HNHacker News
TopNewBestAskShowJobs

pipermerriam

327 karma · joined February 1, 2014

[ my public key: https://keybase.io/pipermerriam; my proof: https://keybase.io/pipermerriam/sigs/ERN5yjf2NPYscK90dEvU-0KTIBaQFzmeOAhAykTszRg ]
submissionscomments
pipermerriam··on Gravity Energy Storage: Alternative to batteries for grid storage
Can you provide a source for this?
pipermerriam··on Greenland ice has shrunk beyond return, study finds
Do you have any reading recommendations on what additional things someone can do to be better prepared for the next 5/10/20/30 years?
pipermerriam··on Mozilla VPN
I use ProtonVPN. Same company as ProtonMail. Highly reputable with a business model around doing privacy and encryption well.
pipermerriam··on The impact of direct air carbon capture on climate change
Can you provide anything beyond conjecture that there is any merit to what you've stated? My understanding is that the effects of CO2 as a greenhouse gas are pretty well understood at this point.
pipermerriam··on Massachusetts Sues Exxon over Climate Change, Accusing the Oil Giant of Fraud
I agree with this sentiment. I've struggled to see a path towards real change that doesn't involve us all getting out our pitchforks.
pipermerriam··on Lahja – A generic event bus implementation written in Python
We've talked a bit about adding TCP support and really like some of the options it opens up. However, we have to move away from the use of pickle for event serialization before we can do that, otherwise we would have some security issues with remote code execution.
pipermerriam··on Lahja – A generic event bus implementation written in Python
It's a library we use in the "Trinity" client for the ethereum network. The lahja library itself is however just an event bus and has no cryptocurrency ties other than being used in the Trinity codebase.

https://trinity.ethereum.org/

pipermerriam··on Facebook adding “fbclid” parameter to outbound links
it was, and thank you for sharing it.
pipermerriam··on Facebook adding “fbclid” parameter to outbound links
There are a number of comments here who seem genuinely happy about this. This is a perspective that is hard for me to understand, largely because I'm strongly in the pro-privacy, anti-tracking ideology.

So if you are part of the group who sees this as a good thing, I'm genuinely interested to understand why you see this as a good thing and whether you view the mass surveillance of the general public by advertising companies as bad?

pipermerriam··on Product Updates Based on Your Feedback
The fact that this all happened in the first place is really telling. It's nice that they've backed these features off (a bit) but there's a reasonably clear signal to take away from this.

When company and customer interest are misaligned this is the result. There are plenty of cases where a strong leader in the company with a strong ideology can hold this stuff back, but companies normally outlast those individuals and eventually there's nobody left to stand in the way.

It's wonderful that we were able to make enough noise and fuss that the cost/benefit shifted sufficiently but this will happen again, and then again, and so on... And eventually, we'll be tired of yelling or won't be able to yell loud enough.

Vote with you attention and your data and your money. Switch to Fastmail or Protonmail. Use Firefox or Brave. Buy a System76 laptop instead of yet another not-so-great-for-developers-anymore Apple macbook pro. Choose these options even if they aren't as good because if we don't support the handful of companies who are trying to do something other than gobble up all of our attention and data we're in for a really dark future for the web.

pipermerriam··on The war between Google, Facebook, Amazon, and Apple
Please provide your recommendations. I've been prying myself off of their services but currently, I've not found a solid replacement for:

Facebook: nothing else has the network effect.

Google Drive: online documents are really convenient

Google Voice: what else has seamless integration with either android or ios.

Amazon: Buying household items like toilet paper, dishwasher detergent, etc, saves me a ton of time.

pipermerriam··on A hacker stole $31M of Ether – how it happened, and what it means for Ethereum
I think the answer to that question is extremely contextual and going to be very different for different applications. I also think that

I'd like to point out that the idea of including the library code within the contract is untennable at a certain level as contracts currently have an upper limit on size which is determined by the block gas limit. It also doesn't make it any safer because it's still functionally the same as executing external code because it's the same code being executed.

pipermerriam··on A hacker stole $31M of Ether – how it happened, and what it means for Ethereum
Your parallel is not an accurate one.

One of the key and powerful features of the Ethereum Virtual Machine or, EVM, is the ability to delegate execution to external libraries. You can think of this much the same way you think of installing 3rd party libraries in your favorite programming language of choice.

