So you want to work in security (but are too lazy to read Parisa's excellent essay)


If you have not seen it yet, Parisa Tabriz penned a lengthy and insightful post about her experiences on what it takes to succeed in the field of information security.




My own experiences align pretty closely with Parisa's take, so if you are making your first steps down this path, I strongly urge you to give her post a good read. But if I had to sum up my lessons from close to two decades in the industry, I would probably boil them down to four simple rules:






  1. Infosec is all about the mismatch between our intuition and the actual behavior of the systems we build. That makes it harmful to study the field as an abstract, isolated domain. To truly master it, dive into how computers work, then make a habit of asking yourself "okay, but what if assumption X does not hold true?" every step along the way.





  2. Security is a protoscience. Think of chemistry in the early 19th century: a glorious and messy thing, chock-full of colorful personalities, unsolved mysteries, and snake oil salesmen. You need passion and humility to survive. Those who think they have all the answers are a danger to themselves and to people who put their faith in them.






  3. People will trust you with their livelihoods, but will have no way to truly measure the quality of your work. Don't let them down: be painfully honest with yourself and work every single day to address your weaknesses. If you are not embarrassed by the views you held two years ago, you are getting complacent - and complacency kills.






  4. It will feel that way, but you are not smarter than software engineers. Walk in their shoes for a while: write your own code, show it to the world, and be humiliated by all the horrible mistakes you will inevitably make. It will make you better at your job - and will turn you into a better person, too.









Jackson Hole and Fed Communication

Fed chair Janet Yellen gave what I considered to be a good speech at this year's Jackson Hole conference (see here).  Not everyone seems impressed, however. The Fed has no credibility, it seems. For example, it keeps saying it's going to do things, like raise its policy interest rate, only to repeatedly back off. I mean, what the heck? Don't they even know what they're doing?

At some level, this degree of frustration is understandable. (I am less sympathetic, however, when it comes to informed journalists and market traders, who should know better.) Let me try to help ease your frustration.

The first thing to keep in mind is that monetary policy is not a precise science. Much remains to be discovered, especially since the environment (technology in particular) continues to evolve. Keep in mind that most central banks employ the services of research divisions. As Einstein is purported to have said: "If we knew what it was we were doing, it would not be called research, would it?"

That's not to say that monetary policy makers are completely clueless. Evidence. Theory. Discussion. Debate. Experience. Wisdom. They all have a role to play in the process of formulating monetary policy. There is considerable consensus along some dimensions (e.g., keeping inflation low and stable). There is outright disagreement along other dimensions. That's just the way it is. And it's likely to remain this way for the foreseeable future. But in the meantime, if you live in the U.S., try to take some solace in this:

Annual Inflation Rates
Now, in terms of Yellen's Jackson Hole speech, what are people complaining about? Well, consider this WSJ article: Yellen Cries Wolf, with the subtitle: Fed chairwoman tries to convince market that a rate rise is coming but investors aren't listening. Of course, digging deeper into the article, the author clarifies that Yellen did not actually say that, only that she came "close" to saying it. Sigh.

The main issue here, I think, is what people expect in the way of Fed communication in terms of its economic outlook and its description/explanation of its policy rule. These are two conceptually distinct objects and are often confused.

My own personal view is that a central bank should make its policy rule clear, but that it should refrain from providing an economic outlook. So, for example, the Fed should want to make it clear that a sharp uptick in inflation would be met with a correspondingly sharp increase in its policy rate (assuming that this is an appropriate policy response). But what would be the use in having the Fed provide an outlook (a probability assessment) over future inflation? All that people need to know, really, is that the Fed is committed to keeping inflation in check. The credibility of this belief is ultimately based on reputation (see diagram above). As for forecasting the contingencies that would trigger this or that policy response, let the private forecasters do their job.

But some people want more from the Fed. They want the Fed to tell them how the economy is going to evolve in the foreseeable future (and in some cases, beyond). As if the Fed, or anyone for that matter, can actually know.

Now, if people generally appreciated the inherent difficulty in offering forecasts of this sort, I'd say that it would do no harm for a central bank to offer its economic outlook--a prognosis that would find its way in a portfolio of outlooks generated by other agencies. Market participants could then combine the information in these outlooks and, together with the Fed's clearly stated policy rule, make their own forecast of (say) the future path of short-term interest rates.

