HNHacker News
TopNewBestAskShowJobs

everfree

1,688 karma · joined December 11, 2015

submissionscomments
everfree··on Global high-performance proof-of-stake blockchain with erasure coding
I think it would be much easier for e.g. state actors to take control of a few of the world's PoW mining locations than to compromise a bunch of people's private keys.
everfree··on Global high-performance proof-of-stake blockchain with erasure coding
To join a PoW chain as a profitable miner, you need cooperation from a chip fabrication factory, a local courier, your local government (customs), and your local electricity company, at minimum.

To join a PoS chain as a profitable staker, all you need cooperation from is literally one person anywhere in the world who wants to sell you some of their coins. Then you can stake on commodity hardware.

everfree··on Global high-performance proof-of-stake blockchain with erasure coding
> Proof of Stake is self serving self referencial database.

Proof of Work is much more self-serving than Proof of Stake, as it demands external expenditures to keep itself running. PoS can perform the same job (running a blockchain) without demanding that the world drop what it's doing to contribute electricity to one massive global tragedy of the commons.

Being self-referential is a beneficial feature, not a bug.

> Proof of stake ends up as chain where 26 dudes in discord can freeze accounts, lock the chain, etc, etc.

That's where Proof of Work ends up, not Proof of Stake. PoW's economies of scale always eventually result in a network controlled by a handful of massive mining operations running at razor-thin margins. The "26 dudes in discord" that people talk about are the CEOs of large mining warehouses with custom chips that make it impossible for home miners to break even.

In contrast, with a well-designed Proof of Stake system, people can contribute by staking at home and running mini-PCs in closets at edge locations. It has the potential to remain a much more grassroots network with less concentration of wealth, if the initial distribution is relatively fair. There is no economy of scale and ideally no concentration of wealth over time - as everyone earns the same percent returns in staking.

everfree··on Making any integer with four 2s
I do wish those rules were a bit better defined.
everfree··on Making any integer with four 2s
Legitimate? What do you mean?
everfree··on Making any integer with four 2s
You don't need the gamma function to get to 7. You can stay at an Algebra 1 level.

I solved the puzzle for 1-10 before looking at the answers, and this was my solution for 7:

⌊√222⌋/2

or more readably:

floor(sqrt(222)) / 2

everfree··on The $1.5B Bybit Hack
> those <expletive> crypto bros, a bunch of failed morons (self-proven by all these hacks)

Bankers are a bunch of idiots, too. I know this to be true because that one investment bank collapsed a bunch of years ago.

In all seriousness though, ETH is just a commodity; a bearer instrument; a thing. It's similar to gold or cash in some ways. If you store it properly, you're fine. If you give it to someone untrustworthy who loses it, of course that's a problem.

Well-regulated banks can start holding crypto on behalf of customers as soon as they're given the regulatory go-ahead. They've stored gold in vaults for thousands of years; they can store crypto in digital vaults too.

everfree··on Apple pulls data protection tool after UK government security row
Without Advanced Data Protection, your data is still encrypted at rest, it's just that Apple safeguards the encryption key. The purpose of ADP is to remove control of this key from Apple, so that it's impossible for Apple to leak your data to any third party, even if they are compelled to.

So to me, backdoor encryption seems like it defeats the whole point of ADP, no? But if not - even if there is some tiny marginal benefit - cryptography is extremely expensive to get right. It's doubtful that it makes financial sense to Apple to develop a new encryption workflow for a single country for very slight security benefits.

And it still wouldn't be complying with the UK's demands anyways. The UK demanded access to accounts worldwide. If Apple is going to be non-compliant, then they might as well be non-compliant the easy way.

everfree··on Vanguard's average fee is now 0.07% after biggest-ever cut
Just because mutual funds are priced and traded daily doesn't mean their market value isn't still bouncing around every millisecond.
everfree··on How to turn off Apple Intelligence
> Then discovered they had to turn it off in each app that uses it individually.

Technically the "Learn from this App" feature isn't an Apple Intelligence feature. It's been there since at least iOS 15 in 2021. I haven't heard people really discuss it at all until recently.

My understanding is that it basically just enables suggestions. So, ordering things on your share sheet according to usage, search suggestions, the little button in Maps that navigates you to the location of your next calendar event, etc.

It could still really benefit from a "turn off all" button, though.

everfree··on How to turn off Apple Intelligence
> I have a local AI analysing everything I do on my Mac, iPhone whatever

Which feature is this? I must not fully understand what Apple Intelligence does. I thought it was just for summarizing notifications, editing text and generating images.

