HN user

flossposse

39 karma
Posts2
Comments27
View on HN

The problem I see here is that many of the things in the "Things that would break the promise" section are pretty much guaranteed to occur - we don't have effective mechanisms to prevent them. Tracking and de-anonymization are big business and age verification mechanisms WILL be exploited for those purposes.

If someone called you up and told you that the magazine contained evidence of a crime, the police ard looking for them, and asked you to hide the magazines, would your assumptions change? Because that seems to be what happened here.

Is it? I've read the testimony provided by the FBI agent who was surveilling Rueda and Sanchez, and the quote he provided from her phone call (presumably he would have selected the most incriminating one) was, "whatever you need to do. Move whatever you need to move from the house."

There are many other reasonable interpretations of that sentence other than "please remove incriminating evidence from the house". Like, that could just mean, "If YOU need anything from the house, go ahead and get it."

As far as I've been able to tell from the publicly available documents I've seen, the materials he moved from the house didn't contain any evidence of any crime. I haven't seen any indications as to whether they belonged to Rueda or Sanchez. It seems plausible that he moved the zines from the city of Garland to the city of Denton because Denton is a college town where political demonstrations and the distribution of pamphlets and whatnot is extremely common, and he was intending to distribute the zines there in the coming days.

It seems to me like law enforcement had justifiable cause to be suspicious and to seize the materials, but I haven't yet seen compelling evidence that the investigation was actually hindered by Sanchez or that he had intent to hinder it. I'm open to revising that conclusion if other evidence is provided.

We cannot rely on millions of individual workers to take expensive stands on principle. And they shouldn't have to. It's an essential duty for lawmakers and regulators to design the rules of the marketplace in such a way that wealth flows to those who do genuine good for the populace, and to designate certain tools and practices as off-limits because they are incompatible with our society's core values. Google's actions here are a clear antitrust violation and should be blocked/punished. If our representatives don't do so, then they should be punished.

Who benefits from AI is smaller businesses who could not afford custom application development at previous development costs.

Of course, as AI reduces the cost to operate in niches, those small businesses who just gained the ability to build an app are also more likely than before to see a bigger player drink their milkshake.

Not to mention that small businesses will have a harder time absorbing the inevitable price hike that will come once everyone has made themselves completely dependent on AI to get any work done.

I agree with you that it's about tradeoffs.

The cost ($$$, opportunity cost, and mental toll) of maintenance is very real. It can be hugely advantageous to outsource that effort to a professional, PROVIDED the professional is trustworthy and competent. To ensure that most professionals are trustworthy and competent two things need to be present:

1. A very high degree of transparency, so that it's very difficult for a service provider to act contrary to their user's interests without the user knowing about it.

2. Very low switching costs, so that if the service provider ever does act against their users' interests, they will be likely to lose their users.

As long as our laws encourage providers to operate in black-box fashion, and to engineer artificially high switching costs into their products, I believe there will continue to be a case for self-hosting among a minority of the population. And because they are a minority, they will be forced to also make use of centralized services in order to connect to the people who are held hostage by those high switching costs.

Somewhere in the multiverse, there's a world in which interoperability and accountability have been enshrined as bedrock principles and enforced since the beginning of the internet. It would be very interesting to compare that world with the one we inhabit.

Alcohol is harmful, and you want to prevent minors from obtaining it without parental supervision. Do you pass a law requiring every car to log the age of every occupant in case the driver drives to an establishment that sells alcohol? No, that's stupid. You require the person providing the alcohol to check age only when they are about to hand over the alcohol. Until someone actually attempt to access alcohol, they should not be asked their age.

Now exchange "car" for "OS" and "alcohol" for "age-sensitive content"

A security camera, on its own, doesn't tell the grocery store who you are. There was a time when CCTV didn't even exist and yet we still had commerce.

"What we've got" isn't "the best we can do". There absolutely are better possibilities that would protect consumers. The best way to ensure we never get to experience those better systems is to shrug our shoulders and passively accept whatever treatment we receive.

If the definition of "fun" sites doesn't even include anything with a login (no youtube, no forums, no HN...), then it feels like it includes so little as to be meaningless. The "business" internet (at least most of it) needs to be anonymous if we want to have a free society and efficient markets.

I don't think separate browsers is a very effective mitigation. If both browsers are running on the same machine, from the same ip address, using the same email address for logins, the same phone number for 2FA, it will be pretty clear that both browsers represent the same person. Even cross-device identity tracking is a real thing.

You cannot have a functioning "Business Internet" without identity verification.

Yes, you can. Just like you can have a functioning grocery store without checking the identity of each shopper that walks through the door.

What you cannot have is a free and democratic society or an efficient free market without robust protections for individual privacy. Privacy is the best shield the less powerful have from being abused and exploited by the more powerful.

We accepted the SLA for the "Business Internet" in exchange for free, billion-dollar tools.

No, we did not accept. There was no informed consent. The full consequences of our use of these services was and is still is kept hidden from us. Tracking happens invisibly, without our knowledge or consent. This deprives us of the opportunity to express our true preference and opt out and choose an alternative. It's employing deception in order to subvert the consumer's ability to make a rational choice that represents their best interests.

on the modern web, anonymity looks exactly like a security threat

An anonymous user who just uses the service normally and does not attempt to access sensitive information without authorization does not look like a security threat.

Your location is still being leaked potentially, for example, by your car. Your car also has a cellular modem which leaks your location, and you probably signed a contract allowing that data to be given to hundreds of third-parties.

Ok, fine. I'll just drive classic cars for the rest of my life. Your location is still being leaked by a global network of automated license plate reading cameras https://deflock.me/

Developing in the open would make contributions from the community way more viable, would give the public the ability to see what's coming and prepare for it, would increase the likelihood that security vulnerabilities or other bad things are discovered and prevented early on. It would make the project more likely to serve the interests of its users.

People prefer ads to paying.

People's use of ad-driven services should not be taken as a true expression of their preferences, or as consent. The data that is collected in the name of ad-tech is used for many things other than to display ads. But most people have zero awareness of that. The true price we are paying is kept hidden from us.

People who would prefer paying with money rather than data are not given the opportunity to express that preference. There is no premium version of YouTube where my viewing history is not tracked. No "AT&T Platinum" subscription where my location history is not sold to third parties.

If Apple really wanted to maximize privacy, they wouldn't be constantly collecting so much information in the first place (capture the network traffic from an apple device sometime - it's crazy). User interactions on Apple devices definitely seem to be surveilled for "safety" purposes.

From my perspective, Apple's behavior indicates that what they want to maximize is their own control, and their position as the gatekeeper others must pay in order to get access to you.

Green, (the author), makes an important point: > a technical guarantee is different from a user promise. [...] End-to-end encrypted messaging systems are intended to deliver data securely. They don’t dictate what happens to it next.

Then Green seems to immediately forget the point they just made, and proceed to talk about PCC as if it were something other than just another technical guarantee. PCC only helps to increase confidence that the software running on the server is the software Apple intended to be there. It doesn't give me any guarantees about where else my data might be transferred from there, or whether Apple will only use it for purposes I'm okay with. PCC makes Apple less vulnerable to hacks, but doesn't make them any more transparent or accountable. In fact, to the extent that some hackers hack for pro-social purposes like exposing corporate abuse, increased security also serves as a better shield against accountability. Of course, I'm not suggesting that we should do away with security to achieve transparency. I am, however, suggesting that transparency, moreso than security, is the major unaddressed problem here. I'd even go so far as to say that the woeful state of security is enabled in no small part by lack of transparency. If we want AI to serve society, then we must reverse the extreme information imbalance we currently inhabit wherein every detail of each person's life is exposed to the service provider, but the service provider is a complete black-box to the user. You want good corporate actors? Don't let them operate invisibly. You want ethical tech? Don't let it operate invisibly.

(Edit: formatting)

A bigger problem, IMO, is that companies are allowed to hold and exploit this data in the first place, with no obligations to act in their customer's interests. Google and Apple arguably govern our lives just as much as the actual government, but with fewer mechanisms for representation, transparency, or accountability.