Monday, April 1, 2024

Hyperlinks for emails?

It's looking like we could be able to hyperlink to emails soon! No more of this "oh uh check your email for the one I sent at 11:27...". You'll be able to add a link that works just like linking the web!

The IETF is working on their "Parsable Mail Pointer Email Protocol" (PMPEP), and I was able to get an advance copy! Check it out below:

RFC 9869: Parsable Mail Pointer Email Protocol (PMPEP)

Personally, I think they backronymed it from "Per My Previous Email Protocol"...

Edit 4/11: Yes, this was a joke. And apparently it would indeed be enough just to use the messageID. So why hasn't anyone implemented this???

Thursday, February 22, 2024

Setting short-selling straight; or, "But who let you short that?"

You might not be aware, but I've been short-selling some cryptocurrencies. (I would have said "been making money short-selling cryptocurrencies", but ...)

Often people ask some from of, "oh wow, what broker lets you do that?" It's actually an interesting misunderstanding, in that it misses a key insight:

You can short-sell any time you have a debt denominated in that asset.

At that point, you are short the asset. You benefit from anything that makes that asset easier to obtain, and thus extinguish your debt.

In the decentralized finance world, there are platforms (in my case, Compound.finance) that let you deposit some crypto asset A, and borrow some other crypto asset B. Once you do so, and sell B, you are now short-selling B!

The concept applies more generally too: for example, if you owe your friend the favor of helping them move, then you are "short moving services" (because anything that makes moving services cheap, also makes your debt easier to service, at least because you have the option to satisfying by paying a service rather than doing it yourself).

Also, if you borrow US dollars, and spend them, you are "shorting the dollar", although it's usually not talked about in these terms. (You hold a debt denominated in dollars, after having "sold" them for something else, which we generally refer to as "buying".) Although, there was an interesting case where people would borrow USDC (a crypto dollar substitute) and then find out they could be bought back for less than a dollar during the Silicon Valley Bank collapse. Thus making them "accidental short-sellers"!

Sunday, January 28, 2024

A serious paper on bits as Joules per Kelvin

My ramblings about thermodynamics aren't so off-base, it turns out!

Remember this one? From 2009? Where I explained how Joules per Kelvin (energy per unit temperature) is a valid measure of information (or entropy, effectively "missing information"), which is normally measured in bits?

Well, now there's a paper that formalizes that idea and related ones. As the title ("Temperature as Joules per Bit") indicates, it looks at a rearranged version of the same insight (mine was "bits as Joules per temperature"). But, it also goes a lot deeper and derives thermodynamics starting from entropy to understand temperature, rather than the other way around, as is conventionally done.

Related thought: I remember back in that 2009 thermodyanmics/info theory frenzy, one of my goals was rederive the Carnot limit based on information-theoretic considerations -- that is, show it as a simple implication of the amount of knowledge you have about a system in a case where only know the temperature difference. (Naturally, I assumed someone had already done this and tried to find it but it was very hard to google for.)

Background: The Carnot limit tells you the maximum amount of mechanical work ("useful energy") you can extract from heat -- like, through an engine -- and, as it turns out, it's a function of the ratio of absoute temperatures you're working between. You don't face this limit when extracting work from a flywheel (spinning disc with grooves). Inspired by an counterintuitive insight in an Eliezer Yudkowsky LessWrong post, and my thoughts about it, I figured you could draw a more direct line from "knowledge of a temperature difference" to "how much energy is extractable".

Now I'll give it a go with ChatGPT, and post my findings!

Sunday, May 21, 2023

ChatGPT4 refines my argument about fish being bad swimming instructors

I finally splurged for a paid ChatGPT subscription! With access to GPT-4, I asked it to refine my earlier argument about fish being bad swimming instructors. Here's what it gave me:

***

Certainly, let's rework the argument using more scientifically grounded explanations and references:

While it's true that fish, with their adept aquatic abilities, may seem like logical swimming instructors for humans at first glance, upon closer examination, it becomes clear that this is far from practical or effective. Even if we put aside the substantial communication and physical barriers, there are fundamental biological and behavioral differences between fish and humans that pose significant challenges.

Humans are terrestrial, bipedal mammals, and our motor skills and locomotive mechanisms are naturally adapted to this lifestyle. Fish, in contrast, are aquatic creatures designed to maneuver efficiently in water (Webb, P.W., 1982, "Locomotor patterns in the evolution of actinopterygian fishes"). Their ability to swim is an innate behavior, hardwired into their neural circuitry, not a learned skill (Gould, J.L., 1982, "Ethology: The Mechanisms and Evolution of Behavior"). Given this, fish cannot consciously comprehend or articulate the mechanics of their swimming abilities as humans would require in a teaching-learning scenario.

In the field of pedagogy, it is well accepted that the process of teaching involves more than simply demonstrating a skill; it requires an understanding of learning styles, the ability to give and receive feedback, and a degree of self-awareness in the teacher (Boud, D., et al., 1985, "Reflection: Turning Experience into Learning"). Fish, as far as current scientific consensus suggests, lack these cognitive capacities (Butler, A.B., et al., 2005, "Evolution of the Neural Basis of Consciousness: A Bird-Mammal Comparison").

Furthermore, many human skills, including swimming, are learned through a combination of instruction, practice, and feedback (Kirschner, P.A., et al., 2006, "Why Minimal Guidance During Instruction Does Not Work"). This model of learning doesn't align with the unconscious, reflex-driven behaviors seen in fish.

Lastly, it's important to acknowledge the vast physiological differences between humans and fish. Human limbs and fish fins have evolved for different purposes and environments, with humans developing more for grasping and manipulation and fish for efficient aquatic locomotion (Thorsen, D.H., et al., 2004, "Biomechanics of Locomotion in Asian Carp"). These differences are fundamental and cannot be bridged by simple observation or imitation.

In conclusion, despite their swimming prowess, fish cannot be effective swimming instructors for humans due to biological, behavioral, and cognitive differences, as well as practical communication and anatomical obstacles. This argument does not discount the value of observing aquatic creatures to improve our understanding of efficient movement in water, but it's clear that such observation is a far cry from active instruction.

Thursday, August 25, 2022

Extended shower thought: Fish would be bad swimming instructors

Obligatory epistemic status: Speculative and hard to test but falls out an as implication under current worldmodel.

Just a shower thought I've had on my mind for a while:

Fish would be bad swimming instructors (for humans).

This remains true even after adjusting for/overcoming the differences in body types and ability to speak your language.

What do I mean? Well, to be sure, fish are good at swimming. And normally, that's what's you want in a swimming instructor...

...but not here. While fish are good at swimming, they have always been good at swimming. They were deft swimmers before they reached any point of being able to reflect on their selves or what they are doing. They have no appreciation for what it's like not to be a good swimmer.

What does "learning swimming" involve (for humans)?

Fish, being fish, never had to make the transition from being a natural biped to one that has repurposed its body for motion in water, which is what humans have to go through to "learn swimming". They never had to start from a mentality that finds walking somewhat natural -- and swimming somewhat unnatural -- and then adjusts its appendage motion in a way more suited to the latter.

We can imagine any kind of instruction session between fish and humans (as above, appropriately adjusted for language) to be fraught with peril. The fish might try to point out deficiencies that hold back the human. But it has never had to think about such deficiencies, because it has never needed to distinguish between the right way and the wrong way.  It was always just "the way" that came instinctually.

The fish might nearly lash out, frustrated that the human attempts an obviously ineffective means of water locomotion. But it has no idea why those flawed attempts are wrong. They just feel wrong.

The fish will happily demonstrate the "right way", just by doing it. But identifying the difference between its "right way" and "what humans do" would be a learning experience in itself, something it has no natural advantage in, as it was never part of the fish's "learning process for swimming".

The converse is true -- humans would be bad at teaching fish to walk (with the appropriate apparatus) or otherwise move on land. (But note the parallel isn't perfect as humans generally do have to struggle and learn how to walk, but not in any way that involves formal instruction.)

Implications for human-human interaction

So far, this insight feels (and, well, is) just idle speculation. But there are implications for ordinary life.

There will be times when someone is a "natural" at some skill. They're good at it. And that is their only teaching qualification. And they try to teach a non-natural that skill. They are then bad at teaching. The missing piece is the learner's mind is very different from what the natural is capable of filling in. Such a teacher will constantly show them how to do it "right" but not be able to identify the difference between what they're doing and what the learner is -- except by drawing on some kind of unrelated, general intelligence.

(I won't give any specific examples of such a skill, because those become contentious issues in their own right and detract from the general point. But I've definitely been on both sides -- learning from someone who has no understanding why they're good at it, and grasping to communicate something I do without ever thinking about it.)

You can also run into this problem when you become skilled at something. You can sometimes assimilate the skill so well that you are effectively a natural, by forgetting the whole process by which you learned it. You may lose the perspective you had as a beginner and are no longer able to relate to them.

Part of why I enjoy teaching what I know is that I seem unusually resistant to this process, and have vivid memories of the hurdles I overcame as a newbie.

Sunday, August 15, 2021

Refuting arguments no one cares about: Exploiting the "help" in the pandemic vs the wildfires

I don't think anyone actually wanted to learn about this, but it's stayed on my mind for being "an argument that's wrong and I can prove".

Background:

A while ago I made fun of a Facebook friend (call her D) for her "let them eat cake" cluelessness. This was during the 2018 (?) California wildfires when she made a big post saying how thankful she was that, in miserable air conditions, she could "still get her groceries" through delivery services. That prompted me (and, among others, another FB friend, "E") to drop our jaws and say, "Um, you don't care that you're just offloading all that suffering to poor workers that can't afford to just stay home, and will be breathing the lung-destroying air in your stead?"

(And, to be sure, there's the argument that someone total utility is increasing by virtue of how said workers still have the option to expose themselves to risks for money, and the counterargument about "well why have OSHA that workers can't opt out of ..." which is its own topic but didn't really appeal to me or E at the time.)

