“Subject: Urgent Warning”
daniel.haxx.se
daniel.haxx.se
We run an eCommerce platform, have a variety of clients using it, they have a number of customers. At least once a week we get an accusation either from a client or an end-user of some outlandish nefarious behaviour, usually due to some complete lack of understanding of the nature of technology.
Way back when, we responded, tried to help, tried to explain, but it tends to be the case that if someone has made their mind up, they've made their mind up, and anything you say can and will be used against you - confirmation bias is a harsh mistress.
The best response is usually no response, I'm afraid to say. It's a drain on your time, they won't be any the wiser unless you're prepared to sink serious time into educating a stranger, and more often than not responding results in escalation, and people doing stupid things like involving lawyers and law enforcement.
Case in point: About six years ago, we had an older guy phone us up frothing about how we'd hacked his wife's computer and she'd accidentally bought something from one of our clients. We explained that it would be hard to accidentally enter your address and credit card details, and that if they didn't want the order they should contact the merchant, not the web developer (they clicked our "ecommerce by" link in the footer of the client site - we don't do that any more!). We thought that was that. A week later we got a stern phone call from an ombudsman who wanted to know why we were ignoring the distance selling rules and taking advantage of old people... and they didn't understand that we weren't a merchant, didn't place an order on their behalf, either - so months of time were wasted, and we narrowly avoided ending up in court over a non-issue.
Anyway. When you have a conversation with an idiot, nobody watching can tell which one of you is the idiot.
They are not idiots, they are average people, tech is complex, I wonder if people who have to be told or explain things to represent a market to attend?
Imagine, something were you call a number ask for something to be bought; later someone go picking up the money, you perform the purchase and you later deliver.
No credit cards, no complex thing to go over.
I'd like to hope an "average" person would not gloss over gaps in their knowledge and jump to a hostile conclusion.
In your scenario, say you're the phone company - would you think it reasonable if the customer who called in your example blames you for their having made a call and placed an order, because the phone line must have made the call itself and faked the customer's voice?
-Defensive: Remove links to: "made by"
-Reactive: Handle the situation every time it appears.
-Proactive: See if this represents an opportunity for you and approach the market.
-Not responding.
Edit: format and form.
To be fair, the email included in the OP is not really bellowing. She's politely explaining that she found his contact information inside the documentation distributed with the app, and providing screenshots as proof. I think a simple explanation that the name is included only due to technicalities of copyright law and that there is no direct involvement whatsoever is sufficient. After that reply, there is no need to respond further, and almost all lawyers will immediately understand and refuse to proceed with a case.
It should also be noted that hosting an ecommerce platform is a lot different from being one of the many low-level libraries employed by the application. It's not necessarily unreasonable to expect an ecommerce processor or host to have reasonable fraud detection schemes in place, and it's certainly plausible that some lawyers would consider suing the ecommerce vendor (especially if the company makes money).
This sounds like bellowing. It's borderline blackmail. Help me with my request or else I make sure Facebook knows what a scumbag you are.
The funny thing about this whole story is that she's not contacting him because she thinks he works at Instagram, which would be an understandable misconception, but instead she thinks he's with the hacking team. You have to be completely imbecile to think of villains answering with their real names.
But the thing is, does the bellower know they don't understand something? Few people are mature enough (especially when angry) to admit they really don't understand something (and this is probably prevalent in software development circles / communities, too)
I don't think these people are dumb, just frustrated. But your phrasing was curious to me.
That is to say: I know what I don't know in the fields that I study/practice in. I don't know what I don't know about the fields I don't.
No, they don't, that's what makes them an idiot.
A non-idiot doesn't have to know everything, but they do need to be aware of what they don't know.
If you think everyone has to know everything before seeking help, then you are the idiot, sorry.
The woman probably doesn't know what a software is, other than a "Download" button on a website and an icon on the toolbar. Do you expect those people to differentiate between the software and the libraries underneath ?
Of course she doesn't understand, but she doesn't know she doesn't understand. That's the very source of the problem, and assuming they're idiot for not having spent the hundreds of hours necessary to understand what we're talking about is ludicrous.
This is what many "average" people do, and people have built businesses and political careers out of this.
I know it sounds elitist but there are people out there who are completely morons. We have to get used to it.
They ARE idiots, but not because they don't know tech. They're idiots making strong accusations without having any idea what they're talking about or any evidence.
People finding scapegoats because they're afraid of the unknown is how we historically ended up with things like the witch trials.
Naiveté is fine, not everyone can know everything, but this sort of aggressive ignorance shouldn't be even remotely humored.
Most are people that should not have stopped taken what their Psychiatrist has given them (or should go to one given the chance)
And let's not forget the scammers, of course
"Look, I saw your company name under my bicycle seat; how can you say you're not involved in the problem of my pedal having broken off!"
Man made stuff is made from parts, and parts have different suppliers; they are not all original, and a given part is not involved in every conceivable problem that occurs somewhere in the whole. Very complicated, that!
"No wait, I know what you are. You're part of a bicycle vandal ring. You go around breaking pedals and sticking your 'calling card' sticker underneath bicycle seats."
A friend of mine who works as a college professor has a fun approach to deal with the kinds of random cranks who contact him out of the blue seeking someone to validate their wild Time-Cube-style theories and "research": he responds to each one by providing an introduction to the previous one. Apparently, he received followups from some of them afterward saying how much they appreciated the introduction and how much it helped them.
http://captainranty.com/freeman-shafted-by-clueless-judge-2/
It seems that many of those scared are those who've learned in a time of knowledge scarcity (it was difficult to find any information at all on any subject. It took at least a trip to a library and some ability to search the index). Today the challenge is to critically navigate in an overdose of information, a lot of it complete rubbish. The hard part is about filtering out, not finding material.
Now what scares me is that, at least in my country, many teachers haven't realised that the times of knowledge scarcity are gone. They tell student that using Wikipedia is cheating, instead of teaching them how to understand and navigate its (wonderful) citation system, to properly assess information quality.
(note: I suspect your comment to be tongue-in-cheek, but I felt like interpreting it 1st degree anyway)
I am worried though about the (further) rise of anti-intellectualism and anti-science. The effects of this should be pretty clear just by reading the news. This does worry me more than the concerns you've described.
My mother is deeply into this stuff, and I have some friends through her who are lovely people aside from the part where they believe in this stuff. They don't make up a large proportion of my Facebook friends, but some of them are very loud about their beliefs.
Now imagine if you don't care a whole lot about this stuff one way or another, you get your shots on schedule because that's what people do, you never considered government conspiracies because the news never mentioned them, and you see the doctor when you get too sick because that's what everybody does. Then you become exposed to all this stuff, written very confidently and seeming to be backed up with solid facts, charismatic people, and high production values.
I think there's a good chance you'd start believing it!
Yes, be careful in that respect, because the story of Galileo is one of the common historical misconceptions.
EDIT: Sources - https://news.ycombinator.com/item?id=10878748.
http://www.slate.com/articles/health_and_science/science/201...
doesnt end well
Anyone here recall?
Rokeach brought together three men who each claimed to be Jesus
Christ and confronted them with one another's conflicting claims,
while encouraging them to interact personally as a support group.
[...]
While initially the three patients quarreled over who was holier and
reached the point of physical altercation, they eventually each
explained away the other two as being patients with a mental
disability in a hospital, or dead and being operated by machines.
https://en.wikipedia.org/wiki/The_Three_Christs_of_YpsilantiNever argue with an idiot. They will drag you down to their level and beat you with experience.
It's not implausible.
Nothing links back directly to SQLite, nice :)
Yet the founders had a collection of letters from people, actual hand-written letters, asking for help with their hacked computers, asking how to hack, at least one probably-paranoid-schizophrenic one about... errr... hacking and the government and chips in brains and all that sort of thing and whether or not this company could help protect them against the hacker aliens (I don't recall the exact details but this is not an exaggeration of the flavor, alas).
There's an amazing amount of this sort of thing going on. At scale the only thing you can really do is ignore them; engagement doesn't go well for anybody, even the sender just ends up more frustrated and angry than when they started if you try so it's not even good for them. On an isolated basis you might get lucky, but don't count on it.
Edit: Kinda commenting on the thread above anchored on madaxe_again's comment, let me emphasize that I'm not saying ignore it because you can't be arsed, or because replying is beneath you, or because elitism... I'm saying that ignoring it works out best even for the sender, which is why you should do it. That it happens to be the easiest course of action for you as well is just one of those rare times when the easy action also happens to be right.
Most letters are just routine congratulations and thanks. But others have the tone you mention. A sample from 1928:
http://mjt.org/exhibits/letters/26ezekielp.1dropped_image.gi...
http://mjt.org/exhibits/letters/23ezekielp.2dropped_image.gi...
People have been having fevered imaginings about little-understood technology for a long time.
I don't know how they did the different ink thing.
Be kind, though. This is a real person, perhaps a neighbor, who's scared and confused and who doesn't know where else to turn for help. These emails are annoying, sure, but might be the last-ditch effort of a desperate person. Ignoring them is kind. Putting their post up for public ridicule isn't.
(It's not perfect, but it's probably as close as you're going to get)
So it's more like Daniel is a supplier of zinc (and just so happens to give that zinc away for free) to a battery manufacturer.. Who sell batteries to Spotify, who manufacture cameras?
... Although there probably is a cartalk episode that would prove me wrong on this assumption
Website might not be quite as complex as an auto but close and a decent analogy as there are different subsystems...
"My facebook suddely split in half and this screen popped up with all these random cyber space options and it was like watching and assessing things soooo weird? and talking about child... and children being forced WTF????? is this some sort of cyber police thing that my IP was accedently allowed to access so i could help stop child abuse on the net or am i going crazy???? has this happened to anyone else??? - :(( - feeling confused".
[what happened, was that this person most likely clicked F12 or Ctrl+Shift+I - and brought up the chrome/firefox/etc. developer console]
I'd prefer to give the author the benefit of the doubt, but it seems odd to even post this publicly at all unless a tiny part of them wanted to have a "haha look at this idiot" rant and they knew it could be justified under "I was only asking for help...".
On the other hand, if someone was woefully wrong about how something works and came at me as if their ignorance was my problem to solve, they can sod off. And I'd be happy to post their threatening and hilariously wrong headed emails all over the Internet, because for a lot of people being publicly humiliated is the only way they start listening.
Having this link to "haxx.se" is a relatively high volume source of comments by my users.
It also helps with curl changes breaking something or other. Once upon a time curl has optimized something, and it triggered a bug in AWS EC2 network driver.
>I’m Daniel Stenberg, a network hacker working for Mozilla.
Sigh. Why does everyone have to be a hacking rockstar ninja? What's wrong with not using a word that has negative connotations to the rest of the world, and just calling yourself a developer/engineer?
I would argue there are practical rules to follow depending on your audience. In this case it seems fine but obviously can cause issues with the modern interpretation of what hacker means.
Who cares that some ignoramus directs her anger at him? Do you also think "hackers" or software devs shouldn't have long hair or listen to rock music?
So nowhere. It's on the public internet which is where 'the general public' is likely to see it so suggesting that you don't use some phrase where 'the public' can't see it in practically means you can't use it anywhere.
I know the last thing I want to do is self censor myself everywhere because someone somewhere might get offended.
OP tried to get around that by trying to say that when you could be heard by 'them' you shouldn't use those words, but this is the public internet. You are always communicating in the presence of those that will be offended.
Likewise, editing a paper to remove grammatical errors is also not "self-censorship." It's improving the clarity of your message.
Thanks to this, I get about a dozen emails a week from people asking for Waze help. (Lots more when Waze changes something, like hardware support for a particular device!)
I've tried contacting Google (either to get these people help, or to get my email address removed...) with no luck.
I empathize with Daniel. It's an unexpected downside to open sourcing something and asking for credit.
Dear Waze User,
We're sorry to inform you that Waze has been acquired, is shutting down - we'll be closing the service at the end of the month and your app will cease working. No new features or bugfixes will be deployed to the app. For a list of alternative apps, please use this link: https://www.google.com.au/search?q=Waze+alternatives
Paid users should contact SergeyBrin@google.com for refunds.
Sorry about that, and thanks for your support,
The Waze Team.
In general, Google is going to give credit to open source developers whose code it uses.
Companies like Instagram, Facebook, Google and others make it hard to get in contact with a real person, but so users start hunting for a way in. In this case an Instagram user think she found a way in.
http://www.acme.com/software/thttpd/repo.html
The only way to win is not to play.
Bless him, the guy mostly kept on signing off his emails as "John," having forgotten to change his name in the "From" field, except for the time he forgot and signed his "real" name again.
(I say "emails" - it was a bizarre few exchanges, starting with "I have a job for you," and myself replying to his opaque emails to find out quite what on earth the guy was on about)
EDIT (thanks mariuolo): http://www.theregister.co.uk/2006/03/24/tuttle_centos/
Some years ago there was a similar issue with the default Apache website on CentOS. Somebody that their webspace being reset by their hoster, but rather than complaining to the hosting community, the user complained to the contact info shown on the default website, claiming they had hacked their website. (Sorry, couldn't find the link of that story anymore.)
https://lwn.net/Articles/177085/
https://web.archive.org/web/20060427011138/http://www.centos...
Instead of complicated, technical and annoyed explanations of what Linux was to someone who obviously just doesn't care, the simple statement that:
Sorry, we make components for websites. This just means that your web people are using one of our components and has set it up wrong. You'll need to talk to your IT people; they'll be able to point you at someone who can help.
...would have gone a long way towards defusing the situation.Given their first reply ('...we produced it for free and you are able to use it without paying us ... and are even threatening to have us arrested...') no wonder the conversation went badly. That's just being an arsehole.
As an aside, hopefully someone can recommend to the emailer as well to use a different service to host high-quality versions of her photography so that potential clients can evaluate critical clarity in her technique. I'm not sure I'd want to rely on Instagram as the sole example of my work, but, maybe she's targeting a different clientele that I'm imagining.
As an aside (#2), who hacks Spotify accounts?
My first guess when reading the article is that her Facebook account is compromised and that she uses facebook login for both spotify and instagram.
Older people also use the word "hacked" to mean a too-wide set of things, from "broken" to "locked out" to actually owned.
Would it have killed him to mention this?
"Dear Photographer Lady: I run a very well-regarded library, you may have had this reaction because I have the tongue-in-cheek name haxx.se [alternatively: because of the coincident name haxx], however I am a well-paid consultant similar to yourself and other than this choice of domain name there is nothing alarming. The library is famous and you should see a similar notice in all of your friend's phones (or anyone else's you check). It is in use by major corporations including Apple and Spotify. Sorry about the confusion."
that's literally all this is about. (obviously.)
In fact, it makes me seriously question the author's good faith that he ends with the call-to-action "I’ve tried to respond with calm and clear reasonable logic and technical details on why she’s seeing my name there. That clearly failed. What do I try next?" without mentioning the elephant in the room.
http://webcache.googleusercontent.com/search?q=cache:http://...
A website where you input a name and it spits out if it contains profanity in any language would be useful.
But yeah, you should definitely change it.
Intelligent people don't bother reading them closely, and the people who have read them often use the information contained in rather stupid ways.
Granted I have spent many hours over the years reading contest / entry rules and ToS type documents, so I'm pretty comfortable picking on myself a bit here and there. Often I've read a very clear ToS and then observed the responsible company basically disregard their own rules and stated processes. Two notable examples were for a Deadmau5 remix project (he 'lost his laptop' and they stretched the contest for a couple months, barely supplied any promised materials, etc) and a Local Motors contest (routinely lied about what they were looking for as judging criteria, then claimed to contact winners on day X to start authorization process, instead vetted winners in advance and then used day X to announce). I've used these experiences to temper my trust of any online engagement or contest, because it's nearly impossible to hold any provider accountable when they're dishonest or just inept.
Antagonizing bothersome people is a form of entertainment [1] from time to time. If there's nothing to be gained from actually being constructive, then being obtuse might be the most worthwhile course of action. YMMV.
It reads like text generated by a computer
I tought it might give me more users... What it gave me was lots of angry emails once someone used my mail client to send out spam. That header was gone pretty quickly.
It's pretty unnerving because the person clearly needs some assistance but also thinks you are the bad guy.
Here's what's going on. Her IG account may, in fact have been hacked. This happens. She's obviously afraid and angry. She is the kind of person who thinks she can solve all of her own problems, and found the licenses section of the app, which included something with a nonsensical name (libcurl) and a domain "haxx.se". Despite having known that haxx.se is for libcurl basically forever, I occasionally see it and associate it with gray or black hat stuff before I remember. So it's not at all surprising that a non-initiate saw this and thought it might have something to do with her IG account being hacked.
Daniel says his reply to her original email was "clear and rational". It should have been "understanding, compassionate, and patient". This is someone who is seriously freaked out, because her livelihood is at risk, and based on the fact that she went digging through the app, she is probably having what a shrink would call a "crisis of control". So here's what the author should have done:
1 ) Patiently explain what libcurl does (it let's programs request web pages, just like a browser). Explain that he's the author, but he's given it away for free. The license is in the app because he took pains to ensure that nobody can package it up with some slick marketing and sell what he's giving away free.
2 ) Acknowledge that haxx.se sounds kind of shady. Explain why he chose the domain. Self deprecating humor would be great here. Explain that despite this, all kinds of apps use libcurl for perfectly benevolent purposes.
3 ) Explain that he has nothing to do with instagram (commenters have suggested the car parts analogy, which seems like a good plan).
4 ) Finally, and most importantly, link her to their hacked accounts page! They have people paid to deal with this stuff, who are much, much better at dealing with panicking laypeople.
There is a lot of "reason good, feelings bad!" stuff in the tech community these days. It makes people see us as a bunch of borderline autistic[1], self centered, stuck up, evil nerds. Many of us, myself included, were terrible with social interactions and dealing with our feelings at some point in our lives, so the finer points of human interaction and emotional thinking left a bad taste in our mouths. But we've all grown up. We aren't social rejects and evil nerds anymore. We have lives, careers, friends, and family. We need to let go of the stuff we suffered in our youth, forgive those "stupid popular kids", and learn how to be nice.
[1] In the sense of the popular conception of borderline autism, not the clinical condition, which generally doesn't make you a jerk.
...
As a tangent, you say:
> 2 ) Acknowledge that haxx.se sounds kind of shady. Explain why he chose the domain. Self deprecating humor would be great here.
I work in a big multicultural office --- I'm the only UK person in my team. We occasionally have these tedious courses on defusing disputes. One of the things they said that was actually helpful is that humour's generally not a good idea; it's way to culturally specific, doesn't translate well, and in particular doesn't come across in text.
Something which to a fellow UKer is obviously self-deprecating snark can look absolutely serious to someone from another culture, and can frequently make stuff worse.
I saw an interesting study the other day on punctuation in text messages. Even as simple a change as using a ! instead of a . at the end of a sentence can have a huge difference in the impact the message has...
It's like he makes paint. He mades this really cool shade of red paint that everyone likes. One day, some really mean dude used this guy's paint to paint his car red. He then used that car to go on a crime spree. The victims of the crime then went to the guy who made the paint demanding their stolen money back.
You have contacted the software design company that licenses these commerce systems to merchants. We do not deal with the merchants' customer service. Please directly contact the merchant instead.
This is an automated message and you cannot reply to it.
> help me salvage my original Instagram photos, pre-hacked, despite Instagram serving as my Photography portfolio and my career is a Photographer.
You keep using that word, I don't think it means what you think it means.
In all seriousness though, she went to the ToS for help with the Instagram app? Why not write Instagram support directly?
She possibly has, and is now being ignored by them, so she's moving onto other contacts.
"...I also have nothing to do with Instagram other than that they use software I’ve written."
I think that's an adequate description of his relationship with Instagram.