Hacker Newsnew | past | comments | ask | show | jobs | submit | fdye's commentslogin

I've never understood why anti-scalpers just don't work backwards from shipping address. Are these scalpers all really keeping hundreds of actual physical addresses they can receive packages at? Like if you see the limited product has 100 orders going to the same building, or apartment, or whatever then flag it before it goes out. Limit PO Boxes, etc.

Sure they can find mules to buy+receive one and then sell to the scalper, but the more steps you put in the better. Same for the people scamming Sam's club by buying memberships, ordering limited items, then refunding the membership. Just lock orders to members older then >1yr and make sure it only ships to the actual physical address attached to the membership. Flag multiple memberships at the same address.

I've run a modest shipping op and the second I saw even a couple orders of the same product going to the same address I would halt it and do additional verification.


I really wanted a PS5 when it was first released, and I refused to pay the scalper tax to get one, so I spent a few minutes a few times a day over a couple of weeks trying to snag one from one of the many retailers selling them. Extraordinarily frustrating, I was not so interested in this process that I was going to script it or any such nonsense, I just wanted to eventually get lucky and snag one.

I eventually did, and when it finally arrived at my doorman building I mentioned what was in the package to the doorman, and how happy I was to finally get my hands on it after the effort expended and he said "oh really? there's a guy on the 5th floor who's bought dozens of them - he sold me one at cost".

At the scale of the PS5 release (I don't know how many they first shipped in 2020, but they're at >80M sold now so undoubtedly X million in the first year) - would an address match intervention have been able to differentiate my order from the dozens of orders the scalper on the 5th floor had placed, presuming some cooperation from the doorman to allow for variance in the details of the shipping address the scalper used? I'm reasonably confident the answer is no and I would have been caught in the net that attempted to prevent the scalper from scalping.


At least I don't think scalper's will be a problem with the Steam Machine and I honestly believe someone with the knowledge of building PCs can build something way more powerful.


Even with today's RAM prices?


Linus Tech Tips built a computer with around twice the performance at the same price with current RAM prices. You lose out on size and SteamOS features like quick resume & CEC.


Yeah, good point.


Surely you have an apartment number? Or is it like in many places in Europe, where the address is the building number and name of the recipient?


You slip the doorman $50 to hold tracking numbers of packages you're having sent to random units in the building. Or just promise him a unit at MSRP for his help.

These sorts of things are pretty cheaply routed around for those making scalping into a volume business.

Sure you can probably lock things down so you catch the vast majority of these mechanisms, but not without impacting legitimate users. So it's a tradeoff of how much more of a hassle do you want to make things for legitimate customers vs. how much you want to lock out resellers.

You don't even really need a doorman in many buildings either. There will be a shared mail room (if you're lucky) where packages get dropped. If you work from home you just watch the UPS/Fedex tracking and run down the moment it gets delivered to snag it before anyone else sees it.

The few folks I know who did this sort of thing were less professionals making a living off it, and more someone who wanted to subsidize their gaming habit by grabbing 3 or 4 units and keeping one while flipping the rest. They'd just ship to friends/family. The folks buying 50 units at a time are pretty rare from what I can tell.


This doesn't seem like a reason not to do address based limiting, just a reason it wouldn't be perfect.

Perfect is the enemy of good.


If you live in a house you can generate tens of thousands of addresses that will be delivered to you without much problem.

You just begin inventing apt. numbers - having up to a thousand apts in a building is not suspicious. And once you cross a thousand, you can invent new buildings by strapping letter names to your home number, so that gives you a-z * 1000 = 24000 unique addresses you can generate easily. Without much hassle you could extend that to a million.

Requiring a unique mailing address is just as pointless as a unique email.


But we have databases of addresses and we can tell if it actually has 1000 apartments.


Who's updating those db's when I turn my single family in to a tri-plex , then convert it to an 10 unit apartment complex?

The answer is "no one".


That depends on where you live. In my country the government keeps an up-to-date db. Everything else in the country depends on and queries that db too, so it's not isolated.


I have since moved out of NYC but yes I had an apartment number. If the doorman was helping this scalper, the scalper could have varied the address he used enough to avoid exact match dedupes while still ensuring he could claim the packages as his from the doorman.


