, yes, I agree that there are ways to introduce damping into many such systems and some has been added since the Crash, as another comment points out.

I think it would be great if the SEC believed that that was their mandate. Unfortunately, I think that is predicated on much more sophisticated and nuanced understand of the dynamics of the markets than regulators typically have.

The claim in the recent CFTC's Complaint that alleged market manipulator Navinder Sarao directly contributed to the crash is only one example of this. If one guy can cause a Flash Crash, there is a bigger problem with the structure of the markets.

clearf··on Researchers work to counter a new class of coffee shop hackers
If you could modify the driver, you may not need to rely on the subtlety of the emissions patterns...
clearf··on Hyundai’s 2015 Genesis will automatically brake for speed cameras
Do you have a reference to this? I've heard this argument before, but haven't been able to find any hard stats.
clearf··on Introducing Paper
Are you sure you're the mark (i.e., their target audience)?
clearf··on Twitter Hacking and the Stock Market
Full disclosure: this is my article, but my hope is that it's interesting to the community here, and I'm really interested in people's feedback on what we got right and what we missed.
clearf··on Man tunnels into GameStop, steals games
I assumed it was an SSH tunnel, and wondered if game stop had ISOs on a server and burn-on-demand business.
clearf··on Coveting possessions is unhealthy.
I've started trying to enforce conservation of clothing. If I acquire a free shirt, or have the "need" to buy something like a jacket, I will eject an older jacket from my inventory. It's a nice way to try to combat the endowment effect.

I've known for about a year that I was going to move November 2010, so that made me take a hard look at my possessions and what I had, and caused me to get rid of a lot. I've just moved with a suitcase and a few boxes, plus some boxes of books and camping stuff. Other than some electronics, I haven't taken any of my clothes out of the boxes, and I haven't needed them yet. I'm thinking about chucking them.

clearf··on 1 Billion Paid out through the Apple App Store - Really?
I suspect that people do not write an app hoping to be the "average" app, but are instead hoping to be a breakout app that becomes very popular. It seems like an example of superiority bias.