Den irrasjonelle presidenten

Asle Toje mener i DN 3. mars at Donal Trumps straffetoll på stål er rasjonell. Toje nevner at tollen kan stimulere økonomien, bidra til et infrastrukturløft, øke lønningene, bedre handelsbalansen og motvirke dumping av stål fra Kina.

Tollen vil ikke stimulere økonomien, men tvert imot svekke den kraftig. Når importprisene øker med 25 prosent vil prisen på stål i USA øke nesten like mye, da tollen kun påvirker en liten del av verdens etterspørsel. Bedrifter som er avhengig av stål får da økte kostnader. Det gir høyere priser, lavere produksjon og lavere reallønninger. Høyere priser gir mindre, og ikke mer infrastruktur for pengene.

Tollen kan gi en «bedre» handelsbalanse for USA, men det er et par hundre år siden vi forlot den naive idéen om at overskudd på handelsbalansen er et mål i seg selv. USA har høyere avkastning på sine investeringer i utlandet enn motsatt. Det betaler for en del av underskuddet. USAs netto gjeld til utlandet er ellers ikke spesielt stor (43,4 % av BNP i 2016), og mye av den er i form av statsgjeld hvor USA selv bestemmer realrenten. Dette er ikke en situasjon Trump bør forsøke å få landet ut av – tvert imot.

Av samme årsak er Kinas påståtte dumping av stål på sikt en gave og ikke et problem, om det stemmer. Dersom Kina vil selge stål til USA til mindre enn det koster, så er det USA som tjener på det. På kort sikt kan resultatet være arbeidsledighet i stålindustrien, men da er det bedre med målrettede tiltak i en overgangsperiode. Å nekte å motta subsidiert stål er ikke rasjonelt.

Og dette er bare begynnelsen. I tillegg vil handelskrigen gi store tap. Toje har helt rett i er at ståltoll aldri har virket godt før. Det er det en grunn til.

Hjemmelaget indeks gav kjempegevinst

Oljefondet har konstruert en hjemmelaget indeks som visker ut tapene fra departementets mislykkede faktorstrategi.


Det er ikke noen faglig uenighet om at Oljefondets aksjeplukking har gitt et ganske stort risikojustert tap så langt, om vi måler mot den offisielle indeksen. I et rapportutkast som DN har gravd frem kommer professorene Ødegaard og Dahlquist til et tap på 1,4 prosent, omregnet til årlig avkastning.

Da den offisielle rapporten kom var imidlertid den offisielle referanseindeksen plutselig byttet ut med en hjemmesnekret versjon. Kjempetap ble til kjempegevinst.

Forrige tirsdag kom avkastnings- og risikorapporten fra NBIM (forvalteren av oljefondet). Også her måles fondet mot den hjemmelagde indeksen. Ikke overraskende kommer den aktive forvaltningen svært godt ut.

NBIMs mandat gir imidlertid ikke anledning til å måle seg mot selvkomponerte indekser, så hvorfor gjør de det likevel? Forklaringen finner vi sannsynligvis i mislykkede faktorstrategier. En faktorstrategi kan for eksempel være å kjøpe små selskaper eller selskaper med høy bokverdi. Slike investeringer har historisk gitt en meravkastning. Men siden 2013, da NBIM startet å rapportere aktiv forvaltning separat, har disse strategiene vært fullstendig mislykket.

Denne type strategier kan i prinsippet automatiseres ganske mye. Men NBIM har antakeligvis valgt et mer kostbart opplegg, der analyser av enkeltselskaper til sammen blir faktorstrategier når vi aggregerer dem. Dette gir en ganske tilfeldig eksponering mot de ulike faktorene.

Finansdepartementet har selv bedt NBIM om å vedde på slik faktorer i mandatet, men uten å presisere hvordan. Tapene på faktorveddemål er derfor i stor grad et ansvar departementet og ekspertene som har anbefalt dette må ta.

Gevinsten fra å kjøpe undervurderte selskaper, eller selskaper som investerer mer enn gjennomsnittet, har vært en gåte for akademikere i årevis. Dersom det er så lett å slå markedet, hvorfor vedder ikke flere investorer på slike faktorer, slik at gevinsten til slutt forsvinner?

Når faktorstrategiene viser seg å ha feilet de siste årene, kan det rett og slett tyde på at markedet virker bedre enn vi trodde. Flere investorer har trolig fått øynene opp for denne type investeringsknep. Vi vet at populariteten til såkalte faktorfond har skutt i været de siste årene. At avkastningen da synker er som forventet.

I motsetning til NBIM er jeg slett ikke sikker på at dette kun er et forbigående blaff. Kanskje er faktorgevinstene borte for alltid. Eller kanskje ikke.

Avkastningen siden 2013 viser i alle fall med all tydelighet at det ikke er risikofritt å satse på slike strategier. Problemet for NBIM er at de ble bedt om å ta denne risikoen av departementet. Nå blir de straffet for det ved at aktiv forvaltning fremstår som mislykket. Det kan ikke føles særlig rettferdig. Så hva gjør man med det? Jo man lager en egen indeks å måle seg mot.

Men her er forvalteren på ville veier. Da departementet ville ha mer faktorforvaltning, så burde NBIM krevd en indeks som reflekterte det, med faktoreksponeringer skrevet i stein. Ad hoc-indeksen de selv har konstruert i ettertid kan vi rett og slett ikke stole på.

Departementet gav altså i oppgave å systematisk avvike fra indeksen NBIM skulle måles mot. NBIM burde visst at dette var et risikabelt prosjekt. Hva om faktorstrategiene hadde lyktes og gitt kjempeavkastning? Indeksen de nå ber om å bli målt på hadde i så fall visket ut det meste av fortjenesten. Hadde NBIM da insistert på å bruke den? Antakeligvis ikke.

Det er vel sent å finne på en hjemmelaget indeks nå.

Departementet bør nå vurdere om faktorforvaltning i det hele tatt er noe de skal be om. Resultatene de siste fem årene viser dette har vært et tapsprosjekt, og langt fra den gullgruven som flere ekspertutvalg spådde.

Den indeksnære forvaltningen imponerer derimot fortsatt. Dette avkastningslokomotivet har levert en halv prosent risikojustert meravkastning hvert år siden 2013. Ikke dårlig.

Setting up bug bounties for success


Bug bounties end up in the news with some regularity, usually for the wrong reasons. I've been itching to write
about that for a while - but instead of dwelling on the mistakes of the bygone days, I figured it may be better to
talk about some of the ways to get vulnerability rewards right.



What do you get out of bug bounties?




There's plenty of differing views, but I like to think of such programs
simply as a bid on researchers' time. In the most basic sense, you get three benefits:





  • Improved ability to detect bugs in production before they become major incidents.

  • A comparatively unbiased feedback loop to help you prioritize and measure other security work.

  • A robust talent pipeline for when you need to hire.



What bug bounties don't offer?




You don't get anything resembling a comprehensive security program or a systematic assessment of your platforms.
Researchers end up looking for bugs that offer favorable effort-to-payoff ratios for their skills and given the
very imperfect information they have about your enterprise. In other words, you may end up with a hundred
people looking for XSS and just one person looking for RCE.




Your reward structure can steer them toward the targets and bugs you care about, but it's difficult to fully
eliminate this inherent skew. There's only so far you can jack up your top-tier rewards, and only so far you can
go lowering the bottom-tier ones.



Don't you have to outcompete the black market to get all the "good" bugs?




There is a free market price discovery component to it all: if you're not getting the engagement you
were hoping for, you should probably consider paying more.




That said, there are going to be researchers who'd rather hurt you than work for you, no matter how much you pay;
you don't have to win them over, and you don't have to outspend every authoritarian government or
every crime syndicate. A bug bounty is effective simply if it attracts enough eyeballs to make bugs statistically
harder to find, and reduces the useful lifespan of any zero-days in black market trade. Plus, most
researchers don't want their work to be used to crack down on dissidents in Egypt or Vietnam.




Another factor is that you're paying for different things: a black market buyer probably wants a reliable exploit
capable of delivering payloads, and then demands silence for months or years to come; a vendor-run
bug bounty program is usually perfectly happy with a reproducible crash and doesn't mind a researcher blogging
about their work.




In fact, while money is important, you will probably find out that it's not enough to retain your top talent;
many folks want bug bounties to be more than a business transaction, and find a lot of value in having a close
relationship with your security team, comparing notes, and growing together. Fostering that partnership can
be more important than adding another $10,000 to your top reward.



How do I prevent it all from going horribly wrong?




Bug bounties are an unfamiliar beast to most lawyers and PR folks, so it's a natural to be wary and try to plan
for every eventuality with pages and pages of impenetrable rules and fine-print legalese.




This is generally unnecessary: there is a strong self-selection bias, and almost every participant in a
vulnerability reward program will be coming to you in good faith. The more friendly, forthcoming, and
approachable you seem, and the more you treat them like peers, the more likely it is for your relationship to stay
positive. On the flip side, there is no faster way to make enemies than to make a security researcher feel that they
are now talking to a lawyer or to the PR dept.




Most people have strong opinions on disclosure policies; instead of imposing your own views, strive to patch reported bugs
reasonably quickly, and almost every reporter will play along. Demand researchers to cancel conference appearances,
take down blog posts, or sign NDAs, and you will sooner or later end up in the news.



But what if that's not enough?




As with any business endeavor, mistakes will happen; total risk avoidance is seldom the answer. Learn to sincerely
apologize for mishaps; it's not a sign of weakness to say "sorry, we messed up". And you will almost certainly not end
up in the courtroom for doing so.




It's good to foster a healthy and productive relationship with the community, so that they come to your defense when
something goes wrong. Encouraging people to disclose bugs and talk about their experiences is one way of accomplishing that.



What about extortion?




You should structure your program to naturally discourage bad behavior and make it stand out like a sore thumb.
Require bona fide reports with complete technical details before any reward decision is made by a panel of named peers;
and make it clear that you never demand non-disclosure as a condition of getting a reward.




To avoid researchers accidentally putting themselves in awkward situations, have clear rules around data exfiltration
and lateral movement: assure them that you will always pay based on the worst-case impact of their findings; in exchange,
ask them to stop as soon as they get a shell and never access any data that isn't their own.



So... are there any downsides?




Yep. Other than souring up your relationship with the community if you implement your program wrong, the other consideration
is that bug bounties tend to generate a lot of noise from well-meaning but less-skilled researchers.




When this happens, do not get frustrated and do not penalize such participants; instead, help them grow. Consider
publishing educational articles, giving advice on how to investigate and structure reports, or
offering free workshops every now and then.




The other downside is cost; although bug bounties tend to offer far more bang for your buck than your average penetration
test, they are more random. The annual expenses tend to be fairly predictable, but there is always
some possibility of having to pay multiple top-tier rewards in rapid succession. This is the kind of uncertainty that
many mid-level budget planners react badly to.




Finally, you need to be able to fix the bugs you receive. It would be nuts to prefer to not know about the
vulnerabilities in the first place - but once you invite the research, the clock starts ticking and you need to
ship fixes reasonably fast.



So... should I try it?




There are folks who enthusiastically advocate for bug bounties in every conceivable situation, and people who dislike them
with fierce passion; both sentiments are usually strongly correlated with the line of business they are in.




In reality, bug bounties are not a cure-all, and there are some ways to make them ineffectual or even dangerous.
But they are not as risky or expensive as most people suspect, and when done right, they can actually be fun for your
team, too. You won't know for sure until you try.


Registration Guide Account CoinExchange floor



In this article I will continue to guide you how to register an account at CoinExchange floor for sale, trading of copper coin that no other flooring. In the previous post we showed you  register for an account at Bittrex floor ,  floor Livecoin

Account registration instructions CoinExchange

To get started you need to access the homepage CoinExchange Here !
Press the  "REGISTER NOW"
CoinExchange
Then enter your email, username and password in the box register. Click  "Register"
CoinExchange
Shortly afterwards you will receive an email request to activate your account, open the mail and click the link in the email offline.
CoinExchange
Inform successful registration as shown below. Now you need to configure security for a little bit more secure.
Click "Account Settings & Security"
CoinExchange
You will be redirected to the account settings page references. Press the  "Manage Google Authenticator"
CoinExchange
Now you need to:
  1. Download the Google Authenticator app on your phone  (depending on the Appstore or Google Play on your iOS or Android users offline)
  2. Enable scanning a QR code on this app and scan the code (shown below)
  3. Shortly thereafter you will be given 6 random numbers (30 seconds to change 1 times)
  4. 6 Enter this number and press  "Confirm Google Authenticator Activation"
CoinExchange
Note:  Remember to save the sequence  Google Secret  to room later restored in case of loss of phone work reinstalling the application offline.
Information security settings 2 baptism by Google Authenticator successful class as shown below.
CoinExchange

How to purchase - traded on CoinExchange

Now you can buy, sell and trade all right. Basically want to buy the copper coin, then you need to use Bitcoins to buy.
And to Bitcoin, you need to load into, so you can load BTC to  MY ACCOUNT -> Balances
CoinExchange
At BTC line right-click  "Action" -> "Deposit BTC"
CoinExchange

You will be redirected to the page created for BTC, press the button "Generate New Address"
CoinExchange
Ok, you will be granted for Bitcoin address. Now you can send Bitcoins from the other floors, or  buy on Remitano  to send here.
After Bitcoin then you can use to buy other copper coin. press  MARKETS
Then type the name of copper coin to buy into the search box  (for example, where your find Bitdeal copper - type BDL)
Click  line BDL / BTC  soon as it appears.
You will be redirected to the transaction, now you can buy, sell and trade as another floor slightly.
Ok so this article I showed you how to register an account on CoinExchange floor, is also very simple and easy to manipulate not it.
REGAL upcoming contract will be listed on this floor so you enlist register an account to prepare traded to participate in projects of Regalcoin Lending

Account registration guide on the floor Livecoin.net coin investment purchases



In this article I will guide you to  register for an account on the floor Livecoin.net  ( Link Website ) to purchase, transaction Cryptocurrency (electronic money).
Livecoin.net known as a trading platform, trading Cryptocurrency (electronic money) reputable, established and registered in England and community tradecoin rated as one of the exchanges leading reputation besides  Bittrex.com  and  Poloniex.com

Registration Guide Account Livecoin floor

Access the " Home " button Livecoin and click  Open a Trade Account "
Livecoin.net
On the next page, in which:
  • Username  : Enter your username
  • Password  : Enter password
  • Repeat your password  : Reset password
  • E-mail  : Fill in your email
  • Referral code  : Livecoin-pDnVdVNa   (Enter this code)
  • Tick're not robots
  • Tick terms:  I have read and agree to the ... ..
Click  "countinue"
Livecoin.net

Shortly afterwards you will receive an email including the activation sequence and confirm the registration link. (You copy the serial number, and click on the link in the email)
Livecoin.net
After clicking the link you will be redirected to the page shown below, paste the copied sequence in the box  "Confirmation Code"  then press  "Confirm"
Livecoin.net
Now you will be asked to sign in again.
Livecoin.net
Once logged in you will be asked to create a PIN. Please enter a 4-digit PIN code (4 numbers you to think and to remember it) and click  "Continue"
Livecoin.net
A new window appears asking you to enter the PIN again to reconfirm. Press  "I have read ..."
Livecoin.net
Success message as shown below.
Livecoin.net

Enable security guide 2FA (Authy) account Livecoin

With the investment account at any floor you should also enable security Authy then, here is how to secure a safer 2-step help so much. Basically after enabling security ie you will Authy must log in 2 layers,
  • The first is to enter a username and password,
  • Next enter the random 6-digit on the Google Authenticator app on a new phone, log into your account.
To enable security Authy, Livecoin your account  Account -> Security
Livecoin.net
Next select the  "Level 2 advanced". Click  "Change security level"
Livecoin.net
Now you need to:
  1. Get a pen and paper to record the code Secret code kept in the closet later restored in case of loss or lost phone app
  2. Download the Google Authenticator app on your phone  (depending on the Appstore or Google Play on your iOS or Android users offline)
  3. Enable scanning a QR code on this app and scan the code nhé
  4. Press the  "Continue"
Livecoin.net
Shortly afterwards you will receive an email from Livecoin next.
  • Copy the serial number in the email nhé
Livecoin.net
Return Livecoin you need:
  • Copy paste the above sequence in
  • Enter your PIN (PIN was created in the previous step)
  • Enter 6 random numbers in the Google Authenticator app on your phone to
  • Click  "Continue"
Livecoin.net
Such is done, now you will be asked to sign in again with your username and password.
Livecoin.net
Then you need to enter the code on the Google Authenticator app Authy on.
Livecoin.net

Guide purchase - investment on the floor Livecoin

Next I will guide you how to load Bitcoin wallet on the floor in order to buy the copper Altcoin Livecoin other, then wait reserves increased and sold interest-nhé!
I will take the example of buying Firstcoin copper, a copper coin and will show great potential to appreciate in the near future there.
Livecoin.net
Basically to buy any contract you should use altcoin Bitcoins to buy, so the first step is you need to transfer Bitcoin wallet on the floor Livecoin first.

Transferring Bitcoin wallet on the floor Livecoin

To load into your Bitcoin wallet should get on the floor Livecoin address before. In Section  banlance
Livecoin.net
Pull down Bitcoin typed into the search box, then press the button in line Bitcoin "DEPOSIT"
Livecoin.net
A window appears, you copy this Bitcoin wallet address offline.
Livecoin.net
Now you need to transfer Bitcoin wallet address above. Moved anywhere to come for this, however, if you are a novice investor, should use the money to buy Bitcoin floor VND  Remitano  and transfer it into the wallet on Livecoin Bitcoin.
Livecoin.net
After moving from Remitano Bitcoin, about 15-30 minutes later you will see the number of Bitcoin wallet on the floor appeared Livecoin.
Note:  Only when the BTC displayed in the Available column then you have begun transactions nhé
Livecoin.net
To check your transaction history can also go to  "Transaction history"
Livecoin.net

Buying guides on the floor Altcoin Livecoin

So you've got Bitcoin already, now is the time you can use it to buy some Bitcoins other Altcoin Council aims wait reserves rose. Does your coin buyer can not tell the details for you, it needs you to analyze, monitor and research.
In this article I will guide you to buy FirstCoin (I said above), but why buy FirstCoin then I believe it will individuals rose into the future because:
  • In the past 4 months FirstCoin still rising average 180% per month
  • FirstCoin plans to expand its network of global ATM transactions, see more information at www coinatms com
  • FirstCoin investment is entrusted own floor ( www FirstCoin Club ) so communities are involved FirstCoin huge purchase. But when more people buy, the market capitalization and volume traded FirstCoin greater will push prices up higher. (This was similar happened with  copper Bitconnect  in recent years.)
  • ...
Ok so temporary, but now we try to buy some copper FirstCoin offline. To conduct buy / sell you to the menu  "BUY / SELL" (1)
Later:
  • In the search box type in the name you want to buy copper coin  (2) ,  here you can type or Frst FirstCoin
  • Right after that will appear below the line of coin transactions you search  (3)  click on that line
Livecoin.net
Pull down you will see two items:
  • BUY FOR frst BTC  (Inside you buy)
  • Frst SELL FOR BTC  (Inside you sell)
Livecoin.net
So if you buy it now: (left column)
  • You get:  type the number FirstCoin want to buy (which show the number of stars to match the number of BTC you)
  • Price per frst:  this will be the price of Bitcoin FirstCoin is calculated by (auto show)
  • You pay:  the total amount you pay per Bitcoin (Licoin automatically calculated)
Press the button  "BUY frst"  to buy.
Similarly if you want to sell it (right column)
  • You pay:  type the number FirstCoin want SALE
  • Price per frst:  this will be the price of Bitcoin FirstCoin is calculated by (auto show)
  • You pay:  the total amount of Bitcoin you would get (Licoin automatically calculated)
Press the button  "SELL frst"  for sale.
After the purchase is complete you can go to the menu "My orders" to view your transaction history.
Livecoin.net
Go back to the Balance for in section you'll find the amount shown in column Available FirstCoin. Now that you have successfully purchased FirstCoin already.
Livecoin.net
This is how to buy / sell or people often referred to as trade coin (traders) ie you buy at low prices, appreciation and sold for profit in accordance with the goals you set (probably 10 % -20% or 30%, ...). If you see this coin may have potential long-term storage at 2-4 months (hold) for profit-x3-x4 x2 ... x10.
When you decide  to sell Firstcoin  into BTC Okay, now you do not want to invest anymore or want to withdraw money, the root of the Bitcoin can move about  the floor Remitano  to sell to Vietnam Dong. Follow the next step to sell BTC following the VND and move into your account Vietcombank offline.

Transfer Guide Livecoin about Bitcoin from floor to sell for VND Remiatano

First you need to get your address on the floor for Remitano ago. Log into your account later Remiatano into position  WALLET BTC -> ADD
Copy address Remitano wallet on the floor slightly.
Livecoin.net
Livecoin turned to the floor, go to  BALANCE,
Livecoin.net
Bitcoin in selected lines  "WITDRAWAL"
Livecoin.net
A window will appear:
  • O  Amount, BTC:  Enter the amount you want to withdraw Bitcoin
  • O  Bitcoin address:  Paste the address into the wallet on Remitano
  • Click " SEND A PAYMENT "
Livecoin.net
Note :  The limit for withdrawal of Livecoin floor is 4.500 USD per day. So if you want to draw a lot of these will need to wait through the day later.
When Bitcoin was transferred  for Remitano  your right, you will take steps to sell Bitcoins into VND for buyers and withdrawn on account advances in 1 minute Vietcombank offline.

Epilogue

So with this article I hope you have instructions for the account registration on the floor Livecoin and conduct investment transactions other Altcoin colleagues are listed here.
Livecoin floor may not be big and popular with floor  Bittrex.com  and Poloniex com but it is different especially because there are some very prospective copper coin is traded on Bittrex and Poloniex here but not there, namely copper FIRSTCOIN in this tutorial example.