But perhaps I'm being naive. If a central bank was to just state its policy rule and refrain from offering its outlook, it would surely be criticized for not providing the market with enough "guidance." It is the demand for this "guidance" that compels central bankers to offer an economic outlook. Here is the outlook provided by JY (emphasized phrases my own):

Looking ahead, the FOMC expects moderate growth in real gross domestic product (GDP), additional strengthening in the labor market, and inflation rising to 2 percent over the next few years. Based on this economic outlook, the FOMC continues to anticipate that gradual increases in the federal funds rate will be appropriate over time to achieve and sustain employment and inflation near our statutory objectives. Indeed, in light of the continued solid performance of the labor market and our outlook for economic activity and inflation, I believe the case for an increase in the federal funds rate has strengthened in recent months. Of course, our decisions always depend on the degree to which incoming data continues to confirm the Committee's outlook
And, as ever, the economic outlook is uncertain, and so monetary policy is not on a preset course. Our ability to predict how the federal funds rate will evolve over time is quite limited because monetary policy will need to respond to whatever disturbances may buffet the economy. In addition, the level of short-term interest rates consistent with the dual mandate varies over time in response to shifts in underlying economic conditions that are often evident only in hindsight. For these reasons, the range of reasonably likely outcomes for the federal funds rate is quite wide--a point illustrated by figure 1 in your handout...The reason for the wide range is that the economy is frequently buffeted by shocks and thus rarely evolves as predicted.

And so, there you have it. Evidently, the Fed plans to raise its policy rate soon. And if it doesn't, its credibility will be diminished. Or if it does raise rates even though conditions do not warrant it, its credibility will be again be diminished. Or, as the fan chart above demonstrates, the Fed evidently has no idea where interest rates will go. There's no winning this game. Go back and look at the first diagram again and give it a rest.


Velferd tapt i paradis

Norge gjør for lite i kampen mot skatteparadis.

EU skal lage en felles svarteliste over skatteparadis og Panama kommer til å havne der. Torsdag kom Panamas infantile svar. Det lille landet lager sin egen svarteliste over land som svartelister dem, og truer med handelskrig.

EU produserer like mye på én dag som Panama gjør i løpet av ett år. Handelen mellom EU og Panama er helt ubetydelig. Panamas reaksjon er mer morsom enn farlig for EU.

Saken viser at kampen mot skatteparadis går fremover. Hvert år hjelper skatteparadis med å unndra femti milliarder dollar fra beskatning i Afrika. Der er omtrent like mye som kontinentet mottar i u-hjelp. Det er beregnet at svart økonomi utgjør rundt én sjettedel i OECD-land. Skatteparadis gjør det enklere å unndra midler fra beskatning.


Panamas fåfengte forsøk på gjengjeldelse viser hvor enkelt det ville vært for USA og EU å avskaffe skatteparadisene. Dette er gjennomgående små land som er helt avhengig av tilgang til EU og USAs kapitalmarkeder og selskapssystem. At det fortsatt finnes skatteparadis skyldes manglende vilje, ikke manglende evne.

Derfor er det merkelig at norske myndigheter ikke gjøre mer for å undergrave dem. Beregninger viser at norske myndigheter taper 130 milliarder i året på skatteunndragelser. Mye av dette skjules formodentlig i skatteparadiser.

I stedet undergraver norske myndigheter sitt eget skattesystem ved å tillate innkjøp fra selskaper registrert i skatteparadis. Det gjør det enklere for leverandører å operere der og det blir enklere for paradisene å overleve.

Oljefondets etiske retningslinjer burde av samme grunn endres slik at selskaper som er registrert i skatteparadis kastes ut. DN fant i fjor at fondet hadde 2,3 % plassert i paradiser. Det kan selvsagt koste noe å sparke ut selskapene, men det kan bidra til høyere skatteinntekter på sikt.

For ordensskyld så er ikke et skatteparadis et land med lav skatt. Det er etisk uproblematisk at enkelte land har lavt skattenivå fordi de er mer effektive eller velger å prioritere ned offentlig velferd.

Problemet oppstår når utenlandske skatteflyktninger gis særfordeler i form av skattefritak, mens innbyggerne betaler vanlig skatt. Særbehandlingen kombineres gjerne med hemmelighold, som vanskeliggjør arbeidet for skattemyndighetene, men hjelper skattesnytere. I det et skatteparadis avvikler diskrimineringen av egne borgere og hemmeligholdet, opphører det å være et skatteparadis.

