HN user

yajoe

973 karma

Completely agree:

- https://news.ycombinator.com/item?id=4685928

- https://news.ycombinator.com/item?id=5386096

And, wow: https://news.ycombinator.com/item?id=5906001

https://news.ycombinator.com/item?id=7360570

Eloquent as an understatement: https://news.ycombinator.com/user?id=simonsarris

Posts1
Comments141
View on HN

$0.02 regarding the name of the feature, which I think anchors too much in the "censorship/free speech" principle discussion when it seems you have much more tactical goals (moderator workload, foster specific topics, etc.).

Consider renaming the feature from "pending comments" to "civility filter." In prose one would say Moderators now can require civility via special-purpose moderation on specific threads.

Similarly, consider changing the "[pending]" text to "[Pending civility check]" and changing the "endorse" link to "Affirm civility" (or just "Civil" to keep with one-word nav elements).

Why?

"All speech must be endorsed" --> "Bad Thing"

"All speech must be civil" --> "Good Thing"

This is an interesting feature, and certainly not something I would have expected as the "next" feature to add. When I read "pending comments" I expected something similar to slashdot's old "preview" feature so one could double-check spelling, formatting, etc. i.e. preview the post before submitting to HN. I would not have expected "pending" to mean "pending moderation" given the successful voting feature here.

I would ask what the goals of the change are, but they seem obvious:

1) Limit nastiness and negativity

2) Encourage deeper and pensive comments

3) Cynically, it seems like a private goal would be to limit criticism of YC, though I know this would never be a stated goal. The criticism may simply have increased the priority even though HN has seemed more civil in recent months as an outside observer.

While the change may achieve these results, I would expect the following effects:

1) Fewer comments overall (there is a new "tax" to post, so-to-speak) and as a result there will be fewer visitors in the medium term (sites like HN, reddit, slashdot, huff post, etc all thrive on both the quality _and_ quantity of comments since that's what entertains people). Without controlling the number of front-page stories, you will in effect decrease the available content for viewers to consume. The demand will be filled elsewhere. I always assumed there was a private, invite-only forum for YC and that you would leave HN alone as a great PR platform... this move makes me wonder some more.

2) Comments will trend towards the quality of bane, tokenadult, ChuckMcM, patio11, cperciva, etc (we all know them) at the risk of fewer "provocative" posts. Often the greatest quality posts, however, are in response or to contradict simple-minded or provocative posts.

3) I am concerned by this line: People who regularly endorse comments that fail one or both of these tests will lose the ability to endorse comments. I like meta-moderation and all, but I don't like being reminded that all actions are recorded and tied back to my account. I would ask for some separation between "endorsing" and "agreeing" -- as a continual skeptic, I like reading and promoting contrarian views since it helps us learn.

I look forward to watching the experiment, and as a parting request, would you be able to record and measure the goals? There must be a YC company that can help with that, and I imagine it would be a wonderful blog write-up!

For those who don't know, Greg is one of the common faces of the Seattle VC scene. He is a staple at nearly every startup event -- Startup Weekend, Geekwire events, TechStars, VC panels, etc.

I don't have a dog in the fight, but I did spend some time reading the actual bill since these blog articles felt like more political campaigns than informative pieces. The last time this came up I posted https://news.ycombinator.com/item?id=7303232

The Seattle city council passed a law that made so-called "ride sharing" services legal after intentionally withholding prosecution for over a year. The law isn't perfect, but it does feel like it strives to balance protecting existing investments with new services. The most salient changes about the bill:

1. Seattle defines uberX, Lyft, etc as Transportation Network Companies (TNC) and declares all drivers as "for-hire" drivers, which is a legal distinction that means Seattle can regulate them.

2. TNCs are taxed at $50k for first year. Second year is the greater of $50k or .35% of gross revenue.

3. No more than 150 drivers may be associated with each TNC at a time, and each driver can work only 12 hours per 24 hour period. Previously the law would have limited 300 drivers per TNC per quarter regardless of who was active, and this was "the cap." For comparison, there are 1100 taxicabs in the city.