In the EVM you can write a "library" which performs some common functionality such as manipulation of date-time objects much like the `datetime` library in Python. Any other contract may then make use of this code simply by delegating execution to the deployed library address. This has inherent risks that every Ethereum developer should understand fully, but with that risk comes some incredible power and potential.

There currently is no "Standard Library" for the EVM but it is looking very likely that it will be comprised of this type of contract. Slowly, overtime, these library contracts will be written and deployed to the network. There is work being done on using theorem solvers to mathematically prove that a contract satisfies certain properties which opens the door to a "provably correct" standard library.

I know of no other computing environment or packaging system that has these properties. For me, it has been an enlightening subject and I feel like we've only just scratched the surface.

pipermerriam··on Introducing Token
This is an early release of something intended to be a platform on which independent developers can build applications. Everything on there is meant to be illustrative of what you can do. Currently it only operates on the test network so it's a toy for the time being.
pipermerriam··on Introducing Token
Isn't the history of technology riddled with inventions that "aren't good for anything except ..." which turned out to be good for lots of things.

From the top of my head the following examples come to mind.

1. Early criticism of the tablet was that nobody would use them because they didn't have a keyboard.

2. Early criticism of the internet was that nobody would ever purchase anything over the internet.

3. Early criticism of dropbox mentioned elsewhere in this thread, "they're just re-selling S3, why would anyone use that".

Disclaimer that I'm pretty deep in the Ethereum space so my perspective is anything but objective, but it is informed as I know the space quite well.

Smart contracts are capable of big transformative change to how we do a lot of things, but they are REALLY new and we're only just starting to learn how to use them and what we can use them for. Here are some examples.

1. Look at [ENS](http://ens.domains/) as an example of what DNS might look like if it weren't centralized.

2. Look at [simple Escrow examples](https://dappsforbeginners.wordpress.com/tutorials/two-party-...) for how smart contracts can remove middlemen from financial transactions.

None of these things are likely to blow up into massive mainstream adoption tomorrow but they are illustrative of what is possible and there are a lot of people working very hard to make these things ready for mainstream adoption.

pipermerriam··on Ask HN: Who is hiring? (March 2017)
ConsenSys | Senior Software Engineer | Boulder CO, New York NY | REMOTE https://consensys.net/

Looking for senior engineer to work with me on the open source ecosystem of python tools for Ethereum. The ideal candidate is self directed and will take the initiative to learn. This doesn't mean you won't get any support but you do need to be self motivated. The following are nice-to-have knowledge and skills.

* Python * Ethereum and the EVM * Solidity * IPFS * General security * React/Redux

Contact me directly at pipermerriam@gmail.com with all of the following.

* Link to your github account if you have one. * Resume. * Cover letter with a brief-ish explanation of who you are and why you want to work on this will go a long way. * A cute animal picture.

pipermerriam··on Use of Ad-Blocking Software Rises by 30% Worldwide
Did you ever think to change the type of ads you are showing on your site? I'm saying this under the assumption that you are using an ad platform where you plug their code into your site and then they show your user's ads.

Have you thought about handling the advertising yourself and hand picking products and services that are directly applicable to your users and displaying them in an unobtrusive manner?

And as a side note: I consider ads from any ad network to be a security risk and while I respect sites for "politely" asking me to whitelist them I feel it's a misguided approach.

pipermerriam··on Dark Patterns – User Interfaces Designed to Trick People [video]
> What do you view is the meaningful reason for users to switch to these other platforms with some kind of better underlying data model?

I completely agree that people don't currently care about their data in the sense that people are complacent about their privacy and aren't likely to change very much in that regard.

I think people care about UX but to what level?? Might be minimal.

There are a few compelling reasons why I think these new open platforms are likely to succeed and I'll try to capture them succinctly.

1. Data Economy: People choose options that save them money or make them more money. While people don't care about owning their own data, they will care about a new platform that lets them earn money for passive things like keeping their smart phone location services turned on, or allowing access to their browsing habits.

2. Account Portability: Currently if you transition from selling on Ebay to Amazon, or from driving for Uber to Lyft you have to start back over from zero. If you own your data then you just bring it with you over to the new platform and all of your reputation and whatnot can come with you.

3. Network Effect: These types of open platforms are capable of robust cross-platform integration. Right now we see the power of this in things like the suite of products that Google provides. We can have these types deep inter-connectivity without needing the applications to be from the same source.

I also want to acknowledge that this isn't going to be a smooth ride and there are big challenges to overcome, but the potential exists and it won't happen if we don't try.

> what's the meaningful reason for a company to adopt such a better underlying data model instead of keeping a data silo and just making better features on top of such a silo?

I believe that the article linked below titled "The Golden Age of Open Protocols" is the most compelling argument I've seen.

- http://avc.com/2016/07/the-golden-age-of-open-protocols/

pipermerriam··on Dark Patterns – User Interfaces Designed to Trick People [video]
> but what incentive do companies like LinkedIn have for doing this?

They don't have any incentive and I suspect they will hold onto that data until it's "pried from their cold dead hands".

I think that companies like LinkedIn and other massive data silos are going to atrophy and die as users migrate to new platforms that treat them better and give them more control over their data and experience. I'd like to point out that while there is little incentive for current companies to adopt this architecture, it doesn't mean that new companies won't be successful implementing their business under this architecture. Admittedly, almost all of this is utterly unproven given the newness of blockchain based application platforms.

One way to look at this is that the current model of internet companies is highly anti-competitive. The data they "own" is really the data of all of their users who can freely give it to any other source they choose. The fact that they have control over the database is what gives them the competitive advantage. These new application platforms which have open public databases can change the game such that the previous closed-data model can no longer compete.

pipermerriam··on Dark Patterns – User Interfaces Designed to Trick People [video]
Blockchain based application platforms can allow re-architecting of applications such that the data that backs the application is not "owned" by the company, but instead is either public or user owned.

Currently, if you want to use LinkedIn you have to either use their website. Sometimes there are 3rd party options that consume the API but in the current model of the web, as soon as one of those 3rd parties is seen as problematic then API access is typically revoked or restricted to give power back to the company.

In the public data model the data and API are publicly exposed and cannot be arbitrarily restricted. In the LinkedIn case this would allow a 3rd party to build a new UX on top of the LinkedIn database that excludes the copious dark patterns. Under this model, companies who abuse their users risk getting displaced by an alternate application backed by the same data that favors the user.

- Disclaimer: I work pretty much exclusively developing software in the Ethereum ecosystem which is one such blockchain based platform.

pipermerriam··on Maybe Blockchain Really Does Have Magical Powers
Any blockchain client for any chain (Bitcoin, Ethereum, Dogecoin, ...) could very easily implement a storage layer for the underlying blockchain data using a protocol like IPFS.

https://ipfs.io/

In this model, individuals would not need to store the entire chain as they could lazily fetch parts of the chain as they are needed. This would allow individuals to store very little of the historical blockchain data if their use case doesn't require them to access that historical data.

There are nuances to this solution. IPFS can be thought of as one giant torrent, and with torrents, someone must have the part you need for you to be able to fetch it. There is a theoretical failure mode in this model where everyone happens to delete the same part of the blockchain thinking that they won't need it and if they do they'll get it from someone else. In this case, this portion of the chain history would be lost. This failure mode should be simple to mitigate, especially since many people participating in the network need access to significant portions of the historical data, and everyone won't use the IPFS based storage layer so, when a chunk is not available over IPFS, the client can just fetch it over normal means.

pipermerriam··on The Golden Age of Open Protocols
This. A thousand times this.
pipermerriam··on Blockchains and Buzzwords
An invalid digital signature is a pretty strong indication that it is the fake. I'd consider this poor journalism as it gives this letter credibility that it doesn't deserve.

My statement was merely to try and point out that one of his quoted sources is likely a fabrication.

pipermerriam··on Blockchains and Buzzwords
This author did not do their research. They are likely quoting from a fake letter that is not from the actual attacker. I did not personally attempt to verify the signature, but others did and they report it being invalid.

The letter in question can be found here.

http://pastebin.com/CcGUBgDG

The Reddit post where it was submitted to `/r/ethereum` here

https://www.reddit.com/r/ethereum/comments/4oo1io/an_open_le...

pipermerriam··on FBI raids dental software researcher who discovered patient data on FTP server
Can you provide a link to said research?
pipermerriam··on FBI raids dental software researcher who discovered patient data on FTP server
The FBI seems to have lost it's way (Same with most of the other 3-letter governmental entities and other law enforcement). How do we change the system so that they are held accountable for these sort of things?

This is getting ridiculous. I can't predict the general public's opinions on things like this but it seems so clearly "wrong".

