Live data from Hacker News

Vouch

github.com

401–410 of 507 posts

Re: Vouch

#401
post #86

How does a potential positive contributor pierce through? If they are not contributing to something already and are not in the network with other contributors? They might be a SME on the subject and legit have something to bring to the table but only operated on private source. I get that AI is creating a ton of toil to maintainers but this is not the solution.

He answered it in the thread: Basically, the system has no opinion on that, but in his projects he will vouch anyone who introduces themselves like a normal human being when opening a PR.

Re: Vouch

#402
post #223

Earlier quoted context omitted.

This thought pattern leads to crypto. In that world there's a process called "staking" where you lock some tokens with a default lock expiry action and a method to unlock based on the signature from both participants. It would work like this: Repo has a public key. Submitted uses a smart contract to sign the commit with along with the submission of a crypto. If the repo merges it then the smart contract returns the t…

The "money goes to the repo part" is the problem here, as it incentivizes maintainers to refuse legitimate pull requests. Crypto has a perfect way to burn money, just send it to a nonexistent address from where it can never be recovered. I guess the trad fi equivalent are charitable donations. The real problem here is the amount of work necessary to make this viable. I bet Visa and Mastercard would look at you funny…

> The "money goes to the repo part" is the problem here, as it incentivizes maintainers to refuse legitimate pull requests.

That's not true. The issue is that the system the comment you're replying to described is escrow. Escrow degenerates in the way that you describe. I explain it a bit more in this comment elsewhere on this post:

https://news.ycombinator.com/item?id=46943416

A straight up non-refundable participation payment does not have this issue, and creates a different set of incentives and a different economy, while there also exist escape hatches for free-of-charge contributions.

> The real problem here is the amount of work necessary to make this viable.

Not necessarily. This article mentions Tezos, which is capable of doing such things on-chain already:

https://news.ycombinator.com/item?id=46938811

> all the annoying KYC/AML that a normie has to get through to use it.

There are always escape hatches. If your code is so great that people will want to pull it, then you don't pay to push. If it's not really that great, then what are we talking about? Maybe it disincentivizes mid code being pushed. So be it.

You can make friends, you can make a name for yourself, you can make a fork that's very successful and upstream will want to pull it in, you can exert social pressure / marketing to get your code merged in. Lots of options that do not involve KYC/AML.

For everyone else, I'd say KYC/AML are a good idea because of the increasing amount of supply chain exploits being pushed out into repos. If pushing by randos is gated by KYC/AML, then there's at least some method of chasing the perps down and taking them to justice.

That's a win-win-win-win situation. Less mid code, less exploits, earnings for maintainers, AI slop blocked. Absolutely amazing.

Re: Vouch

#403
post #139

It should just be $1 to submit PR. If PR is good, maintainer refunds you ;) I noticed the same thing in communication. Communication is now so frictionless, that almost all the communication I receive is low quality. If it cost more to communicate, the quality would increase. But the value of low quality communication is not zero: it is actively harmful, because it eats your time.

$1 might not be a lot to you, but in some countries that's the daily wage. Even in rich countries one dollar for some might be the difference between eating or not eating that day.

Paywalling without any regional pricing consideration it's just going to incentivize people from poor countries to not participate in your project. Maybe that's okay for you but it's something to consider.

Re: Vouch

#405
post #285
post #276

Earlier quoted context omitted.

This might be by design. Almost anyone writing software professionally at a level beyond junior is getting paid enough that $1 isn't a significant expense, whether in India or elsewhere. Some projects will be willing to throw collaboration and inclusivity out the window if it means cutting their PR spam by 90% and only reducing their pool of available professional contributors by 5%.

Indian here. You are correct. Expecting any employed Indian software developer to not be able to spare 1$ is stupid. Like how exactly poor do you think we are?!

So only employed software developers are allowed to make PRs?

Re: Vouch

#406
post #355

Earlier quoted context omitted.

But it could just be made a stablecoin.

It's a huge shame that crypto has been so poorly-behaved as an industry that almost nobody is willing to touch it except for speculation. It could be useful but it's scared away most of the honest people.