Så hvorfor er skatteparadis skadelig? La oss tenke at norske selskaper kunne flytte overskuddene til Danmark og få null skatt, og danske selskaper fikk null skatt i Norge. Fraværet av selskapsskatt ville resultert i en ekstrem høy skattesats på arbeid, lavere produksjon og et stort samfunnsøkonomisk tap. De danske bedriftene i Norge ville bidratt til økt bankaktivitet, men vi ville tapt like mye på skatteflukt til Danmark. Totalt sett ville begge land tapt.

Skatteparadis har altså ingen samfunnsøkonomisk berettigelse. Hovedfunksjonen til skatteparadis er å undra beskatning og skjule informasjon, lovlig eller ulovlig.

Tidligere i vår listet PwC opp noen grunner til å bruke skatteparadis som de mener er legitime, men fordelene som nevnes er helt vanlige i vestlige industriland. Det er normalt med en enkel selskapslovgivning, regler for å unngå dobbeltbeskatning, utsatt skatt på utbytte, ingen begrensninger på valutaoverføringer og et velfungerende rettssystem, slik vi har det i Norge.

Argumentasjonen rakner fullstendig dersom vi ser på Verdensbankens rangeringer over hvor enkelt det er å gjøre forretninger i ulike land. Norge kommer på niende plass, tett flankert av de andre industrialiserte landene. Skatteparadisene ligger håpløst langt etter. Panama kommer på plass sekstini. Det er vanskelig å se andre grunner til å plassere penger i Panama enn lav skatt for utlendinger.

Innfører vi strengere regler for selskaper fra skatteparadis risikerer også Norge å havne på Panamas liste. Den støyten får vi ta.

CSS mix-blend-mode is bad for your browsing history


Up until mid-2010, any rogue website could get a good sense of your browsing habits by specifying a distinctive :visited CSS pseudo-class for any links on the page, rendering thousands of interesting URLs off-screen, and then calling the getComputedStyle API to figure out which pages appear in your browser's history.




After some deliberation, browser vendors have closed this loophole by disallowing almost all attributes in :visited selectors, spare for the fairly indispensable ability to alter foreground and background colors for such links. The APIs have been also redesigned to prevent the disclosure of this color information via getComputedStyle.




This workaround did not fully eliminate the ability to probe your browsing history, but limited it to scenarios where the user can be tricked into unwittingly feeding the style information back to the website one URL at a time. Several fairly convincing attacks have been demonstrated against patched browsers - my own 2013 entry can be found here - but they generally depended on the ability to solicit one click or one keypress per every URL tested. In other words, the whole thing did not scale particularly well.




Or at least, it wasn't supposed to. In 2014, I described a neat trick that exploited normally imperceptible color quantization errors within the browser, amplified by stacking elements hundreds of times, to implement an n-to-2n decoder circuit using just the background-color and opacity properties on overlaid <a href=...> elements to easily probe the browsing history of multiple URLs with a single click. To explain the basic principle, imagine wanting to test two links, and dividing the screen into four regions, like so:



  • Region #1 is lit only when both links are not visited (¬ link_a ∧ ¬ link_b),
  • Region #2 is lit only when link A is not visited but link B is visited (¬ link_a ∧ link_b),
  • Region #3 is lit only when link A is visited but link B is not (link_a ∧ ¬ link_b),
  • Region #4 is lit only when both links are visited (link_a ∧ link_b).




While the page couldn't directly query the visibility of the segments, we just had to convince the user to click the visible segment once to get the browsing history for both links, for example under the guise of dismissing a pop-up ad. (Of course, the attack could be scaled to far more than just 2 URLs.)




This problem was eventually addressed by browser vendors by simply improving the accuracy of color quantization when overlaying HTML elements; while this did not eliminate the risk, it made the attack far more computationally intensive, requiring the evil page to stack millions of elements to get practical results. Gave over? Well, not entirely. In the footnote of my 2014 article, I mentioned this:




"There is an upcoming CSS feature called mix-blend-mode, which permits non-linear mixing with operators such as multiply, lighten, darken, and a couple more. These operators make Boolean algebra much simpler and if they ship in their current shape, they will remove the need for all the fun with quantization errors, successive overlays, and such. That said, mix-blend-mode is not available in any browser today."




As you might have guessed, patience is a virtue! As of mid-2016, mix-blend-mode - a feature to allow advanced compositing of bitmaps, very similar to the layer blending modes available in photo-editing tools such as Photoshop and GIMP - is shipping in Chrome and Firefox. And as it happens, in addition to their intended purpose, these non-linear blending operators permit us to implement arbitrary Boolean algebra. For example, to implement AND, all we need to do is use multiply:




  • black (0) x black (0) = black (0)
  • black (0) x white (1) = black (0)
  • white (1) x black (0) = black (0)
  • white (1) x white (1) = white (1)



For a practical demo, click here. A single click in that whack-a-mole game will reveal the state of 9 visited links to the JavaScript executing on the page. If this was an actual game and if it continued for a bit longer, probing the state of hundreds or thousands of URLs would not be particularly hard to pull off.




Fastlåst i vanvittig oljespekulasjon

60 dollar lavere oljepris gir tap på over to millioner for hver nordmann. Oljen i havgrunnen er et gigantisk veddemål som vi ikke kan komme oss ut av.

I forfjor anslo fremtidsmarkedet for olje at prisen på olje ville ligge på rundt hundre dollar fatet om ti år. Nå mener markedet at førti dollar er en fair pris. Det betyr en forskjell på tolv tusen milliarder kroner for oljereservene som vi ennå ikke har hentet opp (se figur).

Blir prisen lav de neste årene, så er det bare én fjerdedel av verdiene igjen. Fremtidige pensjoner er altså avhengig av tilfeldige svingninger i prisen på olje.

Vi kan ikke pumpe opp all oljen i dag selv om det var praktisk mulig, da ville prisen kollapset. Vi er derfor låst fast i dette gigantiske veddemålet. Men dette er åpenbart et rent luksusproblem. I verste fall blir ikke oljeformuen fullt så enorm som vi hadde ventet. Vi får neppe mye sympati internasjonalt om vi klager på situasjonen.


Enkelte har argumenterer for at olje i grunnen er en bedre og mindre risikabel investering enn penger i oljefondet. Regnestykket viser at det er feil. På det verste falt oljefondet med 35 prosent. Det blir bare en moderat krusning sammenlignet med fallet som har radert bort tre fjerdedeler av verdien på oljereservene våre.

Det kan finnes klimaargumenter for å pumpe opp mindre olje, men de økonomiske argumentene er utvetydige. Minst risiko får vi om vi pumper oljen opp så snart som praktisk mulig og konverterer den til finanskapital.

Oljeprisen er viktig for Norge også på andre måter. Krisen i oljenæringen har vist hvor avhengig norsk økonomi generelt er av oljeprisen. Sammenlignet med effekten på oljereservene er imidlertid oljenedturen ganske triviell. Etter å ha sett en katastrofal lav oljepris på under tretti dollar fatet har veksten i innenlands produksjon falt med bare to prosent. Det gir et produksjonstap på omlag 47 milliarder i 2016. Småpenger altså.

Verdiene av oljeselskapene staten eier er også av forholdsvis liten betydning. Samlet har tapet de siste to årene på Statoil og andre oljeaksjer ikke vært oppe i mer enn seks hundre milliarder. Sammenlignet med de tolv tusen milliardene som oljereservene har falt med, blir det puslete greier.

Småpenger eller ikke, hadde Statoil og oljeaksjene blitt solgt slik enkelte foreslo, så ville mye av tapet vært unngått. Indeksen som oljefondet følger økte nemlig litt i samme periode. Dersom oljeprisen ikke tar igjen børsindeksen vil tapet bli i størrelsesorden to til fire hundre milliarder, litt avhengig av salgstidspunkt.

Det er penger det også, som vi kunne brukt på sykehus, flyktninger eller et annet godt formål.






Slik er beregningene gjort:
  • Årlige skatteinntekter og direkte inntekter (SDØE) forklares hovedsakelig av produksjonsvolum, oljepris og tid.
  • Effektene av disse er beregnet med en loglinær modell som forklarer 88 prosent av variasjonen i inntekter.







Ny statistikkblogg

For de med over gjennomsnittlig interesse for statistikk har vår statistikkguru her på huset, Øystein Myrland, opprettet en ny blogg. Som de fleste statistikere med respekt for seg selv brukes det R her. R er et svært populært «open source» programmeringsspråk for statistisk analyse. Fordelene med R i forhold til andre statistikkpakker er åpenbare: Det er gratis og det finnes et enormt bibliotek med analysepakker som blir stadig bedre og flere. Jeg blir ikke overrasket om R blir nesten enerådende om får år. Besøker du bloggen vil du legge merke til at Myrland også kan skrives MyRLand. Tilfeldig? Neppe.

DSGE Theory

This post is for my students, and whoever else is interested in what DSGE theory is and why I find it useful.

Dynamic Stochastic General Equilibrium (DSGE) theory refers to a methodology employed by macroeconomists to build DSGE models -- mathematical representations of the macroeconomy. DSGE models, like all models, are used for a variety of purposes. They are used to help organize thinking. They are used to interpret data. They are used to help make conditional forecasts. They are used to predict and evaluate the possible consequences of government policies (especially useful for policies that have never been tried before). They are used to help make policy recommendations.

The use of DSGE theory is often criticized in ways that reflect what I view as a deep misunderstanding of the research program, how it fits in with the evolution of macroeconomic theory over time, and how it is actually applied by (say) central bank policy makers. This is, I think, to some extent the fault of DSGE practitioners who, accustomed to speaking in their specialized trade language, find it difficult to translate core ideas and findings in the vernacular. (This is an issue with most trade associations, of course, but is especially acute in economics because so many non-specialists take an interest in the subject.)

Let me first provide some context for my views. We are all scientists trying to understand the world around us. We use our eyes, ears and other senses to collect data, both qualitative and quantitative. We need some way to interpret/explain this data and, for this purpose, we construct theories (or hypotheses, or models, or whatever term you prefer). Mostly, these theories exist in our brains as informal "half-baked" constructs. This is not meant to be a criticism (as long as we recognize the half-baked nature of our ideas and why some humility is always in order). Often it seems we are not even aware of the implicit assumptions that are necessary to render our views valid. Ideally, we may possess a degree of higher-order awareness--e.g., as when we're aware that we may not be aware of all the assumptions we are making. It's a tricky business. Things are not always a simple as they seem. And to help organize our thinking, it is often useful to construct mathematical representations of our theories--not as a substitute, but as a complement to the other tools in our tool kit (like basic intuition). This is a useful exercise if for no other reason than it forces us to make our assumptions explicit, at least, for a particular thought experiment. We want to make the theory transparent (at least, for those who speak the trade language) and therefore easy to criticize. Constructive criticism is the fuel that fires the furnace of new ideas in academia. [ End of philosophical rant :) ]

Now let me turn back to DSGE theory. I think it will be useful to break the acronym into its parts and discuss each component separately.

The "D" stands for dynamic--as in--the phenomena in question involve a time element. The opposite of dynamic is static. While static models have their uses, who's going to argue that a dynamic element isn't desirable? Almost all decisions like consumption and saving, deficit-finance, human capital investments, have a time dimension to them. No controversy here, I hope.

The "S" stands for stochastic--as in--societies appear subject to random events, like unforeseen technological breakthroughs, unexpected changes in government policy regimes, or just random acts of nature. Again, I don't think there's much controversy with this idea. Note, however, many DSGE models do not have the S, in which case we might instead employ the acronym DGE. (For a history of the evolution of these acronyms, see here.)

The "G" stands for general--as in--well, it's not entirely clear. There is a traditional distinction in economics between partial and general equilibrium theory. The partial equilibrium approach (associated with Alfred Marshall) refers to the supply-demand curve analysis that most people are familiar with. The analysis is "partial" in the sense that it typically restricts attention to a particular market--like the market for motor vehicles, taking the price of other goods as given. In contrast, the general equilibrium approach (associated with Leon Walras) strives to model the economy as a closed system, paying particular attention to how markets interact with each other and how prices are determined jointly. Importantly, the "G" insists on giving an explicit account of the government budget constraint (i.e., a government is not to be modeled as Jesus feeding the multitude.) Another way to think about "G" is that it means to capture the possibility of "feedback effects." The notion of feedback effects in macroeconomic systems is not, I do not think, controversial.

This leaves us with the "E," which stands for equilibrium. Here lies the controversy. But why? For all sorts of reasons, some of which are based on legitimate concerns, and some of which are based on simple misunderstanding.

Let me first address the misunderstanding. The concept of "equilibrium" in economics has evolved to mean something quite specific and something quite different from the notion of a "system at rest" (which is closer to what economists label a steady-state). Technically, an equilibrium is simply a set of conditions imposed by the theorist to help determine the outcome of an hypothetical social interaction. In this sense, an equilibrium is probably better thought of as a solution concept. There is no unique way to specify an equilibrium solution concept. In the game theory, there is plethora of alternatives, beginning with the Nash equilibrium. The classical theory of Walras uses the concept of a competitive equilibrium. In my own view (probably not representative), I even think of general disequilibrium as just another type of equilibrium concept. Every theorist has to have a solution concept in mind when deducing the likely outcome of an hypothetical social interaction. There is no right or wrong way to specify an equilibrium concept--there are just more or less useful ways in doing so.

Another misunderstanding is that insisting on equilibrium analysis necessarily implies that one assumes markets always "clear" in the sense prices adjust to ensure supply equals demand at all times. This is understandable because many DSGE models (especially the RBC variety) do in fact make this assumption. But, of course, there's a large class of DSGE models that do not (e.g., the NK variety). More to the point, it's important to understand that the concept of equilibrium is not wedded to the concept of competitive market-clearing models. In DSGE models that replace centralized Walrasian markets with decentralized search markets, conventional "supply and demand" curves do not even exist. In search models, prices are determined through bilateral negotiations and the "clearing" mechanism operates through quantity variables, like labor-market tightness (the ratio of vacancies to unemployment).

A more legitimate concern relates to the equilibrium concept of "rational expectations." Because of the "D" element, the theorist must take a stand on how expectations are formed and updated over time. Macroeconomic theorists have grappled with this question for over a century, if not longer (see Laider, 1999). There is little controversy that people are forward-looking. But exactly how are they forward-looking? John Muth (1961) suggested that, in the context of a model, we might begin by assuming that our modeled agents (somehow) form model-consistent expectations (i.e., "rational" expectations). Intuitively, the idea is that we should not model people as forming expectations that are wildly at odds with the reality unfolding around them and, that as a limiting case, we might even begin by assuming that expectations are formed in a manner that is perfectly consistent with the surrounding reality. Among other things, model agents are assumed to possess common knowledge (see, Geanakoplos, 1992).

Now, if all of this sounds like a bit of a stretch, it no doubt is. The relevant criticism and response is recorded in section 6.4 Stationary Models and the Neglect of Learning in Lucas and Sargent (1979). I'm not going to get into it here, but suffice it to say that there's been a large and vibrant literature on non-rational-expectations "learning" models since Lucas and Sargent wrote that piece. And you'd be very wrong to think it hasn't had any influence in the way policymakers, central bankers in particular, think about policy and its effects. St. Louis Fed president James Bullard, for example, is among those who have made significant academic contributions in this area (you can view his works here).

In terms of their use in policy making, DSGE models are no different than their predecessors. Some applications entail large scale quantitative models to make conditional forecasts. But their main value is the manner in which they (along with other models) are used to organize thinking in policy deliberations. I think I disagree with Narayana Kocherlakota here when he suggests that DSGE models are built purposely not be useful for day-to-day policy making--for example, in helping to answer the question of whether the interest rate should be changed in the upcoming FOMC meeting. Instead, he views DSGE models as useful for thinking about policy rules (which I agree with). But his view here seems inconsistent with a view he has expressed elsewhere, namely, that isolated changes in the policy rate are largely irrelevant--that what is important is how the path of interest rates is expected to evolve over time (I agree with this too). I think that the decision of whether to move rates today has to be made in the context of what the policymaker views as wise policy principles based on some combination of theory, evidence, and experience. These principles should no doubt make allowances for the necessity of discretionary and ad hoc policy actions. But this allowance does not mean that reference to a DSGE model (or any other model) cannot be useful for thinking through the likely consequences of a contemporaneous policy action. [Note: I may have misunderstood the point NK was trying to make.]

In terms of a defense of the use of DSGE theory for policy, I can do no better than Chris Sims here (video, highly recommended). See also this interview with Tom Sargent, who defends modern macro theory. Finally, I have my own related post: In Defense of Modern Macro Theory.