HNHacker News
TopNewBestAskShowJobs

vec

2,000 karma · joined August 9, 2012

submissionscomments
vec··on Glitter bomb tricks parcel thieves
We don't need to defend the inept killer cops to posit that vigilante justice is even worse.
vec··on Novogratz's Crypto Trading Desk Lost $136M in Nine Months
I'm a complete layman whose only knowledge of the financial system is derived from podcasts and magazine articles, and hindsight is always 20/20, but wasn't this always an obvious sucker bet?

As I understand it, a hedge fund is supposed to be, well, a hedge. It's not supposed to make more money than the market when the market's doing well. It's supposed to be uncorrelated from the rest of the market, with the hope that it can maintains or even gain value in the event that the rest of the market tanks. An asset class that could reasonably be expected to substantially outperform both a bull market and a bear market isn't a hedge against anything, it's just a strictly superior asset class and we're pretty good at arbitraging those out of existence in relatively short order.

With that in mind, doesn't this basically devolve to a bet that at least a whole decade's worth of economic growth was going to be consumed entirely by a massive recession? That's not wholly unprecedented, admittedly, but it is a lot rarer than I'd be comfortable putting any money on at flat odds.

What am I missing?

vec··on SIPC Says It Has Serious Concerns About Robinhood's New Product
The grandparent talked about treating it like fantasy sports, and if they advertised themselves like, say, Draft Kings does then it would be one thing. As it is, though, the more thoroughly you trust their representation of how their product should be used the worse off you will be. I usually take that particular trait as a big red flag that a the universe would be better off without the company in question.

And yes, this criticism does apply to most brokerage accounts. Most brokerage accounts don't have half of Silicon Valley fawning over them, though.

vec··on SIPC Says It Has Serious Concerns About Robinhood's New Product
If you understand what you're signing up for and still want to dabble in stock trading for fun then sure. Go wild. Everyone needs a hobby. But the homepage of robinhood.com has the following call to action above the fold:

> Investing, Checking & Savings. All for Free.

> Robinhood gives you the tools you need to grow your savings, invest in your future, and do more with your money.

Does that sound like "this is not an appropriate way to finance your retirement" to you?

vec··on Robinhood launches 3% checking account
How much are you willing to gamble on the prospect that you're in the top 0.1%? And before you answer, consider that you haven't been evicted so you're obviously not in the top 0.01%.
vec··on SIPC Says It Has Serious Concerns About Robinhood's New Product
I do believe that people with limited access to capital can't understand the markets as well as institutional investors, and you should too. It's not about intelligence, it's about access. The rich have more current information about state of the market than you do and can act on that information sooner than you are able to, which allows them to systematically make slightly better trades than you can.

Stock trades aren't instantaneous, and they're not guaranteed to resolve in the order they were submitted. Wealthy traders can throw money at a combination of locating their servers physically closer to the exchanges and just straight up purchasing preferential treatment from them in order to ensure that their trades will always resolve ahead of yours. Moreover, the "price" of a stock is essentially the rolling average of all the buy and sell offers currently in open. When you "buy" a stock from Robin Hood, what you're actually doing is creating an offer to purchase at or below a specified price point.

One of Robin Hood's main sources of revenue is providing access to that stream of trade offers to investment firms who can use it to "predict the future" in ways that will systematically erode your profit margins. There are any number of ways this happens, but probably the easiest one to understand is that after they see you place a buy offer they can use their position near the front of the queue to accept the cheapest available sell offers ahead of you and immediately resell them to you at your offered price, pocketing the difference.

That's the catch with normal humans trying to play the stock market. You can't actually participate in the same way that wealthy institutional investors do, because you can't afford to pay to be near the front of the queue. In fact, the way you participate essentially guarantees that, no matter how well you do, the institutional investors will be able to do slightly better.