4. Drivers can't double dip: They can't both drive for-hire cars and also do uberX on the side. They also can't work for both uberX and Lyft.

5. Rates may either be flat-rate between preset zones OR subject to RCW Chapter 19.94. RCW Chapter 19.94 defines appropriate measurement devices that may be used with commerce, which I think precludes most cell phones... uberX would need to install meters it seems and precludes surge pricing.

6. The insurance requirements are stricter than what uberX or Lyft provide today and are mostly in line with existing taxicabs.

7. There was a 30% increase in the cap on cabs at the same time.

8. TNCs have to report their activities to the city, which will be available to the public for inspection.

Don't have a dog in the fight, but interesting how the uberX page doesn't mention specifics of the proposal beyond "put hundreds of drivers out of business and effectively shut UberX down." Where are the links? The specifics?

The actual proposal may be found on the city's site [1]. It also would help to provide some context for the types of changes, which both an opinionated summary from the local newspaper [2] and somewhat impartial summary from a local tech site [3] do fairly well.

For the tl;dr who don't want to click away:

1. Seattle defines uberX, Lyft, etc as Transportation Network Companies (TNC) and declares all drivers as "for-hire" drivers, which is a legal distinction that means Seattle can regulate them.

2. TNCs are taxed at $50k for first year. Second year is the greater of $50k or .35% of gross revenue.

3. No more than 300 drivers may be associated with each TNC (it's a permit lottery regime, if you are curious), and each driver can work only 16 hours.

Yes, that means that each TNC is limited to 300 x 16 = 4800 hours of work per week. A previous proposal had a limit of 100 drivers [5]

4. Drivers can't double dip: They can't both drive for-hire cars and also do uberX on the side. They also can't work for both uberX and Lyft.

5. I can't find a cap on the number of TNCs that will be licensed, even though that seems to be one of the (perhaps past?) sticking points.

6. Rates may either be flat-rate between preset zones OR subject to RCW Chapter 19.94. RCW Chapter 19.94 [4] defines appropriate measurement devices that may be used with commerce, which I think precludes most cell phones... uberX would need to install meters it seems.

Details likely only I will find interesting:

1. TNCs have to have valid insurance for all vehicles, and this insurance looks like it is stricter than what uberX and Lyft currently have.

2. TNCs must have an office in Seattle that is open and personally staffed all business days between nine a.m. (9:00 a.m.) and five p.m. (5:00 p.m.) with toll-free number

3. The TNC shall submit to the Director a report detailing all rides that were requested but not accepted by TNC drivers. The report shall include the location and zip code of each rejected ride. There are penalties for discriminating against underserved zip codes.

4. 30% increase in the total number of taxicabs, including an immediate increase of 8% "today. "

[1] http://www.seattle.gov/council/issues/taxis.html

[2] http://blogs.seattletimes.com/opinionnw/2014/02/14/seattle-u...

[3] http://www.geekwire.com/2014/seattle-delays-ride-sharing-vot...

[4] http://apps.leg.wa.gov/rcw/default.aspx?cite=19.94

[5] http://www.geekwire.com/2013/sidecar-uber-express-disappoint...

Edit: Formatting and spelling

Similar to another poster, the only person admitted to MIT from my high school 10 years ago out of a class of 1200 from a wealthy suburb was the daughter of an alumnus who ran the interviews for the region. I just find it hard to believe Legacy doesn't play a factor even if there is no checkbox on the admission forms. The father stopped running interviews the year she got in.

Even Harvard, Stanford, and Yale each admitted 3 people that year (which, interestingly were different people -- it's as if they colluded to induce enrollment).

totally off-topic, but because of the SOPA nonsense I've slowly moved my 40-or-so domains to namecheap during 2013 when their renewals came up. I was otherwise ambivalent about which DNS service/registrar to use before that incident...

but thank you for helping the guy get his twitter account back and fixing up the internal controls.

