HNHacker News
TopNewBestAskShowJobs

rxl

197 karma · joined August 9, 2011

Co-founder, Onename (http://onename.com)

verifying that +ryanshea is my openname (https://onename.com/ryanshea)

submissionscomments
rxl··on Blockstore: A Key-Value Store on Bitcoin
Thanks! Really appreciate it.

1. The replication factor of the DHT is set to be high. 2. We'll be committed to seeding the network and will work with others to have them run nodes. 3. We will provide a full index of the DHT, so the data can be retrieved via our API as an alternative to checking the DHT (the data can be stored and mirrored anywhere, since it's hash-addressed).

rxl··on Blockstore: A Key-Value Store on Bitcoin
Bitcoin technically has the capability to store at least 1K bytes per transaction using multi-sig outputs. 66 bytes per output * 15 possible outputs (for standard transactions) = 1K bytes. And you could do even more than that with non-standard transactions, making transactions with 3K bytes or more.

That said, you probably don't want to do this, because it contributes to blockchain bloat.

We made the decision of storing the data in a DHT because it's more efficient and you can store much more data than a few thousand bytes.

rxl··on OneName – Distributed Identity Database using Namecoin
Hey Thomas, thanks for your comments.

1) Every username system has some limitation on usernames. Look at Twitter. There are 650 million twitter users, and all of them picked usernames in the same global namespace. This demonstrates that using a global namespace is quite doable.

2) You're right, people usually have multiple Bitcoin addresses and quite a few people prefer to use different addresses for different transactions. However, the protocol is extensible and is not limited to a single address. In the future, the protocol will support a list of bitcoin addresses instead of a single address. Further, you can use a hierarchical bitcoin address and direct people to different addresses in the hierarchy. In that sense, the bitcoin address listed is just a way to identify the tree of addresses the user owns. Last, the protocol supports data to be linked to from the blockchain, so if you want, you can have a next pointer lead to an API endpoint that returns a different bitcoin address every time.

3) As far as supporting only [a-z0-9_], those are the characters that most username systems support, including twitter. Some say this is due to the fact that those are the only "word" characters. Also, using this set makes it more difficult to confuse addresses. The domain name system has similar restrictions for similar reasons. I know that international readability takes a bit of a hit, but I'm sure we'll find ways to improve the experience. We're all up for suggestions.

rxl··on OneName – Distributed Identity Database using Namecoin
Hey, thanks for the feedback!

I love your pgp-messenger idea - you should do it!

And you're right - the pretty front end is a big component. Two things, though - 1) we're working on open sourcing the profile crawler 2) it shouldn't be that difficult to roll your own pretty front end.

rxl··on OneName – Distributed Identity Database using Namecoin
Yes, when importing the private key into Namecoin-Qt, it needs to be in wallet import format. Make sure it's a Namecoin WIF, though. You might find this library helpful: https://github.com/halfmoonlabs/coinkit.
rxl··on OneName – Distributed Identity Database using Namecoin
No this is a feature. Big profiles (larger than 519 bytes) are chunked into multiple key-value entries in the blockchain. The "head" chunk has a next pointer to the next chunk and so on. The head chunk's key is the username, in the "u/" namespace. We didn't want to polute the u/ namespace with follow on chunks, so we just decided to go with "i/", but really the next pointer can go to any key in the KV you want.
rxl··on OneName – Distributed Identity Database using Namecoin
Apologies for the delay! We are trying really hard to handle the barrage of incoming requests and will get back to you shortly!
rxl··on OneName – Distributed Identity Database using Namecoin
We're working on a profile updating tool for the typical user and should have it out in the next couple of days.

In the meantime, if you're somewhat tech savvy, you can update your profile as follows:

1) download/install Namecoin-Qt or Namecoind

2) use the OneName profile builder and grab the JSON

3) calculate your WIF formatted private key from the passphrase (just a sha256 then a conversion to base58check - you can use https://github.com/halfmoonlabs/coinkit for that)

4) import your WIF into your namecoin client (you should now see the username in your possession)

5) perform a "name update" operation with the new JSON profile data

rxl··on OneName – Distributed Identity Database using Namecoin
We don't have your private key, and so we have you write down a passphrase that can derive the key (sha256(passphrase)). In addition, we have a last resort mechanism to help you recover your private key if it ever gets lost. We use shamir's secret sharing to split up the secret key, and send you a share. The pk can only be reconstructed when both shares are combined. We have zero information about your pk.
rxl··on OneName – Distributed Identity Database using Namecoin
Yes, we want to support Dogecoin soon. One simple thing we need, though, is an icon similar to the fontawesome bitcoin icon.
rxl··on OneName – Distributed Identity Database using Namecoin
A login system is definitely on the roadmap! We just decided to focus on the initial usecase of bitcoin payments.

You're right, the global namespace very well might get crowded, but we'll see how it plays out.

rxl··on OneName – Distributed Identity Database using Namecoin
Include the spaces. Exactly as it appeared.
rxl··on OneName – Distributed Identity Database using Namecoin
We need to be clearer with this so apologies for the confusion. Calculate the sha256 of the passphrase to get the namecoin private key (in hex form). Then import the pk into namecoind or namecoin-qt with importprivkey.
rxl··on OneName – Distributed Identity Database using Namecoin
You can get the private key for the bitcoin address we created for you by calculating the sha256 of the passphrase you wrote down. We're working on improving this process and in the mean time we'll clarify further. Thanks!
rxl··on OneName – Distributed Identity Database using Namecoin
Ok we will clarify this, thanks for the feedback.
rxl··on 3D Printer Comparison Chart
Ah you're right, it's not really a buying guide. The comparison chart is sortable though.
rxl··on Why HN Should Use Randomized Algorithms
Great suggestion. A system like this would also work well to:

1) increase the variability of information consumed by the community

2) combat group think (which is all too prevalent these days on HN)

3) provide a more level playing field for people who don't make an effort to abuse the voting system and exceed the front page threshold

rxl··on Ripple is officially open source
Bitcoin, Litecoin, Feathercoin, etc. are all decentralized currencies, and this fact should give you at least one very good reason to trust them.

Ripple has been pre-mined and is not decentralized, but in fact controlled by one entity (regardless of what the creators may claim).

There is a huge difference here. Not even a comparison.

rxl··on Ripple is officially open source
First, let me quote http://ripplescam.org/:

  But wait – you can become your own validator! [...]
  The consensus system ensures there is only one ledger – the most accepted one.
  If you run your own validator, you must connect with OpenCoin Inc servers, or you
  will be building a different ledger. In practice, it is not possible to
  “dethrone” OpenCoin Inc as you have to co-operate with OpenCoin Inc.
Second, I'll point out that while minimizing the number of validators may be attractive, it also makes the currency much more vulnerable to top-down control, via governments, corporations, etc.

Last, if you're reading this, I'd suggest that you read up a bit about Ripple on Bitcoin Forum before you make conclusions about the currency - there are a lot of interesting discussions about its viability (like this one: https://bitcointalk.org/index.php?topic=146964.0).

rxl··on Ripple is officially open source
Ripple has several huge problems that will prevent it from gaining as much steam as other cryptocurrencies.

First, OpenCoin pre-mined the XRP's so they could hack the cryptocurrency trend and make tons of money if their currency took off.

Second, Ripple is NOT a decentralized currency, but in fact a "distributed" currency, which is actually a much bigger deal than you might think. This means it has a single point of failure, can be easily abused by the creators, and is extremely vulnerable to intervention by governments and other big players.

