Live data from Hacker News

Vouch

github.com

341–350 of 507 posts

Re: Vouch

#341

The underlying idea is admirable, but in practice this could create a market for high-reputation accounts that people buy or trade at a premium. Once an account is already vouched, it will likely face far less scrutiny on future contributions — which could actually make it easier for bad actors to slip in malware or low-quality patches under the guise of trust.

That's fine? I mean, this is how the world works in general. Your friend X recommends Y. If Y turns out to suck, you stop listening to recommendations from X. If Y happens to be spam or malware, maybe you unfriend X or revoke all of his/her endorsements.

It's not a perfect solution, but it is a solution that evolves towards a high-trust network because there is a traceable mechanism that excludes abusers.

Re: Vouch

#342
post #324

Earlier quoted context omitted.

Emails to CEOs they do worth.

So only CEOs will get spam, and it's effective for 99.9% of people? I would not describe that as "will not work as desired".

And it would even still work for the CEO, they would just have to charge more than $1.

The real problem is we don't have a low-friction digital payment system that allows individuals to automate sending payment requests for small amounts of money to each other without requiring everyone to sign up for a merchant account with a financial bureaucracy.

Re: Vouch

#343
post #309

I think a system that allows a reason someone is denounced, specifically for political views or support, should be implemented, to block the mob from denouncing someone on all of their projects, simply because they are against certain topics, or in an opposing political party

Sometimes political views should actually get you shunned. You're always free to create a fork.

Please tell us the correct political views we should have, or at least provide a list of the political views that will result in a shunning.

Re: Vouch

#344

The underlying idea is admirable, but in practice this could create a market for high-reputation accounts that people buy or trade at a premium. Once an account is already vouched, it will likely face far less scrutiny on future contributions — which could actually make it easier for bad actors to slip in malware or low-quality patches under the guise of trust.

That's fine? I mean, this is how the world works in general. Your friend X recommends Y. If Y turns out to suck, you stop listening to recommendations from X. If Y happens to be spam or malware, maybe you unfriend X or revoke all of his/her endorsements. It's not a perfect solution, but it is a solution that evolves towards a high-trust network because there is a traceable mechanism that excludes abusers.

That's true. And this is also actually how the global routing of internet works (BGP protocol).

My comment was just to highlight possible set of issues. Hardly any system is perfect. But it's important to understand where the flaws lie so we are more careful about how we go about using it.

The BGP for example, a system that makes entire internet work, also suffers from similar issues.

Re: Vouch

#345

Earlier quoted context omitted.

The difference is that today this trust is local and organic to a specific project. A centralized reputation system shared across many repos turns that into delegated trust... meaning, maintainers start relying on an external signal instead of their own review/intuition. That's a meaningful shift, and it risks reducing scrutiny overall.

I am still not going to merge random code from a supposed trusted invdividual. As it is now, everyone is supposedly trusted enough to be able to contribute code. This vouching system will make me want to spend more time, not less, when contributing.

I think something people are missing here is, this is a response to the groundswell in vibecoded slop PRs. The point of the vouch system is not to blindly merge code from trusted individuals; it's to completely ignore code from untrusted individuals, permitting you to spend more time reviewing the MRs which remain.

Re: Vouch

#346

This looks like a fairly typical engineer's solution to a complex social problem: it doesn't really solve the problem, introduces other issues / is gameable, yet unlikely to create problems for the creator. Of course creator answers any criticism of the solution with "Well make something better". That's not the point: this is most likely net negative, at least that is the (imo well supported) opinion of critics. If t…

"Please don't post shallow dismissals, especially of other people's work. A good critical comment teaches us something."

https://news.ycombinator.com/newsguidelines.html

Re: Vouch

#347
This is a signal of failure of GH (Microsoft) to limit AI-based interactions, which is obviously not in their superficial strategic interests to do so.

This project though tries to solve a platform policy problem by throwing unnecessary barriers in front of casual but potentially/actually useful contributors.

Furthermore, it creates an "elite-takes-all", self-amplifying hierarchy of domination and rejection of new participants because they don't have enough inside friends and/or social credit points.

Fail. Stop using GH and find a platform that penalizes AI properly at its source.

Re: Vouch

#348
post #139

It should just be $1 to submit PR. If PR is good, maintainer refunds you ;) I noticed the same thing in communication. Communication is now so frictionless, that almost all the communication I receive is low quality. If it cost more to communicate, the quality would increase. But the value of low quality communication is not zero: it is actively harmful, because it eats your time.

People with very little to no skill in software development are spending hundreds of dollars on tokens to fix things for clout, will an extra dollar barrier really slow things down noticeably?

Re: Vouch

#349
post #276
post #219

Earlier quoted context omitted.

It is a privileged solution. And a stupid one, too. Because $1 is worth a lot more for someone in India, than someone in USA. If you want to implement this more fairly, you'd be looking at something like GDP or BBP plus geolock. Streaming services perfected this mechanism already.

This might be by design. Almost anyone writing software professionally at a level beyond junior is getting paid enough that $1 isn't a significant expense, whether in India or elsewhere. Some projects will be willing to throw collaboration and inclusivity out the window if it means cutting their PR spam by 90% and only reducing their pool of available professional contributors by 5%.

I've contributed almost full time to free software as a student. When I became a professional software developer, suddenly I lost the time to do it.

Re: Vouch

#350
post #139

It should just be $1 to submit PR. If PR is good, maintainer refunds you ;) I noticed the same thing in communication. Communication is now so frictionless, that almost all the communication I receive is low quality. If it cost more to communicate, the quality would increase. But the value of low quality communication is not zero: it is actively harmful, because it eats your time.

People with very little to no skill in software development are spending hundreds of dollars on tokens to fix things for clout, will an extra dollar barrier really slow things down noticeably?

There are a lot of _free_ models on opencode.
Post reply on HN