HN user

ds

5,050 karma

Herding cats @ https://redact.dev - Delete your digital footprint

Personal site and contact info -> http://harknesslabs.com

Posts16
Comments104
View on HN

Nearly a decade ago, there was a website called thehunt.com that basically ran out of money and some employees were acqui-hired by pinterest.

All of the assets were left to rot and at the time the company was a good match for another startup of mine. So I reached out to the investors I found on crunchbase and asked if I could acquire everything. We worked out a deal and I did. The issue was the complete lack of people from the old company willing to assist and the complete lack of data for alot of things. There was 1 or 2 people who we could ping from the old company to ping who were super helpful, but the big thing was many things were just lost to time- passwords, history, code repos, etc..

Simply creating a new google apps account allowed us to get full access back to everything - We could even read old slack messages (even DMs!) by resetting each accounts password. The whole thing was shocking to say the least, but with that access we got back into literally every service they used and managed to get it up and running again within a week, which was a good thing because nearly every service it was using was threatening to shut it down every day for lack of payment.

I think the solution here is actually way simpler than most make it out to be and could easily be a startup for someone:

Create a startup that lets customers simply enter in domains. If the domain EVER goes into the "pendingDelete" status, inform the customer. The customer would be random SAAS's that want to protect against this type of attack and could simply choose to disallow access to any account that has had their domain go into that status.

Far more likely is Google was not willing to complete the deal and was pulling the plug after looking at internal data. Wiz, fearing the bad press of Google backing out rushes to tell journalists that THEY are walking away because they are worth more.

Wiz's valuation is insane. Most people havent even heard of them. I think it was a > 60x ARR multiple on this deal. Id actually be kinda pissed if I was a google shareholder and they went through with it.

Something very strange is going on with Wiz. My gut tells me if they ever IPO to go big on puts.

Id get into this debate, but its been done a million times before.

Heres the cliffnotes of how it goes though, roughly:

* So is minimum wage ok then?

* Why cant a minimum wage person invest all their money into a startup? Why do they have to be a accredited investor?!?

* Why cant I just open up a payday loan place that charges 900% interest? Theres no other payday loan places around and poor people willingly will use it!

* What about prostitution, nobody is forcing them to do it?

* Alright then, Should we let poor people sell their organs? Again, nobody is forcing them to do it!

Cliffnotes: Just because someone will 'willingly' do something, or doesnt have any better options, doesnt make it just or moral. You setting up a 'consulting' company in bangladesh that pays people x$ a day to do something is exploiting those people, plain and simple.

Also, as to your phillipine cost- You are completely wrong. The average wage across the majority of regions in the country is under $10 per day. This is where (see my first link below) most shops get setup, obviously.

https://www.outsourceaccelerator.com/articles/average-salary...

https://www.statista.com/statistics/1048636/philippines-mont...

https://en.wikipedia.org/wiki/List_of_Asian_countries_by_ave...

You can trust them only as much as you think they have self interest in not being sued for doing something nefarious.

That said, they could very easily have a data breach and every customers full info would then be out in the wild. Were not talking about ordinary payment details either, just full on dox - every address you have lived at, your license scan, all emails, phone numbers, its crazy. Id be willing to bet all these services are targeted quite alot as well because the people who would be willing to pay for this stuff are likely the ones with the most to lose.

I made a post lower in this thread but in general this entire model is flawed. Deletions should happen directly between your device and the service in question.

Also, its just as important to wipe the data YOU create as the data other people create about you. Just like databrokers, you can either do it manually or automated.

Check out https://redact.dev if you want to automate that part at least (I'm on the team)

I am not OK with supporting someone getting paid 2-3 dollars a day for this labor and would prefer to not support that business model if I can.

I also dont trust those workers not to misuse or sell my information on the side because of the unfortunate financial situation they are in financially.

Its acutally a similar answer for why I dont pirate games or software. I dont want to support the behavior and I dont trust that something bad wont happen as a result (virus/malware/etc.)

The big thing to know is the following:

Google yourself - See what shows up that shouldnt. Go through those sites and manually opt out. Its not too hard and you get the biggest offenders.

Yes, you can use a automated service to do this for you but I think its a really bad idea based on how most of them work.

First of all- Most of the big ones make use of extensive labor in thie phillipines and malaysia to manually type your data into opt out forms. They also have to make use of extensive proxy networks that I can only suspect are not always on the up and up. This is because the databrokers will block IP's from submitting more than a few opt outs per date. So you are supporting both shady practices for the proxys and third world labor thats semi exploited

Second of all- You are trusting yet another company with your data. When you sign up to one of these services, they obviously know everything about you. When one of these services inevitably has a data breach in the future, its going to be a disaster.

The reason that the big services have difficult with the biggest services that are listed in this article is because they: Use captchas, use cloudflare and do email confirmations. They also do things where they show you multiple pieces of data and you have to pick which one is yours, but some of the data is blurred and presented as a image. ( ie- Is this email yours? tee***@gmail.com )

So, what to do if you want to stay on this? Well- Im creating a solution with my team to do what all the big players should have done- Do the optouts from your own device. They of course want you to do it from their servers because its a nice zero friction experience where you just type your info in and they handle most stuff. But as we see, the biggest offenders for databrokers are NOT handled because they are tricky.

So, at our startup https://redact.dev we already built out a ton of tech for this, but targeting social media and messengers. We are now building all of that out for data brokers. And because its ran directly on your own machine there are a TON of advantages:

1: No limit to how often you can scan for new databroker leaks. Most of the players now limit you to once every 30-45 days

2: No limit to adding friends/family to scan/opt them out also.

3: No use of third partys to process your removals. This one is self explanatory. The deletions happen direclty between your device and the databroker- no third world workers involved.

4: Handles the 'hard to delete from' sites listed in the article. Our built in IMAP system can handle email confirmations no problem. Because its running from your own IP, you have no issues with getting blocked there either. Cloudflare/captchas are also no issue

5: Most importantly, you dont have to trust another company with your most personal information. All your data like address/names/phone stay on your device and are only sent to the sites you need to opt out from. Believe it or not, a bunch of these databroker remover sites will just bulk email a bunch of databrokers right now saying "hey, if joe smith @ 123 main street is in your DB, remove him!"

The big drawback is that you need to have a device open that can do the work for you. With other services you can just pay and shut off your PC or phone. You need to keep our solution open for 5 minutes while it does its work. I think thats a definitely good tradeoff for the security you get AND the fact that it instantly removes you from many of these sites. Alot of the players as I mentioned just do emails so it could take weeks or months before they remove you. If you use the databroker sites automated forms, it can be removed instantly or within days or hours.

Technically speaking, Beeper can keep working for a long time. That is, Until apple starts checking if the client is on a official apple device. This may or may not be feasible for Apple to implement, mostly depending on if they even have the resources/method to know if every device is legitimate or not (they may not- especially for older devices)

If they do have a way to enforce 'authentic' devices, the only step after that for beeper to take will be to ask users to purchase the cheapest iphone that still works for imessage and to extract its serial/key/whatever to import into the android client.

This is a 1 dimensional view of things.

Maybe I can simplify it for you with this question:

Does Google have the ability to legally compel you to only use chrome?

Im guessing you would say no- Antitrust and whatnot. So the next followup is, Does Google have the ability to tell blind people they cannot use screen readers? Or that people on linux cant browse the site in lynx?

Again, I am guessing the answer is no- Theres anti competitive, antitrust and 230c reasons why. Legally, ad blocking is fine to do. Heres a great article going over it : https://scholarlycommons.law.wlu.edu/cgi/viewcontent.cgi?art...

HOWEVER- I disagree with the premise that Youtube cant try to stop adblockers- They just need to do so in a way that doesnt target specifically target a user. Twitch did a system where they would not send the video stream to you until the advertisement was done playing (which was embedded in the feed itself)- So if you blocked the ad somehow, you would just look at a black screen for 15-30 seconds. This, in my opinion would be completely compliant.

Its great that Microsoft has teams- but nothing to do with skype as a consumer front-facing product.

Years ago, Skype was the de-facto solution for video calls and video meetings. There was no zoom, there was no google meet. Skype was so known for video chat that it was a verb. 'Skype me'

Skype absolutely and completely fell asleep at the wheel and wholesale abandoned the public market to Zoom, Discord and Google. Its not like it happened overnight either. Skype had the ability to respond to these guys but instead did almost nothing after a redesign to 'skype 8' in 2018.

I cant exclaim how astronomical a failure it is to go from being the defacto verb for video calls and instant messaging to not even having 5% of the end-user consumer market anymore. It would be like if people stopped using google for search, or youtube for videos. You dont get to say "Yeah well google got reworked into gsuite which has 300m users" - Its still a failure of biblical proportions.

They should have been capable of creating a enterprise product and keeping their consumer offering going.

--

Just to be clear, I understand teams is large and doing well. Its also a enterprise product and it has nothing to do with what im talking about above. Discord (~20b valuation) only exists because Skype did zero updates or innovation for years.

How much they paid for Mint vs CK has little bearing. Google bought youtube for 1.6b and Motorola for 12b (later sold for 3b) - Which would you rather focus on today?

I dont disagree Mints revenue is not enough currently, but thats the issue. Mint has 3.6 million MAU. Maybe I need to be more explicit, but the value of a financial services user is high, not just in immediate revenue but also in referred revenue. Mint has never done a good job at pricing their product. Ive used it for 15 years and have never paid them a dollar. Thats a failure on their part, as I would have gladly paid monthly or yearly for the past 15 years. Even if I didnt, there were tons of products I would have IAP'd for that could have been seamlessly integrated into mint. Instead they seem entirely focused on trying to get me to sign up for credit cards or to switch bank accounts. What a lost opportunity.

As for the how much it costs to operate mint, thats true we dont know exactly what it is. But I am not a ostrich with my head in the sand. I can infer that the cost is going to be magnitudes less than the revenue it brings in, even in its current sad state. This isnt a chatgpt startup thats using insane resources on metal or developers to offer a product. Its a application suite that processes and coorelates data provided by plaid.com - Mint doesnt even do any of the heavy lifting anymore.

The fact that this is being shut down vs being sold or at least integrated deeply in credit karma speaks so poorly for the intuit management I am not even sure what to say. The app has to be capable of generating millions a month in revenue at the least. Who is on the leadership team for mint, so I know to never work or partner with them in the future? This is so insanely incompetent its just.. shocking.

This is a fumble not seen since skype fell asleep and did nothing during 2021 while google and zoom came and took their entire market.

At the very least, make the app paid only. If you are worried about upsetting me because I have to pay for something that used to be free, trust me- Im going to be way more pissed about not being able to use it at all.

I dont know, this whole thing just rubs me the wrong way. Intuit is a public company that should be focused on maximizing revenue. Destroying a app thats worth 500m-1b on the private market seems like its worthy of a shareholder lawsuit.

I dont say this out of spite or trolling. I say this as a user of mint since they launched in 2007. Ive been with this app, letting them ravage and sell my data for over 15 years. https://i.imgur.com/XlioSth.png . My old startup even participated in the same crunchies award as mint did, when we both won (us for bootstrapped startup and mint for founder of the year) so I am nostalgic about them being put out to pasture for no reason.

We have a very strong freedom of speech in this country, to the point its kinda insane. (See the citizens united ruling for instance)

So, yes. We cant imagine it because basically the government has extremely, extremely limited ability to control the speech of corporations or people- Essentially limited to yelling 'fire' in a crowded theatre. Aside from that, People and corporations are able to say whatever they want. They can still be held liable for defamation, breaking contracts, etc.. but you cant legislate the right away for people to say things.

Some things to note, unless the bill was modified from the version I read before being signed into law:

This doesnt apply to any information which is public record as a matter-of-fact.

So if you voted, your address and name is public record and can be used and displayed by these sites. If you got a DUI, your mugshot and arrest record may be public record and can be displayed. If you got into a custody battle and your court case was public, that can be displayed. And I guess that all makes sense in the end. If you got into a DUI, how does the government get to tell random website X that they are not allowed to say that you got into a DUI, especially when the information was public record.

So to be clear, if the peoplefinder style websites want to keep whitepages.com/user/john-smith online with an address, phone number and mugshot- They can tell you to pound sand and do so. This bill cant stop that.

Honestly, Theres alot of hype about this bill in general which is going to be... interesting... when people fail to understand what it can and cant be used for.

Additionally, this bill comes with a caveat that the sites can request proof you are living in california currently, via a license scan or some other method you get to now hand over to the data broker.

That said, in our research for https://redact.dev supporting these features from a pure API only interaction, is that most of the sites just delete you if you use their form. They dont want the headache of insane users threatening them and doing crazy shit because they dont delete their profile. And honestly the people who go through these removal processes are less than 1% of the stored data, so its mostly just a cost of doing business.

Is this a whitelabeled version of saymine? Seems like the same type of service.

For what its worth, I think you need to go much farther than this. Saying "delete my account" does not do what you think it does for the vast majority of services.

For instaince, take reddit or discord. When you 'delete your account' it does not actually delete your data. It just removes your email and changes your account handle to 'deleted' - but all of the messages you sent are still there, able to be read and recalled by anyone you have interacted with.

This is a big reason I created https://redact.dev back in the day- I wanted to full delete my skype account because I didnt use it anymore. But when I went through the process, I found out (at the time) that it could simply be reactivated at any time by anyone who got the password. On top of that, all the messages I have ever sent will also be available for whoever logs in. So literally the only solution to actually delete your messages is to one by one go in and individually delete every message.

Also, to be clear- Most of these data broker removal services these days are making use of a mechanic where they simply email a request on your behalf to be removed. I am seeing first hand that more and more data brokers are refusing to honor these requests because they feel legally they are covered by making a 'opt out' page available to the end user. The rise in 'data broker removal' companies has no doubt accelerated that as well.

The best solution is to not go the email route, but to use the automated removal forms. Of course, these guys cant automate that so they dont do it.

You could have no auto-update functionality, and that would go a long way. But then, you are severely crippling your product by doing that. Releasing clientside sourcecode doesnt mean much if the NSA forces you to give everyone else a different binary and sourcode than your target. It means nothing.

Look- the point is, you will go down a endless rabbithole of trying to appease everyone with "bulletproof" security. And the more you go, the more functionality and usefulness you will give up.

The best solution is to be realistic and not make defacto claims. Even things like TOR, which have been open source and audited from day one have had serious issues, and I am sure many TOR developers parroted the "you cant be tracked using us" only to have exploits and code issues pop up multiple times.

Sigh. As someone who is making a company in the privacy space, I hate when privacy products make huge claims like this. Another big offender is proton mail.

They may not be able to track your stuff as it is today, but one single FISA order demanding they push a update out to just to a few specific IP addresses and it will be all the same.

All things you download and install to your device can screw you if they have any functional way to update or have any serverside includes. (like a analytics JS tracker that can be changed to a JS logger)

We run into this a bit with https://redact.dev , but for people who want to be sure the login information they provide is safe. At the end of the day, you are always at the mercy of the courts AND the founders not doing evil things.

Heres a quick meme to better explain: https://i.imgur.com/Vnerxcb.png

The potential for intel to explode is definitely there if intel executes with its AI demand.

I suppose one unknown catalyst with intel is what happens in taiwan/china. If things get crazy over there, suddenly intel seems alot more valuable as the 'US' chip maker (they produce roughly 75% in the US iirc). If the gov starts to even more heaivly subsidize non-reliance on asia, intel could find major gains if TSMC/samsung get shut out.

I mean, just look at the market caps- Intel is worth 6x less than nvidia despite historically having the same or greater gross revenue (not counting the most recent quarter of course).

A huge part of what we are building at https://redact.dev is a unified software suite for managing all data about you and that you created.. To date, that has mostly been data you create yourself ( tweets, fb posts, discord DM's, emails, etc.. ) but the bigger challenge is creating a simple interface that allows people to manage all this data about you thats floating out there that you DIDNT create.

Its not just data broker removals- Its alexa recordings, youtube search history, your mailing preferences, and like 9999 other things. Data brokers are just one part of it.

I enjoy the work we do but it also sucks having to do it. Each endpoint is its own challenge and doing something as simple as automating removal from one database can take days of a developers time. It will be a beautiful day when this stuff gets outlawed eventually.

I tried to use cloudflare email routing and had the same issue. I simply set it up so any email to @mydomain.com would forward to a gmail.

The worst is that cloudflare did not let me know this was happening until I saw I was missing some emails and went hunting. About 20% of my emails would just get rejected silently with "delivery failed" in the logs. I wouldnt blame cloudflare so much if they kept attempting to redeliver, but they did not. They simply give up.