Live data from Hacker News

Security researcher gets threats over Amazon review

techcrunch.com

21–30 of 86 posts

Re: Security researcher gets threats over Amazon review

#22

Earlier quoted context omitted.

If you're a US citizen, you would be a bit better off if it was a US server, because the records from the server would be available to the US court system. This is helpful if a customer ends up suing the company, or if there is a security breach that is investigated by US-based law enforcement. I agree, the inclusion does hint at Sinophobia. But it's also a valid detail for security conscious customers to consider.

Why is it "Sinophobia" to state a fact about where the server is located?

Because it frames the situation in a certain, coerced way.

Re: Security researcher gets threats over Amazon review

#23
post #20

How is this a 'threat'?

> The representative then said that she would report Garrett to Amazon if he didn’t take down the review, and that other Amazon reviewers had written in to complain about it.

Not exactly terrifying.

Re: Security researcher gets threats over Amazon review

#24

Earlier quoted context omitted.

If you're a US citizen, you would be a bit better off if it was a US server, because the records from the server would be available to the US court system. This is helpful if a customer ends up suing the company, or if there is a security breach that is investigated by US-based law enforcement. I agree, the inclusion does hint at Sinophobia. But it's also a valid detail for security conscious customers to consider.

Why is it "Sinophobia" to state a fact about where the server is located?

I don't think it is. Sure, he's pointing out that the server is in China, but I think he would point it out for many, many countries and continents (Africa, Russia, Ukraine, Mexico, etc.)

Re: Security researcher gets threats over Amazon review

#25
The threat of being reported to Amazon isn't very threatening, and I was going to chide Techcrunch for being alarmist, but as I began to compose my post, I realized I couldn't come up with a good alternative word in this case, and skimming some online thesauri hasn't helped. Any suggestions? The thing is, if the company had followed through on its threat, the resulting headline would be much less attention-grabbing.

I am assuming the employee-gets-fired threat is not plausible.

Re: Security researcher gets threats over Amazon review

#26

Earlier quoted context omitted.

If you're a US citizen, you would be a bit better off if it was a US server, because the records from the server would be available to the US court system. This is helpful if a customer ends up suing the company, or if there is a security breach that is investigated by US-based law enforcement. I agree, the inclusion does hint at Sinophobia. But it's also a valid detail for security conscious customers to consider.

I don't see how this would be considered Sinophobia given the history of high-profile security breaches caused by hackers operating out of China. If the article reported that the data were being sent unencrypted to a Russian server, would that be considered Russophobia?

I think the author could have explained why this detail's inclusion was relevant, as you did very well.

The current phrasing is clumsy and reads like a dogwhistle, although I doubt that was the author's intent.

Re: Security researcher gets threats over Amazon review

#27
post #9

Of note, from the amazon review: "But before we get to that: I received this product at a discount in return for writing an honest review of it. Onwards!" Could that have anything to do with the manufacturer's attitude?

I sort of wonder if Amazon is the entity providing the discount. (I spent a minute trying to figure it out and didn't find anything)

Nope, there's a cottage industry of review-for-discount sites that give people discounts/free items in exchange for reviews, but wink wink don't feel obligated to give it 5 stars.

Re: Security researcher gets threats over Amazon review

#28
post #17

Earlier quoted context omitted.

Why is it "Sinophobia" to state a fact about where the server is located?

The suggestion is that the location of the server wouldn't have been reported if it went to say...Germany. Or Ireland.

Is there evidence to support that suggestion? Like a similar review about a device that uses a German server but refers to it as a "server in a trustworthy country"?

Re: Security researcher gets threats over Amazon review

#29

I'm not sure if I'm more scared of a company that makes horridly insecure devices and then tells its employees "do everything you can, be as manipulative as you can, but get this review taken down", or if I'm more scared of a company that actually tells its employees "I will fire you if you don't get this review taken down".

Aren't those things roughly equivalent to the average worker?

Re: Security researcher gets threats over Amazon review

#30

Earlier quoted context omitted.

I don't see how this would be considered Sinophobia given the history of high-profile security breaches caused by hackers operating out of China. If the article reported that the data were being sent unencrypted to a Russian server, would that be considered Russophobia?

I think the author could have explained why this detail's inclusion was relevant, as you did very well. The current phrasing is clumsy and reads like a dogwhistle, although I doubt that was the author's intent.

I think it is highly debatable whether this is a potential dogwhistle. The author explained the facts are they are:

> But if you’re not home, your phone sends the command to a server in China, which then passes the command along to the socket.

> The result is that the unique network ID of your socket is transported in an unencrypted form to the Chinese server — and anyone who gets their hands on the ID can then control the socket.

The problem with tying this to the other security breaches caused by Chinese hackers would actually make this article _more_ sensationalist because that would allege that this company is somehow affiliated with the hacking activity.

If the company and server were located in other countries other than the US, it is highly likely that the author would specify the country as well.

Post reply on HN