As a Google user I'm not in tremendously better shape, but my PCs don't require Google to function, and at least I could load a different ROM on my phone if needed. Not that Android is tremendously useful outside the Google ecosystem.
Macs don't require an Apple account to function either.
i helped someone setup their macbook air M1 a few days ago. the least i can say is that they were asked to create an apple ID and they were asked for a phone number.
those steps were not skippable.
i was disturbed to say the least because i was recommending them to skip those steps and enter that information when they felt comfortable. an OS should only care about the user account. but two accounts and external identification were needed in this case.
What if you set up a Mac with an Apple account, Apple permabans you for something, then you forget your password and want to wipe and restore your Mac?
There isn't a platform any large number of people use that is exempt from this.
I can think of a few. TCP/IP, email, BitTorrent, TLS, RSS.
Millions of people use Linux. A single digit percentage of people, but millions of people. Not even counting the majority of servers on the internet.
And the way Linux does it proves that you can do it that way. The largest platforms just don't.
TCP/IP? Protocol.
Email? You mean SMTP the protocol, or email platforms like GMail that people get locked out of all the time, or you mean a tiny platform with a fraction of the users?
BitTorrent... the protocol.
TLS... the protocol. Are you joking callling this a platform?
RSS... same.
Linux the OS? Because Linux sure doesn't have a centralized platform built into it last I checked.
When you forget your Linux password where's the reset link?
-
Like to be clear, my statement is tautological. For any useful definition of "platform with large number of users" you need to have fraud protection.
It's not really an ideological thing, anyone who's run any platform of a meaningful size knows you get attackers, and attackers scale. So you need to defend against attacks, and legitimate users can accidentally trigger any form of attack detection, human or otherwise.
Email is a platform. Anyone on any provider can email anyone else on any provider. And then you can choose one you trust not to lock you out, or run your own.
The others are the same. A platform is something you build other things on top of. HTTPS is built on top of TLS. Webmail services are built on top of HTTPS and SMTP.
You want a more traditional platform? Java.
> Linux the OS? Because Linux sure doesn't have a centralized platform built into it last I checked.
Who said anything about centralization? The centralization is the source of the defect.
> When you forget your Linux password where's the reset link?
Boot from live installer and reset the password.
But also, why is "password resets" necessary for something to be a platform?
The one everyone else in this thread is using is "an application or website that serves as a base from which a service is provided" (that's straight from Merriam-Webster)
Examples include (also from M-W):
"music streaming platforms"
"has built a cloud-computing platform for use by others"
"billions of photos scraped from Facebook and other social media platforms"
The only one that really could count in your examples is email, and if you think that doesn't have problems try setting up your own server and sending to gmail, hotmail, and other large providers without getting sent to spam or outright bounced.
But also, how does email not fit under (b)? Or Signal etc.?
Email and Signal are kinda on the fence for me, because they're split up in a way where it's not really one cohesive platform in the same sense as a social media platform.
Regardless, even if you consider them platforms in this sense, both have the same issue with the detection of spam and other bad actors.
The scale thing I mentioned is real.
This has nothing to do with call blocking or anything like that. I've had Signal for years and the the only spam in my message history is from more than a year ago and was sent via SMS.
It's all just network effect and WhatsApp being the same company as Facebook and therefore having a marketing budget that a non-profit doesn't. The fact that Signal has grown by a factor of nearly a hundred over the past two years despite WhatsApp's network effect implies that people strongly prefer it.
MAUs are how many people used Signal in a month. DAUs are how many people used WhatsApp in a day.
The DAU/MAU ratio for an app is never 100%. Ever.
20% is like a "good" rating, and 50% is like a best-in-class rating.
So WhatsApp having literally an order of magnitude more DAUs shows the gap in their usage.
The gap in their usage is not something for you to start making excuses about, it explains why Signal has no way to deal with fraud, child porn, spam, etc besides calling the police.
That flies precisely because Signal is small potatoes compared to the platforms I mentioned.
Email: Try setting up your own email server and sending to $largeESP
BitTorrent: Not a platform, but: This issue exists one layer up at the level of BitTorrent trackers (without which BT is mostly useless)
TLS+RSS: Same as TCP/IP
Linux: Not a platform, but you could probably get banned from package mirrors if you get the same IP as some asshole trying to DOS them and waste bandwidth
So then you use a VPN. It's also not the same thing because that's being done by endpoints instead of the platform as an intermediary.
> This issue exists one layer up at the level of BitTorrent trackers (without which BT is mostly useless)
Modern BitTorrent uses a DHT for this. Trackers, to the extent that they still exist, are just to make peer discovery faster.
> Linux: Not a platform, but you could probably get banned from package mirrors if you get the same IP as some asshole trying to DOS them and waste bandwidth
There are many independent package mirrors and also you can access them from any IP address (e.g. using a VPN again). Also, this:
http://manpages.ubuntu.com/manpages/bionic/man8/apt-p2p.8.ht...
Email is fairly dependent on DNS which is fairly dependent on a domain. Your TLD can deregister your domain, and domain hijacking is still a thing. Similarly, most people do not have an appetite to self host email and are subject to the whims of their provider.
BitTorrent is a decent example, DHT are fairly robust but also not easily searched. The discovery method of BitTorrent is frequently subject to DMCA takedowns. These takedowns have taken down legitimate torrents as well.
TLS and RSS are not platforms, and fall victim to the same thing as email.
The internet is built on many levels of trust, but just because we trust in it doesn't mean it isn't possible to deplatform at very low levels.
They can cancel your service, obviously, but that prevents you from using Verizon, not from using TCP/IP. You go sign up for AT&T or Comcast or Starlink and you can still communicate with anyone on the internet.
> Email is fairly dependent on DNS which is fairly dependent on a domain.
Which is why I didn't list DNS. But dependencies are something else. In theory anyone can deny you access to anything by putting you in prison, but by then you're really arguing that preventing this is impossible because a military could wrongfully kill you, rather than talking about whether some specific thing is the thing causing it.
>
> There isn't a platform any large number of people use that is exempt from this.
Okay, but with the other platforms that I can think off[1], my computer and phone still continue working. I can effectively work without those platforms and do not need to purchase a new computer or phone.
[1] Maybe I'm thinking of the wrong ones (Twitter, FB, AMZ, etc). Which platforms were you referring to?
how do you feel about getting locked out of all your money for a false-positive fraud detection?
>
> how do you feel about getting locked out of all your money for a false-positive fraud detection?
I don't feel bad about it - it happened once or twice in the last 30 years and it was relatively trivial to fix[1]. I also don't mind that they freeze spending if they think my account was hijacked in any way.
[1] Go into a branch with my ID, look at the transactions they think is fraud, declare that they are not, and get my account unfrozen. The whole process took about 60m, from leaving my front door to withdrawing money again.
Right now sometimes after the problem occurs you can provide those, but it's tough because they don't have those sitting around for every account.
-
Also fraud in this case is often being considered a bad actor yourself, most people haven't dealt with that from a bank.
That's like the bank thinking the transactions you would admit to having made being fraudulent, so identifying you isn't really enough.
People don't realize, yes sometimes these companies are just ignoring CS, but when it comes to lockouts they want the humans to stonewall you.
Otherwise what's the point of the automated fraud detection? The human operator will just become the new target, and SMS attacks are a great example of why that doesn't work
Like sorry but that pisses me off a bit, have the basic decency to present your point without the theatrics...
-
It's acceptable to make a system that makes it incredibly hard to get your account unlocked in very rare cases just to make fraud a lot more difficult.
You see hundreds of these posts a year and billions of people use these devices a day.
Because OP did not get back their account.
Once your account is locked it is impossible to get it back, the bits that make up your account are instantly wiped right? Some L9 at google waves a magic wand and it's gone.
No one who ever got wrongly locked out of a Google account has ever gotten it back, so it's impossible right?
-
And yes, hundreds out of billions is acceptable collateral damage.
In case you didn't know, all systems are subject to similar tradeoffs, even ones of life and death. Planes aren't just designed with safety in mind, trade offs are made knowing they could cost lives because no one could afford to travel on a plane that was twice as safe for 10 times the cost.
The water you drink is treated knowing that X incidences of illness and death occur for Y amount of contaminates because no one can afford water that's significantly more expensive for marginal benefit.
Fraud is the same. You have to accept hundred out of a billion chances of going wrong because no one will pay not just a monetary cost, but a convenience cost. Most people won't be happy if Apple requires ID to make an iCloud account for example...