Security researcher gets threats over Amazon review
techcrunch.com
techcrunch.com
It's no problem though, they can just keep sending out free review units to get their 4 and 5 star reviews. 2 verified purchases from 11 reviews, and one of those got it for free or heavily discounted "The AuYou Power Socket arrived very fast & was packaged well. I received it for an honest & unbiased review"
That is what's really killing Amazon reviews, free products in exchange for 5-star reviews.
I wonder if this behaviour violates FTC's rules[0], I know it was a big thing on YouTube (YT channels failing to disclose financial incentives/conflicts of interests).
[0] https://www.ftc.gov/tips-advice/business-center/guidance/ftc...
I'm sure that Amazon or any site could detect and cull these reviewers, but would it be in their best interests to do so?
An example of a contract term that must be conspicuous is selling something "as is," ie, claiming no warranty that the thing even works at all.[1]
A note on Universal Codes - nonprofits, usually mostly made up of lawyers, will write model codes for state laws and then try to get them passed in each state so that state laws are predictable. Almost all states have adopted some provisions from the UCC, but several states have adopted modified versions or old revisions.[2]
[0] https://www.law.cornell.edu/ucc/1/1-201
The all caps thing is a holdover from the era of typewriters. On most typewriters, switching to bold face required changing the daisywheel or type ball; alternate colours would be lost on xerox- or carbon-copied documents. All caps was the most convenient option.
It's now a vestigial convention, like the floppy disk save icon.
It's like the last time I bought a car at a dealership I got the line "I'll be honest, I haven't sold a car all week and I'll really work with you if you buy one today." Immediate tip-off that he's lying through his teeth.
Never trust a salesman because they're salesman, not because you think you can read their speech and body language.
I'll say one more thing, I hope that he contacted the company directly. It's great that he left this review for others so that they would know how insecure this device is, but I think it's important that he also contact the company directly so that he can help solve the problem. Leaving a bad Amazon review isn't exactly the best way to report a dangerous security flaw in something if you want it to get fixed. Although, it seems like this company isn't one to fix such things anyway ¯\_(ツ)_/¯
Company is revealed to be completely incompetent with regards to security. So their reaction is to harangue and pressure the reviewer instead of fixing the problem.
But if you give an honest opinion -- even one with which I disagree -- I'll never even downvote it, much less report it.
It's what Sun Tzu did with the maidens. :D Not that I believe it here...
Could that have anything to do with the manufacturer's attitude?
(I spent a minute trying to figure it out and didn't find anything)
I have heard of organizations like this: http://revleap.me/ (I'm sure these guys are completely innocent, they just happened to come up in a DDG search for "get positive amazon reviews".)
If you search for "work from home" you will find lots of shady organizations paying people (pennies) to post reviews, for example on Google Maps.
It's not a huge leap to imagine a service which pays random online workers to contact negative reviewers with sob stories begging for the review to be removed. And it's not hard to imagine that a disposable worker such as that would indeed be fired (simply not offered additional work) if s/he fails to get a review removed.
The organization I linked too shows a picture of what appears to be some kind of negative review alert delivered to a smart phone.
Back when I was among the Top Amazon Reviewers, I'd regularly be asked to review products and (especially) books (primarily those that were self published). I rarely said yes, but when I did I treated them exactly the same as I would for a product I'd bought myself. That included 1- and 2-star reviews... though usually I tried to weed out the crap before saying Yes to such an offer.
The cost really never influenced me. I can afford a $10 novel that I'm interested in. So if you give me that book for free, it's no big deal.
In point of fact I learned to say No to most such offers. Usually novels are self-published only when the author cannot find a traditional publisher. And the traditional publishers usually refuse the book for a good reason. I don't want to waste my time reading crap.... not when there are so many good books to read instead.
Also, the self-published authors really didn't like it when I gave their books less than 5 stars, and magically the review would be downvoted -- as well as the last three unrelated items I'd reviewed. Presumably those neginators were from the author's friends and family. So I just said No, and moved on to books from authors I was sure I'd like.
I design, import, and sell products on Amazon, and when launching a new product I offer them for free or at a deeply discounted price to people who agree to provide an honest review. From my experience, across hundreds of transactions, I can say that reviews that are solicited with free or discounted products are much tougher than those received organically. Most people participating in these review groups are so concerned about being viewed as biased that they move far, far in the other direction. If your product can earn decent ratings with incentivized reviews, you'll do very well with organic reviews.
Amazon offers its own product-to-review system called Vine that is invite-only. Not all sellers can participate in the Vine program as it's available to Vendor Central sellers, meaning that Amazon purchases the products directly and lists them as 'ships from and sold by Amazon'.
https://www.amazon.com/gp/vine/help
Additionally, on each review, the reviewer is required to explain that they received the product in exchange for a review.