I have hope for a peaceful fix but I am skeptical that we aren't well on our way to a much more traditional violent revolution.

Everything I've read on the subject suggests that the early signs of revolution are a sufficiently large disparity between the rich and the poor such that the poor can no longer provide for themselves. It seems like this is well on its way and likely speeding up.

I'd love to see some statistics on situations like the 2014 Ferguson Missouri situation. I'm curious if there's a rise in situations where the government sufficiently crosses the line that the public backlash manifests violently. I expect that we're still in a stage where these situations are still largely centered around poor minorities [1] but situations like this suggest that incidents are starting to expand into demographics that might get the "middle class" [2] to finally pay attention.

I hope we can find a way to unite as a single voice to change things. I hope it doesn't end up being violent. The following things encourage me.

* Decreased relevance of the "mass media". This is a double edged sword. On one hand it allows for news that might be ignored by a major network to still be disseminated widely. On the other hand, the "public" has a really poor track record of consuming news that isn't also entertainment and many of these issues seem to fall entirely outside of people's interests.

* The ability to aggregate these sort of events to establish a clear pattern of behavior. It's getting harder to hide things.

Also these disclaimers:

1. I say poor minorities because based on my knowledge of the law enforcement overstepping it's typically in situations involving people who are poor and black.

2. The "middle class" is used here to reference a predominantly "white" demographic that most mass media caters to. I've struggled to find the appropriate language here, fearing I'll be labeled racists somehow. Hoping that my message reads as intended.

pipermerriam··on A Current List of Use Cases for Ethereum
At present, as far as I know all of the scalability plans for Ethereum are theoretical. That said the plan thus far is:

Light Client Support allows for running a node that does not sync the full chain, but rather downloads and verifies only the small parts necessary to send transactions and read state.

Proof-of-Stake replaces Proof-of-Work which opens up options for things like parallelization.

Sharding is a plan to split the blockchain into many smaller chains that are all linked but operate largely independently, allowing for horizontal scaling of the network. Transactions within a shard are synchronous. Transactions across shards are asynchronous.

pipermerriam··on A Current List of Use Cases for Ethereum
Disclaimer. I have skin in the game. I've been developing on the platform since the Frontier launch and I have some Ether holdings.

1. Checksums are available via the mechanism in https://github.com/ethereum/EIPs/issues/55

2. I don't have any experience mining. Maybe someone else can answer this.

3. If I recall correctly, this is being fixed in Serenity. Transaction validity will no longer require ether to be submitted with the transaction allowing miners to accept transactions that are paid for during their execution.

4. Ethereum only left Alpha/Beta on March 14th 2016, roughly two months ago. Until then there were clear warnings posted that there were likely to be bugs. I'm not aware of anyone losing money due to protocol errors. The losses I've read about are predominantly user error and errors in 3rd party software.

5. This seems like a clear lack of understanding of the intentional design of the system. If you could directly make HTTP queries from smart contracts it would be impossible to reach consensus on what the result of code execution was because two clients could get two different responses from the same query. Everything that the EVM executes has to be 100% deterministic. Take a look at http://www.oraclize.it/ for an example of how communication with the outside world can be done.

I hope that clears things up.

pipermerriam··on Ethereum Contracts Are Going to Be Candy for Hackers
As a developer in the Ethereum space this idea has actually been something I've thought about a lot. It's on a list of things that I'm looking out for because they will inevitably happen.

1. Like you said, a bug will cause the "effective" theft of a huge amount of funds.

2. Someone will make a contract that unexpectedly makes a huge amount of money. That contract however will have absolutely no mechanism for extracting this money, forever locking the money it makes away beyond reach of anyone.

3. Someone will make a contract that the American government has deemed illegal. That contract will have been made such that there is no off switch. The only possible way for them to stop it would be to convince the majority of the network to remove it via a protocol update. I expect they will not be able to get this majority and thus we have an unstoppable force meets immovable object situation.

4. Ethereum will have it's `npm` left-pad moment when a contract that is used widely is suddenly suicided. The number of down stream effects will be enormous. Most of them will be unfixable.

pipermerriam··on Ethereum Contracts Are Going to Be Candy for Hackers
There is actually already fledgling support for this in Solidity (the prevailing language that Ethereum developers use to write smart contracts).

https://forum.ethereum.org/discussion/3779/formal-verificati...

Page 1 of 3Next →