Hacker Newsnew | past | comments | ask | show | jobs | submit | tptacek's commentslogin

This is a huge problem in US health care financing: we have a fee-for-service model, no price transparency, and a consumer base (insulated from a lot of the costs of procedures by indirect payment through employer-provided insurance) conditioned to think procedures are inherently good. We waste billions annually on procedures that shouldn't be delivered at all.

I'm fond of pointing out the stat (true as of a year ago) that Massachusetts (I think it's MA?) has more MRI machines than the entire country of Canada.


I would posit this is more of a function of Canada having too few machines, with a median wait of 10 weeks for an MRI. [1]

To me it's crazy that people are waiting an average of nearly 3 months to get imaging. This is probably after waiting a couple months for their doctor's appointment to get the MRI scheduled in the first place.

[1] [https://getmrifast.ca/mri-wait-times]


One of the reasons I left Canada was it took me 6 months to get an MRI after a severe head injury in 2017. I have since gladly paid nearly 500k in taxes to other countries. Fuck Canada.

If I were waiting that long I’d fly to SE Asia. I got one in Cambodia same week for $1200.

Clearly you had the means... was it not possible to pay for private healthcare?

No, that's illegal. Thats what single payer means, only one payer is allowed [1].

Is meant to encourage rich people to support the health system since everyone's in it. But in reality the very wealthy go to Buffalo and immigrants visit their home countries.

It's also not lost on public policy experts that MAID has the potential of "solving" a lot of structural problems in Canadian health care and... long and behold MAID has expanded tremendously in ten years.

[1] with some exceptions largely grandfathered in


That's not what single payer actually means, since Australia has both a single payer public system and a separate private system. The part that allows these to both exist is that the public system has vast resources (i.e. an entire national/set of state governments) that can act as one for immense negotiating power. This does not preclude a private system from existing.

It's not meant to "encourage the rich to support" the health system, it's meant to avoid completely gutting the public health system by creating a parallel pay-for-play system where only the richest pay and subsequently suck up all of the already finite resources and talent.

Introducing parallel private health care is just accelerationism for privatization wonks who want to just see the death of universal healthcare by sucking it dry for those willing to pay.

There's no magic wand with the resources available for healthcare. Creating private systems so rich people can skip the line doesnt magically create that capability, it means taking that capability from someone who maybe needed it more in the public side of things.


> But in reality the very wealthy go to Buffalo

This has to be a brand new sentence (post 1950s anyway).


What does that have to do with the conversation here?

Some countries have a dual insurance system that might allow wealthier people to get better access.

Think of Steve Jobs jumping to the head of the line for a liver transplant


he was already at the head of the line where he got the liver.

the article below is interesting, as it goes into the hearsay you repeated and the facts of how the system works.

https://www.nytimes.com/2009/06/23/business/23liver.html


That is kindof crazy! Imagine you are suspicious that something is awry in your soft tissue, in which case I think MRI is the main diagnostic (?). Then you don’t find out for ten weeks, plus some for analysis!

MRI's are expensive and difficult to amortize for poorer countries or ones that don't have a great healthcare system.

https://www.statista.com/statistics/282401/density-of-magnet...

Japan is a standout, and then you see most of the West just below them... Canada is way down the list.


Waiting 10 weeks for an MRI is consistent with my experience in the US. This could be a regional thing. When my mom lived in her home state, she had nearly same-month or even same-week access to specialists. Now, living in my state, most appointments are booked more than a year out. She has talked about flying back to her home state every year to have her annual appointments. This is medical tourism within the country.

Not only did I have to wait for my MRI, but as the date approached, I got a call saying that they had canceled it because the insurance refused to cover it. I offered to pay out of pocket. Nope, they simply canceled it.

Of course if you can pay for quicker care in another country, it will seem like care in that country is quicker, but the people living in that country might not have the same privilege. Most of the people I know who move here from outside the US think our system is insane.

There's a billboard on my way to work for a private medical imaging service that offers shorter wait times.


>https://getmrifast.ca/mri-wait-times

It's sad that seemingly the top result for this search term is an AI slop lead-gen site, rather than the actual source:

>Disclaimer: Wait times shown are estimates based on publicly reported data from the Fraser Institute, CIHI, and provincial health authority reports.


Also citing Fraser Institute, a known extremely right-wing hack "think tank" is like citing a used car salesman on the benefits of buying a car. Their entire raison d'etre is to privatize any remaining public good in Canada, so they will always hunt for any kind of information or data they can to paint whatever picture they want from their lobby funds.

>"I'm fond of pointing out the stat (true as of a year ago) that Massachusetts (I think it's MA?) has more MRI machines than the entire country of Canada."

Long wait times (6-12 months+) for MRIs (due to a lack of both machines and technicians) are a frequent complaint by Canadians.