One way to work around this is for normal humans to pool their resources so that they can collectively act as a wealthy institutional investor too. That's essentially what index funds are.

vec··on SIPC Says It Has Serious Concerns About Robinhood's New Product
Offering stock trades with zero fees is pushing you to make a bad decision. The vast, vast majority of investors should be making as few trades as is humanly possible, and the small fraction who should be making frequent trades are essentially by definition working with large enough sums of money that the brokerage fees are negligible.

This isn't to say you can't make money as an individual by day trading, but it is to say that the median day trader would have made more money by buying an index fund and sitting on it for a decade.

vec··on NIST's answer to “Do you need a blockchain?”
> (At least I can see _why_ people (wrongly) thought RDF would; no idea how they arrived at that misconception of blockchain)

There was briefly the bad idea that "NoSQL means we don't have to care about our schemas anymore" bridging the other two bad ideas.

vec··on Philosophy Has Made Plenty of Progress
You're not wrong, per se, but you are parroting the fundamentalist party line. Maybe I've just got a unique perspective on the issue (I'm a Unitarian Universalist; everyone at my church respects my atheism as a sincere and personally fulfilling spiritual journey and a valuable perspective within the community at large), but I don't think science and religion are as opposed as the cultural narrative would suggest.

Religion, broadly speaking, aims to answer a variety of questions; most foundationally but least importantly "how does the world work?". And science indisputably provides better answers, which is why many theological schools of thought are more than happy to cede their authority in the topic. It free them up to focus on the more important question: "given the world, how best should we live in it?".

It turns out that narrativizing and anthropomorphizing the world around us provides an immensely powerful framing device for thinking critically about community values and for approaching consensus on what those values should be, both across cultural lines and between generations.

In other words it doesn't really matter whether the Torah was divinely inspired or not. It's the grain of sand that the Talmudic pearl accreted around, no more, no less.

vec··on Philosophy Has Made Plenty of Progress
> With Religion, there is nothing you can do to understand it. You can only "have faith". If your spiritual leader or holy book tells you the world is a certain way, you can only believe it, or disbelieve it, you cannot do anything to investigate the veracity of those claims. Truly, this is the most authoritarian of world views: Believe this because I tell you to!

There's a few thousand years of Talmudic scholarship you might want to read up on, just to pick one of the more obvious from among the many counterexamples.

Almost every religion is a much broader and much more intellectually diverse intellectual project than their respective fundamentalists would like you to believe.

vec··on You Want 20% for Handing Me a Muffin? The Awkward Etiquette of iPad Tipping
I am ignoring the commission aspect of the service, because in practice there often isn't any. Tips are frequently pooled, meaning all three servers in your hypothetical would end up with the same cut of the day's take regardless of their personal performance. Besides, if muffin vendors want to incentivize their staff with a commission scheme, why not just incentivize their staff with a commission scheme? Why force the general public to do it (badly) for them?

And the idea that eliminating tips would be "jacking up" prices is exactly the line of faulty reasoning that tips are designed to exploit. The muffin already costs 20% more than the number on the little plaque in front of it claims. Without tips the same amount of money would leave the customer's pocket and the employer and employee would still ultimately split the proceeds from that sale the same way. No prices actually change, but the numbers become a lot more honest and simpler for all parties to reason about.

The truth is vendors don't want prices to be simple to reason about because when they're difficult to reason about the other actors in the system will, on average, tend to make mistakes of reasoning in the vendor's favor.

vec··on You Want 20% for Handing Me a Muffin? The Awkward Etiquette of iPad Tipping
You're right about "rewarding exceptional service" being a lie, but I don't think it's correct to frame tipping as "burden sharing". If the muffin just cost 20% more and the untipped barista got paid a higer wage the burdens would still be split the same. In practice, it seems like tipping serves two main functions, neither of which are great for society at large.

First, it allows businesses to advertise lower prices than consumers will need to bear. It's similar to the American habit of adding sales tax at the point of sale instead of including it in the posted price that way. And because, as a species, we're prone to anchoring effects that causes us to systematically underestimate what the final total will be. That's pretty good for proprietors of service sector businesses, but probably slightly bad for the economy as a whole.

Second, it allows those proprietors to price discriminate a little bit (because price sensitive customers will sometimes buy the service but not tip) while pushing the downside risk off onto their employees.

And that's not even touching the way tips allow customers to de facto discriminate against staff (conventionally attractive people get more tips), or staff against customers ("black people don't tip"), in ways that would be anywhere from suspicious to downright scandalous if they were implemented more formally.

This doesn't mean you shouldn't tip well. You absolutely should, as service workers depend on tips to be fairly compensated for their labor. But tips are a bad idea and there's plenty of reasons beyond social awkwardness to wish they would go away.

vec··on Facebook says millions had phone numbers, search history and location stolen
As to the first point, the headline is "Facebook says millions had phone numbers, search history and location stolen". 2FA phone numbers have to be stored, but they should _never_ under _any_ circumstances be released to other users. Search histories, too, are useful to the user that generated them but shouldn't ever need to be exposed to third parties. Location data can be transient or short lived and still meet most of the technical requirements for the customer-facing features that use them, so I'm not sure there's a good rationale to permanently store it in the first place.

And for where better professional ethics could have made a difference, let's walk backwards through the decision tree for 2FA:

* The implementer of this feature could have used the profile phone #, and the copy could have made it clear that the feature required a phone number on the profile to function.

* The implementer could have chosen to treat the phone number as secure authentication data and taken pains to store it in a manner that was opaque to the rest of the application, say encrypted at rest with a key that's only available inside the auth subsystem.

* The designer of this feature could have insisted on using an authentication app instead of SMS.

* The designer of the authentication workflow could have supported oAuth logins through a third party with good 2FA support, reducing demand for Facebook to support 2FA internally.

* New accounts could spawn with the most restrictive permission settings and require users to affirmatively opt-in to sharing everything they want to, lowering the damage to the median user from an account being compromised and thereby also reducing customer demand for Facebook to support 2FA.

* Facebook could have chosen, early and often, to push for open integration with third parties, building a market segment where they were only one social networking portal among many and no single company had anything close to a complete social graph. In such a world 2FA for Facebook accounts might seem no more urgent than 2FA for, say, Hacker News accounts.

The common thread, at all levels, is that Facebook consistently prioritizes growing faster, collecting more data, and becoming more central to the functioning of the internet over what I would feel comfortable describing as the user's best interests.

I run a website with a few tens of thousands of user records, which means I have been entrusted as a secret keeper for some amount of private information by tens of thousands of people. That's a very tangible burden on me, a weight of responsibility that as part of my job I have to carry. It's also a liability for my employer in the event of a data breach. That means our incentive structure pushes us to store as little data as we can get away with and to expose that data to our infrastructure in the most technically restrictive manner we can get away with.

Facebook chose to build a business around treating other people's secrets as an asset, rather than a liability. That incentivizes them to hoard data and to be cavalier about how they capitalize on it, and lo and behold they routinely behave in accordance with those incentives. When I say a "more ethical business model", this is what I mean. An ethical business is, in practice, one where the incentives of the company and the incentives of its users are not in fundamental tension with one another.

vec··on Facebook says millions had phone numbers, search history and location stolen
> Facebook should have also designed their auth system more carefully, but that's a separate issue.

It's not a separate issue, though. One of the main ways they could have been more careful in designing their auth system was by choosing mechanisms that didn't create "legitimate purposes" for additional data collection in the first place.

This is a recurring theme in every data breach story that comes up. Every thread has someone correctly making the point that the company's business model requires them to store the leaked data, but this is not an excuse. Pick a more ethical business model.

vec··on Survey of YC female founders on sexual harassment, coercion by angels and VCs
Well, for a start, we could be a lot more thoughtful about who we're willing to accept funding from.
vec··on Survey of YC female founders on sexual harassment, coercion by angels and VCs
I think that misunderstands the purpose of non-rigorous surveys like this one, which after all only included the "125 [out] of the 384 female founders who have participated in YC", because that's who had signed up for the mailing list they used. It's a rough estimate, and probably a lowball one given that their survey mechanism excludes any respondents who chose not to maintain ties with YC for one reason or another.

