Live data from Hacker News

Ask HN: Should we own the free stuff we pay for?

news.ycombinator.com

191–200 of 309 posts

Re: Ask HN: Should we own the free stuff we pay for?

#191

Earlier quoted context omitted.

How would you even solve porting without breaking legacy systems? You can point the MX records to another provider's server (or your own), but porting single email addresses won't really work.

You could easily oblige forwarding. You cannot shut someone out and then not allow them a) a backup of all data noe unavailable and b) and auto forward to an email of their choice.

Alas, email forwarding is fairly broken since DKIM/DMARC/SPF/SRS came into the picture.

As for not allowing people to save their data before shutting down, I agreee. That's a consumer rights issue though, and not a technical one.

Re: Ask HN: Should we own the free stuff we pay for?

#192
You can't compel a company to provide you with a service. That's a little too close to slavery for society's taste. If a company doesn't provide you with a service you agreed to, you can get damages from a court, but you have to use such services as your contract agreed.

It stinks to end up on the wrong end, but that's part of the cost of getting such massive benefits for free. If you want something more reliable or with better customer service, you have to pay for it.

You don't own phone numbers, emails, names, PO boxes, or addresses. You have them within a legal framework, and you can lose them in that framework. Software products may treat them as unalterable identifiers, but none of them are. Things should always be able to be changed.

Re: Ask HN: Should we own the free stuff we pay for?

#193
I do see this overall situation being at least partially consequence of the early internet community thinking that internet could live outside any traditional structures and especially laws. There was this strong sense that we could forge a new ultra-liberal virtual world, free of the shackles of the physical world. In retrospect that way of thinking now feels pretty naive. That led to outright hostility towards any ideas of government-rooted electronic identity programs, or anything resembling that.

The reason I think government identities are significant here is two-fold. Firstly it left an vacuum for identities that email, despite its obvious shortcomings, then filled. Secondly, weak unconnected identities provide poor means of dealing with abuse.

Sibling threads discuss how kicking people out of e.g. banking or rental involves some legal processes or something comparable. But in those cases both the barrier of abuse is higher because usually there are real consequences, and doing whatever legal process is more practical because the other party is not just some John Doe. In contrast the scale of abuse something like Gmail faces is pretty staggering, and the ability for the operator (Google) to do anything about it is somewhat limited, so it is somewhat understandable how they ended up so trigger happy with bans.

I posit that if we were able to implement real consequences to the actual abusers, then we well-behaved users could have stronger standing to demand better treatment for ourselves and we would be less likely to face the current level of opaque algorithmic bans.

https://en.wikipedia.org/wiki/Technolibertarianism

Re: Ask HN: Should we own the free stuff we pay for?

#194
post #80

Earlier quoted context omitted.

I’ve never heard of someone being their own registrar. Was this hard to set up?

It was about five minutes of filling a form with the national authority. There are some responsibilities that you get along with it (e.g. you're supposed to do risk assessment and document your approach to risks and security, etc.) but you don't actually have to deliver those documents unless they ask for it. They may also require you to respond to some questionnaires and such (I've received only one questionnaire ov…

Here, I'd have to do it on a company, and it would cost $9000 upfront and $2800/year. Not worth it. :)

Free domain lock against NS changes and domain transfers with national TLD authority seems good enough.

Re: Ask HN: Should we own the free stuff we pay for?

#196

I'm curious about blockchain solutions for this. Public blockchains have potential to be part of the solution. Imagine the following: - Decentralized file hosting using IPFS - Decentralized login using ENS / Ethereum Name Service - Email service gives you a UI on top of your data, plus an outbound server for relaying to/from non-blockchain email accounts Overall, you end up with portable data thanks to IPFS, and a lo…

Here's the start of what that might look like: https://ethmail.cc/

As far as I can tell this is just like regular email that you login using your Ethereum Wallet. Data is still stored the web2 way.

Re: Ask HN: Should we own the free stuff we pay for?

#197
> But I lost access to paid services that I had set up with social login, besides all Google's services ( GCP, firebase, youtube premium, google one, subscriptions paid through play store, google ads, etc, etc).

So you gave Google total control over your entire online presence, tying a bunch of things you depend on into a tight bundle that would all get banned at once. And, by including so many things, you created more opportunities for something you did with one of them to trigger a ban of all of them.

> The google stack is very convenient,

... except when you get totally shut down for no reason. Which is an absolutely predictable consequence.

You have a very strange idea of convenience.

> and it's 2022, I'm not going to start hosting my email server,

This reads to me as "I'm unwilling to take even the most trivial steps to solve the problem".

> But what if I get reported on my domain name? What if that gets suspended or blacklisted too?

That is a risk, but, at least as of today, it's much, much harder to get a domain name shut down than to get something like a Google account shut down.

Nonetheless, you should probably be isolating things that are really important to you under separate domain names unless they NEED to be tied together.

> Do we own our phone numbers, emails, handles, PO boxes, addresses?

The user agreements for most of those will say no. The standard on the Internet right now is "We can cut you off for any reason whatsoever and you have no recourse". It's right there in black and white. And it's been that way forever. Maybe it's wrong. Maybe there should be legal changes. Maybe there should at least be changes in common expectations. But at the moment, that is how it works.

So don't become overdependent on any of them, and don't set up a situation where losing one also loses others. This is pretty basic stuff.

Re: Ask HN: Should we own the free stuff we pay for?

#198
post #30

When you put it this way, it's really quite remarkable how tenuous our hold is on even paid for digital services. There is really nothing you could do with a car to prompt the car maker to take it from you. And the state will only take it if you break the law in particularly dangerous ways. When it comes to other possessions it's even harder for anyone to take them away from you. If I take a kitchen knife and stab so…

> If I take a kitchen knife and stab someone with it I will go to prison for sure, but I don't think they will take the knife away. They definitely won't ban me from buying knives.

This is true. Generally if you stab someone the police would seize the knife as evidence, but after your trial if the prosecution didn't file a forfeiture case against the knife, then it is still yours and you can get an order from the judge to return it :)

p.s. civil forfeiture cases give the best names, e.g. United States v. Article Consisting of 50,000 Cardboard Boxes More or Less, Each Containing One Pair of Clacker Balls, 413 F. Supp. 1281 (D. Wisc. 1976)

Re: Ask HN: Should we own the free stuff we pay for?

#199

I also lost access to a previous gmail account - I changed my password with a random generated one, and god (and a google engineer) knows why, I lost access. No amount of appealing would return my access, even if I was wiling to show my national ID card and stuff. Anyway. About your plan with the email server. We ran such a thing for an organisation in Romania. You'll be surprised how many times our emails ended up i…

Google doesn't get social engineered into handing over user accounts since maybe a few hundred people have any access to the Google Accounts system proper, less so for the gmail.com organization (Workspace Support can help with recovering an Admin account in an org). Introducing a way to retrieve an account via human intervention makes the chance of someone taking over a Google account via malicious social engineering, incl. faking national ID cards, non-zero. In fact, i'm sure tons of people have been able to take over accounts using account recovery[0] where it'll ask you things like "when did you create this account" and "what was the phone number you put on the account".

0: https://support.google.com/accounts/answer/7299973

Re: Ask HN: Should we own the free stuff we pay for?

#200

Earlier quoted context omitted.

Most cars do not do this. Teslas are famous for their DRM, restrictive connectivity, and shady upsells. Those will show up in the "cons" column of any honest review. A normal car in 2022 will not constantly surveil you. No critical functionality is tied to an online account in any non-Tesla mass-produced car that I am aware of.

Neither of these points are true. Other manufacturers like Toyota are getting into the "features as a service" game with things like keyless entry. On the surveillance point, I worked for an auto software company that partnered with a big auto manufacturer on a feature. We were granted access to an API that could geolocate any vehicle made by this company in real-time given its VIN. I volunteered my car's VIN to test…

That is amazing since VIN's are often visible from the outside. This is just so open to abuse, especially if it was a casual to lookup as you make it seem (no verification that you were the owner and for just a lark). We as engineers need to establish a code of ethics. Seriously, every profession needs to have a "do no harm" clause because clearly companies have zero ethics.
Post reply on HN