Apple broke up with me
merecivilian.com
merecivilian.com
I went through every possible channel to explain that the card does not send me a billing statement and I cannot possibly produce one, requesting to be called or at least emailed by a human, to no avail. After spending tens of thousands of dollars on Amazon over the course of fifteen years I couldn't even get a personal call from the case manager, and all my purchased media is gone.
To this day I have found no resolution, and the only next step is to contact them through a lawyer.
As soon as you click "update", you are insta-locked out of your account.
Coinbase has to push the boundaries of US legal code interpretation in plenty of other places... picking "letting pre-teens manage accounts" would be a dumb hill to die on.
> the immutability of your birth date.
Another falsehood programmers believe about dates. ))When immigrants move across borders, often if there is no record of date of birth the date used is the first of January on a best-guess year, and sometimes even the year is wrong. Later this information could be updated. I know of a case of a man whose birthday (immigrant from China) went from January 1st, 1900 to some date in the late 1890s upon documentation being found, just slightly before his 100th (living) birthday.
There are, of course, also reasons for deliberately falsifying a birth date. Accessing an online service is one, false claim of benefits (e.g. pension) may be another, avoiding or enlisting in armed forces, purchasing age-restricted material, renting a hotel or vehicle, the list goes on. A robust system must account for these possibilities.
Besides, Even with 1 in 100k, with the US population of 330 million, you've created trouble for 3 300 people based on this edge case alone.
Since we're in the middle of a bad customer service with no appeal discussion... can we assume you are joking?
(She was born in Greece in 1920- AFAIK Greece was the last country to switch from the Julian to the Gregorian calendar, and did so in 1923.)
When he was 15, his parents decided it was time for him to start driving his mother around, who never learned how to drive. They wrote down his birth year to make him appear 16. The Texas Department of Public Safety in the 60s wasn’t quite as strict about proof of identity as it is now.
Fast forward to the late 90s, and digitized driver’s licenses. Fortunately, my mother had an inkling that life for my dad might get a bit complicated with a driver's license that didn’t match his birth certificate, so she pushed him to get it corrected.
I imagine there are at least several thousand US citizens who have never lived elsewhere whose primary ID (driver’s license) shows a different birth year from the one on their birth certificates for similar reasons, and it’s a toss-up on which date they use for various purposes.
There are people who escaped war zones with no papers behin
Syrians in Germany, Bosnians in Arizona and many other such examples in the UK.
They often provide 1.1.year as dob.
That date ended up on their marriage certificate.
And then, after her husband passed away and she was approaching pension age, she realised she would only be eligible for the pension a few years later...
So DOB is not immutable.
(and another common source of DOB errors, mixing up the US MM-DD-YYYY versus the normal DD-MM-YYYY format used almost everywhere else...)
The software works perfectly. It's the spec that's broken. I'm going home.
Of course I have no idea about the actual UI. It's a bad idea to ask for the age because it doesn't update after the birthday. A birth date is much better but it's also personal data and maybe not necessary. If all a site wants to know is if you're 18, just ask it and store a boolean. If you suddenly declare that you're not >= 18 anymore, especially after using the site for a while, smell a misclick on a checkbox, ask for confirmation and explain what's going to happen.
(Assuming there is a save button on the screen and it’s not an auto save on an input change, in which case yes it needs a confirmation dialog)
some years ago the Danish electrical company Dong (wonderful name they've since changed for 'reasons') sent me a message - give us a meter reading for your house or we will send someone around to do it and it will cost you some money, so I figured fine I don't have to do anything they do it for me for money!
next year, the same thing.
third year, the same thing. In Christmas of the third year when I was in Berlin I got an email from Dong, you owe us 15 thousand dollars (approx. translating from dkk in head), then later same day you owe us 18 thousand dollars, and finally next morning you owe us 20 thousand dollars.
So naturally I called them up and said I sure would like to know what you all are thinking (which was a lie, I didn't really want to know but I figured I better find out anyhow)
So they said they had sent someone by to read our meter and we had used more electricity and they wanted their money or they were turning it off. So I said you think I used 20 thousand extra dollars in a year?
No, the meter hasn't been read for three years and this is your fault because when we send you a notice to go read the meter you have a moral obligation to do that.
I asked what about their moral obligation to go read the meter when they said they would (which point they did not understand) but anyway since I was supposed to pay 3 thousand dollars a year (which is somewhat high for a Danish family of 3) and paid that it seemed highly unlikely that I had managed to use over two times more than I was estimated to use per year without an increase in population of the house.
It took a lot of arguing to convince them that somehow there was something fishy in the situation and they might have made a mistake, before they would put it to off closing the electricity and do an investigation.
Some months of investigation later, which involved me going to take pictures of my meter etc., it turned out they had read the wrong meter.
tldr: even obvious discrepancies that systems could easily be set to catch will not be caught and you will have to do the work to fix the problems of the organizations providing you services.
"Our policy is to make it as easy as possible to destroy your account forever with no warning."
Not being facetious, just pointing out the depressing nature of our reality. :/
This is really just a question of the opportunity cost, which can vary.
To their credit, Apple seems to get this mostly right.
20 years ago DHL told me the credit cards I was waiting for in Santa Cruz, California were suddenly in transit to South Korea.
As a one off it was a funny story. 10 years later they told me the computer that was sitting in a depot in London was on a ship back to the US.
I'll keep telling those stories until everyone involved had long since retired.
Don't know what to do, I'll just assume my investments are lost to time...
I would still file with them, they can still escalate on your behalf since they are the regulator, or refer you to the agency you should file a complaint with.
What did Binance do to you?
The complete non-answers from support are almost certainly because they have that as a standard policy with people they've decided are scammers, because the genuine scammers out there are extremely good at manipulating literally any kind of even vaguely permissive support policy into enabling further fraud.
The bigger issue here is that when a company is actually good at this stuff (like that web hosting company I once worked for), there's a department specialized in handling these cases with knowledge of how to properly verify legal identities and filter out the scammers... but quite a few companies today both big and small have decided (possibly correctly, given how they're treated) that it's easier and more profitable to just skip that entirely and instead leave false positives locked out of the system permanently.
In my life, I've known two Mike Wilsons, and when I knew one of them, there was also a cabinet minister called Mike Wilson (in Canada).
Summary: if your company blocks someone based on their name only, your company is a bunch of incompetent losers.
So yeah I agree it sucks, but the issue is not that every company which complies with OFAC is an incompetent loser. It's that the USA has declared a few countries as enemies and has some tough laws to enforce this both domestically and within its sphere of influence (foreign transactions with a "US nexus"[0] fall under OFAC). If I recall there's no upper bound on the fines for contravening OFAC and there's no leniency for accidentally breaking it even though you demonstrably tried to identify people, or were tricked. So these companies are incentivized to err on the side of extreme caution.
[0] - this is a fun one, iirc this can mean obvious things like "a company has a subsidiary or office in the USA", or "a transaction was conducted in USD" or even "an American citizen was in the room when the transaction was performed".
Many things are more difficult for “John Smith” because of this sort of bullshit.
It's aggressively monitored. Jeff himself used to forward prickly ones with a ? to relevant parties, but at the very least, better than front-line support.
I tried this approach when a client was having issues enrolling in Apple Enterprise to distribute an app in-house. Didn't work, took four months until we could release our app.
Completely killed any esteem I had for Apple.
If you ever turned up to a meeting and contradicted something you once said in an email, he'd be on to you in an instant.
Knowing that email address exists makes me less likely to shop with Amazon, and any startup that considers copying it should think very seriously about whether they actually care about their customers. No one should have to email the CEO to fix a basic problem.
Presumably if a startup is copying Amazon it's because of their track record of making money, not their track record of showing they love customers, for the same reason companies aren't copying Google to achieve a bespoke customized nature of services and how they feel tailored to the individual.
Copying any aspect of a much larger company without properly considering the impact of it on your customers when you're running a very different company is usually a terrible idea, but doing that for support and customer success is extra-terrible.
Yes - I slipped 'while' in as a substiutute for 'by'. Arguably the CEO of Oxfam is a 'good citizen' as part of his job, from which he earns millions. So he earns that 'by' being a good citizen. I meant that it's perfectly possible to have a well-paid job that doesn't involve exploiting people or the environment, or generally being a dick. FVSO 'well-paid'.
If 'making a lot of money' means becoming a billionaire, well, I don't think cornering the world's wealth is consistent with being a good citizen.
The "open secret" approach is a high enough bar to filter out 99% of unprofitable support request, but a lower-tier than litigation. Most people will spend time with a search engine before shelling out for a lawyer.
You're thinking about this emotionally, rather than in terms of capitalism.
(But I get now your complaint isn't about that, and this isn't the best analogy. You're saying that this is a slap in the face to people who don't know that address; they shouldn't be likened to "attackers.")
Writing the executive team isn't some trick to get real support, it's something that people figured out you could do and that executives would give vague responses to in order to save face; having seen the end result of a "write the CEO", usually the executive response is just a vague "make this go away", and the "how" of that is left to the imagination of the reader.
Please understand that it's highly doubtful that there is any official policy on what to do with support emails received at the executive level; the end result is that the person who wrote the email gets what they want, but it's not because the executive put any thought into the actual situation, it's because they just wanted an annoying person to go away and wanted to avoid bad PR.
That's all this is, a quick cost-benefit analysis of "what does doing nothing cost me here?" for some executive. For each story you read where writing the executive helps, probably there are a dozen (if not far more) met with radio silence. I've seen customers write the CEO when they were flagrantly and intentionally violating our licensing policy in hopes that the CEO would change something. I've seen them write our product VP because the customer felt they were entitled to salary compensation for the duration while an issue they had with our product was investigated.
Writing the CEO isn't a way to get basic problems fixed, it's a gamble that your particular issue and the circumstances around it are a big enough PR problem that the normal channels of raising concerns aren't enough.
I've emailed this address with problems about scammers and counterfeits on Amazon and never received replies.
Just trying to get my package...
(p.s. tried all the regular support channels)
I had just moved countries and none of my new accounts had statements yet, by the time I got them I just get stuck in this repeat loop of upload docs, wait a few days, says invalid.
No way to get back in, all my purchases lost, no human to contact, I just don't use Amazon anymore. Very annoying
I'm sorry but this does seem extremely suspicious. I've never heard of a bank that does not provide any statements.
Sure, a debit card does not have a billing statement like a credit card, but the bank account that the debit card is linked to should provide a monthly statement where you can see the transactions. At least a downloadable PDF even if they don't send a paper one in the mail.
In any case, I didn't ask them to take me on my word, but to contact me and see if a different set of documents might be used instead.
I've never used one myself but Amazon claims to support them in general.
https://www.amazon.com/gp/help/customer/display.html%3FnodeI...
I wondered if there might be some mention on this page about large transactions or unusual addresses, but there is not.
(I could turn statements back on, I think the bank charges $5/month or some sort for that)
I don't blame Amazon here. This is suspicios. All debit cards are linked to your bank account which always have a statement.
Also, I have found it very helpful to provide not just statement but the photos of the card, your ID and various other documentation in the PDF. It helps the support engineer realize that you are really you.
I've sent them the exact documentation they requested (actually well over and above what was required) - all of it rexboxed and annotated, and each time they send it back saying the documentation is illegible or lacking in the details they require.
There'll come a day even the people who defend copyright won't be able to justify supporting this industry due to how badly it mistreats and abuses them. It's simply appalling how it's almost 2022 and paying consumers still get infeiror products and services compared to "pirates".
Just to give a car analogy, imagine your car is at your BMW dealer for repairs. While it is there you buy some new rims and pay with a credit card that is different from the card you used for buying the car. After that they refuse to give you back your car, because they say this is suspicious. Nobody would accept that.
OP clarified that it is not a debit card, it is a prepaid card.
But it seems more surprising to me than what Amazon did (not that it was good).
But Amazon wants a statement with a billing address and the card number.
That's one reason I only use my credit card on Amazon - it has such a statement available in case I ever need one, while most of my other cards do not.
Stolen by Amazon. They have no incentive to get it back. Amazon hopes that you purchase it again.
Call the consumer protection services. Big tech companies are not the law, they cannot steal things from you. Even if you committed fraud in one transaction, they cannot take away your property. (Amazon will call it 'service', but accessing your property is not a service)
They are not the only company doing this in some ways. ISP's who provide a set top box for watching TV and downloading/streaming service to tv, do the same thing when you change you ISP. Its a form of lock in because whilst you can still get access to the purchased films, you have to jump through more hoops. Its all legal but I question the morality of it, when considering online piracy via torrent streams and then the "hacking" that companies have used to trace and prosecute the worst.
But I've learnt enough to know that everyone has their questionable practices to maximise profits/income, the lucky ones are the one's who would also be the expert witnesses in court or have been able to fly entirely the right side of the law.
At Comcast/Xfinity when you cancel all services your account still remains, and you can stream your purchased content the web or through their mobile streaming app when signed in on your account.
The only real answer is to minimize our footprints in these closed places.
My current phone runs Lineage without a hint of Google. I keep an old Samsung for gmail and other services, but the death of "don't be evil" has meant the death of Google on my phone. They will never be back.
I have seen several people who sold on Amazon lose their accounts. I am not sure what provoked it, but the exchange is certainly not in favor of the smaller party.
And we all know what Ebay did.
I can't really say that any one abusive company's behavior is any worse. They are all tyrants with their "star chambers" and sundry courts of inquiry, and the less authority that you give them over you, the better your position will be.
We left this legal thinking behind long ago, but Apple (among others) has brought it back.
So if you buy stuff and it's going to get taken away from you for arbitrary reasons... you might as well pirate stuff.
Same with games, if possible i buy them from HumbleBundle or GOG. And i never buy something that is bound to a platform that i really care for.
And yes i hate drm too, but since stallman is a extremist that supports un-free licenses (unlike the BSD and MIT) i will not listen to his wannabe rants, and i will never forgive him to change the GCC license to GPL3 only.
If i care for something i remove the drm, if i cant, i will stop buying it.
GPL puts the user's freedom first. Every developer is mostly a user anyway, unless you're writing absolutely everything from scratch like they do in SerenityOS. So I like that stance very much. If you don't, nobody is forcing you to interact with GPLed software in any way.
I think that's much more noble and kind. But as long as it's free software, I'll still use it and be happy it is, regardless of the license. And tbh it'd be nice if the small, loud minority of BSD lovers, GPL despisers would shut up. They give the BSD crowd a terrible look.
BS, i use FreeBSD and no one ever forced me to use Windows, Linux on the Desktop does everything right?
>GPL puts the user's freedom first.
No it's free promotion for the FSF
>scratch like they do in SerenityOS
Yes and they chose a good license (BSD2)
They deserve the promotion, because they created useful software.
> BS, i use FreeBSD and no one ever forced me to use Windows
At some point, Windows was everywhere, you couldn't hide from it. Now, Linux provides a strong competition, forcing even Microsoft to include it into Windows. BSD, instead, served as free labor for Apple, who created a walled garden for users.
What exactly do you want to do with the code that GPL prevents you from?
Afaik, they could in Germany. One of the most BS laws.
Terms are not law, and are most terms are illegal in europe anyway.
The only exception is content I create.
With a couple of minor exceptions that works well for me.
Historically i hoarded content and ended up with 2TB of crap I was never going to watch again. So I deleted it and now don’t have to herd hard discs.
[0] Marie Kondo would disagree
By saving stuff, you future proof the high possiblity that it becomes completely unavailable anywhere online and you have the last copy. And you can easily find it by search, I have this happen all the time. In many cases the audio cassettes that accompany an old pedagogic text have been digitized by one person who shares a zip one time and then the link dies forever. Ten years later when I finally free up time to study the material, it will be too late.
The important skill: don't download or even browse crap you certainly won't use within your lifetime. It is a time sink. Develop a strong preference for only looking for things you'll immediately begin studying or have a concrete plan to study in the coming 6mos.
It isn't always like that. If your data is on somebody else's platform (as for the author's data) your data is gone, possibly for good.
And by the way... onljne communities (and websites in general) come and go. The data you're relying upon today might not be there tomorrow (or it could get altered someway).
For some things yes, for TV shows and movies eh. For roughly the price of a year of netflix you could get a 14TB hard drive, which would hold six continuous months of high quality 1080p video. It's also really easy to keep those things sorted with negligible clutter and wasted time.
As much as this is technically true, anything not currently on your hardware can, and probably will, get snatched away from you, usually without warning, regardless of it you paid for it.
I'm sorry, this is bullshit.
I spend _less_ time if I torrent stuff.
Example: I want to watch the last season of Expanse. Ok, go to iTunes (Apple TV). Nope, not there (Australia). Hmmm, may be Netflix? Nope. I remember it was by Amazon or smth? Oh yeah, it's in Prime.
How much time did I just spend? And I also must pay for all of those?
Torrents:
- go to my favourite tracker
- search, find bunch of options from SD to HD with bunch of audio tracks and subtitles that not a single commercial pos offers
- copy magnet link
- paste in transmission UI
- done, took less than 3 minutes.
Whenever I feel like watching it, open Infuse on iPhone and watch it from my Emby.
also, for everyone: i have been looking for an easy way to allow my parents to browse torrents (via an app on their phones or tv or something), then select what they want to watch, and the movies/whatever are then downloaded on a remote pc that also hosts a plex server. they could watch whatever on plex in minutes, ideally. is there something that sreamlines this kind of thing?
I have a little dashboard just providing quick links to sonarr/radarr that people can go to.
In radarr/sonarr they can search for movies and tv shows, add it to the application and it auto searches for the best download option through jackett and adds it to deluge
unpackrr will auto unpack it if it needs it
radarr/sonarr will automatically pick up the completed download and move it into the correct media directory
jellyfin/plex/whatever will pick it up and show it
everything is pretty easy to setup, i probably got it all running in 3 or 4 hours tops probably two years ago and honestly haven't touched it since.
Torrenting isn’t hard but these days neither is streaming.
Then you find something is only available in x265 so you have to transcode it yourself so it’ll play on the kids 5 year old Samsung TV. Oh and that only supports certain very fussy audio streams.
Just no. I’m on the mark. I’ve been doing this shit for a decade and I’m tired and fed up with it. I pay ~£35 a month for all my services and that’s a bargain. It’s literally fuck all money to make the problems go away.
And I bet that you can find anything you could ever want on nyaa. If an anime/manga exists, it almost certainly is on nyaa, unless it is highly obscure in which case it may not even be there on paid streams.
I want big corporations to abide to the law. To pirate is a patch that does not solve the problem. Let's fix that corporations do whatever they want with your digital property.
I want to buy digital movies, games, music, ... without being at the mercy of some algorithm that can automatically steal what is mine.
I suspect it will be similar with all other consumer oriented content distribution services.
It's roundabout, but at least for audiobooks there is a way to own what you want to listen to and still support the creators.
Digital content is not forever. If I can't purchase it and download it to my local hard drive, I'm not purchasing it.
Reminds me of those old anti piracy PSAs: "you wouldn't download a car." (note: yes, yes I would if I could).
But if the new car-buying process was "pay $20k for this Honda Civic, but just know that we are just allowing you to drive it, we can take it away from you at any time" you can be sure that either no one will ever buy cars again, or they'd just "steal" them.
If compliance is too hard or too inconvenient or just plain stupid or malicious, then people won't comply. Easy as that.
GOG for buying stuff DRM free, and Game Pass for renting it cheaply if you don't care to own it
On the other hand, many games (by number at least) on Steam do not have any DRM and you can back up the installed files as easily as you can back up a GOG installer. Many more games only need Steamworks which is easily bypassed.
Meanwhile Valve is actively working on making Linux gaming better (which I care about) while GOG/CDPR can't even be bothered to port their own games or their store client.
Generally this has only happened with games that are no longer developed, but if they got yanked for any other reason I believe Valve wouldn't distribute any new patches to me.
There is some part of me that increasingly hate Silicon Valley.
To clarify for others: parent is not talking about subscriptions.
When you "buy" content on these platforms, they are not actually yours to take away for ever like a physical book. The software you consume them on e.g a Kindle or iTunes, is actually capable of remotely deleting "your" content at any time, and they are supposedly within their legal right to do so.
They have essentially hijacked the word "buy", it does not implicitly mean what it used to mean, you cannot really buy a copy of a piece of music or a book or a film from any of these large platforms today without removing the DRM and making a local copy (which is technically illegal).
Recently she tried to watch it and Amazon just had "you can't access this content." Maybe Amazon didn't renew the license with publisher, maybe not, but in any case, Amazon really proved to me that no, we do not own digital content.
So, I pirated it for her. If doing things the "right/legal way" is going to screw us over because of fine print, then why bother?
Amazon does not make laws. If a thieve steals your car that does not prove that you don't own the car. The car ownership is still yours, but it has been stolen.
Would you download a car? advertisement has gone all the way around and now big companies are just stealing our property.
I went ahead and torrented the episode the next day to rewatch it in all of its intended glory. Then a few days later, I got a letter from my ISP telling me that HBO was very upset with me and threatening to cut off my service. I felt compelled to send them a reply, explaining the situation and telling them to eat it.
Yes.
Part of me thinks that was the reason why Steve Jobs hated Music Subscription. He said "no" to Beats many times before his death. And why Apple ( at the time ) worked really hard to get rid of DRM in movies ( but failed ). And iTunes Music is DRM free. May be it is time to remind our self how we got DRM free music on iTunes, with Steve's "Thoughts on Music"
https://web.archive.org/web/20070207234839/http://www.apple....
A few years ago, I was vacationing abroad, and ordered a gift from Amazon to be delivered in another country. The payment from Amex bounced for whatever reason, and Amazon permanently banned my account instantly. Difference is it says my login/password are invalid (they're not), there's no other message, no field for contact.
I lost more than 100 paid Android apps. Never took the time to recover that account, if this is even possible at all.
The damage would have been much greater with an Apple or Google account.
Trained human experts will review documents and establish an identity.
However those systems also have financial hurdles to access. Someone with a very thrifty banking service, or someone with very little money (paycheck to paycheck poor) would have trouble utilizing such a resource.
This is unfair and systemically disenfranchising.
I would really like to see a solution to this issue from another part of 'the system' which must already validate someone's identity. A nominal and small fee should be attached, but it should be paid for by the corporation that wishes to ensure anti-fraud activity.
In such a circumstance the corporation would be compelled to also accept this validation, or optionally offer others that may be faster if a consumer agrees.
An individual under such suspicion would visit a nearby police department. Depending on the level of validation asked for said department might also try to actively contact the individual in other ways to cross-validate. If someone happens to be on vacation at the time this check would necessarily involve two departments (the place the person is at and their home area).
Such a system is costly in time for the consumer, and some money for the company. Ideally solutions that don't result in account suspension would be developed to prevent reaching this state; but a good standard for last resort default is necessary to ensure any other solution that survives is better.
There will still need to an ecosystem of companies with the kind of services you’re talking about, but there would be a clear distinction between the “vouching” part (attest to a bank that you are who you say) vs “access” part (multi-party key custody and recovery services)
So many hairy problems (online payments fraud for example) stop existing in the same way if we move payments from pull to push and access control to utilizing cryptographic signatures.
I shouldn’t have to expose my entire identity in order for an online merchant to be sure I won’t bounce the payment. And the scenario OP is describing would never happen.
Everyone involved in a transaction would declare the perceived value of the transaction (which should agree within fuzzing to account for currency exchange). Everyone would also declare their risk aversion thresholds in advance, publicly (pushed through their bank). A maximum accepted threshold would also be declared by each party (E.G. must settle before X). An agreement of contract would involve the maximum thresholds being less than the cross-referenced risk level.
E.G.
Seller [ (< 3 days && RANGE_INCLUSIVE 0 USD TO 24.99 USD) || (< 7 days && RANGE_INCLUSIVE 25 USD TO 99.99 USD) || (< 14 days && RANGE_INCLUSIVE 100 USD TO 999.99 USD) || (<33 days && GREATER_THAN 1000 USD) ]
Buyer (happens to use the same default list as above because it's popular)
Purchase: 105 USD (laptop power adapter)
Among both lists that would fall into the 14 day category, so it would go on the books and 'clear' (like a check in the US today, but with a longer time period) in 14 days.
That gives someone 14 days to discover an identity compromise, publish the revocation certificate, and this SUSPENDS all contracts made by their key within the published clearance time windows.
They may re-sign the transactions they approve with the new "key" (accredited by certificate issuing authorities such as a state or federal government).
For any items / services not yet fulfilled suspension of delivery or limited use might be imposed if the contracts are not reauthorized.
All of the others would be part of a fraud case (or cases).
IMPORTANTLY: to change the published duration of a contract expiration to shorter would require waiting out the whole period, while lengthening it would be 'instant' as soon as the lending institution involved witnessed with their signature (and thus also published the new value).
My energy provider used to perform an immediate change of address which would be visible on your latest downloadable PDF invoice. This allowed even people without the most basic computer skills to validate _any_ address.
Long story short, all those processes eventually depend on “proof” that is really easy to fabricate.
Dutch banks invented the iDin standard, some kind of oAuth with your bank that provides third parties with validated personal information, but it is not widely used and I am not aware of an international standard or initiative for this.
There is no way that my Norwegian bank would accept a utility bill as any kind of support of ID. Instead they send a letter to my registered address (national population register) with instructions to take it and my driving license or passport to the post office who will act as a notary and report to the bank that I am the person that the letter is addressed to.
From then on BankID (using a one time pad, SIM card, or code generator) can be used to log in to pretty much all banks and government services.
We can argue all day about whether or not this is a good idea. But ultimately, it’s red lines we’ve drawn in the ground, and we’ve decided the trade off (such as identity theft) is worth it. In the U.K. at least, two World Wars have taught us to be wary of central government databases. We’ve seen how they can be abused people in power seeking to persecute part of a population, and even now we’re seeing it again with the U.K.s governments persecution of migrants.
At least in the U.K. there are clear and simple guidelines for undoing the damage caused by identity theft. If a bank account or loan was opened in your name, the bank has to close it and write off any losses, and they should compensate you for the trouble. If the mess you around, there’s a number of Ombudsmen and regulators filled with people waiting to take the financial organisation to task and make them really regret their obstinance (I’ve been on the receiving end of their wrath, it’s not much fun).
All of this creates very strong incentive for banks to prevent identity theft in the U.K. Unfortunately US consumer protection is lacking in comparison.
That's because the US and the UK are mentally ill cultures actually engaged in cultural and political suicide, so any practical, useful ideas like that are considered suspect.
> Unfortunately US consumer protection is lacking in comparison.
That's what happens when a whole country decided to mistrust their elected government and instead put their faith in corporations.
It’s a little more complicated than that. KYC requirements aren’t that lax, but there are multiple ways of proving ID. Proof of address in the form of a bill is just one of many components that are used in tandem to prove identity. Rest assured you can’t open a bank account with just a utility bill.
> In many parts of the world (including the US & U.K.) the idea of central government holding an accessible database of everyone’s identifies, and mandating participation, is cultural and political suicide.
Is a very true statement. I am British but I live in Switzerland. If I want to do anything here, I send a copy of my residency permit. Bank statements wouldn't count.
The UK actually did experiment with ID cards under the Blair/Brown government. I never had one, they were only issued in a trial area. There was a campaign against it: https://www.no2id.net/ and the Cameron government (2010-brexit) scrapped the ID cards. The law was: https://en.wikipedia.org/wiki/Identity_Cards_Act_2006 .
One of the main objections was to the national identity register, which would contain biometrics and not need the card in order to query.
I'm on the fence about this. On the one hand, I'm not sure I trust the UK government to run any kind of IT scheme - they tend to pick huge consultancies, waste enormous sums of money and the result is late, 6x the price and doesn't actually work. Also the biometrics thing seems excessive. On the other hand, there are plenty of centralised databases already and if you ever want to drive a car, at least one of them prints out an ID-0 sized card with your photo on it. I would also, honestly, prefer an identity card over proving my identity with easily forged bank statements.
Even that would not fly in Norway. You have to close the loop with a trusted intermediary like BankID by providing a notarised copy of your ID then you can log in to other institutions using BankID's log in service.
Abuses of government power that the average person might experience here tend to come from lower levels like the civil service, police, tax office, immigration or councils. ID card databases could make that easier as they tend to be more accessible (of course, otherwise they'd not be useful). The other thing we don't want is for it to be easy for companies to demand ID for basic things knowing that everyone will have one, or future governments to be able to make carrying an ID card mandatory when in public, and for police - or anyone else - to demand to be able to see it. That situation is often derided as a Nazi Germany "papers please" police state. The idea of needing a permission slip from a state authority to breathe the pure English air is a line the majority of people would absolutely not want to cross at this point in time.
The secret services aren't something that most people think about. We don't typically worry about being mistakenly or maliciously classified as an enemy of the state. Unlike being maliciously classified as an enemy of a local councillor, which is fairly common. Also, you can be pretty sure your secret services are doing exactly the same things as ours, irrespective of what your law or constitution says.
(* Physical ID cards are a bit old fashioned though. We're planning on replacing physical driving licenses, non-citizen residence permits, etc. with digital versions. I suspect we'll end up with a national digital identity system by default without ever having a physical ID card. Some people are worried that will lead to another Windrush situation, however.)
[0] https://en.wikipedia.org/wiki/List_of_national_identity_card...
I think that’s a little hyperbolic, the U.K. and US certainly have large surveillance states built in secret out of the public eye and public scrutiny. But China is on a completely different level, if you don’t think that’s true, then research the prevalent use of facial recognition, and the extreme forms of surveillance applied to minority populations like Uighurs. Everything in the U.K. pales in comparison.
Before you bring up the topic of CCTV and facial recognition trials, almost all CCTV in the U.K. is privately owned and inaccessible to the state without a warrant. It certainly isn’t networked into some super surveillance hub. And the facial recognition trials have been a complete farce, more a demonstration of police incompetence, than state surveillance.
[0] https://www.cnbc.com/2021/09/23/ant-group-to-share-consumer-...
I don't think that's quite accurate; I think it's true that the state can't compel access without a warrant, but in general shopkeepers quite like policemen, and will share their footage vountarily.
You mean like the IRS?
American here. Not having national ID is stupid. The government has an interest in knowing who it's citizens are.
It doesn't have a legitimate interest in knowing where I am at all times, however.
You can avoid both by only accept payments in the form of cash and bank transfers without a proper payroll. Legally dubious, but there are people out there who actually do this.
> The government has an interest in knowing who it's citizens are.
The government has an interest in many things. Doesn’t necessarily mean that individuals share that interest and should capitulate. Personally I don’t think mandatory government ID is a requirement for a well run civilisation. Interestingly Norways Bank ID is an example of how you solve the issue of ID without making it mandatory (Norway doesn’t have a compulsory National ID and only got a National ID last year), and banks in the U.K. are experimenting with something similar built on top of Open Banking.
Ultimately it’s down to the individual (in my view) to decide how much info they give to their government. But equally a government can request that info in exchange for government services, assuming that info is needed to provide that service.
Well there's the issue, isn't it? The government has to know your identity unless you're committing a crime.
> The government has an interest in many things. Doesn’t necessarily mean that individuals share that interest and should capitulate.
This isn't an argument against the government knowing who its citizens are.
> Ultimately it’s down to the individual (in my view) to decide how much info they give to their government. But equally a government can request that info in exchange for government services, assuming that info is needed to provide that service.
Why should we be providing any service to anybody without having any information about them? So one person can show up and collect the same benefits 10x at the expense of everyone else?
At a BARE MINIMUM the government has to know your identity to determine your eligiblity to vote and to levy taxes. And both of those are so fundamental and important that I don't see how you can possibly argue that "shadow citizenry" is acceptable.
Depends how much you earn. Below a threshold it’s entirely legal to earn income and report nothing to HMRC. Taking the stance that anyone not reporting to HMRC is tax-evading would turn the whole idea of due-process and “innocent until prove that guilty” on its head. The government should be forced to substantiate its accusations with evidence, and a lack of any record is not evidence of a crime.
> > The government has an interest in many things. Doesn’t necessarily mean that individuals share that interest and should capitulate. > This isn't an argument against the government knowing who its citizens are.
Isn’t it? Governments should exist to serve their citizens, not the opposite (at least in a democracy). If a population don’t want their government to know who they are, that their prerogative. Nothing inherently gives a government a right to know who it’s citizens are, it might be useful and even necessary to provide certain services, but it’s for the people to decide what the trade off is, not government.
> Why should we be providing any service to anybody without having any information about them?
Yeah, that’s like my entire point. The other side of that coin is “why should citizens provide any information to government with they don’t want to use their services?”.
> So one person can show up and collect the same benefits 10x at the expense of everyone else?
Don’t know how you got to this conclusion. It totally reasonable for a government to make access to benefits dependent on providing basic identity information to prevent abuse. But if someone doesn’t want to access benefits, then why should they need hand over identity information? Equally if those benefits can be provided with collecting the information, then why should it be handed over? I should need to hand over my ID so an NHS doctor can fix my broken leg.
> At a BARE MINIMUM the government has to know your identity to determine your eligiblity to vote and to levy taxes. And both of those are so fundamental and important that I don't see how you can possibly argue that "shadow citizenry" is acceptable.
Sure, but if you don’t want to vote, or earn above the tax free allowance, then why should you need to identify yourself? And even if you do identify yourself, why should that process be centralised. Each organ of a government can figure out what they need to perform their function, and only request that data. Just because you want to vote, doesn’t mean the HMRC and the Home Office should automatically know who you are.
So yes the UK government might not have your adress in a register, but they know where you sleep, go to work, with whom you talk etc..
Lets not even talk about the extensive spying by the 5 eyes.
So unless you think there’s some great grocers government surveillance network (there isn’t, I’ve actually asked), then the government has no idea what your doing. To find out they would need to send a police officer with a warrant to every shop in the country to request the footage. Even then the footage is mostly crap (again I’ve actually seen what the police collect for investigations).
To claim that the mere existence of a camera indicates a surveillance network is just intellectual dishonesty. No one would ever claim that very laptop camera is monitored by the government, but apparently supermarket cameras are?
I would say ignoring the fact that the US and UK have set up and are running (well the UK is really just tagging along) in the biggest worldwide surveillance operation on the planet is the intellectual dishonesty.
Also I never said that the existence of a camera indicates surveillance, that's a straw man. However, the existence of automatic licence plate tracking is definitely an indication of surveillance. The wikipedia article on UK mass surveillance is quite enlightening.
https://en.wikipedia.org/wiki/Mass_surveillance_in_the_Unite...
I can tell you with some confidence that U.K. CCTV infrastructure, both state run and private, is a complete joke, and almost completely useless. Try giving an officer CCTV footage of a bike being stolen, and you’ll quickly discover how useless it is.
Speak for yourself. The anti-ID faction is basically hysterically scared of the idea of 'papers, please'. That's it, and that's why there is a specific statutory defence to not carrying your drivers licence while driving (the HORT1 'producer'), which itself has been made irrelevant by the fact that the PNC has access to the DVLA driver file database.
We need, as a society, an ID document. In the UK, we end up making it up through the use of a passport/DL and a combination of various other official letters. Young adults end up carrying their passports just so they can prove their age to go drinking - do you not see that this is a problem?
While I share concerns re biometrics etc, the idea that an ID card is somehow anti-democratic is ridiculous and, frankly, far fetched.
>At least in the U.K. there are clear and simple guidelines for undoing the damage caused by identity theft. If a bank account or loan was opened in your name, the bank has to close it and write off any losses, and they should compensate you for the trouble.
Which is fine for the consumer, if not a considerable amount of hassle, but is also the source of much financial loss. Fraud, in the UK, takes place on an industrial scale.
I don't think anyone invoked the spectre of 'democracy'.
A common fear of ID cards is that, once everyone is supposed to own one, some government comes along and decrees that you must carry one at all times. Then the police are given powers to arrest anyone not carrying ID; and finally, to stop and search anyone on the suspicion that they are not carrying ID.
Those fears are not "hysterical".
Also: the novel 1981 was written about a future UK.
And can you point towards a European country that isn't in the grip of a totalitarian state where this currently happens?
It's typical British exceptionalism, like unarmed police and Brexit. We'll massively inconvenience ourselves out of principle, while sensible populations look on in bemusement.
>Also: the novel 1981 was written about a future UK.
I'll assume that you mean 1984, which is fiction. Orwell, after all, was English and you would expect him to write political allegories based here.
Odd thing to get worked up about. Not sure why you link brining guns into a potential heated situation is gonna make it any better. Most police offers don’t even want to carry a gun, I certainly don’t want police officers carrying a gun.
That got nothing to do with exceptionalism, I just think a police officers primary responsibility is to their community. We should rate them based on their ability to prevent crime through community relationships and diplomacy, not on their ability to rapidly deliver lethal amounts of lead into a situation.
We should stand up for our principles, and try and build a society to thats a fair and equal as possible, regardless of an individual quirks and differences. We shouldn’t be aiming to create a uniform society just because it economically more efficient, and removes the need for the majority to think about the needs of the minority.
> And can you point towards a European country that isn't in the grip of a totalitarian state where this currently happens?
No, but there are several European countries that are essentially totalitarian at the moment; and there are several European countries that are not currently totalitarian, that have required people to carry ID on pain of arrest during my memory. It's a reasonable fear.
Austria and Germany currently follow such a policy, strictly for the duration of the emergency of course.
A voluntary national ID could be useful, something that effectively the same as a driving licence, but available to all U.K. residents without cost. Not sure I agree we _need_ it, existing documents work surprisingly well.
> Young adults end up carrying their passports just so they can prove their age to go drinking - do you not see that this is a problem?
They can get a provisional driving licence instead, it cheaper than a passport. There’s also no requirement to use an in-date passport. Bars and pubs will happy accept an expired passport with it corner snipped, as long as the photo is recognisable.
> idea that an ID card is somehow anti-democratic is ridiculous and, frankly, far fetched.
I never made this claim. Democracies are just as capable of committing atrocities as totalitarian states, they just tend to do less frequently and with better PR. I personally think people should think seriously about who they hand their identity data too, examine what benefits it might provide, but also consider how it could be abused in the future. I like the fact that most databases in the U.K. are difficult to integrate because there’s no clear single identifier for a person, joining data requires a degree of fuzzy matching and creates opportunities to challenge government agencies.
> Fraud, in the UK, takes place on an industrial scale.
I’m well aware of the scale of fraud in the U.K., I’ve spent years developing systems to prevent it, and run full on into the issues caused by a lack of national ID. However I still believe the trade-off is worth it. I’ve seen to many examples private organisations effectively running a shadow judicial system that can prevent and individual from accessing essentials societal services, like banking, with no oversight or appeals process. A national ID would just make it easier to build these systems, and innocent people who get caught up will pay the price (for a fraudster, getting caught is just the cost of business, they go in with their eyes wide open).
The ultimate goal of society is not to produce the most efficient economic system. There are trade-offs to be made, and achieving zero fraud is far more problematic that having some fraud.
Not really. A passport is expensive, a drivers licence isn't supposed to be a photo ID card and someone shouldn't have to pretend to be a driver in order to obtain one.
>They can get a provisional driving licence instead, it cheaper than a passport. There’s also no requirement to use an in-date passport. Bars and pubs will happy accept an expired passport with it corner snipped, as long as the photo is recognisable.
Some bars might. Others may not. In any case, you've still got to a passport in the first place, so that doesn't remove the renewal cost or the initial cost. It's also a multi-page book.
If we're going to run a provisional DL as a de-facto ID card, why not just have an ID card?
>I’ve seen to many examples private organisations effectively running a shadow judicial system that can prevent and individual from accessing essentials societal services, like banking, with no oversight or appeals process. A national ID would just make it easier to build these systems
If you're verifying someone's ID at all then those issues are going to exist. That's not a problem with having an ID card, that's a systems problem - if you use a DL, there's a URN. If you use a passport, there's a URN.
Not having a national ID card is, frankly, Stone Age. If you want to avoid the spectre of Papiere, Bitte then that is a legislative problem and not a technical one.
Pretty much every bar does. I know this because I have several friends that used expired passports for years without issue. It’s also frequently done be foreign students, because most bar staff don’t recognise any form of foreign ID except a passport. So there’s no need to ever renew the passport.
> It's also a multi-page book.
So what? It no more difficult to carry than a small wallet or purse.
> If we're going to run a provisional DL as a de-facto ID card, why not just have an ID card?
Because the DVLA don’t want it to be an ID because it’s a pain in the arse for them. Which is good, because they go out of their way to make accessing the data difficult for any reason that isn’t driving related. Creates a nice little natural firewall against abuse.
> If you're verifying someone's ID at all then those issues are going to exist. That's not a problem with having an ID card, that's a systems problem - if you use a DL, there's a URN. If you use a passport, there's a URN.
The URNs change on each renewal or replacement, strictly limiting how long they can be used to track an individual. Additionally people can choose which document they use with each entity, and make it harder for different entities to match their IDs.
> Not having a national ID card is, frankly, Stone Age. If you want to avoid the spectre of Papiere, Bitte then that is a legislative problem and not a technical one.
Yes it is, just like paper voting. Thats a good thing, it shouldn’t be easy for future governments or corporations to track individuals without their consent.
With regards to Papiere, Bitte legislation solves nothing. It can easily be changed at a whim, our executive government almost always has a majority in the legislative house, make it trivial for them to amend legislation on whim as it suite them. Surely your not blind? You must have seen the numerous abuses of this powers from Boris’s Tory government over the past year. Just look at anything Priti Patel has worked on.
Throwing away natural defences against abuse for convenience is stupid and short sighted. There are plenty of innovative ways of working within our current ID system, while still offering a high level of convenience, without making it easy to abuse the data. Just look at any recent neo-bank to find half a dozen examples.
This is exactly it. The abscence of a universally accepted identity creates an unregulated shadow system instead.
The European countries with stronger and more developed identity systems also tend to have stronger data protection laws, precisely because universally accepted identity data can be regulated.
>In the U.K. at least, two World Wars have taught us to be wary of central government databases.
Well really it is a little more than a sort of Driving License. We might get away with it by calling it EuroClub Express.
No, it is the US and the UK which is a bit unusual in the way it handles government ID.
A functioning democratic government needs to know who is a citizen and who is not, in order to guarantee their citizen's rights. It may be a right to education, owning property and if not anything else then at least the basic right to vote.
All this require identity. You can not show up at the doorstep of the UK and demand a pension or unemployment benefits. You need to identify as a citizen with the right to this. You can not show up at the bank and demand money from an arbitrary account. You need to identify as the legitimate owner.
> We’ve seen how they can be abused people in power seeking to persecute part of a population
That's not it. All this information is available in government databases. It must be, and it is. It's just the identification that's handled differently in a select few countries.
It's not as if these countries have stronger data protection laws, to explain the weaker forms of identification. In fact, you'd be forgiven to think it is the other way around. Somehow it is only society itself which should use weak forms of identification, the same objections are not raised against certificates and two factor authentication by banks.
Having spend some time in one of the mentioned countries a number of years ago, my impression was that it is mostly a matter that this is a symbolic question of having a strong government. Contrary to popular belief, there are influential forces that desires an ineffective government, to bolster political ideas about the economy. Nowhere is this more obvious than in identification and taxation, perhaps the two most important mechanism of a modern Western democracy. This is probably not a coincidence.
Citizenship is not the point.
I am not a Norwegian citizen. But I still participate in the national ID system.
It's not ID, it's proof of address, separate from proving identity afaik. Mtgox wanted to see ID, but because my ID doesn't say my address they also needed some somewhat official letter addressed to me on this address.
Oh this is genius! Why aren't others doing it? My guess is that Banks have no incentive to do so? After all Auth and validated personal information is not their business anyway?
I'm imagining a lawyer for the injured person hearing they resorted to fabricating evidence, lawyer looking sad or irritated, and telling the person there's nothing the lawyer can do for them now. At least not on the original problem, though now the person might have an additional problem.
I get hit hard by anti-fraud systems.
If I budget 1-2h for any given online purchase, I have <50% success rate with Paypal and ~75% with Stripe. If I contact the bank and merchant, the issue is always with the payment processor. Trying to resolve through the payment processor goes nowhere. The only thing that can work is try again with another of my 6 legit cards (mix of visa/Mac debit/credit) and if I’m lucky it goes through. Sometimes the next day; I guess some cool down is in place.
This feels like discrimination or xenophobia with extra steps. If you’re international enough and have some bad luck, the systems will perceive you just like a scammer and will deny you service or require hours of intervention because of things like your name, location history, and nationality. (For those who haven’t noticed, sometimes PayPal will arbitrarily require you to create an account in order to complete a single payment. Nationality is required information in this step)
If it’s not something I really want provided only by a single seller, I will nowadays abort at merchants only accepting PayPal, and at the first failure of Stripe. It’s not worth the headache.
> Most Afghans have no surname; it is also common to have no surname in Bhutan, Indonesia, Myanmar, and the south of India.
They cannot handle patronyms, and for many people every local document (except passport and tax card) uses initials, for example. The problem is that the bank account name has initials (in many places for many people) which does not match your name.
My friend had an issue with Wise because they wanted the name to match that is on the passport, which was fine because it did. Then it started demanding that it matches his bank account name, which it cannot, because he has only initials there.
They are dealing with international customers. They need to understand these differences, but they do not.
Oh this is completely new to me. So they have single name?
I wish there is a documented difference in all of these so that International companies can all pay attention.
https://www.kalzumeus.com/2010/06/17/falsehoods-programmers-...
Also, why do you limit to “International” companies? Don’t people from all cultures live in most every country, even in small numbers?
A large number of web sites would not let him register at all.
Here is a list: https://github.com/kdeldycke/awesome-falsehood
I never buy anything with my real name anymore.
This is the true support channel for all major corporations.
My heart sank and mind filled with questions and uncertainty.. What if AWS sues me, maybe they will settle it for half or 25%. But their customer support was more than kind to me. In every reply they assured me that I need not worry and they are working on my behalf to resolve this.
I cooperated with them in every way possible and After 16 days I finally got a reply that it was all taken care of and I owed them nothing and they didn't even suspend my account. God knows how the things would have turned out with any other hosting. I did leave them a suggestion to hard-cap the billing instead of just email alerts.
Why would they do that? Enterprise customers are just going to pay the bill, and for small customers they get a lot of good will when they make a "special exception" and don't ask you to pay for charges that someone else fraudulently racked up.
The actual cost of providing the service to the fraudsters is probably so low that they don't have a lot of incentive to prevent the fraud, as long as there is a non-zero chance that someone pays for the fraudulent charges.
gen.lib.rus.ec
Also lookup myannonymouse for audio books, have all the latest titles. Getting an account is pretty easy, they literally checks if you can read their account policy.
Offerers of online banking services take note: even if you don't mail statements to your customers, you should provide an option to generate such a statement that the customer can download as a PDF.
Even standard files on iCloud. Who knows how important the average users' cloud files are to them? (I don't use public cloud storage at all anymore because of this exact fear - what if some arbitrary billing/transaction error locks me out of everything without recourse?).
To be fair I've no idea what the person in question got their account locked for and if there was any shadiness involved but I doubt they'd write about it publicly (or get access restored) if there were, which implies that at any time your account and your data can be taken away for something entirely mundane.
It makes me really concerned in fact how Google would handle something similar to this - given that for Chromebook users everything (literally EVERYTHING you would normally do locally on a computer) is in/via your Google account.
Very poorly, it seems. There are a bunch of stories scattered around HN about Google not only irreversibly deleting personal accounts, but entire paid Google Apps for Business setups. A whole company gone because the admin uploaded one ripped movie to their personal Drive, for example.
Many of these did get mostly resolved after someone carefully exploited the Kevin Bacon rule to get in contact with a Google employee, who then made some noise internally. But many couldn't be even with insider help, as some deletions are (were) apparently instant and irreversible.
So. SyncThing on my phone and laptop, and an a little herd of external drives. It makes me feel like a digital prepper or something. Sigh.
Actually. I think I have just self identified as a digital prepper and I like it. Time to download my Google content.
One recent anecdote: When I used my Pixel 2 with its free original quality backup, I used motion photos for a few things. 3 years later, now, on another phone (or even the web viewer) some of these motion photos are not loading. Some of them then load on the web but have video compression artifacts (i.e.: B-frame artifacts).
I'm glad the original photos are intact from what I can tell, but this is extremely off-putting, given I was 100% in the Google ecosystem -- from hardware to account setup -- and still got burned somehow.
IMO, states should enact laws where you can take the company to court in your local county and no contract can override that right. If the termination is found justified, the company must refund all account assets at fair market value and any remaining balance. If it was not justified, the company must reinstate the account, pay all court and legal fees, and a reasonable amount of mandatory punitive damages.
Also, I don't get why Apple et al pull these stunts anyways. They already have a huge "regulate me" post it on their back.
That's not to say the current setup doesn't suck, but the solution isn't super cut-and-dried.
The thing that gets me is that Apple knows I’ve spent $10,000s with them over many years.
Even if I somehow fuck up and use a dodgy card, I’ve brought so much money into the business that they should at least assume good faith on my part.
I understand cutting relatively new accounts off permanently for abuse but this no-recourse shit for long standing accounts is bullshit.
Using a “dodgy card” ultimately is the problem.
I once sued a company in New South Wales in small claims court. It was done entirely online from the US, and if there had been a hearing, it would have been by phone. The company paid up within 24 hours of the filing.
I pretty sure (I haven’t been following too closely so it might have changed) the Act requires digital gatekeepers to provide human customer support, and provide clear explanations for moderation activity and account closure. Along with a clear appeals process.
In theory all of this should make it much easier for a normal person to appeal an account closure, and refer a company to a regulator, or sue them in court, if they fail to provide a fair appeal.
No we actually do not, and should not.
They are offering the product to the market, it is incumbent on them to fix the problem not just toss their hands up and say "Well it is too hard / expensive for us to solve so consumers just have to deal"
This is similar to my complaint over the concept of "Identity theft" no one identity is ever stolen, no companies fail to implement proper fraud controls then shift the liability to the victim to "prove" their "identity was stolen", that is the exact opposite of how the burden should work
Coming back around to the Apple situation, this is a result of allowing unconscionable contracts (aka severely one-sided and unfair) to permeate the digital goods world. The fact that Apple can terminate a contract in full, with one sided review with out having to notify the other party of the exact clause of the contract they alleged the other party violated, no recourse or notice to correct, no appeal or attempts to remedy, etc would not fly in most contract situations, the fact we allow it with "terms of service" is ridiculous
Get your credit card from a local credit union with at least one physical presence near you.
Do your own backups or contract to an independent company whose primary occupation is doing backups.
Manage your own email either directly or through an independent email provider. Buy a domain and use that for your email address to increase flexibility to move from one provider to another.
Diversify.
Anything else increases your risk of getting caught in a personal and financial wood chipper.
These account suspensions scream for regulation that forces a company to explain the suspension and offer some kind of appeal process. Otherwise I see a very dark future where super large companies kill people's livelihoods and nothing can be done.
It's striking how the guy goes out of his way to not be angry at Apple. Very interesting psychology. Stockholm syndrome or just begging the king for forgiveness?
What would getting angry accomplish?
Hmm, this sounds very familiar, like a certain political class was doing this recently.
Tech Company: At long last, we have created the Torment Nexus from classic sci-fi novel Don't Create The Torment Nexus"
What do you mean future? This is already the reality. I recall reading multiple threads here on HN in the last couple of months alone where people lost access to their Google accounts and only got it back because they happened to have a somewhat bigger following on Twitter or elsewhere. I think it's safe to assume that for each of these cases there are many others where the victims don't happen to be influential online personas and their cases just go unnoticed.
And they would have justified to themselves saying there's always recourse through customer support. But customer support tools to investigate and un-ban users would be slow and painful and lacks capabilities needed to check if the complaining user even passes the basic smell tests for a fraudster. And nobody can really explain why the model blocked the user in the first place. There's no well-lit path from CS to engineering on a case-by-case basis. Escalation would happen in bulk/batches – when lots of seemingly 'innocent' users complain to CS, CS may escalate to engineering.
Btw, the alternative of having to pick really conservative thresholds (with near-zero false-positives) causes more harm – harm that's more visible.
The slippery slope is this – over time the definition of 'trust and safety' would have been expanded to include interests of more and more stakeholders (including company's own business interests) – it is very easy to lose sight of serving the user (who may not be the paying customer).
Every public corporation only serves its shareholders. If they annoy enough of the users and the shareholders take notice when it hits the bottom line maybe then something will be done.
There are always tradeoffs to be made, we will always mistakes (hopefully rarely), and 99% of the time the people behind the curtain are trying very hard to reduce harm for the good actors.
Years working in corporate and I am yet to see people who are “serving shareholders” and “squeezing customers”.
There are strategies that fail, and sometimes there are people who maximize personal gains at all cost. Exact same way as for any other kind of organization.
Big problem is scale. Cost of mistake and collateral damages for big org will always be higher and more impactful due to size. 0.1% of customers for Amazon is 300 people.
A healthy coorporation has these aligned: serving customers well, treating workers well results in shareholder value.
You can have 99% of customers are happy even if 1% are quietly given food poisoning and die, which is why we have laws to protect that 1%.
Or, to stay in your analogy: striving to make a food that is 100% safe for 100% of the people will result in bland, poor food. It's fine to use gluten in your bread, or peanuts in your sause, even if x% of potential customers will get sick and can die, if they eat it. Fire those customers. Be clear: this is not for you. It makes the other customers happier. And consequently your stakeholders happier.
> And they would have justified to themselves saying there's always recourse through customer support. But customer support tools to investigate and un-ban users would be slow and painful and lacks capabilities needed to check if the complaining user even passes the basic smell tests for a fraudster. And nobody can really explain why the model blocked the user in the first place. There's no well-lit path from CS to engineering on a case-by-case basis. Escalation would happen in bulk/batches – when lots of seemingly 'innocent' users complain to CS, CS may escalate to engineering.
Can such a model be trained effectively if isolated reports of false positives are rejected without meaningful investigation? In that case, wouldn't the model be trained with bad data?
What if for each reported false positive there are more users affected who didn't report it (because their accounts were less valuable, because their time was more valuable, because they were too upset, because they were too timid, because they died (for unrelated reasons), etc)?
No, and much like YouTube auto terminating accounts with 10 years of content there is absolutely no excuse for certain very obvious cases to be handled without human interaction. There absolutely must be flags that stop terminations without a human.
These are the richest companies in our country, and print money hand over fist. That they sell online life services like photo, storage, music, etc should require them to provide actual, human support.
I find it really sad they even have to be forced into it. How much could it possibly cost to hire a few hundred 'filterers' that triage out the tech support, and a smaller team of people who look into real issues?
Amazon and Walmart do it, and still both make tons of money. So what's the downside here?
It’d follow logically that if your photos (or whatever) are valuable to you, you wouldn’t punt sole responsibility of their perpetual storage to third parties. Understand instead that the storage services they offer are voluntary, conditional and subject to loss due to error, negligence or even maliciousness (the latter of which rarely serves business interests).
Apple should obviously do better here — assuming this story is indeed accurate - but introducing legislation here seems like a leap.
Understandable. But I'm of the opinion that companies like Google and Apple more or less offer these services and advertise them as one stop shops for you, forever. And in many cases, mine included, I pay for it. That I make an offcolor comment on Youtube or get a chargeback against the Google store shouldn't lead to a complete blackout to said photos, in my opinion.
They should be subject to consumer protection law.
Apple was forced in Australia by the ACCC (our consumer protection regulator) to provide proper warranties and repair/replacement/refund protection, as specified by the law.
I see no reason why they shouldn't be "governmentally coerced into having dedicated support staff" to support their compliance with the law.
I’d agree that there’s too tight a coupling between account access and access to purchased media, but it’s unclear that government intervention is needed to mitigate that. At the very least it’d be useful to know the frequency at which this kind of thing happens before making a judgment call on it.
Why is that? Is there a number like 1 in 1000 where is acceptable for Big corporation to screw people and "steal" their accounts? Think about average Joe story that does not appear in news-papers and HN. Laws seem very obvious here, if you want to close a customer account you need to do some minimum stuff:
1 tell the customer what they did wrong, in the same way if you would show to a judge the evidence that this customer did X and X is illegal or against the TOS you show the customer what he did wrong. I understand that this might make your giant corporations anti-spam/anti-fraud job harder but we don't want to optimize for lazy developers and lazy corporations.
2 Offer the customer a simple way to download his account data
3 If the customer bought media and games you have to either refund the customer or find a way to transfer the media to the customer. You would say that this is a hard problem, the answer is again let's not optimize for making things easy for super rich corporation and super hard for regular people. Maybe some innovation would come out of this , like maybe some kind of way where I can buy a book or game and I can sell/donate it like any physical object I buy.
The issue is that now people are excusing that is would be hard for super rich company to do a decent job so is OK if they do a terrible job as long as I, the HN reader don't care about the poor guys affected.
Also from what I noticed from YouTube it seems that simple obvious solutions are not even explored, you treat a 10 years old account with a good reputation the same as a 1 day old account, are all the developers working on ad targeting and polishing the next version of some shit framework? Is there any Google product that you were impressed by their overall quality?
They are effectively stealing - by accident obviously. But once that happens and they give you know recourse - there is intent that mistakes on their part won't be fixed.
What would the laws protected against?
As technology evolves it becomes increasingly easy to invade deeper and deeper into once private spaces. Such as someone's rooms. Someone's now electronically light and replica-table collection of externalized documents and memories; maybe within our lifetimes even within their minds.
The TIO has teeth and almost always sides with the customer, and they make sure that the fine exceeds any benefit that the telco might be gaining through the bad behaviour that resulted in the complaint. Unofficially, I heard that the fines for any valid customer complaint start at $7500 and go up from there rapidly.
Something similar may be needed. A mega-IT-corp-ombudsman, with powers to fine corporations providing services to the public in proportion to their annual revenues or current market cap.
Point is, even if TIO sides with the telco (unlikely, they encourage both parties to find a middle ground as they are consumer first oriented) on a case where it takes for example 10 days (again, unlikely) to resolve; the margin[1] on a residential NBN service with a budget provider like TPG has already evaporated and that’s without considering costs of having TIO liaison staff, etc.
It’s a good model because it encourages the telco to resolve the complaint properly and in the customers favour before the problem can make it to TIO as once it gets to them, it always costs the telco money. Provider is better off wearing $100 cost to resolve than have the complaint spend 3 days with TIO level 1, taking up time and resources whilst also becoming a publicised negative statistic (TIO regularly publish report outlining telco performance from a number of complaints perspective).
I think your suggestion is a good one. Just adding this detail because I think it’s important to note that the model is actually about encouraging better complaint handling and customer service than just being about fines and punishment.
[1] assuming 12 month term on approx $65/m service but I am speaking in broad terms
IANAL, but doesn’t contract law already cover this? Apple terminated the contract one sided. They are allowed to do so, but only by acting in good faith and fair dealing. That they were willing to let this person open a new account (new contract) but not willing to reinstate the existing contract and also unwilling to explain how this person could avoid a similar punishment seems to indicate at least a lack of fair dealing.
The ABA has this to say: In general, the duty of good faith and fair dealing means, for example, that parties cannot evade the spirit of the bargain, lack diligence or slack off, perform incorrectly on purpose, abuse their power when specifying the terms of a contract, or interfere with or fail to cooperate in the other party’s performance.
I wonder if this person had took apple to small claims court instead of trying to navigate apple’s kangaroo court system what the outcome would have been.
(link in german)
https://www.verbraucherzentrale.de/musterbriefe/digitale-wel...
These days vogons are banks, SV giants, social media...
The striking antipattern (to me) is where official channels are a brick wall. Everyone insists that no other channels exist. Meanwhile, if you ask friends or read blogs, all actual resolutions seems to come exclusively from inside contacts, personal favours, being famous or such.
Paypal broke up with me circa 2010.
> You may not use the Services to: - post a dishonest, abusive, harmful, misleading, or bad-faith rating or review, or a rating or review that is irrelevant to the Content being reviewed
To me it seems like those rules could ban you for just about any reason. I mean, what is even a "bad faith" review? Do you need to assume good faith on the company if you had a bad experience?
> Apple further reserves the right to modify, suspend, or discontinue the Services (or any part or Content thereof) at any time with or without notice to you, and Apple will not be liable to you or to any third party should it exercise such rights.
In this context it basically means posting a rating or review which doesn’t match your actual opinion. For example, crowd-sourced vote brigading (where you don’t have an opinion at all but are just voting in the way someone else told you to vote). Similarly, reviews along the lines of “This app only deserves four stars, but currently it has an average five star rating so I’m going to give it a one star review to try to bump the average rating down toward what I think the average should actually be” would be reviewing in bad faith.
I think the best solution would just to block the relevant capabilities related to the ban rather than deleting the whole account based on some strange activities. Why doesn't companies do this?
2) Notice group of humans costs money
3) Replace group of humans with shitty ML/AI/Neural Net/XML/Blockchain
The word I would pickout as the most ambiguous is "harmful"... harmful to whom?
Even if you lose, there aren’t any downsides and Apple would have to send an employee to participate. I would absolutely do it if I ended up in the same position.
I hate to advocate for more laws and regulations, but these companies have gotten too big to operate without oversight. Losing your ability to log into Netflix would be a bummer, but losing your ability to access your work files, medical records and everything else you need to live your life (eg: Google Drive, Apple iCloud) is just too big of an impact on a persons life to happen without transparency.
But cases like this where the customer actually pays real money for and has accounted assets in Apple's system this is absolutely inexcusable. No face-to-face business could do this or they would be sued to extinction even in the lesser litigious countries.
But really what do they have? They rented something and now they lost access. If they had physical media on CD, DVD, or even stored locally as a stand-alone file that would be different.
Yes I'd be enraged but people have feared for years subscriptions and no physical media lead to this. Games and music have gone from disks, CDs, DVDs, to subscriptions. Today it's become so bad that even physical devices are now seen as owned by its manufacturer and you're not permitted to repair it or even open it to look, if you can mange to open your device.
“Balance” basically means that if you’re going to set up a business that can “easily” take money from millions of people or “easily” create millions of accounts, then you must ensure those people can “easily” reach you, “easily” inquire about status, “easily” cancel things, etc. What we have now is just absurd.
We have become so helpless that AI/ML takes decisions for us. We have put those AI in place, yet we behave as it they have taken over the world and once they have deemed you in the wrong, there's nothing you can do.
Why are we tech people not protesting over this? Everybody is quick to take Apple's side in this thread, or Amazon or Google in others. I don't get it.
Governments fail at being flexible. What they have in Australia for instance allows consumers to abuse the hell out of business driving up costs for legitimate customers.
It needs something more like a Better Business Bureau who can examine both sides, but without a way to accurately verify a consumer is trustworthy it gets shady. Few people want to be tied to a realID so we are stuck with this mess.
Yet people keep parroting the "malicious users are the problem" party line. Please tell me, which tech companies were brought down because of customer service abuse?
Here's what's going on. Having real humans not even making decisions, but reviewing false positives costs money, and the company justifies it by saying it's to prevent abuse from malicious actors. But it is simply a cost saving decision. So, again, I ask why are we quick to defend the company when they could afford to do better by us. Is the entire tech community suffering from Stockholm Syndrome?
Apple, Amazon and Google have good margins, but I would hardly say they could afford to do better. Human hours are incredibly expensive and the number of people attempting to get something for nothing often exceeds the number of people with legitimate complaints. I have run across whole farms of people who found some cheap online job reading off scripts trying to rip off large companies and any knowledge they get about bans they change the scripts for all.
It is has become a hostile relationship unfortunately and it is not due to companies not trying. I have seen for Apple at least they sometimes have people show up in person with lots of documentation and identification at stores and you legitimately cannot tell the scammers from the people who think it should just not be their problem.
I am not trying to justify that they fail. They often clearly do. It is just not an easy problem, especially with the amount of anger and frustration involved.
As the sibling poster suggested, I'm tied to the Adobe suite and C4D. And not about to run Windows.
I do like Apple's hardware. It's a luxury brand but hey, it's my daily driver and it's a tax write-off.
Yeah, no, that's when I start self-hosting my partner.
It is rare, but it can happen. Another threat vector.
After that I moved to hosted Mail (yahoo, then gmail) as I felt it was more reliable. Now I ensure I have more than one email on file if possible with any account. Same with phone numbers.
Imagine that. "oh you broke the TOS, now all your apple devices are bricks"
I’ve been using the same Apple ID for a decade or more. I’ve purchased thousands of dollars worth of apps and content, and probably tens of thousands worth of Apple devices in the last twenty years.
The initial chat support experience was the same as OP: (paraphrasing) “No, we can’t tell you what happened. No, you have no recourse.”
Even when I asked to escalate to their management, I was told that they would have no additional tools to assist me.
My initial shock and outrage was palpable. I managed to get in touch with a Senior Rep who is looking into my case and is scheduled to call me back on 12/9.
My only theory for why my account was banned is that on 12/2 (the day before the ban) I made a purchase using a gift card on apple.com. The gift card was a promo from another device purchase I made on 11/26 (Black Friday). I had both devices shipped to my parent’s house (a different address from my billing address), and so maybe some fraud detection kicked in due to the purchases being so close together, using a gift card, and sent to some other address?
I’ll update once the senior rep gets back in touch on Thursday, but in the meantime I’ve already started drafting my letter to Tim Cook.
I’m happy to have had my problem resolved, but I’m more convinced than ever I need to have offline access to all my digital life’s contents going forward.
We're still in the early days of such a digital-provider-dependent lifestyle, and it seems the legal system hasn't yet reacted yet. The closest equivalent is how US Phone companies do have a "duty to connect the call,", specifically in legal response to the unilateral power they (used to) have. Unfortunately, that's led to the current (US) problem with spam/scam calls & text, because though they have a duty to deliver, they don't have a duty to authenticate.
The user seems to have run afoul of Apple's fraud detection systems, hence the "cold shoulder" response (you don't want to give fraudsters a clue on how to dodge the ban-hammer next time, and you don't want them to DoS your support lines). After all, we only have the user's (carefully constructed) story to go on. At the scale Apple/etc operate at, fraud is a huge, difficult problem. I expect the companies tune their processes in favor of the fraudsters, because bad press like OP's story probably does them way more damage than a few hundred/thousand fraudsters.
No, I don't have a pithy solution for solving either problem, though I do expect legislation to eventually catch up to give legal recourse for users. I guess the cost of fielding such legal recourse will just be added to "the cost of doing business" by these companies, and that cost will somehow trickle down to users. At the very least expect much harder sign-up procedures once that legislation is enacted, and maybe more regular "are you a real user" annoying checks on the users.
Loosing my Apple account would still be a terrible blow. So many more or less essential services are app only these days. Financial services increasingly rely on phone Apps for authentication. Even some government services require a phone with NFC to use your digital id online. Many daily conveniences like cabs, car and bike rentals and the like are not usable without apps.
I think it's time legislators thought about this problem more thoroughly. Just creating a new account is not an acceptable solution in my opinion.
This is one of those situations where the power imbalance is so extreme that some sort of regulation is probably appropriate, but heavens knows I have no idea what it looks like.
And before "there aren't any other options" for goodness sake this is HN. Go build your own environment on private silicon and buy a different brand of thing.
Great that it was sorted for you, but there are dozens who aren't so lucky.
I'm pretty happy with the transition to CalyxOS. Everything works as before, but I can now limit internet access to apps, and there is a much more consumer friendly view of permissions. Not tying the whole phone to system-level user with google services feels great. Specifics that need it still gets it, like YouTube.
Anyway, there are already some laws about this kind of disabling accounts, but there needs to be a better solution for recourse for people who wrongly have their account disabled. Perhaps mandating manual reviews upon request that must state explicitly how the terms of service were violated would be a good step. And perhaps there is a market for lawyers or legal experts to persue and resolve these cases.
Unfortunately those systems aren’t perfect …
My girlfriend once had to replace all of her bank accounts because of something like this. Did a thing while traveling abroad, looked like credit card theft, everything got shut down. oops
If my bank left me high and dry in a foreign country I would absolutely cut ties.
I've done enough international travel that I maintain redundant checking accounts for just such a situation, but there are plenty of people out there that keep all of their accounts in a single place...
Automated systems will never be perfect but there are companies that have policies that are far more respectful of their customers than others.
If you get detected for fraud or did a chargeback on steam, you will be issued a trade ban and a ban on buying games and activating game codes, but valve does NOT take away your ability to download and play the games you already own and legitimately bought in the past. Heck, in the case of chargebacks they can be quite lenient : it can be a temporary restriction on buying that is lifted after a few months (but with a permanent ban on the specific visa card).
If you do something wrong with the community features, your account will become a restricted account and you will not be able to use them anymore, but you will still be able to play your games too.
They also have an actually active online customer support service that help you regain control of your account if there was a fault on their part or something else, like someone hacking your account, and it doesn't require an obscure method like mailing some gabenewell@valve.something to get things done.
What Apple and Google does with their account system should be illegal. It's asinine that society would accept that one could lose thousands of $ of software and media bought because for reason X or Y they banned your account.
Valve can do very granular account restrictions, there's no reason why the wealthiest companies in the world can't.
And this is why I have a humongous library of games on steam and will never spend a single $ on Google Play or the App Store. Concentrating all sorts of digital purchases onto a single point of failure in the hands of companies that treat you like garbage? I think not.
Instead people are trading similar anecdotes, offering ML apologetics, etc. It’s tragic to watch the personal empowerment of personal computing fade away into oblivion like this.
And I think the answer is simply it is not, at least not in Europe. I suspect the companies just do what they can get away with and what's cheapest to implement. When challenged in court they won't have much luck with this, but that puts the burden on the consumer.
There was a recent court case in Germany about YouTube banning a video based on its terms of service, without explaining what exactly was violated. The court ruled YouTube would need to explain what exactly the user did wrong. And that was a case just about publishing a video for free, not blocking an account that's worth hundreds of euro.
I think there should be a law organizing how big companies need to deal with high value (to the user) customer accounts.
Unilaterally taking away hundreds of euros, irreplacable memories, etc., then putting the burden on individual users to sue, seems very lopsided.
I would like the provider to be required to specify in detail what the consumer did and how those actions violated the TOS. No blaming an algorithm or being vague. A specific action and what was wrong with that action. The BS about needing secrecy for security are just attempts not to get sued.
An internet user bill or rights might not be out of line given the power disparity. At least some lawmaker's staff going through the major TOSes and writing a law to ban some of the egregious clauses.
"No company can disable a user account without explaining clearly what they did wrong and allowing them to appeal to an independent review group within the company"
Its not right they can just disable something you paid hundreds or thousands of dollars for.
https://au.pcmag.com/old-hosted-email-providers/87012/not-ev...
> YOU AGREE THAT YOU SHALL NOT SUE OR RECOVER ANY DAMAGES FROM APPLE, ITS DIRECTORS, OFFICERS, EMPLOYEES, AFFILIATES, AGENTS, CONTRACTORS, AND LICENSORS AS A RESULT OF ITS DECISION TO REMOVE OR REFUSE TO PROCESS ANY INFORMATION OR CONTENT, TO WARN YOU, TO SUSPEND OR TERMINATE YOUR ACCESS TO THE SERVICES, OR TO TAKE ANY OTHER ACTION DURING THE INVESTIGATION OF A SUSPECTED VIOLATION OR AS A RESULT OF APPLE'S CONCLUSION THAT A VIOLATION OF THIS AGREEMENT HAS OCCURRED.
I'm left scratching my head as to what the reason(s) were for this to have happened and can only think of 3 possibilities.
- An overzealous, newbie type operator that suspended me by mistake - Some kind of error in automated flagging and error in review - eBay's radical way of engaging with me to spur me to buy/sell again as the account's last activity was more than 1 year ago
Just to give an example: I was using my iPad Pro as a second screen (primary screen is a 4k monitor) to see my terminal below the monitor. Apple calls this Sidekick. After an update of my iPad to iPadOS 15.x this technology does not work reliably. The iPad screen freezes and I need to stop sidekick and start it again. This works for a couple of minutes until iPad screen freezes again.
So I called Apple support, waited half an hour to get someone who tries to help me. Finally they suggest I should go to an Apple store. No, I am not going to an Apple store to get a fix for a trivial problem.
There are many users who have experienced this very problem and written about it, even on Apple support forums (which are the worst: written for idiots, no real help). All you get to hear is: Reset your device(s). Or: It must be a problem of third party software, etc.
I used to use an app for this feature called Duet. Whenever I had a problem, I could reach out to the devs, they would give me very specific instructions for how to solve the problem. Now you could say Apple is too large to give this kind of help. But they have a large database of all incoming issues, so they know exactly that 20000 other users are complaining about this issue, and some egineer might have solved it, so why not give specific instructions on the forum, why these super vage tips that are of no help!?
So prey to god you won‘t have real issues where you rely on Apple to solve it.
Edit: Another example: I regularly have issues with iCloud sync. Sometimes I realize that it was stuck because I need to access a document on the go just to realize my Mac could not sync it to iCloud. iCloud-sync issues are so common you can find thousands of entries on the web about this, also on Apple support forums. But neither will you find helpful answers, or any instructions from Apple how to mitigate.
They are horrible. I once called them to ask if "iCare+ Theft Insurance" works if my iPhone get stolen abroad and they just straight said "We don't know."
If you think about it, it really looks like a religion from the outside: the author got some random problem (account lock) then prayed to the god (emailing tim cook) and then the miracle happens (the executive team unlocked the account).
This is not a story of any sort if not an evangelization story about dealing with a fickle god.
I don't think the author is going to be thinking "wow I really dodged a bullet here, better get off this ecosystem as fast as I can" but instead they're probably going to recall the story about that time when they emailed tim cook and the miracle happened.
It makes no sense.
----
And people should also consider that with an account gone all the purchases are gone... Arbitrarily. Music is gone, software is gone, data is gone. Isn't this scary?
https://appleinsider.com/articles/20/10/15/apple-demands-tel...
As we keep discovering (this is the second one I’m reading about Apple just in the last few days), relying on any of these companies to not disable accounts and access to things that have been paid for is a dicey matter.
Only when consumer regulations get a lot stronger, mere civilians may have a better chance.
I think consumers should demand that whatever products they buy, there should be absolutely no strings attached to it that lead back to the vendor, if the consumer chooses so.
So if you buy an espresso machine, the "no strings attached" law should prevent the vendor from locking you into buying only their brand of coffee. Same with printers and ink. Same with computers and accounts.
If instead you subscribe to a service, it should be properly advertised as such, and different rules should apply.
I split my digital life and purchases between Amazon, Apple, and Google. Book purchases, occasional movie purchases, etc. I have moved on from having a massive personal library of physical books to mostly relying on digital media, eBooks and audio books. Splitting purchases between three vendors makes me feel a bit more secure.
Probably most peoples’ most precious digital asset class is their personal photos and videos. I use a very simple setup: when I am at home on wifi, my phone updates all photos and videos to Apple, Google, and Microsoft OneDrive. If I am, for example, hiking and take a dozen pictures and/or videos, then before getting home to my wifi, I review and delete what I don’t want available during my lifetime. A secondary advantage is that all three companies run automated deep learning based systems that present my own media to me in interesting ways. For most of my digital life I care about and work for privacy, except for my photos and videos where I want maximum enjoyment for myself, family, and friends. I like to create photo albums and share links with specific people - so much better than posting on social media.
EDIT: for book purchases, I also favor buying directly from publishers who provide ePub, Kindle, and PDF formats - all of which I save to all three cloud providers storage and for convenience import into one of Google’s, Apple’s, or, Amazon’s eBook readers.
I told him before I left the store he was leaving me no other option but to email Executive Relations. He kinda chuckled at that.
> So what to do? I emailed the one person I knew who worked at Apple, and I had his email address...Mr Tim Cook.
The upside: Interoperability of the products, prestige, false sense of security The downside: Everything bad about a monopoly
The solution: none. If we,people, were smart monopolies wouldn't happen in the first place. Maybe someday the government decides to split it or to suffocate it, or Apple becomes one with government and its practices become law.
Meanwhile: I don't participate of the Apple ecosystem. I am hurting myself in the prestige field.
In my view this is a form of theft and should be treated as such.
This is why the open decentralised web is important.
Alternatively make sure services do one thing and one thing only so it doesn't break other things, like purchases or access to data.
For example, it's not right that you access to the entire Google account and the stored files and emails if you let's say spammed on YouTube and got your account suspended there.
If you shared files illegally too many times on Google Drive, lock the storage in read-only and disable the ability to share (example).
And
and since 1998 have only bought actual tangible physical books with pages that turn, video games on physical disc, and movies only on VHS and DVD and BluRay. ((But yeah, I have a STEAM library. Nobody's perfect.))
I eventually had to have a friend at Google contact the Gmail team to get my account lockout sorted out.
Reading this thread on HN, I started to panic thinking about what would happen if I lost my Gmail account, and then I saw this comment! What a reason to be a loyal googler until the end of the world!
https://au.pcmag.com/old-hosted-email-providers/87012/not-ev...
If Apple goes down this path it will literally destroy the company, customer service is one of the most important competitive advantages they have.
The executive team that answered this email should be focused primarily on ensuring it never happens again as we speak.
Instead of "Buy" perhaps it should be "Purchase license" or "Acquire license". Instead of "Purchases", it should say "Licensed products/services".
I have a teeny shred of sympathy for Apple here, actually. Creating new identities is trivial (Sybil) and so adversaries would write malware and their accounts get deleted. The more info that apple gives each of the adversaries' deleted accounts, the easier it is for them to probe the logic used to catch them.
I'm sure your shred of sympathy would quickly disappear if this ever happened to you, but... as the saying goes... "pepper in someone else's eyes is a refreshment to me".
Can we get FAANG to respect their customers again?
A few lost purchases is bad but losing all your photos is the worst case scenario.
These are clear cases for better algorithmic governance systems for managing the assets. Eg. Holding the asset on a distributed block chain / ipfs.
In the meantime, commercial companies that provide subscriptions should be favored. Here the risk is contained.
Thing is, I am indeed in kind of permanent violation of ToC due to my account being US and me being in Ukraine. No problems for the last half of the decade though.
> The very next day, all my Apple devices gave the following prompt when updating apps from the App Store: “Your Account Has Been Disabled in the App Store and iTunes.”
> I called Apple Support and was advised that my account has been permanently disabled, and there is no recourse.
> I then asked what does Apple recommend I do. Apple Support representative said: “Create a new account and start from fresh”. This means I have lost all my app and media purchases and the funds in my Apple account.
> I tend NOT to blame Apple because why would they take such a drastic step.
> I am a mere civilian where we are accustomed to accepting decisions put on us and adjusting accordingly.
> So what do next? > The only option is to create a new account and move on. Start fresh with Apple.
> Three days went by, and I took delivery of a brand new MacBook Pro that I preordered before Apple disabled my account.
> After five years, I bought a Mac, but the sour taste of betrayal from Apple made it extremely difficult for me to get excited about my new workhorse…
First question would be: Is this here actually Stockholm syndrome? But let's not get into this. More importantly:
By now everybody should know that you don't "buy" things at those companies. You're not even renting them!
They can at anytime, without reason, take away everything you "bought" there. Cause it's not your property. You don't own it.
You own stuff only if you completely control the hardware and the data. That's what all those beardy open-source freaks are telling you since forever… Maybe it's time you consider they're right?
Besides the point that most customers wouldn't find such kind words for the people they scammed them and wouldn't relativize what those scammers did ("99% won't experience that…", "I don't blame Apple…", *eye roll*) the exact same thing can happen with all the other companies who are doing the same. Apple, Microsoft, Google, Amazon, etc. There's no difference. They're all the same. They own "your" devices and "your" data. So they can take it from you.
And most people won't be so lucky to "get things back" through divine intervention… So don't count on that.
I feel sorry but personally I would never "buy" something of that nature that I can not truly own/control. All my media is in format every player would understand and backed up in couple of places.
I'd rather give my money to put.io than the iTunes Store.
While laws like the DMCA exist I don’t see the point in buying a film and ripping it, as I’m breaking the law just as much as not buying it and downloading it.
Hint: it is legal
“depending on the media and your jurisdiction”
>"Your inability to read shows you up"
I did read it. "Likely broke ... law" and "depending on jurisdiction" assumes / hints to that I am in the jurisdiction and this is totally baseless. I think my answer is proper but whatever.
Don't install App Store apps on the mac. Don't use iCloud at all.
Use a per-device throwaway Apple ID to install free apps only on iOS devices. Don't buy apps or IAPs.
Disable iMessage and FaceTime.
Use a third party password manager.
This is really the only safe way.
The only option is to talk to a lawyer and try to file criminal charge against their interference with enjoinment of the things you paid for.
Also Caocao, “I would rather kill 1000 by mistake than let anyone slip through my fingers.”
It will encourage competition and only those who actually please their customers will thrive
Of course. A different kind of company, one which prioritises function over form, would blame frontenders.
Though I do like your way of thinking. Potentially, if there really is a violation (which there was not in this case, but just an example), then, in theory, the company can implement a system that allows users to still access the content, but remove interactions (e.g. in the case of fraud, remove the ability to transact, etc.). Of course, this requires resources to implement and maintain, so it's unlikely to happen.
One app that I use frequently won’t load unless it is updated (it gives you a dialog that you can’t dismiss when you start it). So now I’ve lost access to another service and my data in that service by proxy.
We absolutely need rights here, especially the right to a full and detailed proof of violation and access to human remediation and review.
There isn't a platform any large number of people use that is exempt from this.
I can think of a few. TCP/IP, email, BitTorrent, TLS, RSS.
Millions of people use Linux. A single digit percentage of people, but millions of people. Not even counting the majority of servers on the internet.
And the way Linux does it proves that you can do it that way. The largest platforms just don't.
TCP/IP? Protocol.
Email? You mean SMTP the protocol, or email platforms like GMail that people get locked out of all the time, or you mean a tiny platform with a fraction of the users?
BitTorrent... the protocol.
TLS... the protocol. Are you joking callling this a platform?
RSS... same.
Linux the OS? Because Linux sure doesn't have a centralized platform built into it last I checked.
When you forget your Linux password where's the reset link?
-
Like to be clear, my statement is tautological. For any useful definition of "platform with large number of users" you need to have fraud protection.
It's not really an ideological thing, anyone who's run any platform of a meaningful size knows you get attackers, and attackers scale. So you need to defend against attacks, and legitimate users can accidentally trigger any form of attack detection, human or otherwise.
Email is a platform. Anyone on any provider can email anyone else on any provider. And then you can choose one you trust not to lock you out, or run your own.
The others are the same. A platform is something you build other things on top of. HTTPS is built on top of TLS. Webmail services are built on top of HTTPS and SMTP.
You want a more traditional platform? Java.
> Linux the OS? Because Linux sure doesn't have a centralized platform built into it last I checked.
Who said anything about centralization? The centralization is the source of the defect.
> When you forget your Linux password where's the reset link?
Boot from live installer and reset the password.
But also, why is "password resets" necessary for something to be a platform?
The one everyone else in this thread is using is "an application or website that serves as a base from which a service is provided" (that's straight from Merriam-Webster)
Examples include (also from M-W):
"music streaming platforms"
"has built a cloud-computing platform for use by others"
"billions of photos scraped from Facebook and other social media platforms"
The only one that really could count in your examples is email, and if you think that doesn't have problems try setting up your own server and sending to gmail, hotmail, and other large providers without getting sent to spam or outright bounced.
But also, how does email not fit under (b)? Or Signal etc.?
Email and Signal are kinda on the fence for me, because they're split up in a way where it's not really one cohesive platform in the same sense as a social media platform.
Regardless, even if you consider them platforms in this sense, both have the same issue with the detection of spam and other bad actors.
The scale thing I mentioned is real.
This has nothing to do with call blocking or anything like that. I've had Signal for years and the the only spam in my message history is from more than a year ago and was sent via SMS.
It's all just network effect and WhatsApp being the same company as Facebook and therefore having a marketing budget that a non-profit doesn't. The fact that Signal has grown by a factor of nearly a hundred over the past two years despite WhatsApp's network effect implies that people strongly prefer it.
MAUs are how many people used Signal in a month. DAUs are how many people used WhatsApp in a day.
The DAU/MAU ratio for an app is never 100%. Ever.
20% is like a "good" rating, and 50% is like a best-in-class rating.
So WhatsApp having literally an order of magnitude more DAUs shows the gap in their usage.
The gap in their usage is not something for you to start making excuses about, it explains why Signal has no way to deal with fraud, child porn, spam, etc besides calling the police.
That flies precisely because Signal is small potatoes compared to the platforms I mentioned.
Email: Try setting up your own email server and sending to $largeESP
BitTorrent: Not a platform, but: This issue exists one layer up at the level of BitTorrent trackers (without which BT is mostly useless)
TLS+RSS: Same as TCP/IP
Linux: Not a platform, but you could probably get banned from package mirrors if you get the same IP as some asshole trying to DOS them and waste bandwidth
So then you use a VPN. It's also not the same thing because that's being done by endpoints instead of the platform as an intermediary.
> This issue exists one layer up at the level of BitTorrent trackers (without which BT is mostly useless)
Modern BitTorrent uses a DHT for this. Trackers, to the extent that they still exist, are just to make peer discovery faster.
> Linux: Not a platform, but you could probably get banned from package mirrors if you get the same IP as some asshole trying to DOS them and waste bandwidth
There are many independent package mirrors and also you can access them from any IP address (e.g. using a VPN again). Also, this:
http://manpages.ubuntu.com/manpages/bionic/man8/apt-p2p.8.ht...
Email is fairly dependent on DNS which is fairly dependent on a domain. Your TLD can deregister your domain, and domain hijacking is still a thing. Similarly, most people do not have an appetite to self host email and are subject to the whims of their provider.
BitTorrent is a decent example, DHT are fairly robust but also not easily searched. The discovery method of BitTorrent is frequently subject to DMCA takedowns. These takedowns have taken down legitimate torrents as well.
TLS and RSS are not platforms, and fall victim to the same thing as email.
The internet is built on many levels of trust, but just because we trust in it doesn't mean it isn't possible to deplatform at very low levels.
They can cancel your service, obviously, but that prevents you from using Verizon, not from using TCP/IP. You go sign up for AT&T or Comcast or Starlink and you can still communicate with anyone on the internet.
> Email is fairly dependent on DNS which is fairly dependent on a domain.
Which is why I didn't list DNS. But dependencies are something else. In theory anyone can deny you access to anything by putting you in prison, but by then you're really arguing that preventing this is impossible because a military could wrongfully kill you, rather than talking about whether some specific thing is the thing causing it.
>
> There isn't a platform any large number of people use that is exempt from this.
Okay, but with the other platforms that I can think off[1], my computer and phone still continue working. I can effectively work without those platforms and do not need to purchase a new computer or phone.
[1] Maybe I'm thinking of the wrong ones (Twitter, FB, AMZ, etc). Which platforms were you referring to?
how do you feel about getting locked out of all your money for a false-positive fraud detection?
>
> how do you feel about getting locked out of all your money for a false-positive fraud detection?
I don't feel bad about it - it happened once or twice in the last 30 years and it was relatively trivial to fix[1]. I also don't mind that they freeze spending if they think my account was hijacked in any way.
[1] Go into a branch with my ID, look at the transactions they think is fraud, declare that they are not, and get my account unfrozen. The whole process took about 60m, from leaving my front door to withdrawing money again.
Right now sometimes after the problem occurs you can provide those, but it's tough because they don't have those sitting around for every account.
-
Also fraud in this case is often being considered a bad actor yourself, most people haven't dealt with that from a bank.
That's like the bank thinking the transactions you would admit to having made being fraudulent, so identifying you isn't really enough.
People don't realize, yes sometimes these companies are just ignoring CS, but when it comes to lockouts they want the humans to stonewall you.
Otherwise what's the point of the automated fraud detection? The human operator will just become the new target, and SMS attacks are a great example of why that doesn't work
Like sorry but that pisses me off a bit, have the basic decency to present your point without the theatrics...
-
It's acceptable to make a system that makes it incredibly hard to get your account unlocked in very rare cases just to make fraud a lot more difficult.
You see hundreds of these posts a year and billions of people use these devices a day.
Because OP did not get back their account.
Once your account is locked it is impossible to get it back, the bits that make up your account are instantly wiped right? Some L9 at google waves a magic wand and it's gone.
No one who ever got wrongly locked out of a Google account has ever gotten it back, so it's impossible right?
-
And yes, hundreds out of billions is acceptable collateral damage.
In case you didn't know, all systems are subject to similar tradeoffs, even ones of life and death. Planes aren't just designed with safety in mind, trade offs are made knowing they could cost lives because no one could afford to travel on a plane that was twice as safe for 10 times the cost.
The water you drink is treated knowing that X incidences of illness and death occur for Y amount of contaminates because no one can afford water that's significantly more expensive for marginal benefit.
Fraud is the same. You have to accept hundred out of a billion chances of going wrong because no one will pay not just a monetary cost, but a convenience cost. Most people won't be happy if Apple requires ID to make an iCloud account for example...
As a Google user I'm not in tremendously better shape, but my PCs don't require Google to function, and at least I could load a different ROM on my phone if needed. Not that Android is tremendously useful outside the Google ecosystem.
Macs don't require an Apple account to function either.
i helped someone setup their macbook air M1 a few days ago. the least i can say is that they were asked to create an apple ID and they were asked for a phone number.
those steps were not skippable.
i was disturbed to say the least because i was recommending them to skip those steps and enter that information when they felt comfortable. an OS should only care about the user account. but two accounts and external identification were needed in this case.
What if you set up a Mac with an Apple account, Apple permabans you for something, then you forget your password and want to wipe and restore your Mac?
But he did not seem to draw any lesson from it.
Eg, he doesn't have to make access to all his music so it is contingent on his one credential, which can be revoked at any time by Apple. He can keep local copies of what he has bought, despite the ecosystem tries to make that difficult. Apple Music will delete any local copies it manages when the credential is invalidated.
https://www.guidingtech.com/what-happen-when-you-sign-out-ap...
This smells like "let them eat cake" except in the context of technology. Not everyone is able or even wants to mess with that stuff. There's a vast difference between "Yes, backup my stuff, Apple; Here's my card" and "I know what an IP is"
At $12/year you literally cannot get anything like what Apple offers just in terms of backup — not the equipment, not the man hours required to maintain it. Even if I were able to set it all up, it would cost me a huge amount of money in lost revenue just to maintain it safely.
It feels like "I could build dropbox in 5 minutes" never stopped.
* Maybe we can get to a point where running your own services is easy enough and normalized enough that most people do it.
I'm doubtful, but there's at least some small winds in that direction-- disillusionment with FAANG, peaking of the large tech economy, some renewed interest in privacy.
People literally managed books full of CDs or jewel cases, DVD racks, cassette tapes, LP collections, people had an entire rack in their house dedicated to hardware designed explicitly to use these cumbersome things, people torrented and used gnutella and managed software CDs, movie CDs, photo albums, VHS collections and the like just fine for ages. Not everyone is capable of playing MP3s on an PM3 player? Since when?
If these new systems that everyone is using is so much more complicated than that that you have to pay a professional service to do it for you, we have royally fucked up somewhere along the way.
Sounds like you’re trying to generalize from a very small set of people. The percentage of the population that had specialized full sized racks for their torrented stuff and what not was very, very small. For the rest of it, I imagine that “large drawer next to the desk” was the #1 solution, followed up by “in the car somewhere” for music CDs.
For the average person, the actual backup procedure from that era was very poor. Frankly, I doubt many did it at all. Even the nerds I knew mostly did a pretty half assed job, all considered. What professional backup software hosted in the cloud today blows even the most thorough technique from any consumer in the 1990s out of the water.
Likewise, it's weird that you need professionals to build such services? Anything that is so complicated that it requires professionals to create it has fucked up? In other words, every industry that ever existed is fucked up because they require more than a passing knowledge... professionals shouldn't exist.
You don't need professionals to build such services, no. Especially considering that the services don't really work better than a drive with MP3s on it.
Software is eating the world, I expect defensiveness on this site particularly, having massive back end data centers and frameworks just for people to do what took a 1tb drive 10 years ago is absolutely stupid.
My grandma wouldn’t know what ‘burning’ a CD means, but she sure knows how to use Netflix.
It’s not defensive to explain the overwhelming reality of todays content landscape. I couldn’t be bothered explaining the difference between a single 1tb drive and YouTube or Netflix, it’s clearly obvious.
There is nothing ridiculous about contracting companies to do work. We hire professionals to perform all sorts of tasks everyday and purchase products made by them. It’s not lazy to do so, it’s smart. Why do I have to explain the basics of how the world works?
For e.g. Do you grow your own food? Fruit and vegetables all that. It's easy right some soil and seeds with minor maintenance. You don't need professionals to do something so basic. Why cant everyone become an expert at growing their own food? Why do we need farmers, a massive global supply chain and mega stores to do something so simple? The idea that we have this global spanning network just to supply a tomato to someone is stupid and we screwed up?!
We don't have time to be experts at every facet of life, the world doesn't work like that. Believe it or not, managing big stashes of content isn't common knowledge or on everyones priority list.
But on the topic of services like Netflix and YouTube, they're used to manipulate peoples tastes these days, discoverability is broken deliberately to push priority content, and really their only advantage is discoverability, so they've got virtually nothing going for them besides network effects and entrenched market position.
Services can be nice, when they work for a user. The problem is these services are designed to disempower users. We could live in a world where all these services empower users and work perfectly, but we don't, because there's a conflict of interest.
Yes, I do grow my own food actually.
Needs to be very simple so my grandmother can build it, and cheap. No maintenance, set and forget. I assume there will be apps available for all her devices to quickly go through the process or will she need to create them? It needs to be easy to search for content and stream on any device at any time without fail.
She doesn’t care about ‘owning digital movies’ or the exaggerated threat of her accounts being closed. She's is much more likely to accidentally lose her own content managing it herself. She just wants to watch movies, how much will it cost to own all that content? Less the $10/month?
No professionals so let’s keep instructions basic and preferably just using a single blank drive with no content.
It must bother you that people don’t grow their own food? That they can’t manage their shit and need to buy it from a store?
You can BTW buy pre built devices where this is already done from owncloud I believe.
It doesn't bother me that people pay other people to do things, no need to be condescending about it. What bothers me is when people are funneled into paying for services that are more stressful to use than doing things themselves, and then making excuses for the state of affairs for whatever reason (either they're convinced by the marketing, or their salary depends on it all continuing this way).
People by and large use what they see in advertisements and justify the decision after the fact. What is preferred is not always what is superior.
Bandcamp is as easy to use as Spotify. Yet people don't use it as much. Why not? Marketing is why.
Mobile UX is full of deliberate friction points put in to support profitable business models at the expense of utility. The mobile experience is designed to funnel users towards making certain choices. This is beginning to happen in windows as well now. And people just go with it.
Is it condescending? Maybe. But if I was wrong you wouldn't have advertisements on TV, marketing people know what works and businesses aren't in the business of throwing money away for no return. People wouldn't bitch about Facebook and continue to use it, they'd go somewhere else.
As for your reference to ownCloud, there are no pre-builds for raspbian. You have to build the web stack on the pi. This is the most inconvenient option imaginable, but I guess it's the hypnotising marketing stopping Grandma from building a web service.
The long term trend is the exact opposite. People don't want to the manage hardware and all the issues of configuration, backups and troubleshooting faults that come with that, just to watch a movie. They want to palm off that responsibility to an external entity.
No, it doesn't. I literally just tested this. The article you linked to is wrong. (The site looks like a content farm, so this is hardly surprising.)
Signing out of an Apple ID will leave any subscription content downloaded from Apple Music present on the device, but unplayable. This is expected -- the user never purchased that music; they only had access to listen to it through their Apple Music subscription. Any other locally stored content belonging to the user remains playable, even if it was downloaded through Apple Music, and the subscription content will become playable if you log back in.
Let's say I have an MP3 file, and I added that to my Apple Music library on my desktop computer. Apple Music will make that file downloadable and playable on my phone, and that downloaded file isn't tied to the subscription in any way -- it's literally the same MP3 file that was uploaded. This functionality is an extension of an older feature which Apple called "iTunes Match".
On the other hand, if I download an arbitrary track from Apple Music which I didn't put there myself, that downloaded file will no longer be playable if I log out or cancel my subscription -- because those files don't belong to the user.
(I ask because I just happened to notice a $25 annual charge for that the other day... and I was like, oh yeah, I've been paying them all these years to host those 5 CDs I bought at live shows in the 1990s that aren't available on any streaming service...)
Update: Like every time this comes to mind, I almost just canceled it, but then I listened to "Track 03" by the band "djiin", purchased at Jasper O'Farrell's pub in Sebastopol, CA in 2002, and I just can't...
good to know, thanks
It's not something most tech people can really (properly) manage either.
These days the bad actors have automated there exploit attempts to the point that its not even really about asking when you will get hit rather then if you will get hit anymore, its almost instant in most cases.
with so little leeway its just not viable to self host anything that is exposed to the internet, and then if you still have to deal with things like off-site backups if you care at all about your data.
I once got a nasty call from Comcast's net abuse department because I was gasp running a mail server. It was locked down tight, and only accepting mail from an old email provider.
They didn't care. I was told that if I had SMTP open or they saw SMTP traffic coming in, I'd be permanently banned from being a Comcast customer because I was "running a server."
Internet needs to be declared a utility and internet companies need to concern themselves only with reliably delivery of network packets and to otherwise completely fuck off. My power company, gas company, and water company don't give a fuck what I do with my electricity, gas, or water.
I'm sure of this because I've made a career of it and I do it professionally for a large corporation. I know how many engineers it takes to have a 24/7/365 follows-the-sun rotation that doesn't lead to burnout. I've personally seen and solved lots of failure modes that result in mysterious degredation. (Hey did you know there's firmware on the SAS breakout board itself?) I've read many more, with solutions I'd never have come up with, by people cleverer than me.
An individual tech person could theoretically manage to do it, but I'd rather have my team helping me while I help them. I'm only human, and can't always see my own shortcomings.
I can. But I know better than to try and self-host something mission critical for myself or (especially) family. I self-host the same way a car mechanic has a classic car in their yard that they'll aspirationally fix one day.
That's not really true, there are offerings on the market that make it a breeze. Take Synology. You get raid with dozens of terabytes, that is self managed and has got instructions on every aspect of usage. It's got Google Photos rip-off for every mobile platform, it's got LDAP, Email, Caldav and Cardav packages with GUI. It's got DNS server with easy to use GUI, it's got packages for NextCloud and it's got something like Dropbox that is made by Synology as well.
You don't need no port forwarding or fancy security, it can connect to Synology's cloud thingy that will route your traffic back home correctly, DDNS on steroids.
So if you really want to self host everything, it is couple grands out of pocket and couple of evenings of clicking around.
I am not affiliated with Synology, just a happy user (although I only use it as raid storage with SMB, NFS and as Docker server).
Also there used to be "Windows Home Server" thingy.
Imagine someone told you "you can't manage your own system on a workstation, you're going to terminal into a mainframe, no normal person has the time or resources to manage their own workstation." You'd say it's absurd, because it is.
We are literally talking about doing something as simple as buying a single board computer and a hard drive, putting a pre built system on an SD card and plugging it into an Ethernet cable. It's not surgery.
Then you realize you need to access this setup while away from your home. You add port forwarding.
You run an audit to check if the system is secure enough so script-kiddies with a port scanner are not able to access your 'cloud'.
Then you realize your router is not so reliable. You add a watchdog which will reboot it once the connection becomes unstable.
Then there is a power outage. And if before you could just access all data using 4G on your phone, now you cannot. You add UPS to all critical parts of your home network infrastructure.
...
And it goes on and on. It is doable, but doing it well requires a lot of time, planning and resources. It's hardly feasible not only for a lay person but for 'power users' as well.
Yes self-hosting is a PITA. Yes things will go down. Yes it takes time to learn.
But owning the means of your production? Priceless.
We need to stop teaching people to be cyber-peasants, sharecropping a land they'll never own.
We should be encouraging self-hosting for those with the risk-tolerance to do so
I self-host a lot, including a smart home setup that is not reliant on the cloud, but in the end looking back how much time I've sunk into this and how often it's down due to _my_ mistakes I don't really think it was worth it.
The problems you say, connection/power downtime are the biggest ones. And they're frustrating, but not near as frustrating as things you paid for going missing, forever.
My point though is, if we can get workstations out of the box ready, we can get home servers out of the box ready. The software already exists, the hardware already exists. The problem is not that people don't want it, that they're lazy, that the tools don't exist, the problem is that mobile devices are deliberately built to herd people to these services. Once they're hooked they're hooked. They're fundamentally disempowering.
With the modern service oriented way of listening to music and watching TV, you risk losing what you purchased, you're manipulated by algorithms, you're trapped in the net of a service provider. Is that really less stressful than pulling out a CD and putting it in a CD player?
Digital media is better than cassettes. But the service oriented way companies expect us to do it now is not better. We really hit peak digital media with mp3 playing software on our smartphones. Everything since has just made the experience worse.
What about when that hard drive fails and you lose all of your data? Do you have backups? Do the backups _work_? Do you regularly check the health of the hard drive? What if you want to access the system from outside of your LAN? If it's accessible to the web, are you handling security yourself? How often are you applying patches? Kernel patches? What if you go on vacation and there's a power outage and you can't remotely turn everything back on?
All this case (and similar others with other companies) demonstrates is that we're lacking in laws and regulation here.
There should be no way that it is legal to just lock a customer like that without paying them all the money invested in virtual "goods". Sure, you want to block me then return all the money I paid for music, apps, etc.
There should be channels in every company where they will precisely tell you what happened and why. If they want to just stop dealing with you - they must pay back.
There's nothing wrong with using a service, what is wrong is that our laws are not up to the task of dealing with those risks.
Not self-hosting, as in having their own bare metal server in the basement, but most people can go to a VPS/cloud provider and click a few buttons to get their own instance running whatever software they need.
Not only this, but people have always been self-hosting without having any technical knowledge. For a long time, kids ages 14 or less have been running their own websites, forums, game servers, etc. And today it's a lot easier and cheaper than back then.
This is the specific thing that customers are prevented from doing. If you want Apple's hardware, whose processors are faster than Qualcomm's, you get Apple's App Store. If you want iOS instead of Android, you get Apple's App Store. If you need iMessage, you get Apple's App Store. And no other.
It's not a separate choice. If it was, what it would look like is multiple app stores on iOS, and the choice would be whether to use any other than Apple's. And then tons of people would use the other stores, especially if Apple continued to reject apps people want.
Do you want the one with the wall, or the one with the barbed wire fence with a tunnel under it?
What if I just want to come and go as I please without crawling through the mud?
Consumers are given a false dichotomy - they have as much choice and agency as a child being asked "do you want a 7:45 or 8:00 bedtime? Mommy and daddy will let you pick!"
Like it or not, being signed in everywhere with iCloud is an amazing experience. I know this because I recently tried a second user account on my Mac that wasn't signed in to my iCloud account. It was jarring.
As an Apple user I take it for granted that my watch unlocks my computer. That text copied to the clipboard on any device is immediately, invisibly available on the others. That all of my contacts and messages are just there. That my Safari history and state synchronises.
You can't 'selfhost' this stuff. You may not like Apple -- I'm not trying to convince you -- but the fact is that there are a ton of benefits that their integrated ecosystem delivers that you just can't emulate yourself.
you can,
- kdeconnect can do clipboard & messages sync
- nextcloud (or anything else that does webdav & webcard) does calendar & contact sync
- Firefox (and chrome probably too) can sync browser history and share webpages feom one device to another
i'm not aware of anything that can remotely unlock another device, but that seems like a security risk to me (also quite hard to implement as pam is synchronous :/).
but you certainly don't need a closed ecosystem, building your own out of free components is very much possible.
Some of the stuff you mentioned seems to cover computer to computer, but isn’t relevant to computer to mobile scenarios.
no, the things I listed are how I sync my linux machines with my mobile phone.
I wasn't talking about computer to computer sync, but the methods I listed (maybe except kdeconnect, which is built for computer to phone sync) apply to workstation to laptop sync aswell.
The problem is that I wish this wasn't necessary. I really like Google Photos and I haven't found an alternative (free or otherwise) that I like. And I'm also sympathetic to people who don't want to do this, even if they have the technical ability to. It wasn't hard for me to set up NextCloud on a VPS, but it took more than a weekend to get backup scripts working, run the security audit, set up New Relic monitoring, etc.
I think about in the past about how a town might have a local blacksmith or a local doctor that everyone in the community trusts. I wouldn't mind being the ops guy for a local co-op for friends and family and neighbors. But I think in this day and age it doesn't work well since people don't care enough about the problem. I told my wife to stop putting files in our shared Google Drive and to install the Nextcloud app and she said sure, but I don't think most people would care.
Full Self Driving strikes me as a problem that can be solved with the correct automation rules. Hopefully Tesla takes this opportunity to do so.
Curing cancer strikes me as a problem that can be solved with the correct automation rules. Hopefully doctors take this opportunity to do so.
If they ban a bot, the bot will be unable to proceed through a manual/human appeal process.
Not everything can be automated and arguments that scale make it impossible implies that the organization has become "too big to fail" and should be reduced in size by regulation/law.