(You can read all about it here: http://ripplescam.org/)

Bottom line: the strength of a currency depends almost entirely on the trust in that currency, and I have no reason whatsoever to place trust in ripples. It's a wiser move to put your money in a non-scam currency, like Bitcoin or Litecoin.

rxl··on Facebook is doomed
This article is quite sensationalist and doesn't seem to consider the fact that every company today is in a different stage of its life cycle.

FB was founded in 2004, while Google was founded in 1998, so it's appropriate to compare today's Facebook with 2007's Google, pre-android and all.

Box was founded in 2005, salesforce: 1999, linkedin: 2001, jawbone: 1999, workday: 2005, amazon: 1994.

Note that the two oldest companies in this list are Amazon and Google, so it's no wonder that they are the ones who have expanded the most beyond their initial markets.

It's always taken a while to build a great company that competes in 2+ markets, and that hasn't changed.

rxl··on TrueVault – HIPAA compliant data storage
I understand your concern, but these days, cloud or no cloud isn't what's important, just that you use a data store in a HIPAA compliant fashion and that the provider will sign a BAA. Health tech startups these days are using AWS, Azure, and Rackspace, all of which will sign BAA's.
rxl··on Angry entrepreneur replies to patent troll with racketeering lawsuit
It would be awesome if someone set up a db like the one you're describing, where users could identify trolls anonymously and submit other information about them, including links to parent companies.
rxl··on A Startup Reading List
I appreciate your modesty Ryan, but one should consider that your book IS about manipulating the media. In fact, in the trailer for your book, you specifically detail how you can create buzz about an article or book (through these very means). Thus, this kind of planning is just par for the course for you.
rxl··on A Startup Reading List
It's perfectly within reason to have respect for him. I have no reason to do otherwise and I actually think he's pretty clever.

I'd just note that being in the personal circles of talented authors is quite different from being a talented author yourself. The book may be good (I haven't read it) - I'm just pointing out that you should be cautious and consider that the hype surrounding the book is artificially inflated.

rxl··on A Startup Reading List
Perhaps, but unlikely. And regardless, I know Ryan is.

Also, yes, I realize that bad press is good press and that this controversy will probably drive Ryan even more sales, just by virtue of the fact that more people are talking about his book than would have otherwise. And I don't really care either way, I'd just prefer that people be in the know.

rxl··on A Startup Reading List
Well done, Ryan. Well done.
rxl··on A Startup Reading List
This list, compiled by Chris Johnson, includes a book called "Trust Me, I'm Lying", by Ryan Holiday.

One thing to note is that Chris worked with Ryan and has a close relationship with him (Chris actually wrote the trailer for Ryan's book).

And judging from Ryan's usual tactics, Chris wrote this list simply to push Ryan's book, which he cleverly included alongside clear classics like The Lean Startup, In The Plex, and The Innovator's Dilemma.

Edit: Here are some other tactics cleverly used by Chris/Ryan in the post...

1) they mentioned Ryan Holiday in the first couple paragraphs so that the reader would have some familiarity with his name and be even more likely to click through to his book

2) they included Ryan's book early in the list but not as the first, and specifically after at least one book that you probably haven't heard of, but that seems credible

3) they marked The Innovator's Dilemma (arguably the most well known book in the list) as "optional," leading one to perceive that the other books in the list that aren't marked as optional must be even better

Edit: evidence for Chris and Ryan's relationship... https://www.google.com/search?q=chris+johnson+ryan+holiday

rxl··on NSA-Proof Your Email Without Encryption
That is correct. If the NSA or any other organization really wants to read your message, it will be able to. There are several ways to accomplish this (including what you just mentioned as well as the image sifting and OCR method I included above), but some of them just involve more work/modification-of-strategy than others.
rxl··on NSA-Proof Your Email Without Encryption
In the unlikely scenario that the app was compromised and stayed compromised, you would be correct. However, if it was compromised and the situation was quickly rectified, only sent but unread messages would be able to be read. If a service like WhatsApp was compromised, however, a much larger amount of messages would be able to be read.
Page 1 of 2Next →