For me that kind of problem is the blocker, and "oh look nobody paid for for the premium version, therefore people don't value privacy" is a bit disingenuous.
I know that there are several defendants [drugs etc] even in my small area who have had deleted snapchat posts, deleted texts, deleted emails, "anonymous" forum posts etc etc etc show up as evidence in court. Now I'm obviously unfamiliar with the legal and technical means by which police investigators made things like that happen, but the fact that they happen means that we can assume that at LEAST the government has access to a record of most everything we do online. Free or otherwise.
Even ignoring the question of the government surveillance net, once your data is on that company's server, how would you even be able to reliably validate what's being done with it? By which I mean, they say they don't share it, but how do you KNOW?
So maybe we would get some pretty compelling new features in a lot of our services if we were to pay for them, but I'm not at all certain that ironclad privacy would be one of them.
In fact, I'm fair certain that it wouldn't be.
Unless you've been extremely diligent, there's no way you're going to escape a targeted invasion of privacy when someone, or some group, government or not, wants it bad enough. Trying to stop that would be exhausting and futile.
Right now, we're allowing highly coordinated, highly detailed, nearly invisible, for-profit, stalking to take place legally. There's no doubt that's bad for society. We have anti-stalking laws for good reason. It's worth doing something about the current state of things, even if it doesn't bring the tracking down to nothing. The free market and tech has failed to fix it so far. They don't have forever to keep trying. Laws are the next line of defense. Laws might not stop criminals from crimin' but I'm sure the Tim Cooks of the world aren't going to risk their company profits (or personal freedoms, if the laws are strict enough) to get a little extra info on everyone.
That doesn't mean I wouldn't use your service (which looks cool). It just means that I would have a plan in place for what I'll do when you sell out ;)
As for Write.as, I spend copious time talking about why I built it [0] and making sure people know me personally, to address your exact point. Personally, I'm a simple dude who relishes putting more value on principles than a number in a bank account. And I'd rather have a tent in the woods than Mai Thais on the beach.
But we do have an open API [1] and one-click export to get your data out, so you can be sure :)
The issue is that the services have to be funded somehow. If they're funded through data mining, you lose your privacy. So if you want privacy, some other funding source is necessary but not sufficient.
> once your data is on that company's server, how would you even be able to reliably validate what's being done with it?
The answer is for it not to be on their server at all. Have it be on your server. Operating a server should be as simple as operating any other home appliance.
That, and there has to be a legal or technical way to prevent them from datamining you anyway. Because seriously, almost no company is going to voluntarily leave money on the table. Why drop old profit source for the new one, when you can have both?
> The answer is for it not to be on their server at all. Have it be on your server. Operating a server should be as simple as operating any other home appliance.
That's an important part of the solution, I believe. Personally, what I'd love to see is the move towards making service providers stop trying to own data. The way SaaS currently works is: I send my data to the service for processing, they basically own it, and I'm lucky if I can even get the data back out and untangled from the service. The way this should be working is that I own and control the data, and I rent their code to be run on it.
Come to think of it, that's how desktop software works, and that's why the abstraction of a file - the one the cloud is desperately trying to kill - is so awesome.
But... operating non-computerized home appliances is difficult, too. Remember all the jokes about the VCR blinking 12:00? This was because every damn thing had it's own completely non-standard, unique interface.
I mean, we've got fewer and fewer clocks we've gotta set, but back in the day, I remember I was the sort of person who would have to jimmy with a friend's car until their in-dash clock was right... and almost nobody I knew had a clock that was right year round, just 'cause they couldn't be bothered to look up or figure out how to set it.
Now, with connected appliances? (as any of your 'social network' appliances would have to be) if you didn't apply the security updates (and maybe if you did) the data would be even more public than it is now.
Not really. It was because the device is a VCR (or a car) that happens to contain a clock and people didn't care enough about the clock feature to bother with setting it. Even the people whose clocks weren't set could still play a video tape or drive to work.
What it points to is the need for good defaults. The default shouldn't be to blink 12:00, nobody actually wants that. It should be to get the time from a GPS receiver or NTP server or something like that. It's a problem caused by no external connectivity, which is no longer an issue today.
> Now, with connected appliances? (as any of your 'social network' appliances would have to be) if you didn't apply the security updates (and maybe if you did) the data would be even more public than it is now.
Security is an issue but it's a separate issue. Huge organizations get pwned all the time. Yahoo, Target, Equifax, OPM, it's a very long list. If the thing holding your data gets hacked, you lose. That doesn't really depend on if it's in your home or not.
For your thing to not get hacked, someone needs go proactively defend that thing, even if defending that thing just means 'install the dang updates' (of course, there's more to it than that, but for most of us, if installing the updates isn't enough, we are compromised and deal with the consequences)
I'm comparing leaving the clock blinking 12:00 to the phone that hasn't been updated in two years. If your data is on devices you control... you need to control the security of said devices, and that's easier said than done.
My point here is that not paying attention to the security of your home appliances has very different and sometimes not obvious consequences to not paying attention to other aspects of home appliance setup.
This test doesn't seem to work in practice due to, I imagine, human psychology. When looking at a free vs not free service, most people are just comparing the cost of the service. The implied privacy costs are too diffuse and complex for the brain to properly comprehend them at that moment.
The individual-based solution is to develop a feeling of ickiness towards such services, but I'm not sure how that could be implemented on a mass scale.
Once they've said "let's monetize our free users" they've already lost. What people miss is that free users are incredibly valuable with a digital product -- whether it's seeing how real people use it or the free marketing they give you. Sure, a freemium product will generally have >95% of its users not paying a cent. That doesn't mean you need to sell of their data to generate value from them.
And as a consumer "outraged about privacy and advertising," frankly we're faced with many products that are overpriced for the value they deliver. More companies need to find the middle ground between surveillance business models and gouging consumers.
Look at the Tor network, for example, the next time you assume that nobody would run a service for free without collecting data or ads.
EDIT: I used Tor as an example because of the contrast with data collection companies like Facebook but there are a lot of people who run Tor relays for free that push quite a bit of traffic around. Things like IPFS, blockchains, Mastodon Project, SETI@Home, etc, are examples of free approaches given our modern hardware proliferation.
Oh an exit node certainly has the capability to collect data. Have enough of them and you can de-anonymize an user.
My point is that most people run those services for free without the expectation of collecting personal data.
It's only after that in the second step that people try to monetise. Nowadays of course it's money from the getgo, but things have changed.
There's still plenty of free today. Lots of people run websites with highly interesting information and then distributed it without benefiting from the ads that run on the site (e.g. a Wordpress blog, where the privacy invasion and ad revenue profits go to Wordpress not the blogger).
See Firebase Hosting [a sister team of mine]: 1GB hosting and 10GB xfer monthly without even dropping a credit card.
And likely even if you paid for a subscription to a magazine, your name and address was sold to marketers to sell you direct mail. And this ended up in someone's database, who resold it to advertisers time and time again.
Cook's Illustrated is an example of a magazine that doesn't sell ads. But the cost per issue is higher and the number of pages is lower. Also most of the magazine is usually printed in black and white to save publishing costs.
The question I ask myself constantly, is do I want to end up being advertised to (Google, Facebook), or do I want to end up being part of someone's brand (Apple, Nike)?
This newsagent delivered the papers and magazines to your door before you left for work in the morning, didn't send your data to organisations and allowed flexible purchasing options (monthly, weekly, etc). Many people still use news agents for their subscription delivery mechanisms.
Perhaps we can see an online agent, where we pay a trusted third party that negotiates transactions on all our online activites on our behalf, and protects our privacy, location, when else we buy, etc. That digital agent would collect a small (1% of transaction cost) as fee, to continue it's operations.
I often don't want to haul out the credit card because it takes so much energy to evaluate a service.
The total comes to just over $300/yr. That's... really not that much, is it?
I'd imagine for minimum mage workers, that's obscene.
I'm not a fan, and I apologize for contributing to it. I'll try to be more thoughtful in the future.
I suspect most poor people hide it in part because the stigma can impede their ability to escape poverty. Classism is alive and well.
Ideally, I would like to see a culture where "rich" people help poor people figure out how to solve their problems. That's all I have ever asked and it doesn't really get taken seriously. I get a lot of flak about just being a charity case, not worth real money, and that I should get a real job instead of trying to figure out how to make money online. Meanwhile, almost everyone else on HN is trying to figure out how to make money online in some sense.
Plenty of other people must value your comments too, because you've accumulated a karma of over 5000 points in about 4 months - say 15,000 points a year, which is definitely a lot - cf HN leaders. [0]
The line gets a bit blurry when you consider that there are a few high school-aged people on HN who can't legally get a full time job.
A couple of years back I was so poor I was sleeping on my brother's couch.
Not to mention that there are people on HN who are from developing countries, where even relatively well paid jobs don't pay a lot by Western standards.
SSDI pays very close to the federal poverty level. Even with the benefit of receiving Medicare, the monthly cost of very-necessary medication plus very frugal living expenses usually leaves me with up to ~$(40 +/- 40) each month in "discretionary spending" that I can use to buy anything beyond rent/medication/food. (e.g. clothes, household cleaning/repair/etc, very rarely travel expenses)
I'm lucky that my interest has always involved computers, which I can use for free for many different purposes. Well, as long as nothing happens to my old desktop (Core 2 Quad Q9650, nForce 790i, RAID-1 of ancient SATA disks). An extra $300/yr would would mean buying new boots and some new shirts. Paying that would mean dropping on of my medications (maybe fatal in the short term, defiantly fatal within a year or two), or skipping a few months of food.
For the record, I'm fine living frugally. I simply suggest that it's important to avoid falling victim to a filter bubble or survivor bias[1], because there are a lot of people - even engineers in Silicon Valley - that have an even worse[2] situation that mine.
[1] https://www.youtube.com/watch?v=_Qd3erAPI9w
[2] I'm fortunate to have the privilege of being male and white. My friends without those privileges have only recently been able to start leaning math/software/etc. They are hackers at heart, but a math/CS/engineering education and SV startup opportunities were not available to black women in the 80s/90s.
(Don't sit at desk ~100% of the time for multiple decades, and get minor problems checked out before they accumulate damage and become major problems)
[1] https://en.wikipedia.org/wiki/Apnea%E2%80%93hypopnea_index ( >30 is usually "severe" apnea. 150 is "how did you survive the severe drops in blood O2 every night?!". The hospital delivered emergency O2 to my house within hours of reading the results of that sleep study)
hi pdkl95,
I'm somewhat new to HN, so sorry if this is bad form, but I couldn't find a way to send a private message.
I've been doing a lot of research on systemd because a lot of the developer practices behind it frankly scare the shit out of me.
I thought you had some excellent comments (these were threads from like 2015/2016) - is there anywhere we could discuss the current state of systemd if you're okay with that? Basically I want to see if any of your opinions have changed, or if systemd still seems like a giant ugly tightly-coupled octopus that attempts to subsume too many features.
tl;dr: I've been playing around with arch linux and I've been loving it, but something about systemd rubs me the wrong way and it feels like an obvious target for security compromise if I were the NSA or [insert evil org] since systemd is present on so many linux distros
The internet is effectively a need, on the level of electricity, so it's closer to being an assumed cost. Nonetheless, some people probably can't afford it, and for those that do but struggle financially, adding more on top of it doesn't at all help. The idea that these people should be concerned about a diffuse danger of privacy violations compared to the very real danger of not being able to afford important things is completely preposterous.
Stop passing the cost to the consumer. Companies that abuse privacy should be regulated. If you're expecting this task to be done by people of low socioeconomic status, whom your own system has deemed as people deserving of less power, you're looking at the whole thing completely backwards.
Would you pay $150/month to not have ads ever again? I definitely would but considering how much people complain about $3/month for no-ad hulu...
I'm all for getting rid of all advertising in any (humanitarian) way possible, but that's the one thing that still bugs me - how to ensure kids with no disposable income will be able to work with the software used by pros?
My point is, people are paying it anyway.
Is paying 1/12th of your total annual income just to get 4 services worth it?
That would be, what?, like you paying $10,000 a year for those services?
It's only an ad model at the moment because we're only just getting started with ways to utilise massive amounts of data. Give it time and, unless we're vigilant and guard against it, it'll be an insurance model, a career model, a justice model, etc. Anything you can imagine turning big data to will become a business model if we let it.
Ads are an incredibly tame use of the data corporations have access to. It could be much, much worse. That's why we need to work out an alternative now.
Can the "alternative to free" be "considered" if that which is "free" has never before been offered for a price greater than zero
Can the "alternative to free" be "considered" when there is no such alternative (e.g. because alternatives have been acquired or blocked by a monopolist)
What if companies exist to serve advertisers and other customers and are not actually "serving" users
What if it was shown that many users do not actually require storage of data in data centers
What if the needs of users and the needs of data collectors are truly not aligned
What if users' "choices" are nonexistant or illusory
While not "the" answer, it could be an option so that you're not paying for each and every content driven website independently.
Of course, the downside is this harkens to the time when we had limited sources of information (newspaper sub, broadcast TV, cable TV and radio).
If micropayments is not working (yet?) and advertising is proving too invasive but we're also not willing to pay underutilized individual subscriptions, what else is there?
Oh, and ISPs would be regulated as utilities so their services would be dumb pipes with high bandwidth, low latency, and no caps or throttling of any kind!
Just because you pay for something doesn't mean you are also not the product. Businesses will maximize value and then they will draw revenue from both subscriptions and advertising. So simply paying will not solve the problem.
Negative externalities are usually handled by regulation in a civilized society as markets are a race to the bottom and cannot account for them. So safety standards, environmental protections, child labour, drugs all have to be regulated and enforced.
In this case the potential for micro targeted propaganda and misinformation are negative externalities. In this specific case its easy to tackle the problem at source by banning micro targeting by advertisers and platforms. Only textual context and immediate location can be used. This protects revenue streams and the current model. But removes the incentives to stalk everyone and hoover up incredible amounts of data to build profiles for micro targeting.
My wild guess is it will not, it will get much clever, it will be able to figure out if a given person is "worth being targeted" (buys expensive goods and services and does this often, has big credit on his card, etc.).
Soon or later those who does not qualify will get nothing or will have to pay a lot to access given service since not being part of it will be considered suspicious (by government, employers, shops). US gov wants people to give their "social" username at the border, Chinese government is working on system to "rate" citizens, companies are setting the prizes in online stores on the base of knowledge they have about incoming customers.
Traversing a saying about communists and capitalists it seems that social networks are giving away a rope they will hang its users someday.
https://www.cnbc.com/2018/01/31/facebook-earnings-q4-2017-ar...
Would I be willing to pay 10x-1000x times that for a half dozen $10/mo subscription? No.
The problem is is that (lack of) apathy is a strong signal, ripe for price-grading, and boy do they price grade!
Actual revenue per user for Facebook in the US and Canada is $26+ / quarter or over $100/year... That is on the order of $10/month [1]. So if a company wanted to be as profitable as Facebook, and not make money from advertising, they would have to charge $10/mo. That is more than I am willing to pay for Facebook -- my friends have my phone number.
If you think profit of providers like Facebook should be limited then that's a regulation issue. Personally I don't think that should be the case.
It is possible to provide the service Facebook provides in a fully encrypted manner. Individual companies would require subsidies and audits to ensure encryption. Essentially regulation.
Another alternative is fully encrypted, distributed services where personal CPU and storage are used to support the service. This is possible through systems like Diaspora or Mastadon, but there is an ease of use / network effect issue there.
I just don't think it is as simple or inexpensive as pennies a day. Or to push a company to charge that little would require regulation.
[1] https://www.google.com/amp/s/www.cnbc.com/amp/2018/01/31/fac...
Will this schema work with Internet? Like if I want FB I will pay for facebook's dedicated TCP/IP port access.
Sounds crazy of course but could it be something along these lines?
I mean, the whole concept of the most widespread p2p networks is piracy, or the act of paying for bandwidth and electricity to save money on the movies that you steal.