HN user

patio11

127,807 karma

Howdy. I'm Patrick. I work for the Internet. Previously: Stripe, Starfighter, Appointment Reminder, Bingo Card Creator.

site: https://www.kalzumeus.com financial infrastructure writing: https://www.bitsaboutmoney.com podcast: https://www.complexsystemspodcast.com

My best email is patrick@ the top domain. Open invitation: if you're reading this, I'm happy to receive email about any software/startup/etc topic from you at any time. I generally reply to about 60% of unsolicited email from HNers, and if I don't reply to you, it is only because I got busy, not because of anything you said.

I write a lot. What I write here is unless otherwise stated in my personal capacity, and opinions expressed may not be shared by employers, clients, friends, etc.

Posts52
Comments10,388
View on HN
blockchain.info 12y ago

A Bitcoin Address with 782,000 BTC Moved Through It

patio11
189pts112
news.ycombinator.com 14y ago

Slicehost STL-A is down

patio11
9pts1
blog.fogcreek.com 15y ago

“Our Marketing Is Up Fog Creek” And What We Did About It

patio11
393pts88
www.seobook.com 15y ago

Why Content Farms Are Here To Stay

patio11
11pts1
mygengo.com 15y ago

Work/Life Balance at Startups

patio11
7pts0
info.groupon.jp 15y ago

Groupon CEO Apologizes For Poorly Executed Offer In Japan

patio11
65pts43
www.kalzumeus.com 15y ago

Quantifying The Value Of A College Degree (By Major)

patio11
143pts73
www.kalzumeus.com 15y ago

Bingo Card Creator (etc) Annual Report

patio11
288pts88
www.appointmentreminder.org 15y ago

Appointment Reminder Launches

patio11
238pts104
www.kalzumeus.com 15y ago

How To Use SSL To Secure Your Rails App Against e.g. FireSheep

patio11
115pts43
www.kalzumeus.com 15y ago

Lessons Learned At Business of Software 2010 Conference

patio11
142pts13
www.bingocardcreator.com 15y ago

Clicking Facebook "Like" Buttons Gives Owner Permission To Spam You (w/ demo)

patio11
139pts52
www.reddit.com 16y ago

What Divvy's Redditing Following License Giveaway Did For Business

patio11
23pts3
www.kalzumeus.com 16y ago

The Most Radical A/B Test I've Ever Done

patio11
127pts32
www.kalzumeus.com 16y ago

Rate my new startup, Appointment Reminder

patio11
195pts162
www.kalzumeus.com 16y ago

Dropbox-style Double-Sided Incentives for Sharing

patio11
62pts12
blog.kevindonaldson.me 16y ago

Slides, Video, & Notes for most of Startup Lessons Learned Conference

patio11
7pts0
www.kalzumeus.com 16y ago

Building Highly Reliable Websites For Small Companies

patio11
121pts23
www.kalzumeus.com 16y ago

Running a Software Business on 5 Hours A Week

patio11
359pts78
www.bingocardcreator.com 16y ago

Panic-inspired Dashboard Made From Photo Frame for ~$150. Code is OSS.

patio11
157pts42
www.kalzumeus.com 16y ago

Dashboard Design For Metrics-Savvy Software Companies

patio11
31pts4
lostgarden.com 16y ago

Using Game Mechanics To Teach Users MS Office

patio11
38pts18
www.kalzumeus.com 16y ago

Strategic SEO for Startups

patio11
137pts24
www.kalzumeus.com 16y ago

Will single founders please stand up? (Musical edition.)

patio11
97pts26
www.kalzumeus.com 16y ago

Visualizing Your Commit History

patio11
13pts1
www.kalzumeus.com 16y ago

Engineering Your Way To Marketing Success

patio11
109pts20
www.kalzumeus.com 16y ago

Bingo Card Creator Annual Report

patio11
164pts38
www.kalzumeus.com 16y ago

Practical Metaprogramming with Ruby: Storing Preferences

patio11
39pts7
www.kalzumeus.com 16y ago

The IE CSS Bug Which Cost Me A Month’s Salary

patio11
152pts85
www.kalzumeus.com 16y ago

How To Do A Seasonal Promotion For Your App

patio11
10pts3

The thing which is beyond intellectually serious dispute is industrial-scaled fraud.

You keep wanting to make me "own" the CCAP's estimate. I will not reciprocally try to make you "own" $5 million, because I am charitable and because history has been unkind to the officials who made it.

I do ask you to own: "Minnesota HAS NOT suffered industrial-scale fraud across several social programs." Otherwise this is judging a high school debate competition, and I've had better.

The way I phrased that point was "The investigators allege repeatedly visiting daycare centers which did not, factually, have children physically present at the facility despite reimbursement paperwork identifying specific children being present at that specific time. The investigators demonstrated these lies on timestamped video, and perhaps in another life would have been YouTube stars."

<LLC voice> We have reviewed your feedback on our editorial choices, and are comfortable that we have characterized the claims in the report accurately. We stand by "Minnesota has suffered a decade-long campaign of industrial-scale fraud against several social programs. This is beyond intellectually serious dispute." This is editorial analysis, informed—as is stated in the plain text—by the experience of several programs. Feeding our Future, for example, is cited in the piece, with analysis. It has resulted in dozens of convictions and guilty pleas, and federal prosecutors characterize it as having defrauded the public of nine figures.

You are welcome to your own opinion as to what could motivate a publication which routinely writes about fraud and finance to write about fraud and finance. Past issues you may enjoy include a year-long investigation into a single incident of fraud in NYC, a topological look at the fraud supply chain in credit cards, discussions of how the FTX fraud was uniquely enabled by their partner bank failing to properly configure their AML engine, and similar. </LLC voice>

FoF claimed to supply meals at the same physical locations as CCAP and paid the same owners. As mentioned, one of nine of the operators profiled, who was previously raided in an investigation into alleged overbilling of CCAP, received $1.5M from FoF. FoF is in fact not a federal nutrition program but actually the name of a non-profit which received grants from a federal nutrition program for forwarding to third parties. CCAP is also funded by federal block funding.

The Swanson memo memorializes the consensus of his investigatory group and, put to question by OLA and legislators, they stick with that story:

Page 14 of PDF:

[The OLA] did not find evidence to substantiate Stillman’s allegation that there is $100 million in CCAP fraud annually. We did, on the other hand, find that the state’s CCAP fraud investigators generally agree with Stillman’s opinions about the level of CCAP fraud, as well as why it is so pervasive.

(Stillman is a line level investigator who gave a media statement which was explosive. Swanson, who authored in the internal memo, was his manager.)

I do mention that other officials only agreed to characterize as fraud fraud which had resulted in convictions. We now, years later, have nine figures just from the convictions (and guilty pleas). These officials pointedly refuse to put any number on fraud other than the number incident to convictions.

Moreover: you should be very clearly correct if you accuse someone of citing a document as making claims it does not say. That is a serious accusation. BAM's citation of this piece is "the state’s own investigators believed that, over the past several years, greater than fifty percent of all reimbursements to daycare centers were fraudulent." This is _absolutely true_ and _is in the report as claimed_.

I am quite likely to do a more formal writeup in the next few weeks, unless Zvi beats me to it. (He had, apparently, directionally similar results.)

As I note frequently, I have a small pile of thank you letters as a result of the negotiation piece. Very few are written by people with an outsized public profile.

How many people do you think would hit that bar in the industry? Hundreds? I have hundreds of letters with numbers attached to them to say nothing of how many people simply negotiate, get the comp bump, and do not feel the need to email me about it.

(I worked at a different processing company, which I am not speaking for.)

We're struggling to find the motive or intended outcome by the attacker(s).

The highest likelihood for me is that they're doing card/credential testing. They have either stolen or purchased a large number of stolen credentials. Those credentials are worth more individually if they are known to function. They can use any business on the Internet which sells anything and would tell someone "Sorry, can't sell you that because I couldn't charge your account/card/etc. Do you have another one?" to quickly winnow their set of credentials into a pile of ones which haven't been canceled yet and another pile. Another variation of this attack is their list is "literally just enumerate all the cards possible in a range and try to sift down to the cards that actually exist."

After sifting through to find the more valuable cards, they sell this onto another attacker at higher price of the mixed-working-and-not-working cards, or they pass it to their colleague who will attempt to hit the cards/creds for actual money.

