Hacker Newsnew | past | comments | ask | show | jobs | submit | reese_john's commentslogin

It is a testament to the bloat and overreach of the Brazilian state in the economy. Such endeavors should be left to the private sector


I disagree. I’d prefer if my government invested more in AI solutions, so as not to depend so much on foreign technology.

In an ideal world, Brazil would have a thriving private sector, capable of competing even in the AI sector. Unfortunately, that’s not the case, and I believe that without government action such endeavors won’t really succeed.


Have you ever worked in a financial institution?

This is such a common occurrence that the BCB had to impose a default $200 nightly limit for Pix trns between 8pm and 6am.

The way it works is, criminals use money mules, or stolen identities, to open legitimate bank accounts, then once the cash hits the account, they fan out the stolen proceeds to crypto rails or other money mules (“laranjas”)

BCB has been trying to solve this with MED 2.0 but it is still a duct tape over the real problem: rampant crime and fraud in Brazil

And let’s not dive into the digital bank heists that have been happening since the last year, when hackers have already managed to steal hundreds of millions of dollars from the financial system by exploiting Pix’s 24/7 network [0]

Such attack to the financial system would have been akin to a war declaration in serious countries, but crime is so widespread and normalized that Brazilians lowered their standards to accept these absurd situations

  [0] Hackers steal R$400m in attack on Pix-connected fintech: https://valorinternational.globo.com/google/amp/markets/news/2025/07/02/hackers-steal-r400m-in-attack-on-pix-connected-fintech.ghtml


> Second, good - they should have an _algorithm_ checking every transaction. MasterCard and VISA do it and do nothing for me;

You are confusing transaction authorization done by card networks/issuers with the kind of fraud analysis that happens post settlement and requires correlating multiple transactions and accounts

> the government could catch all the money laundering

No, you don’t have enough information in transactions alone to identify all money laundering, specially the sophisticated kind.


USD is a hard currency unlike the BRL. It is not supposed to move that fast by design. Google “Regulation E”. Brazil has no such strong provisions for protecting unauthorized transfers out of your account


Your comment is absolute nonsense.


> USD is a hard currency unlike the BRL

How much does this matter in the context of paying in BRL, to a BRL merchant, in Brazil?


>strong provisions for protecting unauthorized transfers out of your account

What's with people complaining that they can't terminate transfers out of their accounts?


It is worth noting that despite all this cheap sovereignty talk from Brazil’s president, in practice Brazil would not be able to operate Pix at that scale without heavily relying on American hyperscalers companies.

Brazilian institutions are paying hundreds of millions of dollars to US cloud providers, specially AWS, to be able to process that many transactions.

Earlier this year, when sa-east-1 was down, major banks were forced to suspend Pix payments for nearly 3 hours. When this happens, some people are literally not able to buy anything because that’s their only payment method. So much for “President Luiz Inácio Lula da Silva proclaiming a nationwide campaign: “Pix is ours, my friend”.”

Don’t get me wrong, Pix has been a great success and a major achievement, but all this adversarial political talk between the US and Brazil administrations is really cringe, both countries are better doing business together.

[1]https://economia.uol.com.br/noticias/redacao/2026/02/07/falh...


Only reinforces the point that relying on american infrastructure as a critical piece of your stack, in 2026, is a liability.


This is not a real problem outside of niche industries

American companies are great to do business with.

Most countries, including Brazil, simply don’t have the capability to pull this on their own. Not enough tech talent nor infrastructure


> Most countries, including Brazil, simply don’t have the capability to pull this on their own. Not enough tech talent nor infrastructure

One really wonders how the internet could even have happened before the hyperscalers appeared.


Mostly grumpy IT people handling small racks running VMWare in their office and taking 6 months to set up a VM for you.

I am not joking.


> I am not joking.

Well, I was...

> and taking 6 months to set up a VM for you.

Your sysadmins were extraordinarily grumpy. Were you working with the ur-bofh?


> It is worth noting that despite all this cheap sovereignty talk from Brazil’s president, in practice Brazil would not be able to operate Pix at that scale without heavily relying on American hyperscalers companies.

> American companies are great to do business with.