Doorman? Do you live in Trump Tower?


Doorman buildings are quite common in NYC.

[edit: to be clear they are not the norm, they are more expensive than buildings without one, but there are still lots of them that are not Trump Tower or other places for the absurdly wealthy]


It’s less about 1 scalper buying 100. Order limits, credit card limits, etc already restrict that.

It’s more about 1000 scalpers buying two or three to immediately resell. There are entire discords and communities around this with thousands of members.


I think there's less motivation to scalp the steam machine than there was e.g. the steam deck or the PS5. With the PS5 there were all those PS5-exclusives where you can either get a PS5 or not play them. The Steam deck was the first of the current wave of practical PC handhelds and it was a while before there were realistic competitors.

The Steam Machine is ultimately a mid-range gaming PC in a nicer form factor and a slight discount compared to building it yourself. I don't think anyone would pay 1.5x for a Steam Machine when they could just buy a regular PC for less. There's no capabilities the Steam Machine has that a regular PC doesn't, which limits the ability of scalpers to charge larger margins and thereby limits the motivation.

As for potentially impacting the wider PC hardware market? Well, retail scalpers are small fry compared to Altman, Bezos, Musk et al.


They do:

> Limit one signup per household. We will use payment method, shipping address, and other information to eliminate multiple entries.


The answer is that once you move past a modest shipping op the people with actual visibility on that would be the warehouse that's fulfilling, also typically people who don't have the power to cancel orders themselves.

Ecomm orders want to drop to the distribution center as soon as possible, which means you can't wait until you have a whole bunch of them just so you can analyze which addresses are on multiple orders. You would either need to 1) detect this in the warehouse systems (I spent my career working on these, so I can say with high certainty that is almost definitely Not going to happen, especially if they go through a 3PL) OR 2) you have to cancel orders after they have already dropped to the warehouse (which means wasted labor in the best-case scenario).

None of that is worth the effort to a company who is fundamentally still getting paid the same for the product regardless of if the purchaser is a scalper or not.


Why would any people need to see the addresses at all? The solution being proposed is something that you'd automate with a series of heuristics. And your point about the company making the same money for shipping to scalpers vs non scalpers seems like it would only apply to the shipping company, but if you view from the perspective of the product company, obviously they have an incentive to avoid scalpers because it negatively impacts the brand and the price spikes are money not captured by the product company and may even reduce further spending (eg if a buyer spaffed half their budget on an overpriced console, that's less for buying games which benefit the product company, eg Steam in this case)


You are vastly over-estimating the tech power the vast majority of businesses have dedicated to logistics. There's a large number of different systems involved with a enterprise logistics stack. Ecomm store provider, ERPs, middleware, warehouse systems, shipping systems, banking, etc. Which part of the pipeline are you going to hold up while you wait for enough orders to pool to build a meaningful heuristic?

The solution Valve came up with is quite brilliant.


It sounds like you are massively overthinking it. When you pre-order anything, you need to enter a shipping address. Why would you need to consider anything beyond that or require 'dedicated' logistics?

that's not to say I don't like Valve's solution - I agree, it is very nice


I don't think they're necessarily overestimating what they've dedicated to logistics, they're overestimating what they've dedicated to anti-scalping. If they cared to detect it, they could invest even just a token effort and make great strides. But why would they care?


many ways to write the same address. abbreviations, fake unit/apt numbers, apt numbers, etc. try to verify that at the scale of nike or adidas.

ultimately they are selling out inventory so it probably takes a lot of convincing to spend money on a cat and mouse game


In the US USPS provides this as a service. Every time I put my address in I get asked to use the standardized version.


For bulk shippers the USPS will penalize you if you have... well it was not bad addresses but non-standard addresses. The mail order company I worked for a few years ago put more effort than I expected to normalize and verify addresses met USPS standards. So I guess the penalty made it worth it.


It is the AddressesV3 service. We're planning on using it (for the website redesign) to make sure that the addresses are correct (enough). There's a significant number of people who register and quit/get fired, yet still have to make one final filing (for a state government agency) that we snail-mail them a final "I'm done with this" paper form to fill out. And every couple of years an envelope gets returned as "undeliverable".

https://developers.usps.com/addressesv3


Yeah so does Australia Post. I've dug too deeply but Google Maps on face value seems to provide it as well.