I didn't realize that it analyzes everything you do on your device and builds a profile. Where can I read more about that?

everfree··on No Bitcoin ETFs at Vanguard (2024)
Not an LLM, just someone who has way too much time on my hands and a penchant for jumping into internet comment threads in a way that I end up regretting later. I'm not sure whether I should take it as a compliment that I can apparently type with flawless spelling and grammar just like an LLM (shout outs to my excellent English teachers!) or as an insult that my writing is not particularly compelling.

Yes, I naturally type in walls of text that are usually grammatically sound but tend to meander in structure. I'm pretty sure I repeated myself in places. You're repeating yourself in places, too. But believe what you want to believe. Maybe you're the LLM and the dead internet theory is well underway.

> With the regular domains, you simply lodge a complaint with the registrar, and they'll roll back the transfer within 90 days.

Domain registrars (for DNS) do not do this and they structurally cannot do this.

> You can lose a domain if you basically register it, don't use it, and then forget to renew it for a year.

Equally true of both systems.

> We're not talking about the general cryptography, which is incredibly useful. We're talking about "code is law" blockchains with proof-of-work/proof-of-stake method of consensus. They are completely useless for anything but paying for illicit drugs and other illegal transactions.

When you say that, what I hear is "When you use cryptography to sign messages, it's incredibly useful. When you timestamp messages, that can also be useful. But if you sign and timestamp messages, that makes it a Blockchain and Blockchains are incredibly UnUseful. That's silly.

To be very clear I think "code is law" is a nonsensical idea, almost as incongruous as the term "cryptocurrency" itself. They are definitely not currencies, and their code is definitely not law. But blockchains can be useful without trying to create new currencies, and without their code being law.

I've been seeing where the tides are headed in both the public and private sectors, and everyone wants to use cross-organization attributable append-only timestamped databases as an accounting tool now, in part because they are so easily auditable. From there it makes perfect sense to want to attach expressive internal constraints to these databases, via a scripting language. And I'm not sure what anyone could call that kind of database except "blockchain".

everfree··on No Bitcoin ETFs at Vanguard (2024)
> If your name is like `microsoft.com`, then you call the registrar.

As I said, large companies like Microsoft don't risk their domains being stolen in the first place, since they use enterprise protection services like MarkMonitor.

> there's a formal process

Ultimately every time I discuss ENS, the conversation turns into a discussion about how feasible it is for a layperson to afford, file, and actually win a UDRP dispute to recover a stolen domain name, which doesn't have any provision for theft by the way. UDRP only considers whether the current owner of the domain is using the domain to infringe upon your business trademark (if you have one).

The answer is that UDRP is completely unworkable for the vast majority of people who are at risk of domain theft; it isn't even an anti-theft tool. In terms of theft resolution, it's a justice theater where you can watch it work for very specific types of companies who have very specific trademark issues that the UDRP covers, and imagine that it must work great for every mom and pop who has a domain name nicked because surely we live in a just world.

The individual filing the dispute is on the hook for the UDRP fees which are significant and I believe well into the four figures (completely unaffordable in developing countries, and likely not worth it for small businesses). Typically companies need to hire a specialized lawyer to navigate the UDRP system, at additional expense.

So you're misinformed that there is a formal process for domain theft - the UDRP is only for trademark infringement. UDRP is unnecessary for large companies (who have the resources to safeguard their name from theft) and it's useless to individuals and small companies who can't afford it and/or have theft problems but no trademark infringement problems. UDRP is only useful if you are a medium-sized company with a well-established trademark in a developed country and you didn't do your due diligence in properly securing your domain name.

So I'll give you that - if you're a medium-sized company with a well-established trademark in a developed country and you didn't do your due diligence in properly securing your domain name, then UDRP might be better than nothing. But depending on what kind of company you are, it still might be cheaper and easier to just switch domain names.

> Never mind that most registrars have protections against the transfer and will generally spam the hell out of you with notifications.

A blockchain can be designed to be more reliable because it doesn't "generally" do anything. It always, specifically, does exactly what it's programmed to do. A smart contract's predictability is a function of how well it's understood, and the tooling for creating and auditing bug-free smart contracts is maturing rapidly.

If you want to be spammed with notifications, there's nothing more reliable than multiple audited pieces of open source software that run directly on all your devices and monitor a public blockchain for an action. Add several third-party blockchain monitoring services for good measure.

