Live data from Hacker News

“PayPal has demanded that we monitor data traffic as well as customers’ files”

seafile.de

231–240 of 348 posts

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#232
post #220
post #161

Earlier quoted context omitted.

Hashes, even md5, are pretty good about going nuts when even one bit is changed in the input. And video codecs (speaking very broadly) are tolerant of a bit error rate like 1e-9 or they'd be useless over the air or on optical media. So simply have your torrent client randomly flip 1 in a billion bits as it downloads. The md5 will never match and the movie quality will be unimpaired.

so if a billion people were to download it, lucky number one-billion would receive a completely garbage file. Ok, ok. That's not statistically likely to happen. But you do have the problem then of other files being shared via bittorrent, it's not all movie files. You'd also have to re-start basically the entire BT network too, as all clients would no longer be backwards compatible - Good luck too getting every single…

Ah the incorrect assumption is that what the filesystem and dropbox scanners see must equal what the torrent client talks about, which isn't actually true.

A preselected and stored in a dotfile or windows equivalent 9 digit number, or the bottom nine decimal digits of a MAC address, or some chunk of a UUID, or whatever. You could salt which bit is gonna get flipped by adding in the filename, or the partial timestamp of the first time the torrent client was ever executed, or one way or another your specific client has a secret nine digit decimal number that it only uses for file operations involving .mp4 extension files longer than a gig (or whatever seems appropriate).

One way or another when you copy a buffer from the torrent system to the filesystem you flip every X-th bit where X is stored locally. Make sure to flip it BOTH when downloading and again when uploading. Your video player won't care when it impacts a single bit error, the other torrent users won't ever know because they never see a flipped bit. Well, technically other torrent users see a flipped, flipped bit, aka the original, unless you're using trinary or something (LOL)

Maybe a mental model is imagining it as the worlds most incompetent FUSE/loop encrypted file system such that the "encrypted" contents on the hard drive have only 1 bit in 1e9 bits flipped and otherwise the remaining billion bits are identical to the "unencrypted" file. Only for "long" .mp4 files, perhaps.

The main problem that would develop is people downloading a torrent, then trying to seed using a machine that has a different "secret bit" above. It would look like your seeder has a tiny bit of file system corruption, which I guess does happen today and is apparently survivable. I would guess most people most of the time do not download a torrent on one system them upload a new torrent on another machine.

There need be no coordination with torrent client devs. Someone could implement this today without anyone else knowing, or it could be done using a FUSE loop filesystem without changing the torrent client at all. I suppose if you never seed a file after copying it to dropbox it would be easy to write a "special cp" that inserts bit error rates around 1e-9 rather than making a perfect copy.

I have no idea based on security posture if you want to slightly obscure every file or just some. Also no need to flip a completely random bit, a smart enough parser could pick the next bit that won't utterly trash the container spec for avi or mkv or ogg or mp3 or pdf or jpeg. So I'm saying flip the next bit that isn't a major file format protocol bit to make it user transparent.

Another weird mental model is think of it like steganography but to defeat 3rd party hash scanners not to hide real data. In fact its hiding not much.

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#233

Paypal only exists because the current infrastructure of payments in the US is a joke Nobody needs paypal in Europe. Of course, they try to sell themselves as "the easiest way" (which is right to a point) but it's mostly unneeded

As a german that's not my experience at all. Credit cards aren't that common here and SEPA transfers are slow as hell and always a minor hassle, that I tend to avoid as long as I can. Without Paypal a lot of european customers wouldn't be able to buy from international vendors.

I'd like to recommend the bank Number26. They're german and operate across most of europe.

https://number26.eu/

Seriously, if you're european, try these guys out - they're worth it.

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#234
post #141

Earlier quoted context omitted.

What about debit cards? I mean, you don't carry cash around all the time do you?

Of course not. Yes, in fact bank-issued debit cards are the default here.

Worth pointing out that "bank-issued debit cards" in Germany usually refers to EC Cards, which is not the same as the Visa / Mastercard debit cards the rest of the world is used to. As a tourist in early 2015, international Visa & Mastercards were useless in most supermarkets & department stores - but international chains that get lots of tourists will take them (eg Starbucks, McDonalds, Subway etc).

I love Germany, but the credit card thing drives me nuts. I understand Germans like financial privacy, but I like having an electronic record of my purchases instead of having to write down every cash transaction I make before I forget it. (If there was a way to get a prepaid EC Karte as a tourist, I might not mind so much.)

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#235
post #232
post #220

Earlier quoted context omitted.

so if a billion people were to download it, lucky number one-billion would receive a completely garbage file. Ok, ok. That's not statistically likely to happen. But you do have the problem then of other files being shared via bittorrent, it's not all movie files. You'd also have to re-start basically the entire BT network too, as all clients would no longer be backwards compatible - Good luck too getting every single…

Ah the incorrect assumption is that what the filesystem and dropbox scanners see must equal what the torrent client talks about, which isn't actually true. A preselected and stored in a dotfile or windows equivalent 9 digit number, or the bottom nine decimal digits of a MAC address, or some chunk of a UUID, or whatever. You could salt which bit is gonna get flipped by adding in the filename, or the partial timestamp…

All that sounds a lot of effort when the reality would be they'd just check the file in a different way than full-file md5 hashes as soon as this appeared.

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#236
post #3

> PayPal has demanded that we monitor data traffic as well as all our customers’ files for illegal content. They have also asked us to provide them with detailed statistics about the files types of our customers sync and share on https://app.seafile.de That's a pretty big WTF right there. I know PayPal has a on overall pretty scummy reputation, but I still I cannot imagine PayPal doing this because they themselves th…

Regulations will probably come in the form of making these types of checks mandatory. See, for example, how US Senators pressure payment providers to check up on whether their customers may be profiting from illegal file-sharing: https://www.leahy.senate.gov/press/judiciary-chair-leahy-urg... If Dropbox-style hash checking of files could be seen as the standard in the industry, I can see how failing to do that could…

Could be a good argument for client side encryption.

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#237
"AML" this is all cover for CIA economic espionage as always the people asking the questions are the competitors. Who need know how, who and where your customers are marketing reasons to undercut your prices for selected customers! You see never hand over your member list when you don't know who the end users are. Think T-mobile and at&t then about the switch offers to selected user based on data usage.

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#238

I'm once again astonished with how much control of our businesses is simply out of our hands. When looking at practices these financial institutions use it makes me wonder what can't they do? Everyone cites "regulations", but as far as I understand, they make the regulations. Directly or indirectly. Take for example the known cases where PayPal freezes accounts holding people's money. If I take someone else's money a…

OK but for the most part when Paypal or others close down your account and/or freeze funds, you /have/ done something illegal. You may not care about billions of dollars of movies, games and tv shows being pirated, but the people who pay for them to be produced do, so the banks and others protect their rights. As far as kickstarter and so on, this is to prevent your customers from being ripped off, which has happened where KS project never delivers the project and so on.

For sure banks and paypal have overstepped but I wouldn't call it "madness". If you want to sell filesharing accounts try bitcoin, I hear it works very well

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#239

Earlier quoted context omitted.

>Agreed; with both of you. Maybe it won't be crypto-currencies, but Paypal Has To Go®. Let them screw up two or three more times. They've already screwed up and screwed people over publicly dozens of times. Paypal does have to go, but I don't think paypal will die until someone offers an equivalent service.

> They've already screwed up and screwed people over publicly dozens of times. If that's the standard, there likely isn't a single major corporation that'd meet it.

Most large companies work hard to keep customers happy because the competition is down the street. PayPal benefits from barriers to entry and a two sided market to make this less of an option for merchants.

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#240

Earlier quoted context omitted.

>Well, over here everyone I my case it would be down there... Took a second to figure out you're probably not in the US. It's more or less the same here, almost no one has real credit card, they're mostly VISA (co-branded) or MasterCard branded debit cards, but everyone has a card that can be used online.

> It's more or less the same here, almost no one has real credit card, they're mostly VISA (co-branded) or MasterCard branded debit cards Er, no. Almost everyone has a branded debit card, as most banks will give you that for free, but nearly 75% of the country has at least one actual credit card.

Those debit cards only work for in-person transactions however. Some German companies let you do direct debits or bank transfers for online payments, but it's very annoying compared to a real debit card.
Post reply on HN