Can confirm.
To generalize and understand why, big corps have to deal with an insane amount of (often automated) abuse, so they build profiles using data collection to assess your risk level. Being in the wrong cohort (say unusual browser, small country, rare language, use a vpn etc) can affect your score. Basically it's these massive bayesian filters that output how suspicious some activity is. Whether you're signing in to Gmail, returning a product, buying something with a credit card or booking an Uber, some form of score is computed and then used to allow/deny/delay/verify. Obviously this is well established in the insurance and finance industries, but make no mistake, it happens everywhere.
This approach is understandable from a business perspective, but imo deeply troubling for an open society. You don't have to squint much in order to see the similarities to social credit systems, EVEN if there is no grand totalitarian state-coordinated behind it.
As usual, the first step is transparency so we can actually discuss these issues based on accurate data, but that's very difficult today. Usually fraud and abuse prevention is among the most secretive departments, they never share anything.
In my book you’re never supposed to fully block a session because of the score, there needs to be a (potentially burdensome) way to prove the score wrong. Blocking a browser should be out of question.
If these numeric scores are affecting search results, recommendations, when sharing stuff, etc etc, there's no question that it will affect societal discourse. These hidden "algorithms" (as in the popular term) and fraud prevention systems are so far from being understood that it may be too late to reverse it when we realize what's happened.
Not sure being corporate centric makes this problem any worse? If you had other kinds of organisation, you'd still have to deal with abuse and fraud? Any people doing weird, unusual stuff, look inherently more suspicious. That's a fact of life in meatspace, too.
There might be some utopian, ideal way to organise activity so that non-mainstream stuff ain't suspicious.
But I would count that as a great feature of that ideal way; not as a deficiency in the corporate way. Just because this deficiency of the corporate way seems to be a common deficiency of most means of organisation that have been tried.
(Keep in mind, this isn't all or nothing. Softening the tendency might be enough of a relief, without having to eliminate it completely.)
Thanks!
> Not sure being corporate centric makes this problem any worse? If you had other kinds of organisation, you'd still have to deal with abuse and fraud?
I think it's definitely not unique to big corps, but an emergent property of a distributed and homogenous system of self interested agents, probably. It feels very game theoretical, at least. What's clear is these systems are becoming ubiquitous rapidly.
Anyway, if my Google account gets locked today, for whatever reason, I am very seriously screwed. Google's human appeal process is best-effort at best, I know people personally who have been locked out for life. Now, I have the luxury to blame myself because I should have bought a domain and so on, but society at large doesn't have that foresight/insight.
Not sure the homogenity is necessary?
To an extent, the market delivers what people are demanding.
For most people, Google's package of cheap or even free services with minimal hassle in the common case, but almost no recourse in bad cases, is compelling.
And for many it's a step up from having everything locally: I'd bet that more people lose their local data than get locked out of Google?
Oh, nice catch, I actually meant to write heterogeneous.
> I'd bet that more people lose their local data than get locked out of Google?
Probably. There's definitely some low hanging fruit/middle ground though. We desperately need to have ownership of the address itself, so we can transfer to different providers. Either with your own domain, or a domain provided by a truly neutral party, similar to phone numbers.
It seemed somewhat legitimate for a small free to use site mods to try to not get their whole life sunk by dealing with trolls, but if the same behavior is applied to giant entities who have much more incentives to do it at scale, it becomes a different issue altogether. Hidden restrictions on search results or other functionalities would be distopian and something I hope doesn’t get accepted as standard.
Unfortunately google doesn't have the support infrastructure like a bank to do recoveries.
It's not so much a social credit score to fear rather than privacy. Any site using cloudflare or Google knows where you're going and what your doing and if they don't then, access denied.
They know so much more than your innocent mind will want to admit.
Total coincidence that it's also "you're not being a good little data source", I'm sure.
I use a privacy-oriented browser on my cell phone to load amazon's website to get that stupid whole foods QR code for the checkout, because I'm not installing their fucking app so it can collect more data on me.
Guess what? Every single time, I'm presented with a "we've emailed you a link" error, and that link is difficult to open in my preferred browser because iOS doesn't offer it as a choice for opening links...
100% coincidental, of course :)
> that link is difficult to open in my preferred browser because iOS doesn't offer it as a choice for opening links...
Hmm, wasn't that fixed? Perhaps it's the email app that won't let you? I seem to be able to open many links in Firefox on iOS these days, but in some cases Safari is indeed the only option.
Speaking from someone in the US--in both insurance and finance I can get a person on the phone to resolve my issue.
Specific to finance, there are a number of consumer laws that protect me.
If I'm denied credit based on my credit history, I'm allowed to know why. If my credit score is not accurate, I'm allowed the ability to fix it.
Lousy customer support is not a tech industry issue--Stripe, Amazon, Apple, to name three all have great support.
True, but they have actual customers. As a user of Gmail, I can hardly be considered a customer.
Google ads has customers though. Their support probably isn't great either, but does it need to be? Where else are you gonna go?
I've not dealt with Google Ad support, but I can say from experience Facebook Ad's customer support is terrible.
Similar to Google, I'd speculate that the majority of customers pay such small amounts, that it's more cost effective for Google and Facebook to not support them, than it is to support them.
I would also speculate, that if you were instead, say Pepsi-Co, you would have white-glove service from both tech giants.
That's probably how they reason about it but I think it's a cultural thing too (pure tech Co's have a bias towards automation for everything, and a reluctance to staff operations at all). Amazon for instance has many low value customers, yet has much better support across the board.
> I would also speculate, that if you were instead, say Pepsi-Co, you would have white-glove service from both tech giants.
Oh absolutely, that's no secret. I know account managers that had a single big customer at one of these companies. It's part of the sales org basically.
> Basically it's these massive bayesian filters that output how suspicious some activity is.
It almost feels like the digital equivalent of racism, xenophobia, homophobia, and other prejudices; people are suspicious of anything that stands out as being somehow "different." Now computers are suspicious and prejudiced because your digital appearance looks out of norm.
> This approach is understandable from a business perspective, but imo deeply troubling for an open society.
Agreed.
First thing I do when creating a new Gmail account, using a "supported" browser, is to save the required parameters of the cookie in a text file then convert the file to a simple shell script, powered by netcat and TLS proxy. This only takes me takes seconds. Then I close the supported browser without logging out. The word "sketchy" seems applicable because unlike, e.g., a bank website, companies like Google and Facebook will let users stay "logged in" for some ridiculously long period like one year. Yikes.
Two ways to disable the script are 1. log out of that session (://mail.google.com/mail/logout?ec=ABCDEF, ://accounts.google.com/Logout?service=mail&continue=https://mail.google.com/mail/, ://mail.google.com/accounts/ClearOSID) or 2. change the password.
This tiny script can be transferred to any computer and used to check and send mail from the command line. No browser, Javascript or password required.
Netcat, the browser of the future! :)