I’ve seen websites say during checkout “your address wasn’t in our db but this one was” showing what was clearly a cleaned up form (changed “Circle” to Cir, uppercased, turned ZIP into ZIP+4) so there are ways.

You would have to tell the user “use the corrected/matched one only” though. Some sites offer the correction but don’t make you use it.


The downside is this service is not up-to-the-minute accurate. I rented a new-construction house and it was the better part of a year before it made it into the USPS address correction database, despite receiving mail just fine.

Might be acceptable collateral damage, but it’d exclude some people.


I think offering suggested edit is ok but requiring the edit be accepted is unwise.


Unfortunately I've had websites strip out the house number in the "cleaned up" address.


Yep this is the right answer, address jigging is the oldest trick in botting. Nowadays with fingerprint browser, generated credit card number and residential proxy, it is very hard to tell legit buyers from scalpers.


I worked for a while at a service company that helped for a few of those issues specifically. It basically served as a back-search against an email address and known connections (social media), and online connections to give it an effective score if it should be manually verified or sidelines into a separate bucket than the general pool.

And even that isn't as icky as a short project I worked on for a major CC company. Still get the icks thinking about it, and I didn't continue beyond the 6mo contract.


IIUC: scalping manuals and scalper ring Discord accesses are sold as get rich quick schemes underground. Gullible individuals join the big supply choking sessions. Many of them don't make much but masterminds don't care.

So it really has to be done like Cybertruck early deliveries to 100% prevent scalping and flipping(the fact that Musk nails it...)


nobody wants the Cybertruck, why would anyone scalp it?


Early deliveries of the cybertruck were highly anticipated and the cybertruck is still the best selling electric truck even after needing to compete with the F150 lightning, Hummer EV, silverado EV, and Rivian R1T


What?


... they pay low income people $2-5, literally, to be the face of their scalping. It's like gig work for those people. The worker uses their own name, address, and credit card even to make the purchase. The scalper reimburses them + $5.


Low-income people have their own credit card? I'm having trouble picturing the situation where someone willing to accept gig work for a few $ can have a credit card that allows a 4-figure spend. That seems like a very bad deal for the bank to me.


Totally doable - I remember talking with a guy that worked at a sports betting company and they flagged any accounts with any duplicated fields as requiring further investigation (to clamp down on gaming bonus bets and deposit matches).


> I've never understood why anti-scalpers just don't work backwards from shipping address.

If Alice and Bob live in the same apartment and try to buy Steam Machines, but Bob forgets to include his apartment number (everything gets dumped on a shared package room, after all), Alice will be confused when an automated email accuses her of fraud.


I believe that's exactly what the Steam Machine reservation does: limits to one per household, so I take that to mean the address without the name.

Although I think the language in the response dialog will be nicer than accusing of fraud.


Knowing how it works is simple. You can game it with different names, you can modify the text of the address. My address I was able to make 20+ versions without trying. You can add unit # to a house address. It becomes wack-a-mole at some point.


I feel like to put that much effort into anti-scalping efforts you actually have to have a product that's really valuable. For a lot of products this really isn't the case (like this Steam machine iteration).


You see only the address when it is already paid and to be shipped. Cancelling credit card transaction is very costly to the merchant.


I'm pretty sure I have to provide my address to many e-commerce shops during checkout, so that happens before payment.


From what i remember during the great GPU Crisis of 2022, the scalpers were shipping them to randomized addresses and intercepting them before the actual owner scooped them up.

Capitalism really does create a perverse incentive here, and when there's significant margin at play, there's an opportunity.


I played the NewEgg shuffle game for months to get the couple GPUs I needed during that time... not fun at all. I had to limit myself to bundles where the other component wasn't complete garbage. I still have a 600W EVGA PSU from one of the bundles (RTX-3080) that I've only used once to test if my issue was the PSU, MB or something else... turned out to be the RAM.


Synthropic | Detection Engineer + GenAI | Full-time / Part-time | Remote (SF) We're an early-stage startup looking for someone passionate about detection engineering and generative AI.

