Hacker Newsnew | past | comments | ask | show | jobs | submit | uberman's commentslogin

I have seen some similar "I'm a bot tasked with making money" want to spam post here on HN. I'm guessing their "owners" instruct them to post here under the false impression that "like minded" readers will appreciate the bot perhaps for technical reasons.

Weird huh?

Bots that emulate people, serving people that think like bots.

What is the world turning into...


I have a friend who is one one the best programmers I know. He worked for an ad tech company more than a decade ago optimizing time to respond for personalized ad delivery. He was not proud of working to act on fingerprinting to optimize delivery but it was a challenging task and he framed his part as addressing the challenge not the ethics. People in our circle where like "good for you optimizing network delivery to 50ms!" even people who despised the idea of tracking users around the internet to serve them ads.

I'm sure most people who work for flock compartmentalize their jobs to "I work on fingerprinting vehicles" or "I work on advanced OCR", or "I work on creating camera to camera trajectory graphs". This way they don't need to think about (too often) the larger ramifications of what they are doing. When the press points out what is the reality and that most people are pissed at Flock then the employees likely have to confront what they do in a way that they never had to.


It is also reasonable for employees to hold the position that Flock is a public good and the vocal minority of people complaining about it are simply wrong.

That’s not a reasonable position to hold, unless and until Flock does much, much more when it comes to safeguards against abuse.

I can understand being pro-surveillance, but Flock is a case study in how not to implement surveillance systems. Believing that surveillance can be a public good can’t somehow turn Flock into a public good. It’s not.


Such an opinion does not seem plausibly believable, by the people building it and in full knowledge of what it can do, and is being used to do.

This isn't an uncommon opinion among the public either. It's probably a minority, at least among those who are vocal about it, but it's not hard to find people who think they are beneficial.

A Milgram experiment in real life.


> he framed his part as addressing the challenge not the ethics

I didn’t know that Arendt’s concept of the banality of evil was something people willfully embraced.


I'm not sure why you're being downvoted. Perhaps it makes some people uncomfortable about their own jobs. In any case, it's not uncommon for people to moralize about something they're not doing, but given the opportunity to do that thing for some handsome reward (good pay, prestige, technically interesting work, etc), they easily rationalize their choice to participate in that thing.

If you were able to do so would the result not be the same. We dont accept your terms update so we and terminating your subscription. Essentially the same that you can do.

Not the same though. A lot of people are just too lazy to cancel. If Disney had to terminate all the subscriptions that would probably have prevented this type of behavior

I think that would actually be a great regulatory move; If they change the terms then they must cancel your subscription.

You'd have to elect to resubscribe with the new terms. Bonus points if it has to be the normal subscription flow, not some kind of one click to resubscribe.

I'd bet the pressure of instant drop in revenue and the likelihood of people being less motivated to resubscribe would kill some of this behavior.


Remember that the last time Disney fucked up a MASSIVE number of subs cancelled via Apple’s 1-click cancellation. Which Disney promptly exited from.

No industry seems to have a good culture that supports whistle blowing

This. Can't you get your number moved to a new phone? I have never don't anything magic when upgrading my phone other than move contacts.

How would moving your number to a new phone help? We're talking TOTP here, not SMS "auth".

does google not offer a backup via sms? it's a common enough recovery flow elsewhere. (i dont use google stuff, so i am genuinely asking)

Any less secure backup method, means others are less secure.

Google actually puts effort into security for "normal" people who don't want to earn a PhD in cryptography just to have a damn free email account or watch Mr. Beast

That's why they had powerful and effective account takeover protection even 15 years ago. The kind that will prevent the hacker from taking over your account even though they got access to all your factors, because it shouldn't take expertise to know that if you logged in from Oregon twenty minutes ago, you definitely aren't also logging in from Ecuador.

Which of course makes it all the more stupid that your credit card company, all your medical service providers, and Facebook don't meet that absurdly low bar. Facebook will happily hand control to the scammer in Laos who got one of your factors and somehow that gave them access to change your password and recovery email


The best backup method doesn't need any computer knowledge, it's writing down or printing a few passwords and putting that piece of paper in the same box as your taxes or birth certificate.

A required “more secure” method is less secure if it means you can be locked out by not-exactly-uncommon real-life situations.

Denial of service is a security issue.


I’ve repeated it a hundred times security = confidentiality, integrity and availability.

One reason to strongly prefer Apple over Google is that (as I understand it) you can still walk into a store with ID and recover your online identity.


> One reason to strongly prefer Apple over Google is that (as I understand it) you can still walk into a store with ID and recover your online identity.

Is this true? If so, in what countries? (Poland has no Apple stores, for example, for inexplicable reasons Apple has been giving the middle finger to this market)

That would be a huge difference.


I think Google’s own textbook on SRE has an example in its very first chapter where everyone gets locked out of their bus fleet WiFi thanks to their secure system reaching an unforeseen state

yes, i understand. i was asking specifically whether google has sms recovery flow, not how secure sms recovery flow is compared to other options.

You can export from Google Authenticator to another device just fine.

How do you export from a phone you no longer have?

I misread your comment, you're right.

The opposite is true for me. I have always wanted to try Godot as a platform and AI is helping me make that happen.

Much better link not the least is the description and name of the problem being solved!

When I was a kid twisting a swing so you could ride it as it untwisted was something that happend dozens of times every recess. This was something every kid did. If your playground equipment falls apart as a result of the standard way kids use a swing then I think that is a manufacture issue not criminal behavior by a 10 year old

https://www.yahoo.com/news/us/articles/pennsylvania-girls-10...

"The borough also says visitors encounter its "Play Smart Rules" when entering the park, including a specific instruction: "Do not twist chains.""

So the town buys crappy swings, knowing full well that kids are going to spin them (who hasn't done this a million times as a kid?) Then they slap up a sign telling the kids not to do that. Basically entrapment.

Here's an idea for them: maybe the town shouldn't cheap out on unsafe equipment for children...


My company makes dangerous equipment like lawn mowers. Because of this, I have to go through training on how to design equipment to be safe.

And the rule is very clear. If there is any possibility of an issue, you need to redesign it so the problem can't happen, you need to put gaurds in place so the problem can't happen, or only if those two fail, are you allowed to put up a warning sign. That is an ordered list so if anything is possible in the previous step you cannot go to the next.

In this case a chain that can take twisting is obvious and so the sign won't protect them from liability should someone get hurt from twisting the chains.


You're both right. What you're describing is liability. A warning does not guarantee safety from liability suits, that's why the other options are preferable (only being a Chinese or outside-of-the-west manufacturer guarantees safety from liability suit).

But the problem with twisting chains is that it needs a warning.

And so both putting in the law, and arresting the kid, are a way to protect the borough, a government organization, from liability when something goes wrong.


Decent swing chains $250. Mass surveillance recurring cost of $5000/mo. Someone please help me budget this, I'm dying.

If the town feels that arresting children is a good use of public money they that's their right. At some point the citizens have to actually care about how their town operates if they want it to get better. Most townspeople care about UX as much as f2p mobile shovelware developers.

> If the town feels that arresting children is a good use of public money they that's their right.

TF? Doesn't your country have a Constitution?


Does your country have a constitution that explicitly handles this scenario?

Of a government body deciding to go around arresting people for no reason? Yes.

As a reminder - if you put an unsafe swing on your property and just had a sign as the only thing stopping it from injuring a child and a child got injured, you'd be automatically liable under the "attractive nuisance" doctrine.

Why is a 3rd party company keeping videos of people's children? Why aren't the parents concerned about this?

Right? Growing up in the eighties we'd twist, stand on them, double up, back flip out of them.

And if you really had the balls, the 360 ...

Yep! We used to call it "twist and shout". Tons of fun.

It's marginally cheaper to install flimsy chains and surveillance than to pony up for a slightly thicker gauge chain get out of here with your common sense /s

Until someone gets hurt and the court find they are liable for millions because signs and cameras did not work and because they thought it would they apply punitive damages to make sure the message is sent.

Do you have proof for you claims? I am under the impression that 500 rep essentially maxes out your standard privileges and that no reputation based weighting is applied to votes.

If your fear is that there are voting rings (which apparently the system tries to detect) then resetting the rep will give them more relative power not less.

Personally I dont pay any attention to the rep of a user when evaluating how I should or should not engage with them. I think things are working just fine at the moment.

If you are frustrated by repetitive homepage content, I recommend you switch to the "new" view as there is lots of diversity there.

Again, if you have any proof that a cadre of nefarious high profile users are somehow abusing the system I would love to see it.


[dead]


So then no proof whatsoever? So for fun I looked at your user and color me shocked that you are complaining about the use of sock puppets while apparently using one yourself. Alternatively has 8 days allowed you to devine the inner workings of this site?

He gave no links nor did the original post. I did no flagging and did not vote on any item in this thread. Yet I see that four accounts with a combined age of 10 days wants to complain about sock puppets.

[dead]


Neither link you posted showed anything to me other than you need a negligible of karma to unlock comment downvoting.

Do you want to quote the sections you feel detail how "high karma posting" is treated?


If the contnet aligns with the interests of this community as apparently it did generation a bunch of views that I'll take your word for, then if it really a problem? If the community does not like something they can ignore downvote and flag and it will go wherever the crap goes.

I tend to agree, although I wonder if we won't get flooded by agents pretending to be regular users and submitting their slop to HN. It might well be happening already (e.g., [1]).

Worse: it will get harder to differentiate what is a legitimate ShowHN from a nefarious agent trying to infiltrate malware. Yes, supply-chain attacks existed for ages, but now script kiddies can create xz-level attacks without even realizing it.

[1] https://news.ycombinator.com/item?id=49667385


We will get flooded eventually. Bad actors already know how to game HN, e.g. https://news.ycombinator.com/item?id=49517728 .

the problem is that the "aligns with the interests of this community" can also be manipulated.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: