https://www.huffpost.com/entry/reddit-ceo-edits-user-comment...
https://www.huffpost.com/entry/reddit-ceo-edits-user-comment...
First, consider the context: the CEO (spez) was an easy punching bag on the_donald subreddit, in fact it was a bit of a meme there to attack reddit's admins (and those in the know do know that the attacks were often crossing a line, like accusing them of being pedophiles and things of the nature). The change that spez made was a bit of a joke itself, it was turning an attack on its head. If the edit had been made in the early early days of Reddit, especially in the jokey context it was made in, I don't think anyone would have batted an eyelash. But in the last few years, right around the time these things happened, it became clear that Reddit is a big deal.
I think what I'm trying to say is, whatever may be your feelings of Reddit and its stature, this particular act by spez was pretty insignifiant in the grand scheme of things. Indeed the subreddit that this happened in actually no longer even exists, the_donald and similar subreddits were banned to make Reddit a friendlier place such that it's now an easier decision for corporate America to put ads on there.
It was super significant in that it was evidence that Reddit employees have the ability to edit messages with no audit trail and no governance.
So while the individual edit was not important, the fact that it happened was. And there is an unknown number of other edits that were never disclosed and is unprovable. So Reddit broke the one thing it’s supposed to do- allow users to talk to each other.
Important for this article too because Knight claims her boyfriend’s Twitter account was hacked and someone else posted about fantasizing about kids. If it was Reddit we wouldn’t be able to know if it was Knight’s boyfriend, hackers, or some Reddit admin.
Yeah this is an issue, but let’s be real here, this matters to you me and a few other people here, and outside in the real world no-one cares. Even this expectation is new, any admin who was hosting phpbb forums or whatever else had this freedom to change a few entries in their Mysql Db, heck there was an engineer who was able to go inside people’s private gmail (https://www.wired.com/2010/09/google-spy/) — and Google is a company we expected to have better safeguards. Better security measures, sophisticated software architecture to prevent this, these things only happen after a startup reaches a high level of maturity in its timeline, Reddit hadn’t quite reached that point when this happened. I would be concerned if such a thing happened now though. Now these safeguards do exist on Reddit so there’s that.
I think it's less about the technical aspect and more about the expectation that people with the ability to change your comments won't do that. If you wrote an opinion letter to a magazine, and they published it, but only after changing a few words in your letter to make you seem dumb, everyone would understand why you were upset even though nobody would doubt that magazines have the technical capability to do this.
And I also set up audits and alarms so if someone does change things that shouldn’t be changed then alerts get pushed out to the right places for review. Even if it’s simple stuff like putting a trigger on a column that shouldn’t change so it’s logged and reviewed when someone changes it.
This is just a reasonable thing for an admin to set up. Decades ago, I got really pissed when sysadmins were just reading email and worked to set up controls so people could only do this with the right controls and reading a users’ content was a big deal that was super hard, hopefully impossible to do inappropriately.
There are situations where this has to happen right- HR investigating a complaint, laws, audits, etc- and that’s still possible. But casually browsing and changing without anyone knowing should not be allowed in any serious business. It’s not that hard to set up.
How did you come to this conclusion? It is entirely possible that there was an audit trail and governance, spez simply ignored the governance, and he would have been fired after an examination of the audit trail if he was anyone else but the co-founder/CEO.
That assumes theres an ethical corporate culture which many doubt.
If there’s not auditing to identify when someone bypasses governance, then that’s not effective auditing.
Assuming effective controls are in place without any description of them and evidence that they fail is foolish, I think.
Reddit could have shown off their governance and audit process, but didn’t. I’ve worked on similar systems where someone can just edit the db records and there have been places with no and decent governance. It’s more likely that anyone with admin rights can change stuff. This is bad for a company as big as Reddit with as many users.
Sorry I don't see your point, I work in systems in very large e-commerce multinationals and I have been given the production database credentials many times allowing me to change anything of any user or any product using the mandatory company VPN and the admin account. What are you going to track? The VPN IP and and the general admin credential that can be 100 different people not including hackers that could have compromised any of our PCs?
The only important thing is that she doesn't stand behind the comments, she denies them. So that's it. She clearly doesn't support those statements, end of story.
Doxxing on the other hand is a federal crime in the US and thus is not considered "free speech" and must be censored according to https://www.law.cornell.edu/uscode/text/18/2261A
Whoever with the intent to kill, injure, harass, intimidate, or place under surveillance with intent to kill, injure, harass, or intimidate another person, uses the mail, any interactive computer service or electronic communication service or electronic communication system of interstate commerce, or any other facility of interstate or foreign commerce to engage in a course of conduct that causes, attempts to cause, or would be reasonably expected to cause substantial emotional distress to a person described in clause ...
Uh, this was already known by then, though. What made it significant is that it happened to be spez.
Help me understand this. Reddit is a private company. Is there some sort of contract somewhere that says they won't edit messages and will maintain an audit trail? I mean, I might not like that they are doing it, but I'm also not paying a dime for Reddit (and I have all ads blocked, so they doubly aren't making any money off of me) so I don't see where I can be upset if Reddit does this. You get what you pay for.
If we want governance and audit trails, it either needs to be maintained as a public resource, paid for out of tax dollars, or needs to be a fully paid for product that involves entering into a 2 way contract. Otherwise, I think they are free and clear to do whatever they want to do with any subreddits, posts, or comments.
Legal contract? No. Social contract? Yes.
> Otherwise, I think they are free and clear to do whatever they want to do with any subreddits, posts, or comments.
I'm surprised this is where you went with your rationale. The parent was clearly saying that the intent of the communities is the ability for people to freely speak each other. Any function, especially by authority, to undermine that will erode confidence and thus eventually cause people to use the site less.
You mean like the massive russian "troll farms" that have effectively coerced people into political beliefs, or places like /r/RedPill that have galvanized young males to be ant-feminine, or WSB where thousands of people have placed savings into Gamestop. Want me to go on?
So yes there is most definitely a social contract. Just because you don't believe the information, doesn't mean others don't as well.
> It's not social. There is no contract.
You should probably read up on what "social contract" means: https://ethicsunwrapped.utexas.edu/glossary/social-contract-...
It was a pretty common occurrence on Twitter back when people posted their gang crap everywhere.
Surely you jest! Do you know how programs work? You don't think HN comments can't be edited by anyone with access to the DB and permission to make changes?
Frankly the idea that people on HN thought that people who run a website can't edit the content on it is one of the most bizarre, disingenuous things I've read on here.
You all know it can be done. Why is everyone pretending otherwise? Is it performative?
In a system as large as Reddit, there's rarely a good reason for a human to be running hand-written SQL commands in prod.
In practice, it was impossible to debug software if you didn't have knowledge of how it ran and it was impossible for teams to cooperate when designed as antagonistic. "Operations" people needed to know enough programming and SQL to be able to audit engineering access, or they became blind drones parroting the actions that the Engineering team took. A useless layer of signaling that added no substance. And it was easy to align bad actors in Ops and Eng, at least in places where it mattered - Usually with money.
My career in DevOps has been breaking down these barriers, promoting a "shared ownership" model where it's devs are directly oncall and have production credentials to their services. Still, there are serious protections in place: The passwords to the production databases are stored securely, not typically visible to devs - They have to jump through hoops of using a auditable bastion box to run SQL commands directly on the production databases. Not that it's not possible, not that it's not done (Though good engineering practices make it an uncommon task, I think we've actually used the ability half a dozen times in the last year), but as the commands are being typed they send out logs to a third-party service that's instructed to archive them. It's not hard to get access, but it would be easy to see the trail.
That said: This is on a mature team. That doesn't come out of the box and we didn't get there easily. Many teams, even with all of that protection, don't actually audit the logs, and do generate a lot of logs because of poor system behavior.
Knowing the engineering talent at Reddit, I doubt that it's a concern. Whether by malice or naivete, it has likely never crossed their mind that anyone would break protocol and access databases directly for anything other than legitimate debugging purposes. I'm convinced that the SF bay has some of the narrowest focused minds... and also many of the most malicious.
Still, agreed - The fact that they've now shown, multiple times, to have insufficient auditing and repercussions for the administrative abuse is sobering.
I've worked on production DBs that have had these kinds of restrictions- like, an alert gets sent if an SVP accesses a system. There are a lot of good reasons for this but most of them come down to avoiding fraud.
https://www.dailymail.co.uk/news/article-2681390/Cooper-Harr...
Search for 'reddit' on both pages
For comparison, I don't expect that a Google employee, or C-level executive, has an "Edit" button next to every single post on Google Groups.
Being able to silently change the content appearing under a user's name is a big deal. It's a more significant capability than being able to e.g. take down content.
That’s worse though, right? Why does he have this special functionality the other admins don’t have? Why would the CEO ever legitimately need to personally edit a reddit comment? Surely he has many better things to do.
And there are many very legitimate reasons to have the capability to modify entries in a database, but honestly even if there weren't, making a system where it's impossible for anyone other than the originating user to modify an entry is a challenging task.
He wrote the site's first version, and co-wrote the (modern) Python version. Lots of things stay in place in legacy systems.
The clear harm is that Reddit posts have been used in court cases. People have and will go to jail based on that content.
The unclear harm is they use “we’re being professional business” as an excuse to do unpopular and unfriendly things and also “it’s just a prank bro” when stealth editing posts... no dude. Can’t have it both ways. No one should trust this company at all, and they’re proving why.
https://bgr.com/2018/03/12/reddit-election-interference-stev...
That sounds exactly like what a Donald Trump meme subreddit would say.
In court there’s a concept called “falsus in uno, falsus in omnibus”[1]. If you’re shown to have lied to the court once, then anything else you’ve said can be considered to be a lie as well. You lose the assumption of good faith of the judge and jury.
It might not be a courtroom, but the same concept applies to a so called “bastion of free speech” platform like Reddit.
[1]: https://en.wikipedia.org/wiki/Falsus_in_uno,_falsus_in_omnib...
This is the problem of free stuff, you have no leverage and little to no value to the company as a single user, and if you are the kind of problematic user such as the ones in The Donal, you have negative value because you scare away the ads and ruin the companies reputation, so they actually have a very powerful incentive to push you away and make you leave the site.
Like is that really the most important thing for any CEO to do? It's incredibly stupid and worse it kills user trust. I think Reddit should have banned TD early on but I still think this act was awful.
If you are not paying don't complain, just move to another site or pay for the service so you are under a different contract and relation and you are no longer the product and are the customer instead.
You are not the customer of Facebook, Reddit or Google, the ads buyers are, and the customer is always right. If they don't like your post, it makes all the sense in the world to change it, censor it or kick you out because you are making them lose money and they are not a non-profit existing to serve you. They exist to make money for their share-holders like any other corporation.
Ponder this. Unconstrained. Doesn't see what the big deal is. Can do, will do. Frictionless, untrackable.
Some search engines like Duckduckgo actually keeps a bang shortcut (!) awaiting the day when that subreddit gets unbanned.
Its hard to really make something disappear completely once it's on the internet.
I barely even use Reddit anymore because I simply dont trust it for an accumulation of reasons. Its ~50% astroturf for political and commercial reasons, you can somewhat easily game the votes, and I don't think they care because they make money.
It's a bit ironic that the group that likes saying how other groups are "snowflakes" get the most offended by what was essentially a joke.
“easily offended” is more often than not to be taken as “offended by something I do not find offensive”.
It's been interesting to watch the community actually grow (it was thedonald.win, but there was a difference between moderators - aka the domain owner wanted to make money).
I'm not justifying it; obviously it was dumb, given that people are still using it to denigrate him years later. But the implication that this means he is more likely to have edited other peoples' posts surreptitiously is (again IMHO) not true.
In what way can you support this claim? We’re you provided any indication or proof that this is the first this has happened? Or is the first time they were caught?
More subjectively, none of us can know for certain, but this line of reasoning just isn't supported by an honest reading of the thread in question. The Reddit leadership was in between a rock ("this sub is full of white supremacists and if you don't ban them you're racist!") and a hard place ("we're being persecuted for being conservative and white and if you ban us you're racist!"). Spez isn't perfect, but he seemed to be at least trying to engage honestly and field questions about what he had done and why. After many hours of arguing with people (and, it goes without saying, taking a fair amount of insults and abuse) he did this thing where he edited some posts in a way that seemed pretty clearly to be an attempt to blow off steam.
Now, was that wise? Clearly not, and I'm not defending it. But neither is it defensible to selectively pluck the fact that he edited some posts out of its context and use it to push the idea that Reddit leadership is in the habit of editing peoples' posts surreptitiously to push a viewpoint. AFAIK that's never happened, and I feel like Reddit is under enough of a microscope that we'd know if it had.
That we know of that he admitted.
I don't like reddit, and I don't like spez for other reasons (downgraded from Lisp to Python), but what he did was literally just a harmless joke. All reddit posts and comments are publicly archived by services like pushshift; we'd know if they had a habit of doing this.
I have no stake in this story, but how could you, or anyone, possibly know that?
But I also have no stakes here.
Are you sarcastic? This is logically a very useless statement due to the nature of trust. Once trust was broken it’s hard to obtain because does clearly lied about other things, why should he be trusted now that he’s been caught.
“I’ve been remarkably open about all the extra marital affairs where I’ve been caught, please trust there are no others.”
“I’ve been remarkably open about all the robberies where I was convicted, please trust that there are no others.”
Etc etc.
I would feel foolish even presenting any unsound logic and can’t even think of a situation where it would be relevant to trust. Officiated lie detector? Sodium pentathol administered by an adversarial government? Testimony under oath?
If you have extra marital sex right in front of your spouse, that is no indication that you are hiding secret affairs.
If you walk into a police station and tell them you robbed the bank across the street, there is no reason to believe you have secretly robbed many others.