How would you recommend getting reviews for a product, apart from offering them at a discount?
Edit: Added link to Vine FAQ
Sure, some authors build a fan base by themselves, go viral, and a publisher gets interested in them (see The Martian, or 50 Shades of Grey, etc). But as any viral phenomenon, quality is not necessarily the reason (see 50 Shades of Grey).
What if you're a good author but not a good marketer/salesman, or just not interested in that part?
I'm biased in all this. I have a full time job, I write as a hobby, publishers ignored my queries, so I self-published my novel. It's far from a masterpiece, but according to a majority of people who have read it, it's also far from crap. My main problem is how to get it in the hands of more people, but I don't have the time or the energy (nor the inclination, really) to also do marketing & sales. That's what publishers are supposed to do :(
Better yet, don't review free products. It's just spam that the rest of us don't want to sort through, and it buries the truly unbiased reviews.
I ended up publishing a glowing review of the CodeBug anyway (https://www.stavros.io/posts/codebug-review/), but that's because I sincerely enjoyed it. I didn't get around to doing anything with the BeagleBone, sadly. Maybe that's why they didn't send me anything else, though :P
Both are forms of moral bankruptcy, I was just curious whether the seemingly-desperate employee was a victim or a player.
I am assuming the employee-gets-fired threat is not plausible.
Wouldn't it be in Amazon's interest to shadowban these accounts?
Do any "smart" devices not try to connect to remote servers, automatically, without asking the user for permission?
Do users care that "smartphones" they carry or other devices they put in their home automatically connect to remote servers so various companies can collect data, ..., turn sockets on/off, etc.?
If we do not like this practice and we want to see change for the better, then maybe we should put our comments in Amazon reviews instead on HN, security blogs, etc.
I believe this is the point of Apple Homekit. And probably whatever Google has in the works will follow the same path.
Your IoT devices only talk to your Apple TV, and the Apple TV talks to Apple which provides the cloud-connected app on your phone.
That way the million IoT vendors shouldn't have to worry about security as much, becuase their devices are behind your NAT and communicated with through Apple's security.
Still, he shouldn't cave in. The 'they'll fire me' story probably isn't true!
The use of The word "Chinese" in this article is amusing.
Is it really important or necessary? Would it be preferable if the data was sent to a US server ?
I agree, the inclusion does hint at Sinophobia. But it's also a valid detail for security conscious customers to consider.
If the author had instead attempted to tie this to, say, past security breaches caused by hackers operating out of China, then that would be framing the situation in a coerced way.
Man kills man.
Man kills black man.
White man kills black man.
Assuming the facts are all the same, do you understand how the selective informing of facts frames the readers understanding or impression of the issue?
Thanks for the downvote though.
Human kills human.
Life form kills life form.
At what point does it end? You are splitting hairs and I think you know it.
You are splitting hairs and I think you know it.
No, not really. I'm explaining how a fact can impart bias. Not sure why this is such a difficult concept to understand.I do not think that is a valid comparison. The author did not go out of her way to point out that the server was located in China. There is no mention of China in the title, and the only place where the author mentions China is several paragraphs in explaining how and where the data is transmitted. There are more mentions of China in this comment than in the entire article.
Finally, for the record, I do not have a verified email associated with this account and thus do not have the ability to downvote.
I think HN applies a rate limiter to comment threads, to help reduce flame wars.
> Finally, for the record, I do not have a verified email associated with this account and thus do not have the ability to downvote.
Accounts get the downvote when they reach a karma threshold. I think that's currently 500, or maybe 750.
If the article reported that the data were being sent unencrypted to a Russian server, would that be considered Russophobia?
The current phrasing is clumsy and reads like a dogwhistle, although I doubt that was the author's intent.
> But if you’re not home, your phone sends the command to a server in China, which then passes the command along to the socket.
> The result is that the unique network ID of your socket is transported in an unencrypted form to the Chinese server — and anyone who gets their hands on the ID can then control the socket.
The problem with tying this to the other security breaches caused by Chinese hackers would actually make this article _more_ sensationalist because that would allege that this company is somehow affiliated with the hacking activity.
If the company and server were located in other countries other than the US, it is highly likely that the author would specify the country as well.
These devices are developed in China and hence have Chinese IPs for some call-home feature. As much as I want to be skeptical, I wonder what the HN community would say if it'd be a US or French IP.
I don't live in the US or China and I find it naive to single out Chinese ip address as bad addresses while not thinking twice about IPs in the US. There is no basis to trust a random ip address in the US more than one in Russia or China. And again, these devices are developed in China so it's natural for them to have a call-home ip that's in China. Instead of reading too much into it, let's first consider the most likely explanation.