YouTube suspends a YouTuber's Patreon-exclusive account for self-impersonation
twitter.com
twitter.com
We ordered two pairs of Beats. One was ordered by me, the other by my spouse. We’d discussed the purchase but we weren’t clear on who was actually going to order. Received both via Prime.
I setup a return. We return the item which was received on her Order ID against my return.
Amazon tells us we’ve returned a fraudulent item because the Serial # do not match. Multiple emails (5+) back and forth with Customer Service to explain fall on deaf ears. We give them both Order IDs. We ask for ANY option to solve this mess. We’re told repeatedly that this is their policy, their decision is final, go away.
Amazon won’t even send us the headphones back so we can send the correct ones — those have been destroyed.
“To protect our employees and customers, we have disposed the incorrect item that we received as per our policy.”
In a nutshell Amazon stole $250 from us, and is apparently creating tons of e-waste by destroying brand new, unused and perfectly good returns like ours.
I expect this has been considered when creating policy at the largest companies — what’s the ease of obtaining recourse for unhappy customers?
What’s additionally interesting is I thought Amazon CS had a degree of goodwill factored into policies based on LTV or some other calculation. We saw zero goodwill here despite having spent >$100k on Amazon.com in the last 5 years.
Both this and the YouTube example seem like bad business; you’re disincentivizing your most ardent users from continuing to tolerate your services. They hadn’t looked at shopping on Walmart or B&H with every purchase previously and now will. They hadn’t considered Twitch or other places to serve video and now will.
Then they’ll just keep doing it.
Logitech, Kaiser and Capital One all suddenly changed their tune when the AG simply forwarded my complaint.
They’d sold a LIFX to Customer A who bought a $0.69 BR30 from Home Depot, substituted into the LIFX packaging and then returned to Amazon, who refunded them, and listed the item on Warehouse Deals.
On that one Amazon CS was also somewhat useless but they did at least refund us.
When it eventually came to a senior leaders attention, Amazon got it sorted out properly. They ended up auditing all their stock in Warehouse Deals for this type of item and discovered widespread fraud. Sounds like they fixed smart bulbs but haven’t fixed GPUs though!
I'm on the verge of getting banned as they've warned me I'm returning too much, and have had enough negative interactions with their support that I'm in a similar boat.
It's been somewhat freeing giving them up. There's plenty of D2C out there we've been neglecting due to AMZs marketplace...
I don’t understand Amazons destruction policy. I ordered some stuff a few years ago and it never arrived. Amazon replaced the order for me which arrived in 4 days. About 5 months later the original package showed up… I tried to contact Amazon about it and they just said keep it…
Yet when my kindle stopped working after a month they sent a replacement and asked for the old one to be destroyed…
Ebook / audiobook and other licensed-not-bought content may no longer be accessible.
(I avoid this problem by not shopping Amazon full stop.)
The ability to do charge backs will probably disappear in future. When the system was created we didn't have the same ability to authenticate cardholders that we do today and many jurisdictions didn't have small claims courts.
I'm tired of these giant companies having their cake and eating it too. These companies have structured themselves in such a way that it's win-win for them, and lose-lose for the customers and smaller businesses around them.
With great power comes great responsibility.
The problem is that for any of the new security features of cards to drive any of those kinds of changes the old mag-strip style of card authentication has to be deprecated and removed - which is likely not going to happen in the next 20 years.
Visa and Mastercard (and the layers between them and the merchant) have tried pretty hard to apply financial pressure (extra fees) to promote chip-only transactions and it still hasn't stopped mag-stripe from reigning supreme.
We're basically in an IPv4 and IPv6 situation in the payment industry =/
didn't amazon pledge to stop destroying functioning products or was that just in the EU?
It makes it even worse wenn we all know that if a person has enough clout or gets enough attention it isn't final.
If you are going to say stuff like that, then you should keep your word and when you do make a mistake don't undo that mistake. Live with the bad press you are going to get for being the assholes you are.
If they’re not willing to change their mind, at least say so.
In reality, i simply signed in with github because why not and suddenly everything is gone. A single email from github about "engaging in illegal behaviour of star farming so my account is deleted".
I signed in to github, i just clicked a bunch of buttons simply out of form fatigue and in the background, the dev had used my account to star their repos.
the problem is, why not punish the dev and why me? if the workflow was sign in, why did it allow my account to be used for stars farming? secondly, why to blame me? did i willingly engage in stars farming when i clicked on "sign in with" ?
they said the same thing, "decision is final". I made a bunch of noise on HN and tomorrow everything was back in order for me.
Learning outcome: dont use sign in with. ever
That's horrible, I'm so sorry that happened to you. But I think that's the wrong learning outcome. As a technology, OAuth uses scopes to grant permissions. You mentioned that you didn't read the permissions before granting access. An app that requests zero scopes is still safe, as it can't star repos for you, but the burden falls on you to read. This is inherent to the design of OAuth.
There is a problem with GitHub scopes being overly broad, and users can't audit what an app actually does with those permissions. GitHub and others should be policing apps that request unreasonable permissions.
Auditing is only one problem.
Why is granting permissions an all-or-nothing approach?
Way too many apps are requesting all the permissions. If I want to use it, I've got zero choice. I want an 'Advanced' option with a way to deselect certain permissions.
JIRA wants all the source code for your entire organisation.
Tailscale wants to read all the organisations you're a member of.
The problem is not just limited to Github. Grafana's Slack apps want to be able to read the entire Slack organisation, post messages as me, and a whole bunch of other things I'm just not comfortable giving it.
1. If you can't be bothered to read the terms, then don't use OAuth. This is GP's conclusion.
2. If you are willing and able to carefully read the scopes, and you are willing and able to abandon the app if the scopes are too broad, and you comprehend the meaning of the scopes, then use your discretion. But that's a lot of conditions, so...
3. All scopes should be revokable by the user, and potentially spoofable at their discretion.
4. The resolution of scopes should strike a balance between being understandable and following the principle of least privilege.
5. GitHub and other OAuth hosts (even all app platforms?) should audit apps for misbehavior, both in abuse of permissions and unnecessary permission requests. Especially when the user regrets the actions taken by the app.
Unless and until GitHub fixes its combination of allowing overly-broad authentication/authorization scopes and victim-blaming over abuse of said scopes, the above is precisely the right learning outcome. At the very least, if GitHub supports programmatically adding 500 stars, then it should be downright trivial to support programmatically removing those 500 stars and giving the user a slap-on-the-wrist warning if the user really is the one at fault.
It's the right outcome. Why would you tell microsoft anything besides your interactions with github.com
There were some explanations, that they are sincere and they do only good thinks, but i retreated
Yes? You clicked accept to give access to an application to do stuff on your behalf. It is 100% your fault you didn't read what the very clear prompt said to you.
That being said, the owner(s) of the application in question should be banned for their malicious practice of stars farming, and I don't see why you would be.
* Have another team review the complaint
* Be more transparent as to the "offense"
* Have an appeals process other than direct messages
* Click the button to unsuspend the account, since they run the software
* Give him a phone number to call to talk with a real person
Remember, when using Big Tech products, you are not a customer, you are the data.
I wonder how well customer service serves AdSense customers?
YouTube is making money here.
The issue is that YT (Google/ Alphabet) is making so much money from so many folks that they don't consider it significant to mistakenly screw over one producer at a time, because they've got millions of others.
Even for large channels, YT allows false copyright claims by large companies to hit the producer in the wallet, because Channel Bob 1M Subscribers doesn't compare to Mouse That Thanks China For Filming Near The Concentration Camps.
But the whole time, Youtube is making money on ads.
If that big cloud hosting company decides they don't like your company anymore, and you've put all your eggs in that one basket - that's your fault.
There's ample evidence now that big tech companies are elephants that don't even notice the ants they're stepping on as they lumber around.
Built your entire company on AWS, or Google or Azure? You're a fool if you haven't built it to survive a cloud chucking you out.
Most unfortunately, there's no alternative platform for YouTubers. Hard to understand why no company has directly taken on YouTube - not Apple, not Netflix, not Amazon, not Microsoft - until there's an alternative platform, YouTubers just have to hope they don't stray in the way of the elephants foot.
Up until recent history, it was a money losing business. I’m sure that’s turned around now but mainly through heavily injecting ads. It would be difficult to disrupt them because of the network effects of all the content, viewers, and creators. And it would be hard to compete on price (whether subscription cost or amount of ads) without having the kind of infrastructure Google has.
It might be done in the future, but it will be anything but easy.
HNers are more likely to use an ad blocker so they may not quite appreciate how severe this has become. I recently switched my casual/kitchen computer from an old MacBook Air (where I’d browse with Firefox and uBlock Origin) to an iPad (where I use the YouTube app) so I got to experience the difference first hand. The amount of adverts is horrendous - two sometimes-skippable ads every three minutes. I guess they want me to go for YouTube premium, but I have simply been put off from using YT altogether.
So that’s now Twitter and YouTube who have lost me as a user just through sabotaging their own product :-)
Nebula and Floatplane did, though both are relatively small.
Onlyfans and Patreon have so far been relatively active as well.
What all these three have in common is that they're for paid subscribers only, the only way this business can be sustainable.
Plenty of companies have tried to take on youtube in one way or another - Vimeo was a very similar product before they pivoted; some youtube creators also post to Floatplane, Utreon, Nebula, Odysee etc; and many social media sites that used to be awash in youtube links now have their own video hosting.
But youtube seems very durable.
Good reminder to back up all of your Google data[1], just in case they determine you've violated some random policy and terminate your account without any warning.
[0]: https://twitter.com/craig1black/status/1645655035517476865
Adrian specializes in mostly Classic mac and apple hardware
A company I was involved with had a business account with Wise (Transferwise). One day out of the blue they froze our account and said only withdrawals from now on. The "reason" they provided was Violation of Acceptable Use Policy. They wouldn't even say which clause or give any details whatsoever. When asked for review we got an reply that after extensive review they can't reinstate the account, the decision is final. During the whole process it was painfully clear that they didn't read our messages or even try to understand the situation. After a few weeks and many emails with supporting evidence that we really can't see how we broke any of the terms the account was reinstated - a surprise to us. It seems like eventuall someone actually did take a look at the issue. But we never heard why it was frozen in the first place or what made them reinstate it. We probably just got really lucky. During that time we couldn't do payroll. We couldn't collect customer payments. It could have killed us did we not quickly scramble to get an alternative setup.
The common theme is that a company makes ill-advised banning decisions that have a big impact on a single user and then appeals are not treated seriously. This can have devastating effects. Usually this happens after the company who is running the platform grows to a certain size where they don't need to care about a low percentage of users anymore and rather save on support staff costs. And to add insult to injury they lie in your face about having conducted "extensive" reviews and having "carefully" decided all the while it being clear that they spent no energy or time on the matter. What's the solution here? Some mandatory third party appeal service which you can call upon? Many victims of wrongful banning would be glad to carry the costs of a review by a real human to get their accounts back.
Maybe he posted comments using that account which broke the terms?
> He never even uploaded a single video nor post any comments.
He wasn't really using it in that way. It was a pure video watching account.
Google just doesn't care about you - regardless of your size.
The fact people can get session jacked by Google, though, is still wild. Linus explained that their access control granularity is woefully underdeveloped, especially for such a large company.
Google and especially Youtube seem to be run in a reckless, careless and incompetent way in this regard. Similar to Youtube seemingly being uninterested in solving the huge comment scam problem. I don't buy that the company that successfully filters out billions of spam messages in Gmail can't detect these really obvious spam/scam comments on Youtube. It's just baffling.
Well.. I hate to be the one to tell you this, but they actually do[1]
[1] https://www.protocol.com/policy/onlyfans-visa-mastercard
And no “Google decides”. Google is not an AI (yet), people make decisions so everything “carefully reviewed” is [not] done by a human.
But honestly it’s high time to break up Google. 0 customer service and 0 consequences is incredibly crazy in 2023. Imagine getting away with stuff like this in a retail store, regulators would shot you down in a second.
TGIFs would often shed light on such policies and issues which resulted in behaviour changes. No idea if that's still the case though.
One thing I do have insight to from working at multiple companies is that for every error in applying policies there are often 10s or 100s of individuals trying the scam or abuse the same policies for their own gain. The amount of attempted fraud for non-profit / charity programs is eye opening. :/
Honestly, they should be required to simply have a case worker look at everything if the person has exhausted other options. Those other options should be easily found on the company's website (or facebook page, etc). And the case worker should actually have the power to decide either way, free from coercion and without quotas leaning either direction.
Remembering again, perfection is the enemy of good, what we have here is more than good enough for most of the cases perhaps.
In 2041, Google begins offering a service where you can pay $28 ($50 in USD2041) for a human to review your claim. Since it costs them $8 to do this, they will allow you to appeal their decision as many times as you want.
In 2042, a data analyst discovers that routing claims to a specific subset of reviewers maximizes this revenue stream and updates the business logic accordingly.
This is supposed to be a win win for both the platform and the user and not a source of revenue.
Of course if google decides to try and squeeze a couple of extra bucks of profit from this then it is useless.
Though it should be noted it's not the Adrian's Digital Basement channel that has been booted.