Digital items are useful because people selling them have high margins and have lower defenses against fraud as a result. Cheap things, especially cheap things where they can pick their price, are useful because it is less likely to trigger the attention of the card holder or their bank. (This is one reason charities get abused very frequently, because they will often happily accept a $1 or lower donation, even one which is worth less than their lowest possible payment processing cost.) The bad guys don't want to be noticed because the real theft is in the future, by them or (more likely) by someone they sell this newly-more-valuable card information onto.

This hit the company I used to run back in the day, also on Paypal, and was quite frustrating. I solved it by adding a few heuristics to catch and giving a user matching those heuristics the product for free, with the usual message they got in case of a successful sale. This quickly spoils your website for the purpose they're trying to use it for, and the professional engineering team employed to abuse you experiences thirty seconds of confusion and regret before moving to the next site on their list. Back in the day, the bad guys were extremely bad at causing their browser instance to even try to look like a normal user in terms of e.g. pattern of data access prior to attempting to buy a thing.

Hope some of that is useful. Best of luck and skill. You can eventually pierce through to Paypal's attention here and they may have options available contingent on you being under card/credential testing attack, or they might not. I was not successful in doing so back in the day prior to solving the problem for myself.

Would also recommend building monitoring so you know this is happening in the future before the disputes roll in. Note that those disputes might be from them or from the legitimate users depending on exactly what credentials they have stolen, and in the case they are from legitimate users, you may not have caught all of the fraudulent charges yet. (Mentioning because you said "all of the charges" were disputed.) If I were you I'd try to cast a wider net and pre-emptively refund or review things in the wider net, both because the right thing to do and also because you may be able to head off more disputes later as e.g. people get their monthly statements.

She does not misrepresent her wealth in her article. At no point does she claim to be scraping by.

A direct quote:

Initially, I was afraid that I wouldn’t be able to afford my taxes this year, but then my accountant told me I could write off losses due to theft. So from a financial standpoint, I’ll survive, as long as I don’t have another emergency — a real one — anytime soon.

I quote several more bits from the piece verbatim.

I seem to have set you off somehow, and I do not understand precisely how, but I feel this is important: I did not publicly accuse the writer of anything. (I did heavily imply publicly that I thought that the publication had no real fact checking; when they told me otherwise, after I requested a statement, I swiftly corrected that publicly.)

I had some doubts that the story, as presented, was true. I did what I hear journalists do, and went out and reported the story. Some people apparently believe this was an aggressive action, and some people believe that the original story was strictly true, and I can understand either of those beliefs separately but holding both at the same time seems tricky.

I did not believe that New York Magazine was complicit. I harbored the suspicion that they might be incompetent. This suspicion was exacerbated by unambiguous evidence of them being incompetent, in failing to detect that a 17 year old claiming to have made $72 million trading stocks, and then doubling down on that story because their fact-checker had passed it.

You have made, in this thread, several claims that I am wildly miscalibrated with respect to banking procedure. I do not believe I am. For example, I seem to be able to make confident predictions like "Oh, if the teller window is on the second floor, that narrows the selection of bank branches sufficiently to be probably uniquely identifying given any other piece of information" and be proven retrospectively right on those predictions.

If you would like to take issue with my other claims about banking procedure, pick the one that looks fishiest to you, and then propose odds.

Tiny correction: in 2010, I invented a thing parallel to something many well-educated Americans of my acquaintance believe with respect to the centrality of their experience, for the Falsehoods essay.

In 2012, a clerk actually asked my wife and I, when we got married, whether it wouldn't make more sense for me to change my name. Then he wouldn't have to spell Patrick McKenzie on the wedding paperwork, and, approximate quote, "I already have to get one name change form out for her so filling out a second one is no trouble at all."

This is occurring against a backdrop of e.g. hearings of the U.S. Senate Banking Committee. I regret to inform you that the broader issue is of great interest outside our circles.

One of the three witnesses the Senate Banking Committee chose to call requested, the following day, a retraction from me… for reasons.

I certainly did not see this ever happening when I started selling bingo cards on the Internet, but here we are.

They literally have no computer system that can tell them the difference between you and a hedge fund manager, and so an email to IR fairly reliably gets the white glove treatment. I used to send them on behalf of, cliched but accurately, Kansan pensioners to banks, in at least one case justified by “I am a shareholder because my IRA holds SPY, which holds your common. It was therefore with great displeasure that…”

(Obviously one can still email IR without actually owning a share, but I both prefer not lying and also enjoy the aesthetics of capitalism, which are extremely invested—ba dum bum—in seeing someone who owns one share as a shareholder.)

Anyhow: bored person, near top of org chart, with access to escalation group if that exists, who earns six figures and really wants you to come away from the experience satisfied. Exists in almost every publicly traded company in America.

I could have quoted the roadshow verbatim in support of the point, but it felt tangential. The point is not “Chicago is on the precipice of a pogrom.” It is “political elites in Chicago’s African American community believe the community is impoverished in part because of extractive practices of vice entrepreneurs, and required as a condition of their political assent that Chicago keep equity ownership of a vice business in their community.”

The point is a true one; this _really is_ what some community leaders believe. This belief _really is_ why Chicago is doing this program.

“Tonight is about a new opportunity on how to participate, about not just being a consumer but to be an owner,” Ald. Ronnie Mosley (21st Ward) said at the pulpit in front of the crowd of a couple hundred people.

https://thetriibe.com/2025/01/chicagos-black-residents-can-i...

There is much more support for that having actually been the sales pitch and political compromise there and elsewhere on the record.

And yes, this is a belief with a long and storied history in American politics.

Does your envisioned product allow someone to direct deposit a paycheck? Then congratulations, it is a credit account, because a) we expect to spend paychecks including very soon after receiving them but b) payroll companies sometimes screw up payroll and can in some cases pull the money back.

Japan had a similar policy, with respect to legal immigrants it had made a point of recruiting, in the immediate wake of the global financial crisis. They'd buy (largely) Peruvian/Brazilian factory workers of Japanese descent a plane ticket and approximately $3k of compensation (IIRC) in return for them surrendering their work-compatible visa.

It was controversial, from a number of angles.

https://www.nytimes.com/2009/04/23/business/global/23immigra...

Depends on the country and weight class of the financial institution, but among e.g. U.S. money center banks, branch bankers have been successively de-skilled for the last ~3.5 decades or so.

It is still nominally a white collar occupation but has, indeed, suffered in terms of prestige, compensation, and socioeconomic makeup of workforce versus other middle class mainstays, against a backdrop where the upper edge of the middle class is doing exceptionally well for itself.

Citation available if I Google for the academic papers but the handwavy version is “I write about this sort of thing for a living so uh self-cite for the moment.”

With the limited roll out, it wouldn't take much capacity for individual sites to schedule their available doses.

You'd think so, right. You'd think that the state of California was certainly able to successfully inject more than 25% of doses delivered in January 2021, right. You'd think that simply calling around for places that had nobody coming in could not possibly work, right.

A thing that continues to blow the minds of many: there is literally no one whose job it is to generate demand for most doses at most locations which were allocated doses. This was entirely on a pull model. If there was no pull, then they would have sat in the freezer until discarded.

This didn't just strand doses in the freezer at places like Rural Clinic For Low-Income Farm Workers Who Accidentally Got A Supersized Allocation Due To Political Considerations. It stranded doses in the freezer at e.g. the third largest pharmacy chain in most well-populated cities because people called the first largest, heard a No, and then assumed "Well if they don't have it clearly no one has it."

Bureaucracies don't punish people for mistakes. People get punished for non-compliance.

It is a bit remarkable that nobody in California will take either a career or political hit for instituting a policy of redlining [0] in the provision of medical care, in the clear light of day, despite that being very obviously illegal, but that we actually literally prosecuted people for end-of-day shots. It calls to mind that mind that Joker quote: "Nobody panics if everything is going according to plan, even if the plan is horrifying."

The health equity experts and medical ethicists were enthusiastically onboard with redlining. And so we redlined.

[0] Access to medical care early was conditioned on living in the correct zip code, and there was a list of priority zip codes adopted by the state as a result of a coalition of county health offices pooling their resources to create that authoritative list. That list was designed, and I am using that word very deliberately, to proxy for race of residents of those zip codes.

De gustibus non est disputandum; there are some things that ruin many people's lives that have no appeal to me, there are some things many people enjoy responsibly that I have learned to stop myself from using because I will not make good decisions over a period of years, and then there was that freaking cat song, which gave me the strongest "WARNING: Your brain is not in control of your response to this song, in a way which is qualitatively different than the usual ways music is moving." when listening to it that I found it remarkable.