And, of course, it's easy to write custody code in such a way that transfers are time-locked, so you have time to see the notification before the name changes owners. Write-once, audit-once, use-many.

> Have you actually ever done anything like that in real life?

Yes.

But aside from that, I use cryptographic keys in my life for countless reasons other than cryptocurrency. Git, SSH, E2E messaging apps, web passkeys, object storage, HTTPS server certificates, tapping my credit card at the supermarket, accessing the cell network, unlocking my car, etc. Everyone is already managing cryptographic keys whether they know it or not, and everyone's cell phone has keys already available and quite safe in its secure element, ready to sign messages with.

No need to break out the pocket protectors and meet up in someone's living room. A key signing ceremony for ENS could be easily piggybacked off a standard E2E group chat, like for example a Signal or iMessage chat:

* Someone creates a group chat on their smartphone and invites people (specifying the "M" value, aka the threshold for a valid group signature)

* The invited people join, their devices silently and automatically exchange keys, and the chat displays the group key

* Whoever has the asset transfers it to the group key

* Whenever someone proposes a message to sign, the system messages the group chat showing how many more signatures are needed, with a "sign" button that people can click.

This is pretty similar to what Safe Wallet already does, and it currently secures over $100 billion worth of cryptocurrency for some of the largest companies in the industry. But it's also quite simple to just download the app and use it as an end-user. It's directly compatible with ENS, since they both implement the ERC-721 token standard.

I've thought through all of this extensively, I know quite a lot of details about how both blockchains and the current DNS systems work, I've had numerous conversations with countless people about it, and it all adds up to me.

everfree··on No Bitcoin ETFs at Vanguard (2024)
> So call the registry?

Verisign's phone tree is pretty gnarly last time I checked.

> The difference is that a judgement will actually get you something

It could easily cost tens to hundreds of thousands of dollars to win a lawsuit in the registrar's jurisdiction, which is not feasible for an individual or small business.

As far as large corporations go, they don't have to worry about domain theft anyways. They all just pay tens of thousands of dollars for MarkMonitor to guard their domains with enterprise security, never have their domains stolen, and call it a day. I think where ENS shines is for small businesses and individuals.

The better option than recovery is just to prevent your domain from being stolen in the first place. For ENS or DNS this is fundamentally the same concept - just make sure you trust the company that holds custody of your domain name. For ENS, you have the option but not the obligation to custody your name yourself, or to use an M-of-N signature scheme amongst trusted friends, business partners, and/or third-party companies. It's hard to steal a domain name when you need to fool 3 out of 5 executives plus a third party into approving a transfer.

> the registry can give the domain to whoever they want

Could be a feature, could be a bug.

everfree··on No Bitcoin ETFs at Vanguard (2024)
Aside from my point that most contracts can be based on highly-vetted templates, smart contracts don't need to be written in JavaScript or Rust. They can be written using little puzzle pieces that anyone can understand.

https://i.imgur.com/MgEw0Bd.png

As a fun fact, a puzzle-piece style editor like this is how I wrote my first computer program as a toddler.

everfree··on No Bitcoin ETFs at Vanguard? Here's why
> If it's a high-value domain, you call the registrar and get it back.

When a domain name is stolen, definitionally it leaves control of the registrar.

> Worst case, you can sue the thief if you hold a trademark for the name.

You can also sue a thief who has a blockchain name. Blockchains don't magically make it so you can't sue someone and win a judgement.

International lawsuits for domain recovery work fine if you're a medium to large company. But "just sue an international thief" doesn't work so well if you're a small business or an individual. In that case, DNS doesn't hold any legal advantage over ENS, whereas ENS allows for much greater flexibility in secure custody setups to prevent theft in the first place.

> There is. It's called "a lawsuit".

And you can just as "easily" sue someone who steals a blockchain name. Just dig past the fake identity they're hiding behind, figure out which city and country they live in, hire a private investigator to determine their name and address, and hire a lawyer that practices in the theif's country but speaks your native language. It's not any harder than suing someone who stole your DNS name.

everfree··on No Bitcoin ETFs at Vanguard (2024)
> After a decade, there are no examples of widely used smart contracts or even long-running projects that haven't been fueled by boom and bust speculation cycles

MakerDAO, Aave, Uniswap, Ethereum Name Service, and OpenSea are all long-running smart contract projects that have weathered multiple speculation cycles chugging along all the same.

> Every time there is a "code is law" gone wrong with large $ at stake, people immediately fall back to real life police.

It's one potential recourse. As opposed to legal contracts, where falling back to real life police is the only recourse.

Code is not law, but it does solve the "possession is 9/10 of the law" issue by aligning possession with legal ownership more closely than legal contracts do, so that the law has to get involved a lower percentage of the time. This is especially helpful for low-value contracts in the hundreds of dollars or less where it's not economical to involve a lawyer. Same for cross-border contracts where international litigation is infeasible.

> There is both a ton of money in crypto and it has completely failed to reach its promised potential.

Smart contract tooling has only been mature since about 2018 or so. Blockchains have only started scaling since about 2021. Coinbase, the largest cryptocurrency-related company, didn't launch their chain until 2023. Sharded data availability won't even be in production on a major blockchain until next year, with Ethereum's PeerDAS. Zero knowledge proof technology is both in its infancy and developing extremely rapidly. In other words a text-based browser isn't going to host a video stream over a dial-up connection. These roadmaps are long, and it takes time for new breakthroughs in math and computer science to mature, standardize and reach production.

> The largest uses in the next half decade will continue to be scams, pump-and-dumps, speculative frenzies, and money laundering.

The "largest" uses aren't really relevant unless you're trying to make an overarching moral judgement and say "blockchains are bad", which whether true or not, I think is an observation about as useless as "knives can be used to hurt people".

If you're trying to determine whether a tool has any legitimate helpful uses, look for an increase in its legitimate helpful uses.

everfree··on No Bitcoin ETFs at Vanguard (2024)
Crypto lets you engage in any contract you and your counterparty can codify. The reason that so many scams are run through crypto is because the vast majority of people either don't use smart contracts (in which case you're just sending your money to someone and praying), or if they do, they don't read or understand the smart contracts they're using.

The solution to this is maturity. The endgame is to be able to create smart contracts that are as readable to a layperson, if not more readable, than legal contracts. And to come up with a set of standard smart contract templates vetted by programmers, just as today we have a set of standard legal contract templates vetted by lawyers.

That, and encouraging people to actually read what they sign, whether it's a pen-and-paper signature or a cryptographic signature.

everfree··on No Bitcoin ETFs at Vanguard (2024)
Possession is 9/10 of the law. A guarantee of possession gives you that 9/10. A legal contract leaves you calling a lawyer to grasp at the other 1/10, if it's even worth it for the financial value of your contract.

In short, the legal system is pretty useless in enforcing any broken contract that's worth less than a few thousand dollars, especially one of any complexity.

And as an aside, I feel like I enter into low-trust transactions all the time. Don't you?

* I don't trust people who sell products to me online. I've gotten bad product many times. But I need to be able to buy from independent sellers online.

* On a related note, I don't trust half the websites I put my credit card info into. But it's an important part of sending money over the internet.

* I don't trust my ride share drivers or short-term-rental hosts. I could do without short-term-rentals by only staying at trusted hotels, but I can't really do without ride shares.

* When I trade a stock with some random counterparty, I don't trust them to actually deliver the stock to me at T+1. But I need to be able to trade stocks with whoever else can give me the best price.

The typical solution is to have a corporation step in to act as judge and jury for contract breaches that are too small to be worth bringing to court (brokerages, credit card companies, Amazon, PayPal, AirBnB, Uber). In fact, these companies' main value creation has come from adding a layer of trust to traditionally zero-trust transactions. Thus, these zero-trust transactions have been able to thrive while the dispute resolution corporation charges fees for their value-added trust.

The only reason these roles traditionally have to be performed by companies is that autonomous money-custodying software did not exist. But programmable blockchains now allow for this. You could easily imagine a dispute-resolution alternative to PayPal where the organizational structure is a piece of autonomous software directly employing people/AI, rather than a traditional corporate entity.

everfree··on No Bitcoin ETFs at Vanguard? Here's why
Have you ever had a domain name stolen? They're also gone forever in most cases. There is no standard recovery path once a domain leaves the hands of your registrar. You might as well be trying to reverse an international wire transfer.

ENS is not worse in this respect than DNS. The DNS solution is for your registrar to require 2FA to protect your name from being transferred out in the first place. The ENS solution is for your custodian to... require 2FA to protect your name from being transferred out in the first place.

The difference is that anyone has the option to custody their own domain name if they want to - entrusting a third party is not a necessity.

Edit: Additionally, ENS gives you the equivalent of DNSSEC for free. So no need for certificate authorities, which represent DNS' reliance on cryptographic keys that would be catstrophic if stolen anyways.

everfree··on No Bitcoin ETFs at Vanguard (2024)
Blockchains can potentially produce value by receiving transaction fees and burning them. This is similar in some ways to a stock buyback.

Both Ethereum and Solana are currently coded to do this, though AFAIK neither of them are currently cash-positive due to their burned fees not being enough to offset issuance yet.

everfree··on No Bitcoin ETFs at Vanguard (2024)
Of all blockchains that have any current relevance, only Bitcoin runs on ASIC/GPU - all the rest are staked rather than mined.
everfree··on No Bitcoin ETFs at Vanguard? Here's why
Auditing isn't typically about forcing people to be honest, it's about discovering when people haven't been honest and being able to attribute the fault to a specific bad actor.
everfree··on No Bitcoin ETFs at Vanguard
My favorite example is Ethereum Name Service (ENS).

Instead of a patchwork of DNS servers that can go down, registrars that go through enshittification cycles, and complicated ownership/transfer rules that vary based on country and TLD, ENS presents a single unified database that runs on signed message broadcasts.

To change an ENS entry, you just sign a message and broadcast it anywhere. No need to interface with a registrar. The global resolver gets updated seconds later.

It reduces an incredibly complex system of registries and registrars, authoritative and recursive resolvers, domain transfers - it distills it down to a system of just sending signed messages to update a single global name database that gets replicated to everyone who cares to have a copy.

everfree··on No Bitcoin ETFs at Vanguard? Here's why
The major problem is that private solutions (like consortium chains) offer privacy but no standardized interoperability or neutral root of trust, and public solutions (like Ethereum blobs) offer interoperability and neutrality but no inbuilt privacy.

I believe this will change either when consortium chains figure out the interoperability problem (so they can bridge seamlessly with public chains) or public chains figure out the privacy problem (allowing consensus over entirely private transaction zones).

To me it seems like the latter is more likely than the former. We've finally got both featureful/performant Ethereum roll-ups and private Ethereum roll-ups. Now the trick is to combine all those properties and bundle them into a business ledger that's high-performance, with customizable privacy zones, with consensus and data availability provided by a credibly neutral setup such as the Ethereum validator set.

This seems to be the direction some firms are going, for example Ernst & Young with their Nightfall product, and more recently their OpsChain Contract Manager to try to bring it to enterprise customers.

everfree··on 0-click deanonymization attack targeting Signal, Discord, other platforms
I think the more important question is how many people in the world don't live within a 250 mile circle around New York? An investigator could potentially cut their geographical search down by 95%+.
everfree··on 3blue1brown YouTube Bitcoin video taken down as copyright violation
Pretty sure if someone is misusing your company logo, they’re violating both copyright and trademark, among other things. I’m not a lawyer though.
everfree··on 3blue1brown YouTube Bitcoin video taken down as copyright violation
From their home page, it looks like their stated goal is to remove brand impersonation materials. Lookalike websites, social media compromises, malicious links, etc. They allege to work with registrars, contribute to blocklists and take down scam content. True brand impersonation of this ilk almost always includes copyright infringement.

Sure it's possible that the company is a truly malicious actor that has a fake website and does not actually submit any valid claims, while working alongside the top brands in the industry to tear down that same industry. Personally though, I think it's more likely the company is a startup rushing to grab profits, has bad algorithms that come up with a lot of false positives, and is generally a bull in a china shop. Not that that's excusable, but being sloppy and taking shortcuts that hurt people is a bit different from being a "copyright hit company" where hurting people is the company's entire raison d'etre. The former calls for better regulation; the latter calls for being stamped out.

I don't know if you've tried to consume any crypto-related content on YouTube recently, but YouTube has a major problem with fake "live streams" from "Elon Musk" and other prominent crypto figures who promise they'll "double your crypto for a limited time" if you just send it to them within the next ten minutes. Someone's gotta fight that, on behalf of both the scam victims and the impersonated brands, because YouTube themselves don't give a shit.

everfree··on SSH Artwork
Vanity addresses are a similar idea.
everfree··on 1374 Days – My Journey with Long Covid (2023)
> In basically every case, the initial group that claimed to have it and the main promoters of it have been young females. Thus, some skepticism is justified. Women are generally more prone to social contagion.

I think the most useful question isn't whether women are more prone to contagion. It's whether more women would be saved by a doctor's skepticism of their symptoms, or whether more women would be denied proper treatment by it.

← PreviousPage 2 of 29Next →