Yep. Wealthy Canadians often come to the USA as medical tourists and pay cash to skip the queue at home for elective procedures like MRIs or joint replacements.

You can pay for MRIs in Canada. My friend needed one and he had it within the week for $800.

I think private MRIs have been around, at least in my province anyways, for close to 30 years.


That’s about 2X as expensive as the cash pay MRIs near me in the United States, which is interesting. You don’t have to wait a week here, but that’s to be expected with how many MRI machines are all over the place. For specialty imaging like contrast or doing time resolved MRI you do have to wait a little longer to get someone qualified to do it properly. Some of those take a little more expertise that the cash walk-in places aren’t good for.

$800 CAD is around $600 USD

Hmm, that's good information to have, I had no idea. I just had an MRI appointment that I had completely forgotten about or what it was for I was waiting so long (and obviously not having the issue for anymore). I'll know this for next time and consider it.

$800!!

Jesus... I can get a chest-abdomen-pelvis MRI on US insurance for less than half of that, and the lead time is measured in weeks at most.


I'm happy to confess I don't understand US medical care but OP was saying that $800 was the price they paid but you're saying that if one had "US insurance" it would be "less than half of that" ?

I mean if you have insurance I don't know why it's costing you anything but regardless it's hardly surprising that you're cost is less than the person paying cash ?


[flagged]


I think the actual issue is that America often has infinite wait times because people can't afford the procedure.

Oh yes I see, America bad, got it.

> I'm fond of pointing out the stat (true as of a year ago) that Massachusetts (I think it's MA?) has more MRI machines than the entire country of Canada.

I'm also quite fond of pointing out that Canada and the state of California have roughly the same populations.

Canada's population is incredibly spread out, but also concentrated in about 5 major cities.

When I needed an MRI on my brain is was roughly a week, and that was in a smaller (under 100K people) city.

It's a triage system, although I wouldn't want to suffer through a "less important" issue.


At least most medications and interventions have to go through RCTs and tend to be quite standardized.

Don't even get me started with mental health therapy...


People love to complain about health insurance companies denying claims and prior authorization requests. While there are frequent errors and abuses on the payer side, the reality is that about a fifth of all treatments are "low value care" which aren't justified by evidence-based clinical practice guidelines and may even harm patients. If we want to reduce healthcare costs and improve outcomes then we've got to get that under control.

https://www.bloomsbury.com/us/price-we-pay-9781635574128/


A lot of surgery that isn't directly saving you from death is worthless if you're lucky...

To be fair to your latter point, Massachusetts is arguably the biomedical research capital of the world, those MRI machines are being put to research purposes.

I’m reminded of a quote from my biomed days: “If there’s ever a zombie apocalypse, you can bet it started in Cambridge.”

I just thought it an amusing anecdote until COVID, and then realized it’s less that said virus would be developed here and more that we have the business idiots to let it loose.


Careful which Cambridge you are on about. I take you are referring to Cambridge MA, US and not Cambridge, Cambridgeshire off of England, UK.

I'll note that COVID-19 "broke out" in Wuhan a city which has a virology laboratory nearby - the Wuhan Institute of Virology, who perform research on viruses.

I'm sure that is completely incidental to the pandemic of 2020-21. Clearly, some rather nasty live food markets are to blame.

It wasn't your numpties wot did it then, it was another lot that time!


There’s no evidence that Covid started in wuhan. The wet market was ruled out.

Wow, amazing how wrong such a short comment can be!

That's an odd point to make when in the actual world we live in, Cambridge was where the first COVID vaccine was developed.

An elderly relative of mine went to get an MRI to prove the occult fracture of the sacrum that was hobbling him.

It took about 12 hours, much of it waiting for his blood pressure to subside low enough to get admitted (a pre-requisite for the MRI).

This is in a city with of about 750k people and nowhere near Massachusetts.


Did that study involve contrast?

It's not strictly a US health care problem either - I've been dumbfounded by foreign coworkers pressing for totally unnecessary medical interventions as if there's no risk associated with doing such things. It's most apparent from the socialized states where the healthcare is ~free.

My impression is this is a modern civilization stupidity in general.

apropos Dead Kennedys track: https://www.youtube.com/watch?v=lVULKYbAeEo


The most important thing to know about this work, which is awesome, is that it relies on access to a raw RSA oracle, where you have a public key and an API that allows you to directly do RSA operations with the corresponding key. The idea is that you then lose access to the oracle, and thus to the private key, but you've gained enough information from your session with the oracle to make forgeries in the future.

So it's not a straightforward general-purpose RSA-1024 signature break; it's pretty situational. The paper goes into detail (in section 5) about how those situations can emerge in practical scenarios.


It’s important to note that by “raw” they mean without padding, which is more rare than just a signing oracle, see section 7 of the paper.