US officials involving themselves in your national market because they are unhappy with the market share of their companies in it, with the implicit threat of stopping other areas of trade if you dont allow the companies to gain a larger market share makes US companies too untrustworthy to do business with. If Trump implements a trade ban for Brazil, will these hyperscalers continue providing the service at their own risk, or are they going to prioritize their state over their customers? I would assume the answer will be the latter. Given that, I believe it is in Brazil's (and most other states) best interest to divest and reduce partnerships with companies operating in the US


> US officials involving themselves in your national market because they are unhappy with the market share of their companies in it

Just to clarify, for anyone who’s been paying attention to the matter, it’s clear that the true reason for that Section 301 investigation is not due to Pix stealing market share of MC/Visa. In fact, if you check Brazil’s central bank own data, Credit Card usage has not gone down since Pix came in. What Pix really replaced was physical cash.

The fact is that Brazil’s (current) government has been publicly on the other side of Americans interests for a long time, even before Trump’s term. e.g. blatantly ignoring Iran sanctions https://www.cruz.senate.gov/newsroom/press-releases/sen-cruz...


Why would Brazil's government be on the side of American interests on a matter like this?

Pix is clearly mentioned as one of the topics for that investigation due to 'unfairness' and 'harming the competition'.


There are exceptions but the "hyperscalers" and pretty much anything that handles personal information is highly toxic and should be fiercely avoided.


You are incorrect.

What went down were apps from banks that use PIX, not the core infrastructure.

That is responsibility of the banks. It means private banks like Itau and Nubank rely on Amazon, not the Central Bank. They relied on those hyperscalers for their operation, and their gateways went down with it.

PIX has sovereign, private infrastructure on brazillian soil managed by Banco Central. NIC.br and other essential services do the same.

PIX is ours.


This is a minor technicality, if private banks are down then the SPI is basically useless. Banks can send money to each other but clients can’t see it.

> What went down were apps

Plus, this is an oversimplification.

Transaction authorization, Fraud/AML screening, account validation are not just part of an “app”, they are core functionality of private banks operations, and they are made scalable by big cloud providers.

The true scaling burden is on private banks not the BCB


> The true scaling burden is on private banks not the BCB

Exactly. That is one of the aspects that allow for the system to be sovereign and scalable. Banco Central controls the core, and that's all it needs to.

This is good design. Descentralized, modern, resilient and efficient.


> Banco Central controls the core, and that's all it needs to. This is good design. Descentralized, modern, resilient and efficient.

I agree. But was that not the case before Pix/SPI? It really didn’t change the status quo.

The STR (transfer reserve system), which SPI is still fully dependent in practice btw, is decentralized, modern and efficient.

The biggest change here was scale and adoption by private banks and end users, not sovereign infra.


That is an offshoot topic which is, in my opinion, irrelevant for the sovereignty discussion.

I'm here just to clear out the confusion regarding the infrastructural pieces. The core PIX is undeniably sovereign and state-owned, and the Amazon downtime was lack of resilience on the part of the banks (which they could have totally designed around but decided not to).


> I'm here just to clear out the confusion regarding the infrastructural pieces. The core PIX is undeniably sovereign and state-owned

Sure, I can see the confusion, I should have made that clearer.

Let me rephrase it: the "core PIX" is mostly an implementation of ISO20022 (pain,pacs, etc) messaging on top of HTTP APIs and BCB's own ledgers, plus a centralized KV datastore (Dict).

The implementation was excellent, but there is no technical moat in the "state-owned" part of the solution

The biggest technical challenges were, by design, delegated to the private sector, heavily relying on US hyperscalers to achieve Pix's operational requirements.


There is a wide misconception that state stuff needs to be fully state-developed. I don't subscribe to that view. Delegating and designing just-enough simple solutions, avoiding bureaucratic tanglements, is an immense challenge and done beautifully in this case.

The other direction (not using standards, owning parts you don't need) would make it for slower adoption, lots of new government responsibilities and very few additional sovereign control. It would be worse.

Building a "technical moat" is for companies which have direct competition. The state can solve this by making regulations. It doesn't need that technical moat, simplicity is better suited. It's acting exactly at the intersection it needs: in the regulation, delegation and coordination realm, not execution.


Yes, but my point was more nuanced, I didn't mean to say that the state needs a fully owned solution.

The original article opens up with "Pix is igniting a geopolitical and commercial battle."

The point I was trying to make, specially in the last paragraph, was that: Brazil doesn't really have full control, or the capability, to operate Pix without US infrastructure. Therefore, it is not smart, to engage in a geopolitical, ideological battle against the US. If Brazil wants to tough it out and claim sovereignty, then it must be willing to walk away and build its own infra.

Case in point: the recent US-Canada tensions were enough for the Canadian government to consider cancelling the purchase of American-made F-35 fighter jets.

Is the Brazilian government willing to do the same? Is it even in its best interest to do so? In my opinion, no, hence the aggressive anti-US rethoric from Lula must stop


Brazil has not started in any ideological battle regarding this. It has developed a national technology, and it allows other payment systems to coexist peacefully in the spirit of honest competition.

The ideological and geopolitical provocations comes from the US. The government is merely defending itself, and being decisive about our sovereignty is not an act of aggression. It's just good statesmanship.

The phrase "PIX is ours" wasn't even directed at the US. It was promoted because a previous Brazilian president tried to attach is personal name to the technology. It was later adopted in that defensive posture, but it was never about fostering any grievances with other payment systems.

Data centers are a commodity, and the US gets tremendous revenue from Brazilian businesses that use it (fourth largest AWS customer location). It's a symbiotic relationship, and there are other countries able to provide computing power if we need to cut ties with it. If that happens, businesses can rent those from somewhere else.

You underestimate our ability to handle these things. Watch us.


In Brazil case, there's actually public banks, and they use Brazilian servers.


It was not. TED had to talk with banks, only the final settlement went thought Central Bank.

With Pix, banks don't talk with each other. They are basically using Central Bank API to send and receive money.

before it was Bank Z ---> Bank Y

With Pix it's Bank X ---> SPI/BC ---> Bank B


I don’t even understand what you mean by “banks had to talk to each other” and why you are referring to TED in the past tense when it’s still the largest settlement method by BRL amount


Because TED is not the only way to send money now...? It's basically legacy, although yes, still used. Very rare you'll see Person to person/business using TED. Basically business to person...

And yes, literally banks had to "talk" with each other. Which is why it was paid and slower in first place and didn't worked 24/7.


I suggest you go read the SFN messaging manuals from BCB if you truly want to understand how interbank communication works. It is very well documented.

You clearly don’t know what you are talking about since you are conflating the STR (transfer reserve system) with TED (one of the many settlement methods in STR)


Obviously there's several other ways to send money. I'm talking about the popular ones... The others are niche-systems.

And yes, in TED only the final settlement were done by BCB.


Ultimately, this is all irrelevant.

The goal with Pix was not to increase the total amount of value tranfered, but the amount of small micro-transactions, increasing fluidity and bypassing unecessary bureacratic processes.

TED still wins by raw value, but that amount is irrelevant. It is what is left after the small-fry micro-transactions were liberated from complicated, archaic systems. Those small-fry transactions provided a lot of fluidity to the market, which is the realm in which Visa and Mastercard were supposed to act (incresing consumption) but were unable to compete due to their own legacy devices. They really need to catch up with the competition: those systems and their culture are ancient relics.


So they get to decide when a transaction is in their national interest and do business on that basis?

That sounds like "sovereignty" to me. You don't need to be fully protectionist to be sovereign.

If you have an ax to grind with Lula, just say so.


Don't get me wrong. But mentioning Brazil's president on this meter just adds even more politics to the discussion. Which global systems don't depend somehow on US infrastructure? Do you have the same opinion about the European leaders that are creating/created cloud infrastructure? I believe just one of the parts is really into adversarial talks lately. Brazil is just following what other countries are also doing.


> But mentioning Brazil's president on this meter just adds even more politics to the discussion.

This quote is literally from the linked article — he is mentioned there

> Do you have the same opinion about the European leaders that are creating/created cloud infrastructure?

I don’t understand the question, I think it’d be great to have an European AWS equivalent just for the sake of competition, but as far as I know, we are very far from that


As long as the foreign companies operate within the country under the country's laws, it shouldn't be a big problem. But being dependent on only one vendor and not having redundancy in the system is a problem though. This is why cash is important to provide the ultimate redundancy against all technological and infrastructural failures.


Funny annecdote: I have a friend who worked at iFood (brazilian food delivery company) and apparently they moved their entire AWS stack to us-east-1 because sa-east-1 did not have enough capacity to handle the load they had. This is why iFood has a very high latency* during user interactions.

*: for people used to online gaming


Context is important, the Brazil's President said that about USA investigations with allegations that Pix is a "unfair business practices"[0] he is not at all saying that Pix is "100% powered by Brazil", in his political proselytism he does make clear that Brazil and USA are partners by centuries and should keep being.

0. https://www.bbc.com/portuguese/articles/cm2vrnq17vdo


Please, he literally went on national TV on Brazil’s Independence day to claim that

“We will defend PIX from any attempt at privatization. PIX belongs to Brazil, it's public, free, and will remain so.”

Lula has been historically hostile to the US for ideological reasons.

He’s done plenty to undermine that relation, stemming from attacking the dollar dominance, ignoring Iran sanctions, to indirectly financing the Ukraine war by becoming the largest buyer of cheap Russian oil — and that’s why we have those investigations going on


Most of these could could be put another way as protecting sovereignty (and that would be the most charitable interpretation IMHO). Examples:

- "being hostile for ideological reasons" becomes entirely warranted when you consider the many CIA regime-change operations in the past.

- "Undermining the relation" (with the US) is just being smart about how much dependency one has on external factors, like exchange rates and infrastructure.

- The "investigations" are political posturing. PIX is not "unfair business practice", its a modern, cheap, state-of-the-art payments system that is better than what private businesses like MasterCard and Visa are willing to offer. I can think of plenty of ways they could offer actual value to customers so they can still be relevant. The fact that they don't, and chose to try and lobby against it tells me that its a lot cheaper to just buy some politicians and manufacture some controversy instead.


> The "investigations" are political posturing. PIX is not "unfair business practice"

Agree

> its a modern, cheap, state-of-the-art payments system that is better than what private businesses like MasterCard and Visa are willing to offer. I can think of plenty of ways they could offer actual value to customers so they can still be relevant.

This is a common misconception. Pix is a form of bank transfer, not a full blown payment infra like MC/Visa. They are different products, Pix doesn't make credit cards irrelevant.

Per BCB statistics: In 2020, before Pix implementation, credit cards accounted for 2% of the monthly BRL volume transacted (~ 200M BRL)

As of 2025Q4: credit cards still accounted .... for the same 2% (~ 800M BRL)

The main question is: historically, why haven't credit cards been more popular in Brazil, even before Pix?

You'll find your answer looking at structural issues (high interest, delinquency rates, bad credit offerings ...), not technical concerns


> Lula has been historically hostile to the US for ideological reasons.

Care to elaborate and give examples?


This is just a legacy of the hopefully-soon-to-be past. We all went way to hard on the aws bandwagon (myself included). I worked for a bit in the past for a company doing 100 mio. API requests daily off of 6 boring old servers.

There is no explicit need for AWS in this. But it was probably easier to build since it is what we are used to.


Yeah we need to accept that sovereignty costs money. American hyperscalers are the cheapest alternative- but freedom isn't free.


It was not Pix being down, though. This is about banks using US cloud providers. The issue here was with private banks even.

As far I remember, Banco do Brasil and Caixa - both public banks, didn't went down, because they use Brazilian owned servers...


… and yet they both suffer from availability issues despite not having nearly the same scale as e.g. Nubank who uses AWS

Caixa was down yesterday: https://www.techtudo.com.br/google/amp/noticias/2026/05/caix...


Baby steps. If AWS starts unfairly exploiting its market position the way visa and mastercard do then brazil will move pix to another provider


TED is still very much alive.

In fact, the BRL amount settled via TED is still higher than Pix, although the gap seems to be closing


The treasury has an account at the FED called TGA[0] which is funded by tax payments and proceeds from new Treasuries issuance

https://en.wikipedia.org/wiki/Treasury_General_Account

> The total number of dollars that exist in circulation is reduced.

Not accurate. Dollars are a liabilities on the books of the Federal Reserve. Tax payments to the federal government only cause a liability shift from commercial banks’ reserves at the FED to the TGA, it doesn’t really change the net amount of dollars in circulation.

The most you could argue is that it momentarily reduces the net commercial banks’ liabilities (which economists call M*) until the Treasury distributes those dollars again to the broad economy


If you are a company founder, what scenario would you rather find yourself in?

a) a pristine, good codebase that follows the best coding practices, but it is built on top of bad specs, wrong data/domain model

b) a bad codebase but it correctly models and nails the domain model for your business case

Real life example, a fintech with:

a) a great codebase but stuck with a single-entry ledger

b) a bad codebase that perfectly implements a double-entry ledger


"Perfectly implements" is doing a lot of work there. Enterprise software is very rarely perfect out of the box, and the issue with bad code is that it can make it extraordinarily hard to solve simple problems. I have personally seen tech-debt induced scenarios where "I want a new API to edit this field in an object" and "Let's do a dependency upgrade" respectively became multi-month projects.


> Perfectly implements" is doing a lot of work there. Enterprise software is very rarely perfect out of the box

Fair, by “perfectly implements” I meant to say that it correctly implemented the core invariant of a double entry ledger (debits = credits), not that it was 100% bug free


Since most won't actually deal with fintech (I don't know the stats on HN, but I'm talking devs as one industry), your first "a" example might actually be better than your first "b" example, depending on the complexity of the software. In lots (probably most) of industries, having a good codebase would mean architecture decisions were solid, but the domain/service layer is bad. Maybe my experiences don't match most of the HN crowd, but usually I get stuck with very detailed domain/service rules, but the architecture is a problem where too much memory or CPU is being used, just to abstract away the actual rules of the application (the purpose). Usually when I've been brought in to rebuild an application, the client is fine with the results, but they are upset over performance and/or cost to run the application. For anything of actual complexity, it's usually the supporting code that is the biggest failure, because complex apps usually have decent requirements. Now, if the requirements were bad, and the architecture was bad, AND the domain/service layer is bad, I don't know if there's anything to fix that.


With CRS and FATCA, no one is hiding their wealth just by having offshore assets.

Owning offshore assets also doesn’t automatically exempt you from paying taxes, since your tax liability is mostly determined by your tax residency.

  Just a fraction of that money could end extreme hunger and provide clean water to everyone on Earth.
Clickbait article


I'm one of that 0.1%, since my yearly salary is more than about USD90k. And my attached wealth is the most typical kind, too: my wife and I bought a place to live, which we haven't sold in the 20+ years since moving in. It probably could be sold for a fair bit more than we paid: untaxed wealth.

I suspect that we won't pay 100% tax on whatever we earn when we sell, if we sell, but if we were taxed 100% I'm sure something nice could be done with that money.

I'm quite impressed by the rhetorical skill here. It's easy to overlook that what they're saying is "by taxing something/someone 100%, it would be possible to...", ie. "If pigs would fly, it would be possible to..." and making it easy to overlook that takes real skill.


  Why build each new airplane with the care and precision of a Rolls-Royce? In the early 1970s, Kelly Johnson and I [Ben Rich] had dinner in Los Angeles with the great Soviet aerodynamicist Alexander Tupolev, designer of their backfire Bear bomber. 'You Americans build airplanes like a Rolex watch,' he told us. 'Knock it off the night table and it stops ticking. We build airplanes like a cheap alarm clock. But knock it off the table and still it wakes you up.'...The Soviets, he explained, built brute-force machines that could withstand awful weather and primitive landing fields. Everything was ruthlessly sacrificed to cut costs, including pilot safety.
  We don't need to be ruthless to save costs, but why build the luxury model when the Chevy would do just as well? Build it right the first time, but don't build it to last forever. - Ben Rich in Skunk Works


That's an interesting story, but not a great analogy for software.

If a technology to build airplanes quickly and cheaply existed and was made available to everyone, even to people with no aeronautical engineering experience, flying would be a much scarier ordeal than it already is.

There are good reasons for the strict safety and maintenance standards of the aviation industry. We've seen what can happen if they're not followed.

The fact that the software industry doesn't have similar guardrails is not something to celebrate. Unleashing technology that allows anyone to create software without understanding or even caring about good development practices and conventions is fundamentally a bad idea.


Soviet engineering wasn't sloppy. It was designed for robustness, loose tolerances and simplicity. It was well thought out design. In the same way that as much thought went into the cheap alarm clock than went into the Rolex watch, maybe even more so, the engineers just had different requirements.

It takes a lot of work to make cheap, low precision parts work together reliably. The Rolex has it easy, all the parts are precisely built at a great cost and everything fits perfectly. With the cheap alarm clock, you don't know what you will get, so you have to account for every possible defect, because you won't get anything better with your budget and the clock still needs to give you an idea about what time it is.

The parallel in software would be defensive programming, fault tolerance, etc... Ironically, that's common practices in critical software, and it is the most expensive kind of software to develop, the opposite of slop.


There's a narrative that gets passed around in physics circles about how the Soviets were better at finding creative and analytical solutions than Americans, because of the relative scarcity of computing versus intellectual labour resources.

It would make sense to me that a parallel mechanism could apply to Soviet engineering. If material and technologically advanced capital are scarce, but engineers are abundant, you would naturally spend more time doing proper engineering, which means figuring out how to squeeze the most out of what you have available.


> Soviet engineering wasn't sloppy. It was designed for robustness, loose tolerances and simplicity

aka "fitting".

I wrote a blog on why Soviet-style engineering is bad https://blog.est.im/2026/stderr-04


Let me highlight this part:

> Everything was ruthlessly sacrificed to cut costs, including pilot safety.

If we translate this analogy back to AI driven software development, what would be the equivalent of "pilot safety"?...


Be very careful who sources your pacemaker.


And then everyone disagrees what counts as luxury in software.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: