One of the weird realities is that in order to combat fraud you need to be able to identify the source, which is a hard reality as a privacy advocate.
One of the weird realities is that in order to combat fraud you need to be able to identify the source, which is a hard reality as a privacy advocate.
Bam - I am anonymous, but have (mostly) proven I am a real person with (mostly) reasonably good intentions.
I joined HN for one or two reasons. To research a book. But also to promote my last book. Anyone can post here with a throwaway, yet I didn't want to be an interloping dick who felt entitled to hit and run posting links to my own vanities... so I decided; join, contribute, participate, earn. After a few months I don't feel bad about plying my own wares a little. Reputation (social capital) is natural and ancient and doesn't really need crypto.
Most of the Web isn't that though. As an information system, as Sir Tim first coined it, it's a publishing machine: You advertise a service, I send "requests", you send "responses", we part ways without complications. Quick anonymous sex on the beach. So-called Web2.0 f-cked that massively. Web2.0 wants to exchange phone numbers. And once the surveillance capitalist creeps latched on to stalking everyone around the neighbourhood... well here we are.
I think what some Web3.0 people think is that crypto can repair some kind of "middle ground", where Web2.0 type behaviours can take place but anonymously and under conditions controlled by "stakes". I think this won't work for psychological and game theoretical reasons we can't get into here. Instead I think we need to repair the Web1.0 layer at least, and since transport level security and anonymity have become necessary in a post-Snowden era, for me that means getting rid of the selective prejudice inflicted by systems like Cloudflare.
Its a put up or shutup kinda system. Fund your wallet with $100, hold it, and we will let you post that reaction to a news article after its been held continiusly for 30 days, and automatically delete is as soon as its unfunded.
ssh bruteforce top 5 offenders:
147 (Tor: 0) TENCENT-NET-AP-CN
133 (Tor: 0) DIGITALOCEAN-ASN
31 (Tor: 0) CHINANET-BACKBONE
17 (Tor: 0) BAIDU
13 (Tor: 0) CHINANET-SH-AP
Overall there where 737 unique IPs from 241 ASNs and 1 was a Tor node.
access log top 5 offenders:
76 (Tor: 0) DIGITALOCEAN-ASN
58 (Tor: 0) CONTABO
54 (Tor: 0) AMAZON-AES
50 (Tor: 0) KAZTELECOM-AS
34 (Tor: 0) CORBINA-AS
Overall there where 1672 unique IPs from 618 ASNs and 4 where Tor nodes.
I spent a recent chunk of my career combating fraud on a niche-eBay style site and the people trying to defraud other users, pay with stolen credit cards, login with phished credentials, etc were consistently trying to hide their origin.
Until we started using fingerprinting techniques to track them across multiple accounts and IPs, we had no way to spot this. It was a shock to me when I realized there were legitimate uses for fingerprinting technology because I'd always associated it with ad networks and trackers. They're fairly necessary for combating fraud though.
When we stopped letting any untrusted users run a credit card if their connection couldn't be trusted, our charge backs virtually stopped. That experience makes me completely understand sites scrutinizing anonymized traffic.
"Sinners look just like saints, so it's necessary to punish all, to
destroy the riches of the many in order that wicked few do not
escape."
Is that a fair framing of the "ethics" of what you said? (I'm not
attributing that as 'your' argument, I understand you're kinda just
trying to 'explain' something as you see it).Do you think this kind of thinking can continue to stand if technology is ever going to be fair and useful to everyone? Or do we just accept that technology always amplifies as least as many problems and injustices as it solves?
I'm trying to map the technical explanations people give onto what may be going on for them at "ethical reasoning" level.
You're welcome to add your interpretation of course.
You probably guessed I'm looking to distinguish a Bentham from Mill sort of utilitarianism.
A reasonable challenge would probably be fine. But so many sites block, or sometimes use obnoxious unfair challenges.
I added some of my own experience here: https://news.ycombinator.com/item?id=31252676
If an army is attacking your border and somebody walks through them saying, "It's okay, I'm totally legitimate!" that person is probably still going down in the crossfire. Enter from the direction where the attacks aren't coming from and your odds will increase significantly.
Ultimately, companies will either adopt a very strict security policy on their own or they will respond to the problems that they are experiencing. If you are a US only company and you start getting malicious traffic from Romania, it's fairly common to just block all of Romania. When you're using tools like Maxmind for network identification, VPNs and Tor are just another traffic source that you can choose to block if it's causing you problems.
What I'm getting is that you consider the "attack" an immediate mortal threat and the granularity of tools and techniques for discerning enemy/friendly identity and behaviour are lacking. The principle ethical stance is really self-preservation.
> "It's okay, I'm totally legitimate!" that person is probably still going down in the crossfire.
Nice analogy. I may have to steal that :)
Given that we can't rely on identity [1], can we improve analysis and response to behaviour?
[1] I see in an earlier response you talk a bit about fingerprinting, and of course anyone serious about privacy will modulate OS and browser FPs without malicious intent.
For example, at the site where I worked we needed much stricter protection but we didn't want to bother the established users of the site...so we setup trust scores and implemented stricter controls on a sliding scale. The higher your trust score, the less strict we would be with our policies.
As a brand new user, your score was a flat 0. You could boost it by verifying a credit card, phone number and address (without using a VPN/Tor). Successful transactions rewarded your score. Transactions with established users are more valuable than transactions with other new users, etc.
All the security was virtually invisible to the established users and it worked like a charm.
Regarding the fingerprinting, at the time that we were doing this anti-fingerprinting technology barely existed. We had some other tricks in the bag too to fingerprint based on behavior. It was a lot of fun working on that stuff though. Very much a cat and mouse game.
HTML isn't cached by default with cloudflare