The fact that people around the world are trading hundreds of billions of dollars of stable coins [1], with India, Pakistan, the Philippines and Brazil in the top five countries [2], not least of all for the purpose of "greater monetary stability" [3], I think points toward the revolutionary usefulness of its inherently non-speculative properties (as referenced in positive applications of crypto in above comments).

It really has been a shitshow of get rich schemes, and yet crypto keeps not dying, instead increasingly getting applied to extremely valuable real world every day use cases, which I think is evidence of the value of the inherent technology.

[1]https://defillama.com/stablecoins [2]https://www.trmlabs.com/reports-and-whitepapers/2025-crypto-... [3]https://www.goldmansachs.com/what-we-do/goldman-sachs-global...

Re: Vouch

#407
post #223
post #139

It should just be $1 to submit PR. If PR is good, maintainer refunds you ;) I noticed the same thing in communication. Communication is now so frictionless, that almost all the communication I receive is low quality. If it cost more to communicate, the quality would increase. But the value of low quality communication is not zero: it is actively harmful, because it eats your time.

This thought pattern leads to crypto. In that world there's a process called "staking" where you lock some tokens with a default lock expiry action and a method to unlock based on the signature from both participants. It would work like this: Repo has a public key. Submitted uses a smart contract to sign the commit with along with the submission of a crypto. If the repo merges it then the smart contract returns the t…

I see no advantage with this over real money transfers. At all. Just use some kind of escrow.

Re: Vouch

#408

Earlier quoted context omitted.

> The real problem is we don't have a low-friction digital payment system that allows individuals to automate sending payment requests for small amounts of money to each other without requiring everyone to sign up for a merchant account with a financial bureaucracy. Its called cryptocurrency

First you have to make it low-friction. If I want Joe Average to send me $1 in cryptocurrency, how is he getting $1 in cryptocurrency to send me?

>First you have to make it low-friction. If I want Joe Average to send me $1 in cryptocurrency, how is he getting $1 in cryptocurrency to send me?

Absolutely. You're 1000% correct. Cryptocurrency is way too high friction for stuff like that. When I wish to spend crypto, I need to:

[If you don't have an exchange account already, you'll need the 0.x steps too!]

0.0 Create an account on an exchange which is legally allowed to operate in your state/country;

0.1 Provide all sorts of KYC/AML info including photos of yourself and your government ID;

0.2 Wait hours/days/weeks for the exchange to "validate" your KYC/AML info and allow you to purchase crypto;

1. Log in to an exchange which is actually allowed to operate in the place where one resides;

2. Purchase Bitcoin or other coin the exchange deems appropriate (leaving aside the hefty fee charged for using fiat currency/traditional credit card);

3. Wait days/weeks until the exchange allows you to transfer the purchased cryptocurrency out of your exchange-hosted wallet;

4. Transfer crypto to a wallet you actually control;

5. Convert the crypto purchased on the exchange to the crypto coin required for whatever your purpose may be;

6. Transmit the crypto to the destination wallet.

Total time (not including setting up the exchange account, which can take anywhere from 1-10 days): 3-10 days.

Much too high friction for small payments, IMHO.

Re: Vouch

#409

IMO: trust-based systems only work if they carry risk. Your own score should be linked to the people you "vouch for" or "denounce". This is similar to real life: if you vouch for someone (in business for example), and they scam them, your own reputation suffers. So vouching carries risk. Similarly, if you going around someone is unreliable, but people find out they actually aren't, your reputation also suffers. If vo…

> Then again, if this is the case, why would you risk your own reputation to vouch for anyone anyway. Maybe your own vouch score goes up when someone you vouched for contributes to a project?

That is an easy way to game the whole system. Create a bunch of accounts and repos, cross vouch across all of them, generate a bunch of fake AI PRs and approve them all because none of the repos are real anyway. Then all you need is to find a way to connect your web of trust to a wider web of trust and you have a whole army of vouched sock puppet accounts.

Re: Vouch

#410
post #146

Earlier quoted context omitted.

Sounds like a black mirror episode.

isnt that like literally the plot in one of the episodes? where they get a x out of 5 rating that is always visble.

Yes, there is one that is pretty close to this scenario.
Post reply on HN