The purpose of this survey is to jump up and down while waving its arms in the air and yelling "WE HAVE A PROBLEM"!

We have a problem.

We don't know the exact size and scope of the problem, but at a glance it looks like it's probably bad. I would love to see reliable data about precisely how bad, including among many other things gender cross-tabs. But that data doesn't exist because nobody's gone to the substantial effort to properly collect and publish it. Maybe, if we're lucky, this report will help to create the political will to bring some of that data into existence.

vec··on An Update on the Security Issue
One underrated option is not to keep extensive personalized records on your entire user base in the first place.
vec··on A Taco Truck on Every Corner, or Not?
If by "nice things" you mean salmonella and grease fires, then sure.

Not to defend Boulder, specifically, but when thinking about regulations it's really easy to tally up "all" of the costs and benefits without crediting them for the nonexistent costs of the bad things that didn't happen.

vec··on Why Paul Romer Won the Nobel Prize in Economics
> "Paul Romer says he really hadn’t planned to trash macroeconomics as a math-obsessed pseudoscience."

If I understand his critique correctly, it's that macroeconomics has used mathematical rigor and internal consistency to mask the common-sense observation that the models' actual connections to the real world phenomena they seek to simulate have almost completely eroded away.

I, for one, can think of a couple of reasons that vein of criticism might not be the sort of argument HN is primed to embrace.

vec··on IQ Matters Less Than You Think
Moreover, our industry has a questionable habit of describing all kinds of human accomplishments as "brilliant" "innovations" done by "geniuses".

Being a competent professional engineer requires some raw intelligence, true, but also determination, interpersonal communication skills, organizational skills, time, training, resources, access to the infrastructure you want to work with, and no small amount of luck. Those all interact in complicated ways, and most can be used to buttress the others depending on where one's personal talents lie.

There's probably some minimum necessary raw intelligence necessary to become a hacker, but I suspect that bar is much lower than HN would like to admit. And I am very sure that there's no maximum past which the rest of the list ceases to matter.

vec··on Voting Machine Used in Half of U.S. Is Vulnerable to Attack, Report Finds
There's a line for a signature that the flap of the envelope ends up glued over the top of. There is no identifying information visible on the outside of a properly sealed envelope.

The envelopes have to remain sealed until they're brought into the room with the election monitors to be counted. If the seal isn't intact or the envelope isn't signed underneath or the bar code under the flap doesn't match the one on the ballot then the ballot is considered spoiled. The actual ballots are wrapped in a "secrecy sleeve" so that the votes can't be seen without unfolding them, and the election monitors separate the envelopes with the signatures from the ballots before they begin counting, so the secret ballot is preserved.

From that point forward they're processed just like any other paper ballots.

vec··on Voting Machine Used in Half of U.S. Is Vulnerable to Attack, Report Finds
I live in Colorado.

A couple of weeks before the midterms I'm going to get a packet in the mail containing my ballot, instructions for filling it out, a pamphlet where every candidate on the ballot gets a paragraph or two to make their case, and a prepaid return envelope. I fill out my ballot at my leisure, stuff it in the envelope, sign the envelope underneath the flap, and drop it in a mailbox. There's a receipt with an anonymous serial number in the packet that I can go online and use to verify my ballot has been received. If I'm worried about missing the deadline there are also dropboxes in most government buildings I can drop my ballot in up through the day of the election, along with a few traditional polling places open on election day.

Voter turnout here is about twelve points above the national average.

vec··on How Blockchain Works
> is remarkably stable - until it is not

I think we're saying mostly the same thing, just with slightly different framing.

We have one mechanism for maintaining a stable store of value (centrally managed fiat) that in practice seems to work well most of the time but periodically experiences catastrophic failures. We have another mechanism for maintaining a stable store of value (crypto markets) where catastrophic failure appears to be standard operating procedure. The first is far from ideal, for all the reasons you mention and many more, but from where I'm sitting it still seems like the lesser of two evils.

Also worth noting that central banks predate fiat currency. Back when currencies were metal-backed governments would hoard or release metal to try and control the market value. That's what Fort Knox is for. It didn't work as well as in fiat-world, because there are bounds to how much metal you can actually manage to store, but it worked well enough. It'll still work well enough when the Fed has a Strategic Bitcoin Reserve that they can manipulate the market with.

> the smart contract would likely require its own level of background on any given ID

Oh, yeah, no halfway competent vendor is going to allow themselves to get scammed like this. And the technical solutions are pretty obvious. My whole point, though, is that we're almost immediately reinventing credit requirements for market participation.

-----

There are a lot of people making starry eyed predictions for exciting new developments that a crypto-based economy would allow to happen, but when you dig into the details the vast majority of those things are just as feasible under a halfway decent centrally-managed ACH system. There are also a lot of people joyously awaiting the collapse of large sectors of the financial system, but again when you dig into the details most of those sectors exist to solve problems and meet needs that are still present on a blockchain.

We've been through half a dozen currency transitions over the past few centuries. From precious metal coins to private scrip backed by precious metal to government scrip backed by precious metal to government scrip backed by fiat to paper transaction logging (checks) to electronic transaction logging (ACH), and the financial sector has not only survived but embraced the infrastructure shift every time.

Don't get me wrong, I've got my fair share of complaints about the modern financial system. But for good or ill I just don't see a fiat to crypto transition having anything close the apocalyptic effects that HN, collectively, seems to expect.

vec··on How Blockchain Works
> Yes, you have paper money in your possession that is only worth as much as a centralized bank SAYS it is...

Do you really want to bring volatility into this? Because in the real world fiats are orders of magnitude more stable than cryptos.

Besides, that's tangential to why people prefer banks to cash. If the Federal Reserve screws up and tanks the dollar I'm just as screwed regardless of whether my money's in a dollar-denominated bank account or a suitcase under my bed. Why do you think the vast majority of people prefer to keep their dollars in the bank instead of the suitcase?

> I am glad that you have no doubt they will be profitable but you are pulling such sentiment out of thin air.

I'm pulling that sentiment out of a basic understanding of a bank's business model and value proposition, neither of which are actually directly related to the underlying currency. We had banks with metal-backed currencies, we have them with fiats, and we're starting to see them with cryptos. Unless you can somehow convince me that Coinbase isn't a bank.

> And the final point, the ledger is open, and everyone can see everything.

Right, I can see that three dozen pseudonymous wallets owe me for 15 minutes of service each.

Anyway, the whole point of credit is I can't actually pay up today, but there's reason to believe I will be able to in 30 days. Or 6 months. Or 10 years.

vec··on How Blockchain Works
I can exchange value today without a banking system in place. I have some paper currency in my possession, and if that doesn't work there are plenty of commodity goods available to barter with. You'll notice that even in situations where cash or barter are feasible the vast majority of actors opt into the banking system anyway.

Cryptocurrencies are genuinely useful for parties who don't have access to the formal banking system for one reason or another, but I've got every reason to believe that crypto-backed banks will still be profitable and that people will flock to them as soon as they're available.

As for microtransactions, I can also consume 15 minutes of some service and not pay for it at 15:01, then automatically generate another burner account to consume another 15 minutes. This might not work for power, since there's physical infrastructure that would have to be cut over, but it would work just fine for a very large number of other services. The service provider is going to pretty quickly generate some fraud prevention strategy to prevent you from doing that, and now we've reinvented credit requirements for market participation.

vec··on How Blockchain Works
"Proof of work" means the total number of hashing functions, from the point of divergence forward, used in signing the blocks.

Consensus doesn't work like you're implying. If it did, I could spin up a peer on N+1 AWS servers, where N is the current number of peers on the network, and now my version has the majority of peers supporting it.

The whole idea behind proof of work is that it's impossible to fake. The version that took the most net computing power to generate is by definition authoritative. This means that the only way to make a malicious version of a chain is to actually, genuinely do more total work than the legitimate actors collectively did. The other side of this coin, though, is that it explicitly allows me to generate a malicious version of the chain by actually, genuinely doing more total work than the legitimate actors collectively did.

vec··on How Blockchain Works
> Bankers go away

People will still need loans. People will still want low risk investment vehicles to "store" their wealth in. At least some sizable number of them will want an institutional actor to handle operational security and insure against key loss.

> auditors go away

The blockchain mostly guarantees that a ledger hasn't been tampered with, but it doesn't guarantee that the transactions were correct and complete in the first place. Plus, it's trivially easy to transfer funds without it registering on the ledger; all I have to do is create a wallet and give the private key to you out of band somehow.

> credit requirements for market participation go away.

There are no credit requirements today, as long as you're only spending funds you have on hand. Credit requirements allow an actor to spend funds they don't actually possess with a reasonable expectation that they will be willing and able to produce those funds (plus interest) at some later date. Having the ledger public reduces, but doesn't eliminate, the need for the actual providers of those temporary funds to want to form some expectations of future performance.

Most of the ancillary infrastructure that's grown up around fiat currencies is there for really good reasons, and most of those reasons don't automatically go away when the underlying currency type changes.

vec··on How Blockchain Works
Nope. The whole point of proof of work is that it informs clients which version to consider authoritative in the case of a conflict. If my tampered copy has higher proof of work than the peer with the correct version then, by definition, mine is correct and the other peer's is outdated. Correctly implemented peers will recognize this and overwrite their local cache with mine, and even if they don't other peers will always prefer my version to theirs when deciding which update to sync.
vec··on How Blockchain Works
> Programmable blockchains allow generalized applications requiring decentralized trust.

Yeah, they don't really though. They allow a few extremely specific applications requiring decentralized trust. The trust guarantees only hold if no single party can, even momentarily, control more hashing power than was collectively used to generate the last X blocks, where X is number of updates made since the data you want to tamper with was inserted.

To put it in concrete terms, pretend we have a blockchain for publishing PGP keys, and that your public key is 10 blocks down in the chain. If I want to maliciously replace your key with one of my own then all I need to do is rent a few dozen servers off of AWS for a day or two and use them to generate a modified chain that has my key instead of yours in the 11th block down and then rehash all ten blocks spending slightly more compute power each time than the original committers did. The network will recognize my fork as the authoritative one because it's got more proof of work. That's expensive, but it's certainly not infeasible.

This trust mechanism works out for cryptocurrencies because their only value is monetary. That means that people are incentivized to set up mining rigs to spend a lot of real resources on mining because they automatically get compensated. It also means that there's a bounded maximum amount of effort that a rational actor will spend to tamper with the chain, because there's a finite limit on the available profit to be gained.

Neither of these are true for PGP keys. Publishing a secure update to a PGP key database is not, in and of itself, a profit generating enterprise, meaning fewer miners and far less resources spent per mining rig. And the potential upside of successfully tampering with the right key is enormous.

The actual mechanism which produces the security guarantees in blockchains isn't cryptographic, it's economic. Tampering with a cryptocurrency's blockchain isn't actually impossible, or even difficult, it's just by definition more expensive than it's worth. When you try and move to an application other than financial assets the economics break down, the security guarantees go out the window, and all you're left with is an extremely inefficient git clone.

vec··on How Blockchain Works
Yes, but if you have a mechanism (either technical or institutional) that you trust to attach real-world goods to your blockchain in a sufficiently correct and tamper-resistant manner, why not just let that mechanism manage your ledger directly and skip the blockchain entirely?
← PreviousPage 2 of 13Next →