Live data from Hacker News

Flock Safety's controversial CEO just got a taste of his own medicine

neowin.net

31–40 of 61 posts

Re: Flock Safety's controversial CEO just got a taste of his own medicine

#31
post #16

Earlier quoted context omitted.

Why is cloudflare a problem?

Cloudflare doesn't reliably let me through.

It regularly blocks me too. I've begun search Google for: what does [url] say about [search query]

It'll make a Gemini summary of the page, and can be prompted for more details. It's really the only use for Gemini I've found reliable. I'd still rather directly view the output of the scraper bot, though.

If anyone knows a good scraping bot that lets you view the output directly, without running it through an LLM, please let me know.

Re: Flock Safety's controversial CEO just got a taste of his own medicine

#32

In the USA, is it really that easy to find the home address of a business owner? The EU briefly had a similar registry but that got shut down quickly.

Yes, but only for the business directly owned. In the US, it's perfectly legal to run things through shell companies that make things much more difficult. E.g. instead of directly owning the company, he could put his share in fully-owned shell company, based in a country that doesn't report the owner.

Re: Flock Safety's controversial CEO just got a taste of his own medicine

#33
post #18
post #5

Earlier quoted context omitted.

Because they slow down and often block access to websites, particularly for people that try to avoid being fingerprinted or otherwise tracked. Pretty evil behavior.

"Never attribute to malice that which is adequately explained by stupidity."

Hanlon's Razor is especially effective at getting Good people to put out their own eyes to keep them nice and soft targets for the malicious. I'll take being a harder to find likable by people I have no desire to be liked by to make myself a harder mark. The honest ones will understand. The malicious were never worth being close with, and I'm doing the world a service by getting the borderline enlightened.

Sufficiently advanced stupidity being indistinguishable from malice is also something to keep in mind.

Re: Flock Safety's controversial CEO just got a taste of his own medicine

#35
post #27

Earlier quoted context omitted.

My employer is a small business that has an e-commerce website that is attacked by fraudsters trying to validate stolen credit cards or obtain customer information hundreds of times per day. Operations like CloudFlare are the only way to foil these actors. Just trusting you is not a viable strategy.

The people who downvote could propose how to solve the fraudster problem instead of shooting the messenger.

That isn't the done thing here, lamentably. Downvote is a de facto disagree button

Re: Flock Safety's controversial CEO just got a taste of his own medicine

#36
post #29
post #27

Earlier quoted context omitted.

My employer is a small business that has an e-commerce website that is attacked by fraudsters trying to validate stolen credit cards or obtain customer information hundreds of times per day. Operations like CloudFlare are the only way to foil these actors. Just trusting you is not a viable strategy.

Your rate limits on adding and removing credit cards? Your input sanitization? Designing your system to not just disclose details around anything but that relevant to a logged in/authenticated user? There are many practical ways to handle that sort of thing that isn't Cloudflare. It just requires thinking and a bit of dev time. t. Been there, done that, cartels used an app to try to launder money through loyalty prog…

> Your rate limits on adding and removing credit cards?

All those requests will appear from different ip's and different browsers, made by someone who can spend months on trying to defraud you. How do you differentiate this from valid customer who happens to try to buy something between 20 tries by bots?

> Your input sanitization?

All those fraud requests will give you valid credit cards which will work perfectly, but then defrauded people or banks will try to chargeback later.

> Designing your system to not just disclose details around anything but that relevant to a logged in/authenticated user?

They can register as normal buyers.

> It just requires thinking and a bit of dev time.

And they can spend months trying to outthink you, then will drain your service in 4 hours when you are asleep.

> Management was deadset against doing the one single thing that would make it impossible to do that at scale.

So, did you actually ever implemented and checked a good solution? Cloudflare isn't perfect, but not everyone has resources to implement their own solution that is better than cloudflare.

> Fingerprinting is far more intrusive than just only allowing one to add at max 2 cards a day per user.

The fraudsters will appear as completely new users each time, adding only one card and making one purchase.

Re: Flock Safety's controversial CEO just got a taste of his own medicine

#38

It’s been interesting to see this vitriol towards Flock increase over the past couple of months or so.

What is interesting about it ?

Because Flock is the first company to so brazenly violate the post-2011 social contract: if you're going to track somebody you need to give them coupons and content as compensation. They have failed to provide the people whose privacy they are violating with internet drama and buttcheeks videos. Other companies with many times greater reach and market cap collect GPS, cell tower, and 802.11 ESSID data to observe their users' movements; they track them across web sites and apps without explicit consent to serve personalized advertisements and adjust prices for durable goods and services depending upon user behavior. They do this with impunity because people enjoy short-form videos and image macros and will readily trade their privacy for easy access to them. Flock has nothing to offer in this regard. This is why they are shunned whereas other companies that understand how this game is played are forgiven for equivalent or worse sins.

Re: Flock Safety's controversial CEO just got a taste of his own medicine

#39
post #20

The article is very one sided, implying without evidence that Flock is for recreational tracking of individuals. With San Francisco SFPD’s ALPR cameras at least, this would be an abuse of the cameras according to the policy linked from https://transparency.flocksafety.com/san-francisco-ca-pd . Here are the Authorized purposes: Locate stolen, wanted, and or other vehicles that are the subject of investigation To appre…

The unwarranted mass surveillance and dragnet part. We have a thing called the fourth Constitutional amendment here in the United States. We also have the first amendment, which the Supreme Court has ruled in the past must not be subject to a "chilling effect". The Flock camera system, and any dragnet surveillance system, is a direct chilling effect to the rights to freedom of speech, freedom from religious persecuti…

You carry a phone with you broadcasting constantly. Not sure why police just don’t buy your location data from data brokers. Maybe they do…

Re: Flock Safety's controversial CEO just got a taste of his own medicine

#40
post #29

Earlier quoted context omitted.

Your rate limits on adding and removing credit cards? Your input sanitization? Designing your system to not just disclose details around anything but that relevant to a logged in/authenticated user? There are many practical ways to handle that sort of thing that isn't Cloudflare. It just requires thinking and a bit of dev time. t. Been there, done that, cartels used an app to try to launder money through loyalty prog…

> Your rate limits on adding and removing credit cards? All those requests will appear from different ip's and different browsers, made by someone who can spend months on trying to defraud you. How do you differentiate this from valid customer who happens to try to buy something between 20 tries by bots? > Your input sanitization? All those fraud requests will give you valid credit cards which will work perfectly, bu…

> All those fraud requests will give you valid credit cards which will work perfectly, but then defrauded people or banks will try to chargeback later.

How are they getting pass 3D-S?

If they are able to get past it, then your liability drops off.

Yes it could be designed better, but that is a separate discussion.

Post reply on HN