This is a good question about the macro US economy. In general I agree with GP.

Fact: The Fed has injected large amounts of cash into the asset markets using http://en.wikipedia.org/wiki/Quantitative_easing . I've never added up the cash as a percentage of GDP or one of the Ms, but it always seemed significant (i.e. 5-10% of GDP, but this is debatable). I should caveat by saying that this cash never entered general circulation, which has meant treating it as part of the monetary supply is tricky.

Now, based on this fact of Fed intervention there are a few opinions:

1. While the Fed directly isn't buying equities (i.e. stocks, but this is as far as we know), its presence means that all the other cash holders have to seek out other investments to get inflation-beating rates of returns. There isn't hard data to support this, but it is the conventional wisdom of both people in the game and macro economists.

2. The magnitude of the impact on the asset markets is up for debate. I've seen numbers as low as -5% and has high as 60% of last year's stock market returns can be attributed to the Fed intervention. Some of the difficulty is that there was large federal fiscal stimulus impacting during this time, and counter-intuitively there is some argument that the Fed neutralized the fiscal stimulus to hold inflation rates constant. The important part is that there was a stock market surge, and it is not a result of retail investors pouring in money: It is a result of institutions balancing away from bonds to stocks (this is what the GP means by "supply-side"). It's just not clear if the institutions did it because they have confidence in the economy or if they were "forced" by the Fed. The "why" is opinion, and many people believe the fed is the "why."

3. On the micro side, seeing 20-something kids get 150k budgets to screw around for a year is maddening. "It's ok, VCs play the numbers game... we just need one tulip to pay 100x." There is too much money chasing "talent" right now, and should the correction to the asset market happen this year (as I predict from the fed's cessation) then we will see the startup bubble unwind.

Agree on needing comments.

My C++ is a bit rusty, but I think the code is in fact checking if the number is divisible by 2 (i.e. n % 2 == 0).

I think it's using the bitwise and operator (single &) to AND each bit in n and (n-1) and then checking if the least significant bit is 1 or 0. The code would need to shift (<< or >>) to check if the number were a power of 2.

I thought there was another bitwise NOT operator, not the !, but I think, and this is the part I'm hazy on after getting home, that the ! applied to an int is intended to flip each bit. Here's why:

------------

n = 6 = 110

n-1 = 5 = 101

n & (n-1) = 110 & 101 = 100

!(110) = 001 => true

------------

n = 5 = 101

n-1 = 100

n & (n-1) = 101 & 100 = 101

!(101) = 010 => false only if the least significant bit is used for logic decisions... this seems non-portable for some reason, just like using the ! as a bitwise NOT. It may actually be that ! only looks at the least significant bit, but I can't find c++ docs to say one way or another.

Whatever the code actually does, this is exactly the kind of example to use as a poster child for adding just a few comments.

Thanks. We've been segregating authenticated vs non-authenticated traffic to different domains for a few years now (we had the same realization as moot), but I was unaware about this specific exploit related to TLS compression.

That said, it seems on nginx TLS compression was not enabled by default, so we are ok (for this known vulnerability).

Don't forget to disable TLS compression and HTTP compression for pages containing session ids or CSRF tokens.

Dumb question: Is this general advice or is it specific to django due to the "BREACH" [1][2] https attack? It's not clear if it the underlying flaw is in using a CSRF token or something specific to django's implementation. I had never heard this before, so thank you.

[1] http://news.softpedia.com/news/Django-BREACH-Attack-Against-... [2] http://stacks.11craft.com/what-is-breach-how-can-we-protect-...

This isn't as serious of a proposal as some of the W3C documents on how XML and WS-* works with my name on it (among many, many other smarter people)... and I have a lot of sympathy for someone who had to deal with Win32 APIs (they are locally optimized but globally bad).

I have no love for XML, but the details tend to matter. And you are right that saying "use HTTP" is a bit hand-wavy. XML is great at serializing nouns when you want to enforce the schema of those nouns. It makes interop of nouns, verifying, quantifying, and some types of searches must faster and consistent. XML was a reaction to widespread RPC and endless bit-order compat that wasted so many lines of code. It comes from the same mindset as the people who made SQL -- "conforming to schemas is good and what most people want."

However, in the last 10 years we've seen that it isn't possible to conform to a single schema as requirements change, and that is why XML has generally lost favor to JSON. This is a similar reason why NoSQL wins in many cases over SQL.

HTTP, in contrast to XML, is a set of verbs (called methods) and identifiers (typically urls), which is similar to what a file system is. It leaves the nouns (the body in HTTP) to the application, but it does promote some properties (headers in HTTP) and have conventions for common properties (content-type). The big difference between HTTP and most file systems is that HTTP is stateless, whereas many file operations are stateful (get a handle to a stream, write to a stream, close the stream).

HTTP would work as the API for a file system because it provides pretty good addresses for both local and remote and relatively low-level operations.

HTTP also has the benefit of being widely adopted, even during the Cairo development, which would have solved the chicken-and-the-egg problem from the first essay.

Using HTTP as a file system has key drawbacks: Applications would have to be re-written to use both the new APIs and new mindset of possibly high-latency operations. You can't always assume that a particular endpoint will be available, unlike many assumptions about inodes.

So, do I think they should have done this? Maybe, there were a lot of variables at play. But, I don't think it is a crazy idea to use HTTP as the file system, and I predict we will see a popular -- nay, credible -- operating system use it within the next 5 years.

And I also think it's telling that even in the post-mortem hindsight, the author fails to see alternatives that were widely available in the industry because they weren't invented at Microsoft.

I love this read, and I would love to read entire books of people from the trenches making software. However, most of the specific details Hal cites are... well... dated from someone who learned the craft in the 1980.

This line struck out to me as especially myopic:

Most of the world of commerce we are used to was made possible by the creation and growth of the concept of Structured Storage. The modern world of Credit Cards and ATMs is 100% predicated on this work. Amazon.com was in the realm of science fiction in the 1940s. By the 1970s the conceptual basis for everything you needed to create it was in place. It took until the 1990s for those concepts to mature sufficiently to let Amazon happen.

I can't put my finger on why this seems wrong, and it could be such a strong contrarian view I need a moment to accept it. I feel like the 1990s .com boom AND the modern social boom may depend on structured storage, but structured storage certainly isn't the sufficient condition.

Reading through Hal's prose, it struck me that HTTP is the very thing Hal set out to build, and it seems that since he was so focused on file systems he missed another obvious technology choice from which to draw. Would it have been dog slow for every application to make local HTTP requests to read files? Heck Yeah. Is it insane? Yeah. Would it have been slower than what they built? I don't know...

And HTTP was so well understood and supported it would have allowed applications to start to mix content from local and remote sources, what we effectively have with pure JavaScript apps today. But HTTP was a standard, and Microsoft from those days was allergic to standards. Alas, someone will eventually build a JavaScript-based OS that treats all files as HTTP endpoints.

And then we'll get photos to sync with metadata. Just saying.

It's also weird that they didn't explain the how behind this line:

Instead of serving images directly from their original external host servers, Gmail will now serve all images through Google’s own secure proxy servers.

In most cases, the unique identifiers are embedded in the URLs themselves, so simply serving through a proxy is ineffective. Should I blindly trust that you, Google, did the right thing?

Edit: looks like Google isn't stripping out the query parameters AND it isn't proxying for iOS devices! This is by far the least effective set of decisions... http://blog.movableink.com/gmails-recent-image-handling-chan...