Thank you for this nice explanation. I skimmed the abstract but didn't really understand it.

[flagged]


I'm pretty sure you just described an IACR paper --- with Nadia Heninger's name on it --- as "clickbait"?

They rule for maths. I had an extremely good experience going from high school trig through multivariable calc with them over a year. Best math teacher I ever had.

I think the difference is between someone like you who wants to learn and a teenager who has to learn.

I used to be a tutor, and the kids who wanted to get ahead were people who more needed someone to give them hints as they learned. The ones who needed to get the grade were a lot more reticent and needed a lot more attention and prodding.

I don't think AI as it currently exists is a good choice for those folks.


It comes down to the same issue that all AI comes down to really.

If there’s proper oversight (tutor teaches the student and reviews knowledge while the student uses the AI to study or test themselves) that’s fine.

If it’s just the AI then a student isn’t going to know what they don’t even know to ask.

This can also work with books or adequate material someone is basing their learning on.


If you watch none of the rest of the music, at least watch him play Roland The Headless Thompson Gunner at the end; kind of an amazing song, especially given when Zevon wrote it.

Klippenstein. He's counting on you not looking up the elements of a FARA violation charge. You can't accidentally violate FARA simply by opposing AI; you have to literally be an agent of (that is, under the direction of) China, and a felony violation has to be willful.

The DOJ announcement is surely in supremely bad faith, as is everything else in Trump's DOJ. But this kind of breathless response is exactly what they're hoping for by publishing this stuff.


You're right that there is supposed to be a legal bar for being "directed by" a foreign government, but would you want to gamble on the jury pool setting the bar that high?

Look at the hacker news comment section any time China comes up, and then consider that the average American is considerably less sophisticated.


Yeah, if I'd had no knowing contact with elements of the government of China, I'd take that bet every day of the week and twice on Sundays. I don't even think it'd get to a jury.

You can beat the rap, but you can't beat the ride, and as outright fascism flourishes, you might not even manage the former. When you spend years in an ICE gulag because your speech crosses some nebulous line, it will matter very little what legal rights you think you have.

Ok, that covers you, but there are 100M party members, any Chinese-descended or Chinese-married person in the US probably has a connection to a party member.

"Have you, now or in the past, had contact with a member of Chinese Communist Party?" sounds really scary compared to "Is your uncle a mid-tier director at Huawei?" even though they're describing the same fact.


If you want to formulate a bank-shot argument about how this preys on people of Chinese ancestry, I'm fine with that. All I'm here to say is that you can't plausibly be charged with a FARA violation simply for arguing or protesting for a policy position that China happens to want you to take; the DOJ bears the burden of proving that you knew you were coordinating with China, directly, and, if it's a felony, willfully (that, is, voluntarily, deliberately, with a purpose to break the law).

Read Klippenstein's piece again. Does he want you to know this?


You can't plausibly be arrested by ICE if you're in the US legally, in theory, but look where we are.

I'm afraid that a paranoid, worst-case, bad faith assumption isn't something we can handwave away anymore.


amazing how his responses stopped immediately after posting this very obvious and overwhelming rebuttal.

Is that really how you think conversations work?

The fact is that I don't have a stake in analyses about whether the administration is operating in good faith. I'm an opponent of the administration. I'm already sold on that point.

My problem is with the Ken Klippensteins who are engagement farming with posts that misinform people about how the law works.

If you're already winding up with a reply about how the law doesn't matter anymore, ask yourself "why are we talking about this then?" If it doesn't matter, they don't need to announce anything, and their announcement has no content.

As it stands: the announcement really doesn't have any content anyways; they generate this stuff specifically to rile people like you up, and Klippenstein feeds off that energy like a remora.


Unfortunately for you I don't happen to like Ken Klippenstein, he is not a regular part of my information diet, at all, and I regularly criticize him on other sites under my handle linked to my name. and *you* are *relying* on analysis that assumes that the administration is "operating in good faith" in your post that the person above me replied to. That was the point of the "conversation". Whatever weird projective logic trap you're trying to do, predicting my reply, bad news stranger, I think the law and its enforcement is in a very strange and differentiated state across the country and across federal, state, and municipal boundaries. The California ballot seizure case against Sheriff Bianco is a perfect example.

Apparently my logic "trap" here is making claims about Klippenstein that you agree with.

I don't think this really follows. Negotiation would be problematic, but you can just version the protocols and do WireGuard v1 and WireGuard v2, with v2 in a PQ configuration. As long as the configuration about which to use is static, you're not running up against the IPSEC problem.

I don't think there's anything necessarily complicated about MLKEM that would make this too difficult.

Switching to IPSEC loses you other WireGuard benefits; the wins don't end at "just one carefully curated set of cryptography primitives", but extend into things like DoS prevention and a design that admits to processing incoming frames without dynamic allocation.


Right, but what's the limit of what you can deduce computationally from truly vast training sets? How much structure is there in the subtext of what's written down? It looks like there's rather a lot.

I don't understand this definition of "fair". Things are either good or they're not. Signed XML is not good. That's a fair claim, even if the designers of XMLDSIG didn't know as much as we do.

The DSIG problems are wildly worse than syntax! There's a document object model to contend with, along with invariably-fatal parser differential bugs, and that's before you confront the one global C implementation that almost every DSIG implementation ends up relying on.


My comment was aimed at the particular critique I was replying to, namely, that using XML for ordinary structured data is bad because XML is a markup language. I am not defending SAML more broadly or claiming that none of its mistakes were foreseeable, and particularly am not defending the idea of signing a DOM tree instead of a sequence of bytes. (Though the latter mistake is in principle orthogonal to XML vs. JSON; I confess to not really understanding why they're so correlated.)

OK, totally fair: I'm hair-trigger about attempts to rehabilitate DSIG and SAML, but I have basically no opinions about XML itself. Sorry!

SAML has audience checks and selectable algorithms. I don't like JWT, but it's no XMLDSIG.

Does Tailscale support SAML? If not: why would any other enterprise product need to? Tailscale is like the sine qua non of modern enterprise products, and I believe it's OIDC-only.

I don't believe it's plausible for any non-specialist firm to implement SAML without grave vulnerabilities. I'm not sure I've ever seen it done well. It's been a minute since I've looked (I haven't consulted in several years, but, more importantly: most firms avoid SAML now), but I'm guessing that assertion still holds.


> Tailscale is like the sine qua non of modern enterprise products, and I believe it's OIDC-only.

I think you're drastically overstating Tailscale's share and ubiquity in the market. Maybe it's heavily represented in tech companies or those in The Valley but among rank and file normal companies not dominated by developers, they've never heard of Tailscale


I think you're wrong about this, that basically every F500 with an access VPN setup has heard of Tailscale, and further, despite their penetration being much bigger than "tech companies in the valley", my point was that Tailscale is a modern business that exists to make (at this point) large amounts of money, and they're not doing SAML.

(It is good that they're not doing SAML, because SAML is the worst security specification ever written, and very few organizations have ever implemented it safely).


There are a lot of smaller providers that will eschew some features, require a fairly limited integration surface (was the case with a lot of things with Slack integration before Teams' COVID explosion, for instance) to keep their support and development costs down

The best estimates I could find have TS at a 1-2% market share. And that was my point: You suggested "well if Tailscale can get away with not supporting SAML, anyone can!" and I think that's wrong. 98% of the market already is buying Tailscale's competitors, they can hardly do worse

I'm sure they can juice that a good deal more, but eventually they'll have to start picking off features that they have been avoiding to this point. Will that be SAML? Maybe not, most companies are on Entra ID which supports OIDC. The real tell will be when Tailscale either goes public or sells to private equity. When their backs are to the wall and they need to squeeze out another percent or two in growth and they have a big customer that must have SAML, then they'll do it


And I think you're wrong about this too.

You're overestimating the importance of Tailscale, underestimating the importance of SAML to enterprises and completely skipping over the fact that the customer base that Tailscale has restricted itself to, probably doesn't use SAML to begin with.

Here, I'll share you my thoughts on Tailscale:

I don't use Tailscale. I don't care about Tailscale. I don't know what Tailscale is and I don't really care to know, but I know what SAML is and I know that I will keep using SAML for the foreseeable future, and I know I won't be using Tailscale.

"sine qua non" is hubris.


Agreed.

Pretty much every large enterprise (inc. half a dozen non-tech F500s) I've seen in the past 5 years has used either GlobalProtect or AnyConnect. Slightly further down the scale, you start to see some Prisma, Fortinet, or F5 as well. All of them support SAML, and market it as being a key feature.

Personally, I'd love to see Tailscale being deployed more widely, but I've only ever seen it deployed by tech companies.


One of the issues I've run into with Tailscale OIDC is that an email domain must be mapped to a single tailnet. So if my IdP has consultants or if my domain contains multiple businesses with different tailnets, I need to do some domain mapping in my IdP and train users to login with that special non-email address.

This isn't strictly a limitation of OIDC, but I do see this issue more often with OIDC implementations. With IdP-initiated flows, the app doesn't need to know who's in my IdP ahead of time.


When we started C1.ai - 2020 - as someone who worked previously at Okta - I made a decision to only implement OIDC. (see article for all of the reasons). We were worried in the first 2 years, that some big enterprise would force us to implement SAML.

But it turns out, all the major IDPs support OIDC now. It's a non-issue.


You can use Keycloak as a SAML/OIDC -adapter.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: