I accidentally built a spying app
withblue.ink
withblue.ink
At the time (2010), link shortening services were all the rage, but they were being used to obfuscate malware links. To fight this, we wanted to create a link shortening service that couldn't be used for malware. Instead of redirecting to a webpage, it broke the page apart into its core elements so you could see what it was about before you visited it. If the site had photos, we even put them into a nice looking image gallery that you could peruse.
We finished the project in 72 hours and got an honorable mention for the competition, but we didn't win. A month later, our free server hosting we were given for the competition was about to expire. I logged in to spin the whole thing down.
Poking around the DB a bit, I realized our little weekend project had thousands of links shortened and the traffic for the site was actually exceeding the limits of the server. Looking at the URLs, I realized they all had one thing in common; they were all porn sites. The simple inclusion of the image gallery had inadvertently created a porn scraping service. It was like your browser's reader view, but perfect for adult sites!
It was so obvious in retrospect, but sometimes in your rush to build an idea, you can be completely blind to its true nature. This time it was amusing, but the next time it could be dangerous, and the lesson always stuck with me.
You could search for and browse movies by clicking on directors, actors and other staff, download a movie with one click, preview it to select what you want to clip, and make a gif out of it.
Turns out it was a very convenient interface to discover, download, and view movies. All we had to do was front-end to TMDb, a torrent search scrapper, and a layer between the Transmission CLI and the front-end.
We inadvertently built a popcorn-time clone in a day.
Found myself in a situation needing it a few weeks ago and was like, ugh, what do I do now.
If Firefox had used something other than firefox.com the brand trust could be decoupled from the service but by offering it for free they received PR. Catch 22 I think.
The nature of Mozilla not having access to the files eliminated any sort of scanning/vetting and malicious actors quickly exploited it.
If Firefox had decided to charge for send I’m sure fraudulent payments would have been used to procure accounts intended for malware. That could have helped expire out malicious links before unsuspecting users clicked them but it wouldn’t have completely addressed the issue.
I guess this is why most no-account file hosting is on sketchy sites.
ffsend uses this host, but I don't widely advertise it's address to prevent overloading the server with spam.
I think a decade ago I started paying ~5$ a month for a server at OVH with a lot of storage. SSH/Filezilla, Nginx on an obfuscated URL, has solved a lot of my problems. I also use it as a server to test docker images, a VPN when I want a French IP, a pictures backup server and a professional presentation website.
My free email account I am using since the 90s is now telling me it is almost full so I am considering to switch it.
Really, storage is cheap but is not free. Save yourself a lot of hassle: pay it yourself, take back control.
Do you think that would be useful to many people?
Having more diverse voices in your team and in your life is a big part of getting better at this stuff.
But if you’re starting from a position with almost no diversity even seemingly “superficial” measures can help you move forward. You can’t turn around and tick a box and say “well that’s diversity taken care of!” But it’s a step on the journey.
(And the journey isn’t “being diverse” it’s “making good things that aren’t accidentally riddled with blind sides”)
In the future, you can view all of your "favorite" comments from your profile page (click on your username in the top-rigtht of the page). As an added bonus, it's much easier than having to sift through your own comments to find that one specific thread you're looking for.
Kool-Aid is good for some of your group.
The opposite is also good for your group.
Your first hires determine largely your culture. The people that end up creating teams, and that eventually hire and influence people themselves, make your culture.
> I had, unknowingly and unwillingly, built a spying tool, and a really convenient and efficient one.
> Thanks to background uploads, people could install the YouArchive.It app on another person’s iPhone, set it up, maybe even hide it (something possible on a jailbroken iPhone), and then watch as the text messages come in, almost real-time. Jealous partners, stalkers and the likes could install this tool on an unknowing victim’s phone with relative ease.
...
This hit home: (The absolutely otherwise fantastic) NextDNS (and anything that's similar to it) comes pretty close to a spying app, too (300,000 DNS requests per month conveniently stored for a long time, for free). I know a handful people who I introduced NextDNS to as a privacy enhancing service ended up using it to encroach upon privacy by configuring it on unsuspecting user's Android and iPhones (doesn't even require jailbreak or root and runs forever in the "background").
The more powerful and impactful something is, the greater the potential for abuse. You don't even need that something to be abused - bad people benefited from electricity just as much as good people. This doesn't mean we should stop building powerful and impactful things, or think of ways to restrict them such that only the "good guys" can benefit.
For cars we have seatbelts, airbags, traffic lights, speed limits, guard rails on mountain roads, and you have to undergo training or certification before you're allowed to get a license. All cars have numberplates for tracking, and identifying these in CCTV and dashcam footage can be useful in identifying those who have caused accidents or other damage. Vehicle manufactures have a lot of regulations that they have to comply with.
For electrical distribution networks and equipment there are also many safety mechanisms in place, such as insulation, circuit breakers, surge protectors, and lots of regulations covering the installation of electrical wiring in buildings. While growing up, everyone learns of the potential dangers of electricity, e.g. don't stick a fork in a socket and keep that hairdryer away from the bath tub. Similarly everyone knows the damage and trauma that can result from car accidents.
The same is not currently true of social media. I don't know what the right answer is regarding regulation - I'm wary of unforseen negative consequences it may have and the potential for it to be poorly thought out. But I think education on how to use social media responsibly is important. Things like be careful about how much information you share about yourself, don't believe everything you read (check to see if the source of news is reliable), learn how to identify fake news and propaganda, and even how to decide whether to opt out of using certain services altogether.
I agree with your main argument, but it's overly simplistic - we should think about how to achieve the benefits of new technologies while minimising the costs.
This iterative process is working fine for social media. The platforms are changing, how the users use them is changing, it just needs more time to mature.
I want my tools to be sharp, pointy, and effective.
Blunt your own tools, but don't tell me what I can do with mine, please.
You should still think about how a car or a generator could hurt someone when you're building one, right? That's how we got crosswalks and fuses.
Electricity is also especially amusing in the US because we picked the frequency of AC current that requires the least juice to stop your heart. Other countries picked slightly different frequencies....
None of these platforms are going to improve though. The money that they make is now closely entwined with what started out as unintended consequences and those consequences are well known. And that just makes them intended consequences.
The author shut their service down when they realized the harm it was doing. They could have solved it other ways as well. Social media and other companies could fix their unintended consequences too, but aren’t likely to so long as money and engagement are the primary metrics of success of a business.
Yes, if you know how to jailbreak an iPhone and are able to have the other person use the phone, you can spy on them. You are already "on the other side of the airtight hatch". I don't think there are technical solutions to having physical control of a person and their phone.
Many times tech people want to imaging a perfect tech solution to a problem, but many times you need legal and social solutions.
Every powerful tool can be abused. In fact, the more powerful it is, the more it can be abused. The abuse of the tool is the responsibility of the person abusing it.
We don’t require baseball bat or hammer manufacturers to think about how their product can be abused, even though baseball bats and hammers have been used to murder people before.
You skipped the slippery slope and went straight to the scariest outcome. That isn't healthy.
Most people on here will agree that banning encryption is going too far. But it's ridiculous to use the worst-case solution as a pretext to avoid even thinking about the problem.
Are we talking about the same people, many among us here, who don't have any problem manipulating content to fit their view and banning Free Speech ? It's a tad of an hypocrite argument...
You are placing an almost legal liability on engineer to ensure the tool is gonna be only used to fit their definition of "good" which is a problem in itself.
Gun makers are not responsible for mass shootings. The ill-intended shooters are the only one responsible for their actions.
In a case like this, the developer could have added some periodic notification to the device or require the device user to rotate a code or reauth with the service periodically to limit abuse.
Can you think of a modification like that you could implement on a baseball bat? Of course not. Is merely a straw man.
Maybe it's better to come up with some lesser way to discourage people from using this kind of software on somebody else's phone without their knowledge than shutting down the whole service entirely.