AT&T's website raising the price every time I refresh the page
reddit.com
reddit.com
Hahahaha. It takes more code to add $10 to a price. It takes a cookie or something to remember how much they quoted you last time. This explicitly programmed behavior can NOT be a bug, it's a feature that someone took time to implement. The "feature" might be buggy in the sense that's its too obvious and perhaps was only supposed to increase the price once or something, but the overall implementation is almost certainly not a bug.
Yes I do.
>> I have, on multiple occasions, introduced bugs that are orders of magnitude wackier than this.
Those would make a nice blog post. I've done some stupid things and seen some unexpected results, but I've never encountered the likes of this "accidentally" incrementing price thing. ;-)
It could be that some local taxes or fees comes out to $10, and the client code does `price += taxes` on page load.
There could be code to round up to a $10 increment, and then subtract 2 cents so the prices are all $X9.98, but the rounding logic is incorrect. Since this is JS, they will be using floating point prices. That is a minefield in itself.
I'm not saying it's definitely a bug. But it trivially could be.
* Modify value to give local amount, not realising it's modifying a cached value
* Never test refreshing doesn't change the price
But why would ANY price be determined in part by the users browser. It gets it right the first time, so why would page reload do anything different? This makes no sense.
> gets it right the first time,
Maybe, you don't know.
It may be adding $10 the first time too.
Okay slowly turning the 800 pound steel beam 1 degree per minute, and now it's trying to toss it across the room... Boss we need a new $1,000 dollar motor!, and maybe a new wall.
No idea if GP is correct, but that would not even be close to the weirdest thing I've seen in production code in companies. Very plausible to me that an engineer for a large company could write code like that. Short answer, corporate codebases are messy and weird, and because they are already messy and weird they are therefore breeding ground for even more baffling decisions based on time constraints and partial understandings of already weird systems.
Especially in legacy systems, questionable, weird design choices keep producing other questionable, weird design choices until explaining why AJAX requests are getting parsed through hidden input fields or why all of the localstorage fields are Base64 encoded suddenly requires a multi-part, 5-10 minute story about the history of the codebase -- and that's if you're lucky enough to have anyone around who knows the story in the first place.
Related to the above, if you're in charge of an engineering team at a company please build more time into your team's schedule for refactoring and code cleanup.
----
To jump off of OP's (at the top of the thread) point, it could also be a bug with malicious pricing. A programmer might have tried to build a dynamic pricing system based on geographic area or whatever and just accidentally read the base price from the same cache they're writing to.
And if your followup question is "but why would you read the base price from localstorage instead of from the server, or why would you even have that logic clientside in the first place?" -- then see the first point above.
But none of the explanations here would be surprising to me at all. It's not really a debate about whether AT&T alters prices based on stuff like area and customer data, I'd be surprised if someone tried to claim they don't. But like OP said, this doesn't make much sense from a conversions point of view; and it's way more likely to be a bug than it is to be an executive mistakenly believing that raising the price by $10 on every refresh makes people more likely to buy Internet.
That executive already has better methods to increase prices: adding hidden fees and service charges, and raising prices behind the backs of long-term customers who aren't checking their bills regularly enough or who are unlikely to go to the trouble and inconvenience of switching or fighting the bill.
My suspicion is bug.
This is the first time reading HN has made me scared to live on this planet!
A) like 2 or 3 people total care about them way more than they're obligated to and keep them from falling over,
B) it turns out that in many instances people just don't exploit or crash stuff, and broken systems can take a while to fail.
----
That could be a longer conversation and it's not necessarily all pessimistic; the reality of how software (and systems in general) get built is one of the reasons I don't have a lot of patience for people who say there aren't any ways they can contribute to or improve anything and that the world is too connected or competitive now for people to make a difference. There's a ton of stuff to do and improve in most systems regardless of your talent level and there is no shortage of small but really impactful things that people can do around infrastructure, even if it's as simple as documenting how systems work.
But I'm dead serious about this: internalize that real world systems are messy and that everyone involved in them is doing car maintenance on a still-moving vehicle. Internalize that systems decay over time and that as things become messy, they get messier at a faster rate. Internalize that this is not an exception, but the rule. All systems and codebases that are seeing regular development by nature decay and become unmaintainable unless you expend extra energy to keep reinforcing them, pruning them, and refactoring them. And it's not as simple as hiring good programmers, messy systems actually have momentum towards messiness, and regardless of who you hire they'll spend the majority of their time just keeping the system from falling over.
That is an incredibly important principle about the world for people to understand -- both because it helps make sense of a lot of the world and because internalizing it will make you a better manager if you're ever in that position.
It also helps with evaluating security, because it's one thing to say that extra data storage and processing might increase security risk by multiplying attack vectors, and it's entirely another thing to actually have a sense for how much extra risk of bugs/mishandling/exploits each extra layer of software and corporate handling adds to data. At the same time, it also helps with understanding threat models and managing expectations, because you realize that very few things in the world are actually secure, but that for some reason (absent coordinated effort or a lot of attention) they very often don't get exploited or destroyed, and that there are ways to mitigate that kind of inescapable ambient risk.
Not in the web space but I've seen similar with using pythons lrucache as using that on a function modifies the programs behaviour (if you mutate the returned value, you're in trouble).
Um, I know you said you work in software, and the rules say not to doubt you. So I'll press Y and move on.
There are so many levels of bugs that almost nothing would surprise me, and this falls very easily within the range of bugs I've witnessed personally. Let's try this:
Hahahaha. It takes a single off-by-one errors to accidentally increment prices. It would take a lot of effort to deliberate design a feature that deliberately adds to quoted prices on every refresh, for the purpose of... um... well, that part is unclear. This bug can NOT be explicitly programmed behavior, it's too obvious incorrect behavior to be something someone took time to implement.
Yeah, that was easy. Except mine makes sense.
I haven’t, but I’ve coded trading systems. Typo a dividend or convert and your dumb little bot starts incrementing its offer every millisecond. (The fun is when another bot gets thrown into a complementary loop and the exchange yells at you.)
Have a system that e.g. codes a local tax or maintenance allowance run on lookup, or have these data in two systems that try to sync but do it wrong, and you get something like this. (This is not a legitimate pricing strategy. Nobody gets FOMO buying an AT&T plan.)
Color me skeptical.
I built web sites for a mid-sized B2B and B2C company, and had to build all kinds of games into the pricing.
Refreshed the page more than three times? That's a price change.
Returned to the same page 24 hours later? 36 hours later? 72 hours later? Price change. Price change. Price change.
Using a tablet? Price change.
Connecting from an IP address believed to be in a particular geographic region? Price change, and inventory change.
An unintended side effect of all of this was that it gave the illusion that pricing was dynamic based on supply and demand. It wasn't. There was no link between inventory and pricing. It was all games based on the user.
But these were luxury items. The cheapest item in the inventory was $5,000ish. With add-ons, they could go up to $30K.
Taking it a step further: a browser extension that tries several scenarios (like Honey, but just for re-fingerprinting and stuff... can an extension make a request that suppresses/manipulates cookies only temporarily?) as you're shopping.
Not in $10 increments every refresh though, that's most likely badly coded.
If anything, it seems one should slightly -lower- prices when suspecting a customer is shopping around.
And I doubt that these quoted prices have any relation to the actual bill that they will eventually send.
But at least once in the last 5 years it was exact to the penny. So there's that.
That could be the AT&T motto. See most everything they have done in the past 15 years.
By the same token, AT&Ts malicious pricing malware running in your browser could be construed of "unauthorized access" of your own computer, thus AT&T would be violating CFAA.
The server validated that the coupon code was legitimate, but the actual discount value of the coupon code was validated client side in JS for some reason.
So he could turn any 10% off coupon into a 100% off coupon by modifying the API requests during the checkout flow. I'm sure this was illegal but he ate a lot of free fast food before they ever fixed it.
But don't sit there and pretend that you can say, "well, they let me do it because some of the code ran client side." No, that's not how it works. Changing the price of a $100 service to $10 on a website, is like taking a bar code from a $10 product and slapping it on $100 product. The biggest difference is, since it involves computers, there are even more crimes committed.
In none of these cases are the companies condoning or supporting your actions. You can try the argument that the bank teller gave you the money and that it's bank policy to do so. But it probably won't work.
It's strange to see people bending over backwards to deny that this is a crime. Surely if someone manipulated your bank's computers to wire transfer your entire balance to another account, you wouldn't be asking, "what crime could [they] have committed?" You'd feel like somebody stole from you.
Using your store analogy it would be like bringing a television to the cashier and telling them you will pay $10 and they accept.
I doubt a “reasonable” person would think of it like the latter case, but for people who think about software agents, it’s interesting to think about.
Disclaimer: don’t try this at home…
Just because you can physically enter a strangers house does not shield you from trespassing charges.
Society / the legal system is not code. There is all sorts of nuance and morals and subjectivity involved beyond the "bits on the wire", so to speak. You can go to prison for accessing a website you know you shouldn't, even if the HTTP response code is 200.
This is why educating the public about jury nullification is so important.
Don't ever do critical calculations like this client side. It's just dumber than dumb.
[ ] Plan X $30
[ ] Plan Y $50
[ ] Plan Z $70
And I pencil in "Plan W $10" at the top with a checkmark and mail it back. Is that illegal?You are basically just giving a counter offer, the company can choose to accept or reject that offer. There have been cases (cba to google them right now, just going off my memory) where customers have done what you have suggested, the company have blindly accepted the "counter offer" and have had to honour the amended contract they agreed to.
EDIT: The problems happen when trying to enforce such amended contracts, trying to prove the company agreed to such changes. For me when I'm negotiating my annual broadband contract I record the phone call (granted I'm in the UK, recording calls as an indivial is legal) just to make sure I have a record of what was agreed. But my current provider has always followed up with a updated contract after the phone call with the new terms, so it would be easy for me to prove that my provider agreed to those terms. My current provider agreed to a price which is £1 per month cheaper than the cheapest like fore like competitor I could find at the time and also agreed to waive any cancelation charges if I choice to cancel before the end of the 12 month contract.
However a) been pretty happy with their service todate so unless the shit hits the fan I have no plans to leaving them unless b) my local area finally gets FTTP but if that does happen I will prob use my current provider as my FTTP provider. So they really don't have any risk of myu cancelling during the current contract.
Maybe I'm misremembering but I vaguely recall a story of a man who altered a contract, signed it, and mailed it back to a telecom company. They signed it without reviewing and when it went to court it was upheld because both parties signed the altered contract.
But I understand that's different than "demanding" they accept it so it doesn't negate your point.
In the example I gave in my edit with my own ISP recently, the inital offer they gave me when my contract was coming up to expire was to keep my existing price and level of service, however over the previous year prices for new customers had dropped below what I was paying and a competitor was even lower than my own ISP's new customer pricing (For the same level of service - the pricing diffence wasn't much but it was still there).
So when my contract was due for renewal I called them up (easier to negotiate with a human than a computer) pointed out that a) I was happy with the service they had provided but I was not happy that the price they initially offered to renew was higher than if I was a new customer. b) Because they hadn't offered the price that they gave new customers it incentived me to compare prices elsewhere which lead me their competitor and I was inclided to switch, but suggested that if they sweetened the deal I would stay.
The rep offered a lower price and I said I would agree aslong as they wavied any cancellation charges during the contract. I did say to the rep that I had no plans to cancel unless my street finally gets fibred. It took a bit of wording in the contract, tech speaking the early termination charge is still there however the discount I have cancels out that charge so it would end up being a zero owed balance which I was happy with (Chances are that my street won't get fibred during the remainer of my contract and even if it did I would prob use my existing provider as my fibre provider as they do offer it where its available, so it was a safe bet for the provider and just gave me a bit of reassurance).
My ISP had every right to tell me to go pound sand, my choices would have then been to take the best deal my ISP offered and stay or switch ISPs (which here in the UK has been fine-tuned to a point there is very little downtime, basically for most people its a case of swapping out the ISP issued router, for me it would be configuring my own modem to the new ISP's auth come switch over). Customer retaintion reps usually have a bit of leeway to keep non probmatic customers happy, and tbh I would have been happy if they had just price matched the price they offer new customers, but hey if you don't ask, you don't get :-)
It's not like if you write it, they automatically need to honor it.
https://www.nasdaq.com/articles/updated-russian-man-turns-ta...
Eg the F12 debacle: https://www.theverge.com/2021/12/31/22861188/missouri-govern...
I haven't read the CFAA in a while but it is extremely broad. It boiled down to "if you access a system in a way you should not, illegal".
Or how accessing the same page a billion times per second, a page you have every right to access a few times, is illegal.
Or if you dial into a nuclear arms facility with your phone.
At some point "technical debt" becomes "incompetence."
I had about a 50% success rate of just frickin' logging in.
Meanwhile, the local co-op ISP just finished running underground fiber to the township. Full gig connection for $250 set-up fee (with a 1000yd drop to your house if necessary) and $80/month forever.
They apply lessons their fathers and mothers learned in the 50's and 60's about how business is done with a handshake and a friendly disposition to today's world.
And if you don't have the right last name or the willingness to defer to their ignorant authority, you can't get anything done.
It's frustrating to see the same people from the same families making the same stupid mistakes for literally generations. It's more frustrating to be excluded from that process that you know you can help fix just because you dared to leave the community for any period of time regardless of whether it was for fun or for advanced university studies or your last name is tainted because your grandpa was a complete shithead, regardless of how you turned out.
A bit of a rant. But. I have been tempted to run, and I have been elected to the council. And I couldn't get anything done, because I was purposefully excluded as an outsider with too much education, regardless of what I tried. It was frustrating.
Even Comcast decided not to find a way around that.
Aside, but I was recently helping my mother-in-law get Internet. She's in a place serviced by Sonic, but only over AT&T copper. Their pricing was not great. I ended up discovering Xfininty (Comcast) pre-paid. $45/month for 10'ish/50'ish Mbps service which is plenty for her, no data cap, no dealing with Comcast customer retention when she wants to cancel. This is not a well advertised service and I came across it only by accident.
https://www.xfinityprepaid.com/
https://www.reddit.com/r/Comcast/comments/rsp555/question_co...
My only complaint is their subpar gateway. WiFi signals keep dropping when there's any kind of interference and the automatic channel finding is awful. But a one-time investment in a router and you're good.
Good thing that you only refreshed your browser once while using it.
Way back in the day, when DSL was The New Thing, I had a good experience with it as well. Damn you, ATT! I try to hate, but you keep meeting my expectations!
That said, a friend is getting royally jacked up by ATT incompetence and complete disinterest in slightly rural service.
2. https://en.wikipedia.org/wiki/Russell's_teapot seems relevant here
People will go to endless lengths to justify their spending habits.
Cynically, I suspect that the fabricated number will be disregarded when it comes time to signing a contract, and you will always be presented with one of the same small number of rate buckets. That may be higher or lower than what you saw on the website. If you complain a service rep will be able to drop you into a lower bucket, but they predict that most people will either not care or not notice the price. Not until you get your first bill.
Just wait until you see US medical bills.
I could have gone with $15/mo if I didn't use so much data.
You can spend more but you're basically just paying for the privilege of having a provider that more readily offers flagship phones subsidized via contract.
with "unlimited data" that is capped at 15g. unfortunately it's the only provider that works where we live in Michigan
I have a friend on the police/emergency responder ATT network (FirstNet) and he said he's NEVER had it slow down since those EIMIs get priority routing. I'm sure someone in telco network operations could explain this even better than I can.
Its even more extreme than that, they have their own frequencies.
On the top tier plan it's $70.
* 2 lines is $60/line ($120)
* 3 lines is $50/line ($150)
And you have to regularly shop around. Do you want more data or voice? Do you want international roaming? International calling? Spotify? Netflix? Hulu?
I, for example have a T-Mobile Magenta Plus. It also includes, Netflix, Apple TV+, Paramount+ (the Star Trek Channel), and Spotify. Those services are $40 separately.
Mobile carriers are no better. They're basically wireless cable companies.
https://support.hughesnet.com/en/faq/internet/unlimited-data...
This would be more like paying for Sky TV subscription.
Still, in US there's no TV license you have to pay like in the UK. So if you don't want to pay for TV service in the US, you don't have to. In UK, if you own a TV you pay for TV service, it's the law.
[1] This is not an opinion. AT&T just put in fiber and I got 6x faster download, 20x faster upload at a fraction of what I was paying before. My existing provider countered (after I cancelled) with a much faster internet plan plus cable at 40% of their previous price.
However, I have found that by using my cable subscription to gain access to the various streaming apps, it is cheaper than buying all of the apps a la carte.
That's the shocking thing. I've heard of cases where dropping cable would increase the bill. I suspect that's because it's easier to defend leveraging your monopoly power if you can show customers are "buying" other services like cable.
That's one reason I have zero regrets on torrenting TV shows.
Honest way: "Here's a base price for the product; here are some extras (even if Veblen) that you can also get by giving us more money". Lots of video games do this (buy the presale premium edition, get some merch); streaming sites also do this (see Netflix's pricing tiers).
Dishonest way: "Here's your price." (Unsaid: it's different than Chad's price, but there is no way to know what factors make that distinction).
Airlines will tell you "An economy seat on this flight costs $100. There is 1 ticket left at this price." ; you'll think "Great!" and proceed to click into it, with the intent to buy at that price. You'll get to the part where you need to choose your (specific, not simply class of) seat on the plane, and the diagram will show no seats available: your only option will be to "upgrade" to a costlier seat. So, in reality, there weren't any seats at that price, and the whole "There is n seats at this price" thing was simple bait & switch meant to just wear you down into purchasing the more expensive seat.
There's a lot of ways you could organize the data so it's less terrible, but all of those involve a lot more IT involvement than airlines want to invest it.
[1] often to Sabre or Galilelo or similar
You can restart the flow from scratch, and you'll still get "n seats available at this price", which rules out that it was booked while I was looking.
> so they cache a lot of things and only get realtime inventory when you're very close to booking; then they often do a very poor job of cache invalidation (because it's hard)
Yet the end result is the same: the consumer gets a bait and switch.
You're not wrong here, but what you point to is the problem: companies using "blame computers" as a way to abdicate responsibility for the problem.
> There's a lot of ways you could organize the data so it's less terrible, but all of those involve a lot more IT involvement than airlines want to invest it.
Precisely. One can look at it too as there is no penalty these days for screwing consumers over, so there's no economic impetus to do anything about it when it happens.
Pricing is subject to multivariate testing all the time on e-commerce sites, this is likely supposed to show x for Segment A and x+10 for Segment B. I'd be shocked if OP could check out with the inflated price. Otherwise I'm opening up web inspector and getting myself a $0.00 AT&T monthly plan...
https://www.att.com/acctmgmt/dtvlander
So all it takes is someone with AT&T to go pop open the devtools. (It apparently requires a login, and I'm kinda in Australia so that won't work)
I JUST NOW experienced the opposite of this with an airport parking website.
I double-checked my reservation dates (maybe hit the back button in doing so) before pulling the trigger on the order button and it applied my $19 'free day' discount twice.
And, yes, my credit card was charged the post-double discount value!
Can we for instance jack the price up to thousands, perhaps millions of dollars?
most importantly when contacting ATT to purchase at such price, will sales think that is reasonable, or will they have a different price in front of them?