I wonder if this change is a result of backlash over the promotions tab. These type of referenced images are most commonly used in marketing campaigns and were from businesses likely to pay good money to AdWords. As a concession for fewer overall impressions, perhaps, these groups got Google to let them track easier? The whole thing smells fishy.

Yes, many public stocks on major exchanges are just other forms of currency. It just depends on whether the underlying asset is highly liquid (which implies easy to trade, confidence it will exist in short and long terms, etc). I would humbly submit not to get hung up on the word 'virtual' since the practice of using stocks as a liquidity source (and at times to actually print money) have been done a few times in the past.

My favorite example is from the 1890s: Amalgamated Copper

Summary: http://www.jstor.org/stable/1884999

Book describing the process of getting banks to print money by ficticously reporting assets: http://www.gutenberg.org/ebooks/26330

Had the author written the book today, he would compare the practice to quantitative easing or injecting liquidity: http://en.wikipedia.org/wiki/Quantitative_easing

The big difference? Amalgamated Copper was a private entity whose owners used fraud and banks to print them millions of dollars.

Like you, I place little weight on the findings from a few keyword searches. Such vacuous analysis.

That said, there are a few incentives in play for the "X for Y" or "<this> for <that>" language and why to use it over more simple, implementation-free descriptive text:

1. Newly-entered startups: Your wonderful description about why it is more efficient. See above :)

2. <this> companies (the Ubers and AirBnBs): Having other people constantly repeat the Uber and AirBnB label is brand advertising. Period. The Uber and AirBnB brands have good penetration in the HN demographic, but they are unknown to >50% of the US and >70% of the world. Those companies need advertising to fuel growth, so they have an incentive to encourage this practice since it's free for them AND a lot of startups are getting press in the midwest, etc.

3. <this> Stakeholders (investors, accelerators, etc): Moreover, using <this> in the context of another upstart business suggests that <this> was successful. When you say Uber for pizza, you are suggesting that Uber is both a successful model and a successful business. That makes both Uber and Uber's Stakeholders look really good. It's a form of social proof, which is especially valuable in this boom.

And remember, the Stakeholders eventually make their money in an IPO and not from direct profits. These Stakeholders have a strong incentive to convince others that <this> is a good business and worth mimicking in another market. "Look at all the others who followed suit." The Stakeholders need more fundraising rounds. And at a place like YC, you'll hear how it's a good idea because when you go looking to find the <this> that matches you, you're more likely to pick a <this> from here.

And at the end of the day, using "X for Y" is co-branding ( http://en.wikipedia.org/wiki/Co-branding ). It is a tool that has positive and negative aspects. In some places saying you are "Uber for pizza" means you are willing to skirt local health codes to deliver pizza faster than it takes to cook...

My advice is to recognize the "<this> for <that>" as a derivative of co-branding, and to understand the incentives in play for the advice on how to use it.

Completely agree, and I didn't know this practice had spread so widely. While doing the HR-sanctioned stack ranking requires X > MIN_POP_SIZE, in practice each line manager (i.e. lead) provides a pre-sorted list up the chain for merge-sorting. That way the line managers minimize the number of arguments during the official org-wide stack ranking. Many managers have gotten good at balancing their teams with high and low performers so they come "pre-sorted" as the lingo goes. If you don't believe me, ask about "pre-sorting." The fact your manager recognizes the term should be telling... Remember, managers get graded on how well they appear to their peers in stack ranking. It's ok as a manager to have low performers so long as you are "managing them." Managers have a disincentive to overrepresent their team to their peers, and managers are perfectly fine pre-sorting their lists. Again, it's easier and better for them to do so.

The unofficial pre-sorting when X < MIN_POP_SIZE is what most individual workers notice (managers play favorites, careers are differential functions anyway), and HR has prepared the logical response (MIN_POP_SIZE is larger than your team) for managers to say when an employee asks.

It's clear that the primary effect of stack ranking is to induce churn in the org at the expense of loyalty and morale. The people making the decisions are smart, so I presume the effect is part of the strategy. My theory? Software development isn't as skilled as we like to think it is, and it's often cheaper to hire a young kid and pay a "high" entry-level salary with vested bonuses than invest in long-term employees. Think about all the unvested money that the company saves by pushing employees out before 4 and 5 year maturity cycles. Plus, actual senior engineers (not the title!) tend to say "no" more often to clueless middle management and create unnecessary headaches.

I thought everpix was a great product and had my family using it (4 paid accounts). I'm very sorry to hear this, and I wish the whole team good fortune.

Would you mind sharing the P&L statement and/or pitch deck that the verge used in its reporting? The verge's article seems confused, and I think one of the best gifts you could make to the HN community is to teach us from this outcome with actual source documents.

PayPal Redesign 13 years ago

It's for the favicon of all things: http://bruceackerman.com/paypal-redesign/img/favicon.ico

Holy cow, Google, this is pretty good for automatic protection. It looks like Google sees that the guy is hosting the Paypal favicon (or something very close to it)... why would any legit site do that? Even the redesign doesn't need to show the Paypal favicon. So Google errs on the side of caution.

Wow, that is really cool. Good job Google!

For comparison, the actual Paypal favicon: https://www.paypalobjects.com/en_US/i/icon/pp_favicon_x.ico

Off 13 years ago

You're right, and you are the first person I've seen say it out loud.

Further evidence: the Office competitor from Apple is also free. Why? The low-end Surface devices bundled Office for free, and one cycle later Apple began bundling its Office version alongside new devices. Microsoft would bundle Office with the high-end Surface devices (Surface Pros) if it weren't for pesky anti-trust threats looming (Windows RT is advertised to regulators as a separate OS from the Windows NT line, and a lot of weirdness stems from this distinction). It's very clear that Apple is trying to head off the Microsoft efforts with these pricing games.

Personally? I'm bummed there was no mac mini update... I need a new personal server at home, and I had been waiting for a supposed refresh... now I need to build and set up my own Linux server... that was fun when I was in my early 20s, but now it just feels tedious.

Square Cash 13 years ago

I also wish the limitations would disappear, but there are two reasons keeping them in place:

1) Government wants to ensure it can track all digital transfers (many pre-paid cards require activating with SSN)

2) Failing to approve certain transactions is the equivalent of a financial firewall because banks and payment processors know they haven't hardened their servers enough to prevent another one of these: http://www.nytimes.com/2013/05/10/nyregion/eight-charged-in-...

Now, if policy-makers were convinced the online-children-purchases market were bigger than the drive-by-ATM fraud, we would see the rules changed tomorrow.

I completely agree :)

Success-styled self-help is a lot like the lottery. There are millions of analytical, intellectual, objective issues with each (e.g. YMMV, survival bias, terrible odds, etc.). What they have in common is they allow users to dream "what if" and have fun (e.g. "escape") with those dreams. Both advertise this fantastical thinking in terms of "how you can" -- either buy the lottery ticket or buy my book -- but they still mostly boil down to entertaining people with dreams.

And heck, I love dreaming as much as the next person and love articles (or his comics) like this for that very reason... but I don't get hung up on trying to predict whether the content is strictly perfect just as I can't predict whether a random number printed on cheap paper will be life-changing.

I work in the industry. Chip and pin is not statistically safer (fraud rates in Spain, UK, and US are all the same despite having very different payment landscapes). The fundamental problem is that in traditional chip-and-pin setups you also type the pin into the same machine... so adding a skimmer + video camera OR adding a skimmer that records pin is marginally possible and not that hard.

The real security would come with a second factor that the user controls, either by approving on your phone or by using one-time-numbers for each transaction. The reason why these do not exist yet is because they would impede transaction flow, and the basic math with these companies is if fraud rate > rate loss of transaction volume from security feature then use security feature. Otherwise, don't.