428 karma · joined September 11, 2013
Location: Palo Alto, CA
Remote: yes
Willing to relocate: no
Technologies: software engineering leadership
Résumé/CV: https://www.linkedin.com/in/sbonds/
Email: scott@ggr.com
Software engineering exec. 20 years of leading transformation and growth with both consumer facing and backend software.Secret sauce:
1. deeply technical but also have experience leading product
2. know how to take UX to 11 from my time making video games
3. leadership nerd passionate about org health, teamwork, and culture
Bonus: led through the full journey from series A to profitable
Looking for:
1. B2C
2. team of 50-150
3. cares about profitability
4. cares about org health
5. not centered on trendy tech, i.e. not web3
" Hello brokeninfinity, We're pleased to let you know that your account is reinstated.
If you had any listings that were removed when the account was suspended, we've restored those listings... "
Perhaps this discussion caught an eBay-er's attention, and if that was you, thank you for helping out. And thank you HN for helping call attention to my case.
That said, it shouldn't take this sort of attention for eBay to do the right thing. My point stands that eBay inappropriately suspending accounts without explanation or hope of appeal is not ok. And the email reinstating my account did not contain an apology or an explanation of what went wrong, so while I appreciate it, it's not enough. eBay needs to stop treating people this way.
The first link led me to the State of California Department of Consumer Affairs. I filled out the form to file a complaint and got an error: "The requested URL was rejected. Please consult with your administrator. Your support ID is: 18093870959457122962". LOL it's dead ends all around. No one wants to hear from plebs.
I'm not giving up though. I'll go through your links and I'll figure out how to get through to someone. Might have to write a physical letter. :)
AFAIK eBay doesn't support WebAuthn. I got a set of 3 Yubikeys some months ago (1 for my laptop, 1 for my workstation, 1 for backup in my fire safe) and I wanted to protect my eBay account using them, but eBay only offers me options to add SMS or eBay's mobile app as 2nd factors.
I got a flurry of what looked to me like phishing emails 'from eBay' right before my account was suspended...they claimed to cancel my bids on a bunch of old, long over auctions, with the call to action asking me to click on link with a URL referencing a local DLL.
So yah, something fishy is going on, but I can't help eBay figure it out if they just disable my account and make themselves unreachable. Is this what ghosting feels like?
My brother got kicked off Facebook a couple weeks ago because his account was hacked and they couldn't decide who was legit and who wasn't, so they just threw up their hands and shut down his account. It hurt because he used Facebook a lot.
I agree that 2FA doesn't solve the problem of companies deciding not to invest in good, considerate, human, security conscious, customer support. More technology isn't always the right answer, especially when it comes to questions of companies harming and then dehumanizing their customers because it's cheaper than doing than the right thing.
That's fair. FWIW I wasn't trying to focus on Linux in my post. I'm grateful for Linux and the volunteers that contribute to it, both the apps and the security work. The work everyone is doing on FOSS lifts all boats. And you're right of course, not all Linux distros are created equal when it comes to security. And my anti-privacy, anti-security sentiment was more pointed at proprietary software, i.e. a lot of iOS apps.
When my father-in-law bought a computer from Costco a year ago, it was full of malware from the start. He didn't care about the spyware--it was the constant popups, and the prompts to enter credit card info and login info that was the most worrisome. When my 'mom' sent me an IM message from her Hotmail account, claiming to be somewhere in Europe and needing emergency money, I had to call her up (she was not in Europe), get her to rotate her passwords on a bunch of accounts, work with her work IT team to investigate the security breach, etc. I've had one of my personal OpenBSD servers sucked into a DDOS zombie army (did I mention I'm a security newb?) and had to wipe the thing, rebuild, and ponder my mis-configuration sins. Security is hard enough (for me anyway) as it is without starting on a less than ideal foundation.
Criminals, for the most part, are (just) trying to steal money from people I care about...and when they're lucky enough not to lose their money, it can still cost a lot of time.
States have power over life and death, and there are plenty of examples in the US and elsewhere of bad people in government abusing their power to the detriment of relatively powerless people (and giving all the good people in government a bad name). I don't want to live in a police state, where saying the wrong thing over email can lead to bad things happening to me. We're not there yet (in the US), but we're not pointed in the right direction either. I think FOSS, secure software has a positive, important role to play. It cannot answer the larger political questions, but it can help, if only to buy us time to have the debate before the abuses get too far.
That's not to say there aren't distros and contributors to Linux that care deeply about security--clearly there are. I just don't find the overall ecosystem nor the most popular distros nearly as focused on or as trustworthy on security and privacy. And as the stakes get higher with more of our lives going digital and more companies, states, and criminals trying to take advantage of that trend, I worry.
As for OpenBSD vs FreeBSD, I've had an easier time getting OpenBSD working on my hardware and OpenBSD seems to me more concerned with, focused on, and practically innovative on security--that is to say, they don't just introduce new security features that can be configured and used by someone smarter than me, the OpenBSD folks work hard to introduce new security tech that's on by default with no special knowledge required by the end user, i.e. pledge, W^X.