Live data from Hacker News

Vouch

github.com

311–320 of 507 posts

Re: Vouch

#311
post #285

Earlier quoted context omitted.

Indian here. You are correct. Expecting any employed Indian software developer to not be able to spare 1$ is stupid. Like how exactly poor do you think we are?!

It's not that outrageous. Apparently, 90% of India is living on less than $10 per day ( https://ourworldindata.org/grapher/share-living-with-less-th... )

I suspect most of these people are not software engineers with a computer?

Re: Vouch

#312
post #297
post #256

Earlier quoted context omitted.

It feels like the problem here comes from the reluctance to utilize a negative sum outcome for rejection. Instead of introducing accidental perverse incentives, if rejected your stake shouldn't go to the repo, 50% could be returned, and 50% deleted. If it times out or gets approved you get 100% back. If a repo rejects too often or is seen doing so unfairly reputation would balance participation.

No, the perverse incentive is that there will be RepoCoin, and the people involved will be incentivized to make the price of that as high as possible.

Ahh, I see now the angle you were coming at it from, my wrong!

Re: Vouch

#313
post #309

I think a system that allows a reason someone is denounced, specifically for political views or support, should be implemented, to block the mob from denouncing someone on all of their projects, simply because they are against certain topics, or in an opposing political party

Sometimes political views should actually get you shunned.

You're always free to create a fork.

Re: Vouch

#314

The underlying idea is admirable, but in practice this could create a market for high-reputation accounts that people buy or trade at a premium. Once an account is already vouched, it will likely face far less scrutiny on future contributions — which could actually make it easier for bad actors to slip in malware or low-quality patches under the guise of trust.

Amazing idea - absolutely loving vouch. However, as a security person, this comment immediately caught my attention.

A few things come to mind (it's late here, so apologies in advance if they're trivial and not thought through):

- Threat Actors compromising an account and use it to Vouch for another account. I have a "hunch" it could fly under the radar, though admittedly I can't see how it would be different from another rogue commit by the compromised account (hence the hunch).

- Threat actors creating fake chains of trust, working the human factor by creating fake personas and inflating stats on Github to create (fake) credibility (like how number of likes on a video can cause other people to like or not, I've noticed I may not like a video if it has a low count which I would've if it had millions - could this be applied here somehow with the threat actor's inflated repo stats?)

- Can I use this to perform a Contribution-DDOS against a specific person?

Re: Vouch

#315
post #51

Earlier quoted context omitted.

> Indeed, it's relatively impossible without ties to real world identity. I don't think that's true? The goal of vouch isn't to say "@linus_torvalds is Linus Torvalds" it's to say "@linus_torvalds is a legitimate contributor an not an AI slopper/spammer". It's not vouching for their real world identity, or that they're a good person, or that they'll never add malware to their repositories. It's just vouching for the…

That’s not the point. Point is: when @lt100, @lt101, … , @lt999 all vouch for something, it’s worthless.

Real world identity isn't sufficient or necessary to solve that problem.

Re: Vouch

#316
post #139

It should just be $1 to submit PR. If PR is good, maintainer refunds you ;) I noticed the same thing in communication. Communication is now so frictionless, that almost all the communication I receive is low quality. If it cost more to communicate, the quality would increase. But the value of low quality communication is not zero: it is actively harmful, because it eats your time.

I built a side project to solve this for myself that’s basically an inbox toll system. It funnels emails from unknown senders into a hidden mailbox and auto replies to the sender with a payment link. After the sender pays, the email gets released to recipient’s main inbox. Recipient can set custom toll amounts, whitelist, etc. Would be happy to share the code, just lmk!

I’m interested in seeing this too. Heh an agent will gladly pay a dollar of their human’s money if they can declare success.

Re: Vouch

#317
post #309

I think a system that allows a reason someone is denounced, specifically for political views or support, should be implemented, to block the mob from denouncing someone on all of their projects, simply because they are against certain topics, or in an opposing political party

Sometimes political views should actually get you shunned. You're always free to create a fork.

And this is why it needs a reason/ban rule. You guys simply can’t help yourselves.

Re: Vouch

#318

The underlying idea is admirable, but in practice this could create a market for high-reputation accounts that people buy or trade at a premium. Once an account is already vouched, it will likely face far less scrutiny on future contributions — which could actually make it easier for bad actors to slip in malware or low-quality patches under the guise of trust.

[deleted]

Re: Vouch

#319
post #307

Unfortunately, the mob mentality, and gate keeping from the Reddit mod era, proves that these types of systems simply don’t work.

They're negative sum, but even negative sum systems usually have many winners (so it 'works' for some subset of individuals). That's why it perpetuates.

Re: Vouch

#320
post #139

It should just be $1 to submit PR. If PR is good, maintainer refunds you ;) I noticed the same thing in communication. Communication is now so frictionless, that almost all the communication I receive is low quality. If it cost more to communicate, the quality would increase. But the value of low quality communication is not zero: it is actively harmful, because it eats your time.

I built a side project to solve this for myself that’s basically an inbox toll system. It funnels emails from unknown senders into a hidden mailbox and auto replies to the sender with a payment link. After the sender pays, the email gets released to recipient’s main inbox. Recipient can set custom toll amounts, whitelist, etc. Would be happy to share the code, just lmk!

Has anyone ever paid you?

The technical side of this seems easy enough. The human side, that seems more complicated.

Like, if I were your doctor or contractor or kid's schoolteacher or whoever you hadn't happened to already whitelist, and had sent you something important for you, and got that back as a response... I'm sure as heck not paying when I'm trying to send you something for your benefit.

Post reply on HN