If you know SIEM, threat intel, logs, detection modeling/strategy, purple teaming, and adversary emulation — and you've been wanting to explore how LLMs/agents can accelerate detection engineering workflows — we'd love to talk.

The role A lot of it is what we call AI babysitting: guiding 1,000 kindergarteners (LLMs) as they try to become senior detection engineers. Sometimes they're brilliant, sometimes chaotic — your job is to shape that into something production-ready.

You'll be part detection engineer, part researcher, part builder, with a big say in shaping the product and how AI gets applied to real-world problems.

Details Full-time or part-time Remote-friendly (SF-based, local a plus but not required) Early team, high ownership, fast iteration

Email Resume: john at synthropic.com


Synthropic | Detection Engineer + GenAI | Full-time / Part-time | Remote (SF)

We're an early-stage startup looking for someone passionate about detection engineering and generative AI.

If you know SIEM, threat intel, logs, detection modeling/strategy, purple teaming, and adversary emulation — and you've been wanting to explore how LLMs/agents can accelerate detection engineering workflows — we'd love to talk.

The role A lot of it is what we call AI babysitting: guiding 1,000 kindergarteners (LLMs) as they try to become senior detection engineers. Sometimes they're brilliant, sometimes chaotic — your job is to shape that into something production-ready.

You'll be part detection engineer, part researcher, part builder, with a big say in shaping the product and how AI gets applied to real-world problems.

Details Full-time or part-time Remote-friendly (SF-based, local a plus but not required) Early team, high ownership, fast iteration

Email Resume: john at synthropic.com


Yeah MCP isn't really doing a whole lot. You can give an LLM a generic HTTP extension. Then list a series of GET/POST/PUT and ask it to form the calls and parse the response. The problem is its not really ideal as the calls aren't natural language and its common for it to misguess the next token and mess up things like the route, body, headers, with a hallucination. So people started shortening these calls to simple things like read_file, etc. Prior to MCP there was a ton of playgrounds doing this with simple Playwright functions.

The thing that surprises me is with MCP we have shirked all of the existing tools around OpenAPI specs, OIDC, etc. We could have created a system where all 'services' expose a mcp.slack.com/definition endpoint or something that spit back a list of shortcut terms like send_message and a translation function that composes it into the correct HTTP API (what most MCP servers do). For security we could have had the LLM establish its identity via all our existing systems like OIDC that combine authentication and authorization.

In the system above you would not "install an mcp package" as in a code repo or server. Instead you would allow your LLM to access slack, it would then prompt you to login via OIDC and establish your identity and access level. Then it would grab the OpenAPI spec (machine readable) and the LLM focused shortcuts 'send_message', 'read_message', etc. LLM composes 'send_message Hello World' -> translates to HTTP POST slack.com/message or whatever and bob's your uncle.

If you wanted to do fancy stuff with local systems then you could still build your own server the same way we have all built HTTP servers for decades and just expose the mcp.whatever.com subdomain for discovery. Then skip OIDC or allow ALL or something to simplify if you want.


Interesting read. Curious how the author feels re: the attack on airbases using shipping containers/drones that was so successful?

Seems to be a unique case that worked especially well for (higher end I'm sure) FPV drones. Getting artillery in on shipping containers would have a higher likelihood of detection. Similarly, the ability to 'guide' in the drones with munitions seemed to allow for greater flexibility during the attack and its effectiveness.

I imagine eventually these cheap FPV's will be augmented with low-cost GPU's allowing for running smallish models and self-guided autonomy. This would seem the next evolution where a commander deploys them in bulk and overwhelms the enemy in a way that can't be jammed like radio-communication. Similarly, horrifying when you consider their eventual use in terrorism scenarios...


That didn't use FPV drones, they're rather difficult to control at 6000km and they didn't have operators nearby.

Most likely it's the first major deployment of their semi autonomous drone tech, driven "declaratively". They've shown that stuff recently, they probably used it before showing it.


Ukraine’s drones were primarily LTE/4G-connected for remote operation


Likely, but that's not enough


The report said they were guided remotely.

I suspect reality is a combination--think RTS game. You give orders to your units but you don't babysit them.


Yeah that's how I think it went down.

Autonomous control, likely from a base station nearby, or one of their new carrier drones, and remote command.


8Flow.ai | Founding Backend Engineer | FT | OnSite | San Mateo

-- Key skills: Nodejs/Typescript, Python, Nextjs, Terraform, CI/CD, ETL (Airflow), Postgres/Mongo

-- 2-5+ years of experience with strong academic background and excellent communication skills.

-- Full-time, on-site position with equity options and comprehensive health benefits.

8Flow.ai | Founding ML Eng. | FT | OnSite | San Mateo

-- Key skills: Python, Tensorflow, PyTorch (or similar), AWS

-- Design and develop machine learning models for various applications, including but not limited to transformers, hidden Markov models, GRUs, BERT, GPT, LSTMs, reinforcement learning models, and diffusion models.

-- Expertly preprocess and encode unstructured, time series, and structured data into suitable formats for diverse machine learning models.

-- Implement cutting-edge machine learning algorithms and frameworks to solve complex problems.

-- 4-5+ years of experience with strong academic background and excellent communication skills.

-- Full-time, on-site position with equity options and comprehensive health benefits.

Send resume and any relevant projects or links to frank (at) 8flow.com


8Flow.ai | Founder's Associate | FT | OnSite | Palo Alto, West Hollywood

Launch Your Career in Tech: Work directly with our CEO in a high-growth startup.

-- Key skills: Business, Economics, Computer Science; data analysis, strategic planning, project management.

-- 1-2 years of experience (recent graduate) with strong academic background and excellent communication skills.

-- Full-time, on-site position with equity options and comprehensive health benefits.

Send resume and any relevant projects or links to jobs (at) 8flow.com


So as someone who took many of those remedial math classes this article rubbed me a bit the wrong way. Not necessarily that any of his descriptions are wrong about the students or the type of things it covers. Instead there seemed to be this underlying theme in the article about it being a waste of time and of little value to society. I strongly feel any time us as humans sit in a classroom and try to better ourselves even when we ultimately fail, it benefits society overall.

Personally, I was in the basic math in High school, like long division/multiplication freshmen/sophomore year. When I first went to community college around the age of 16-19 I got farther, taking Algebra I and then II. However, once I reached Calculus I crashed and burned, although I did great in my CS and other science classes.

I eventually entered the work force (programming/tech) and over the next half dozen years tried and failed at least 3 times to restart at community college usually failing at Calculus I or college level english. Finally, at 30 it seemed to take, I eventually passed Calc I, Discrete, Linear, got my degree. A blend of community college and state school so I didn't break the bank.

I have friends from other sides of the world that have told me this would only really be possible in the US. In many places their is no equivalent of community/junior colleges or an attempt at adult remedial education. Instead you place in your teens, and if you score well enough you get to go to college. Otherwise, its trade school or similar and much more difficult to escape your socio-economic class. The author and others seem to be advocating for something similar here under the guise of it being unethical to waste resources or give hope to the dumb dumbs. I can't say I agree...


He's talking about taking students who can't do grade 7-9 math and charging them $200,000 and several years of their life for the promise of a career they almost never get. These students are getting screwed over hard. Most of them don't want to be taking the class.


I understand where you're coming from, the author definitely had a chip on his shoulder, but what he's describing is a situation where the students clearly do not want to be sitting in that classroom. They're being manipulated to believe they need to take out loans and go to college to succeed. That system just ends up wasting the time, money, and mental health of everyone involved.


There's a huge difference between failing Calculus and failing Algebra. Calculus is not required for most degrees. Algebra is required for almost all.


8flow.ai | Backend, Front-End, & Data Scientist/ML Engineer | FT/Contract | OnSite | Palo Alto

Backend Engineer, $120-140K/yr:

  --  Contribute to our AI-driven personalized automation platform.
  --  Key skills: NodeJS, Python, Docker, Terraform, Serverless; GCP (Preferred); NoSQL/SQL databases.
  --  2-5+ years of experience in backend systems and cloud ecosystems.
  --  Full-time, on-site position in Palo Alto.
Front-End Engineer, $120-140K/yr:

  --  Proficiency in React, Typescript, Javascript, modern front-end development.
  --  Experience delivering reactive UIs for web pages and Chrome Extensions (Manifest V3)
  --  Skilled in transforming Figma mockups to live UIs.
  --  Full-time, on-site position in Palo Alto.
Data Scientist/Machine Learning Engineer, $125-150K/yr:

  --  Full-time contract role with potential to convert to employee.
  --  Work on predictive models for user automation and workflows.
  --  Experience with BigQuery, GCP ecosystem, and Vertex AI preferred.
  --  Remote candidates considered, Palo Alto location preferred.
What we offer:

  --  A dynamic environment for professional growth in a leading AI company
  --  Competitive compensation + equity in a seed stage startup
  --  An innovative and collaborative team culture
  --  Medical, Dental, Vision
  --  Comprehensive amenities including breakfast, lunch, dinner for on-site employees
Sorry no visa sponsorship at this time.

Interested in being a part of AI-driven innovation? Email your resume/LinkedIn and a brief introduction to frank at 8flow.com


So my $0.02 from being on both the hiring and trying to get hired side of the fence. Also I can't do a whiteboard interview to save my life, never could. I mostly think the process everyone is running makes a bit more sense for entry-level applicants. You are dealing with a candidate pool exactly like what you describe above. However, for anything above a junior dev it is horribly inefficient.

Instead I'm always surprised more places don't rely on references and prior experience. Yes people lie, but in my experience its relatively easy to tell the difference with a simple glance at their LinkedIn. If I look at a candidate that spent 2-3 yrs as a Software Engineer at some company that I'm relatively familiar with, and they seem to have 2nds and thirds to people I know in the industry, then pretty good chance they aren't lying. Same for people taking the time out to write recommendations for them. Even bigger signal if they want setup some calls with their prior co-workers who can vouch for them, to me that means they stand by their work and reputation.

I recently went through about seven rounds for a senior role. During that time I repeatedly offered to setup some time with my prior coworkers from those I directly managed, to peers, to those I reported to (executive team). My thinking being that they could hear from the horses mouth how I lead a team, my work ethic, etc. They did not take me up on the offer, which to me was crazy. Yes, I could be running some machiavellian scam with 2-3 people who also made a fake LinkedIn, I also could have put up fake articles in PR Newswire announcing my last position, could have spoofed all those blogs I co-authored from the company I worked at 2 jobs ago, etc. But really, wouldn't it be a better signal for a candidate to offer and have all these things?

Instead you see an industry that puts someone with ~10 yrs experience through a whiteboard interview. It makes no sense.


I think this is more in line with how hiring works for senior jobs. I've been part of 50+ hiring decisions and do it like this.

Social stuff is absolutely the first thing I'm checking. It's a quick test to spot total lies, e.g. you claim you worked somewhere but are connected with zero people on any social network, or claim attendance at a school with zero connection to anyone. If nothing else, it helps to build rapport for the interview.

I would 100%, absolutely trust a personal recommendation over a dumb whiteboard interview.


> Social stuff is absolutely the first thing I'm checking. It's a quick test to spot total lies, e.g. you claim you worked somewhere but are connected with zero people on any social network, or claim attendance at a school with zero connection to anyone. If nothing else, it helps to build rapport for the interview.

There exist quite a lot of people who have no account on any social network for privacy reasons.


You want to make it hard on yourself, that's your business.


> If I look at a candidate that spent 2-3 yrs as a Software Engineer at some company that I'm relatively familiar with, and they seem to have 2nds and thirds to people I know in the industry, then pretty good chance they aren't lying.

The problem is: there exist a lot of companies - you can only be familiar with a very small fraction of them. Also, for many big companies, the differences between departments or groups can be a lot larger than between companies of similar size and sector.


Seven rounds! What questions was this company asking you for seven rounds?

Every time I’ve had a company go longer than 2 rounds, another company got me an offer first.


Not the OP, but Elastic and Glassdoor had me do 6-7 rounds.

Glassdoor had the gall to just ghost me after the 6th! Never again.


What questions were they asking you over so many rounds? Like how much more information about a candidate could one possibly need?


I think they were stringing me out while interviewing others. I should have seen through it, but wanted it to work out at the time.


Wow. I feel like for most recruiters, a simple "hey just to let you know you're still in the running"-type of check in would suffice?


If you could credibly spoof all that most companies would love to hire you. Would likely be your most valuable skill.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: