If that’s wrong, and they were removed, then you’re completely right and everything I said is very wrong.
104 karma · joined January 7, 2022
If that’s wrong, and they were removed, then you’re completely right and everything I said is very wrong.
There’s a couple of ways (that are best practices for any company) to avoid this problem: - Have separate Google accounts for work / personal use - Remove old employees from the developer account when terminated
Risk bans or bans for suspicious / illegal activity? Totally different story (see the stories of Stripe / PayPal / etc shutting down accounts). The government (at least in the US) will punish banks pretty hard if they don’t crack down on fraud hard, so banks tend to lean more towards over enforcement.
Fraud is hard. If you don’t crack down enough, you get in trouble with the government, many legitimate account users, and companies working with you. If you crack down too hard, you might mess up people’s lives who did nothing wrong. Even with an appeals process- its rare to get everything right. I think the reason we had about it with big tech so much is because their userbase is so large, so even with a low false positive rate, you’ll see high numbers of people getting flagged.
I see your point, though.
If the signals used are made public, fraudsters will win every time. It’s the same with search engines- if they publish how a score is calculated, people will game it immediately.
Maybe the signals should be required to go through a review with authorities? Idk.
On the other hand- at every company I’ve worked at, this is why there’s clear onboarding and off boarding policies. Yes- if you have someone on your developer account violating terms of service, they’ll shut down the account. No, it doesn’t matter that it wasn’t you personally.
To put this differently: if you had a bank account shared between your developers, and someone who left the company started using it for money laundering, the entire account would be shut down and you would not be getting that money back. In fact, you might even be investigated by authorities for money laundering since it ran through your account.
As someone who works in FinTech, we deal with tons of people just trying to steal / defraud others on a daily basis, and we’re required but governments across the world to be on the lookout for people doing “fraudy” things and terminate their accounts ASAP. If we just said “oh, it’s fine, you’re not in trouble because your (insert X relative here) was the bad person, not you,” then social engineering fraud would be rampant everywhere.
To me, the Google situation is identical to the bank situation. There’s not a good way to prove the bad account shouldn’t be associated with your Play store account. This is why you have to be diligent about who has access to these things.
This is just regulatory capture cementing the OS owners above app developers.
Now it’s scheduled to fall over in about 6 months and everyone is freaking out again. It’s not new features that are hurting us, it’s the existing core product line. All the new stuff is built on horizontally sharded DBs from the get-go.
I feel bad for this person because it’s a horrible place to be stuck in, but even if Google had great customer support allowing people to reset passwords over chat / phone would be ripe for abuse
Other examples of where cross-site tracking is useful is for preventing online payments fraud. You have a similar IRL version of this where your bank will freeze your card if it sees purchases being made in different countries simultaneously.
Somewhere along the line, counting views or helping reduce fraud for customers turned into “store full demographic information about someone who never signed up for our service”, which is where everything went wrong in my mind. The cookies themselves aren’t the problem, it’s how they’re being used.
Debt forgiveness addresses a symptom, not the core issue. I support it because I’ve seen firsthand how much of a hole it’s left people who made bad choices as a high schooler in, but we can’t keep making the same mistakes that got us here in the first place.
I don’t really care where I work, but I’ve come to strongly value travel / face time with my coworkers given that my team is fully distributed and Google Meet is just not the same as meeting someone face to face. For example, I ended up having a 5 hour rambling conversation about the history of our company with another coworker which suddenly shed a lot of light on why I wasn’t able to make progress pushing for certain org-wide changes. This would’ve never come up in a WFH context, since it’s “inefficient socializing,” but in the long run it’s going to help my communication skills a lot.
And the last thing: whenever I’m in the office, I get lots of interruptions, mostly from other ICs (I’m a tech lead). Although my personal progress slows down, I’ve noticed that my coworkers all move faster because they tend to be more likely to ask questions in person than scheduling meetings to pair. In person we tend to dive a bit deeper into the “why are we making this change” which helps people grow more than a direct answer to the “what”. To be honest, Slack and email are far worse distractions for me than the office ever is.
"get the 10 latest comments on this market, plus the associated avatars" couldn’t be better suited to a relational DB. That’s a textbook use case that Postgres would be amazingly well suited to.
Also: remember with Firestone that you’re paying for redundancy and availability that’s entirely Google managed. Most DB offerings you work with on your own are significantly more hands on as far as recovery / backups / replication go.
Engineering time is usually more expensive than server costs when you’re a startup, so think about how much time it’d take to do it yourself before you decide to optimize your server costs over R&D costs.
Plus it’s all a moot point because you need blackout curtains for good sleep in the area anyway.
There’s more challenges around the short term disabilities, but pretty much every US state has a low-income / zero-income healthcare program that helps cover those individuals.
And as for overall homeless numbers, the US is pretty much middle of the pack per-capita with a lot of European countries: https://en.wikipedia.org/wiki/List_of_countries_by_homeless_...
The only place where you need more completeness is if you’re building a social app, in my experience. People want to be able to respond to messages everywhere.
Take away the delivery companies’ bad practices, you take away the Google experience the restaurants don’t like.
They’re just an aggregator and get paid in referral fees. The value for you is in the aggregation engine.
The WAF took away at least 99% of our random nighttime pages from the bad payloads. Best investment we made for oncall quality of life.
It’s a really hard problem.
Now, none of that means that Google can actually build and market a chat app correctly, but I’d say these are all “top engineering talent” foundational infra that only are needed at companies that operate at that scale.
As a US citizen I just don’t really care anymore, I sometimes get a good chuckle every time someone tells me I’m oppressed or living in a hellhole. I’m happy where I live and though I recognize there’s faults and I do try to improve them where I can. Maybe it’s state actors, maybe it’s not; I wouldn’t care about a stranger’s opinion in real life, so why would I bother caring about a stranger online? Too little time in life for that.