So far, so good.

But later, during the pandemic, it came out that E, for similar reasons, didn't feel comfortable just getting delivery so she could stay home when we were being asked/mandated to.

Those ... situations don't seem analogous at all to me, and I don't think someone should feel bad for ordering delivery during a pandemic like in an air quality emergency like wildfires. Here's why:

A) In a wildfire, you are shifting all of the hazard of the smoke onto the people who bring your deliviers.

B) But in a pandemic, moving to delivery reduces the hazard for everyone, including the delivery people.

In Kantian terms: If "everyone did it", then everyone would still benefit in case B). But in A), all the avoidance by the rich "D" personas would be matched by losses to those who still have to deliver.

To elaborate on B: the way a delivery service works, every worker involved has less Covid-spreading contact than than if everyone were shopping at a grocery store. The warehouses that set up the goods for delivery can, for their part, refactor and apply inexpensive countermeasures to reduce those worker's exposure. Furthermore, with everyone moving to delivery, you get economies of scale, allowing everyone to afford the delivery service.

So, to me, it didn't didn't seem like you were doing anyone a favor out of solidarity to keep getting your grocerys through in-person shopping.

Thursday, April 1, 2021

Leaked Google initiative: No more passwords!

I have an inside source that's claiming Google will be rolling out a new replacement for passwords and other secrets for authenticating users. They shared the upcoming blog post/press release with me. They're moving to a more "holistic" authentication system? Let's see if this pans out. In any case, here's the not-yet-released announcement.

***

Are you who you claim to be?


User logins protect websites from malicious actors, like spammers and trolls. So when you go online, only people with legitimate credentials can access the useful features of the site -- and others can't impersonate you. For years, you've used logins -- such as a username and password -- to prove to the site that you are who you claim to be, like this:



Some go even further and add a second factor to authenticate with, like an SMS code or one-time-password generator like you might have in the Google Authenticator app.

But, we figured it would be easier to just directly ask our users who they are -- so, we did! Following on our earlier success with No CAPTCHA reCAPTCHA, we’ve begun rolling out a new API that radically simplifies the login experience. We’re calling it "Credential-Free Authentication" and this is how it looks:

On websites using this new API, a significant number of users will be able to securely and easily verify their identities without (separately) having to provide credentials: no password, no rotating code. Instead, with just a single click, they’ll validate who they claim to be.

A brief history of user authentication


While the new login API may sound simple, there is a high degree of sophistication behind that modest interface. Authentication has long relied on attackers not having critical secrets, like a password or random number generator seed or other private information. You may have heard the traditional formulation, that authentication requires you to provide something you have, something you are, or something you know.

However, our research recently showed that it's about as likely for the genuine user to be missing the credentials as it is for a malicious actor. How many times have you forgotten your password or encountered a bug with your password manager? (Not GPM, of course!) Thus, challenging users for credentials is no longer a dependable test.

Furthermore, attackers are often able to steal user credentials, forcing providers to rely on a secondary layer of fraud identification, so as to lock accounts when users behave suspiciously. You've seen this if you've ever had a credit card declined for an unusually large or remote purchase.

Introducing Credential-Free Auhentication


That got our security engineers thinking: if we already have to analyze a user's behavior in order to catch account compromises, why not just use that as the authentication? It would cut two carrots with one knife! After all, an attacker might be able to guess your password or your credit card information, but they will never be able to mimic the full depth and breadth of how you interact with websites, from your browing history, to your cookies set, to the way you move your mouse.

Following the "No CAPTCHA" model above, we developed an Advanced User Analysis backend for logins that actively considers a user’s entire engagement with the the Internet to determine who that user is. This enables us to rely less on "Do you have the secret?" and, in turn, offer a better experience for users. Now, users can just click a radio button, and in most cases, they’re logged in. In fact, you'll rarely have to log in at all, because sites will "recognize" you, just like you don't have to show your ID to go into an event venue a second time if the bouncer recognizes you.

But are you really that person?


However, authentication challenges aren't going away just yet. In cases where our tracking cookies and other behavioral metrics can't confidently predict who someone is, we will prompt the user for additional information, increasing the number of security checkpoints to confirm who the user really is. For example, you might need to turn on your webcam or upload your operating system's recent logs to give a fuller picture.

Adopting the new API on your site


As more websites adopt the new API, more people will see Credential-Free Authentication. Early adopters, like Snapchat, WordPress, Twitch, and several others are already seeing great results with this new API. For example, in the last week, the number of support tickets for account resets on WordPress went down by 90%. Twitch reported similar figures -- and also was able to unmask several sockpuppets who had been manipulating discussions and vote totals.

To adopt the new CFA API for your website, visit our landing page for more.

Good users, we'll continue to keep the internet safe and easy to use. Bad users, it'll only get harder to hide yourselves and take over legitimate accounts -- sorry we're (still) not sorry.

***

Edit: Yes, this was an April Fools joke.