Live data from Hacker News

Honey's Dieselgate: Detecting and tricking testers

vptdigital.com

111–120 of 175 posts

Re: Honey's Dieselgate: Detecting and tricking testers

#111
post #22

I used to work for an ad tech company (which I know already makes me the devil to some around here), and even I think that they crossed a line with this. A lot of industry terms are coded in corporate speak to make them sound better (think "revealed preferences" or "enabling personalization"), but I would genuinely like to know what the engineers thought when doing design reviews for a "selective stand down" feature.…

> what the engineers thought when doing design reviews for a "selective stand down" feature. Possibly a version of, “I lack the freedom to operate with a moral code at work because I’m probably replaceable, the job market makes me anxious, my family’s well-being and healthcare are tied to having a job, and I don’t believe the government has my back.”

More like "well, they pay well and it's interesting problem so who gives a fuck"

Re: Honey's Dieselgate: Detecting and tricking testers

#112

Earlier quoted context omitted.

> what the engineers thought when doing design reviews for a "selective stand down" feature. Possibly a version of, “I lack the freedom to operate with a moral code at work because I’m probably replaceable, the job market makes me anxious, my family’s well-being and healthcare are tied to having a job, and I don’t believe the government has my back.”

In my experience, sometimes your employer blatantly lies to you about what you're making and how it'll be used. I was once recruited to work on a software installer which could build and sign dynamic collections of software which was meant to be used to conveniently install several packages at once. Like, here's a set of handy tools for X task, here are the default apps we install on machines for QA people, here is o…

> Ultimately it was only used to install malware in the form of browser extensions, ...

Like any other MDM software.[0] Everyone who has been long enough in the infosec industry knows that MDM is fundamentally nothing more than a corporate-blessed malware and spyware package.

In the past 2-3 years the criminal gangs have realised that too. The modern form of socially engineered phishing quite often entices victims to install a legit MDM software package (eg. MS InTune) and hand over their device control for remote management. Why bother writing malware that has to fiddle with hooks to syscalls and screenshot capabilities when you have a vendor approved way of doing the same?

0: https://en.wikipedia.org/wiki/Mobile_device_management

Re: Honey's Dieselgate: Detecting and tricking testers

#113

Earlier quoted context omitted.

From my experience, it’s more likely that the engineers who got far enough in the company to be working on this code believed that their willingness to work on nefarious tasks that others might refuse or whistle-blow made them a trusted asset within the company. In industries like this there’s also a mindset of “Who cares, it’s all going to corporations anyway, why not send some of that money to the corporation that…

Do you know of anyone declining to work on a project For ethical in their view ( non military non killing) ? I’ve led a sheltered life and never met one, people have told me they wouldn’t apply for a role with a company for ethical reasons maybe they even believed they would get the job

Hello. I have. The first time, I was offered a job working on missile guidance systems. I told them I would not work on weapons, so they offered me a job working on something else instead. Then they asked me to move to another project that would require getting government security clearance. I said I wouldn't do that either because I was not willing to make the required promises to my government, so they gave me other projects that didn't require it. It's really not that hard to have a penny's worth of a moral compass if your skill has any kind of value. I think maybe the problem is people who only have value to companies that only hire people without any morals.

Re: Honey's Dieselgate: Detecting and tricking testers

#114
post #34

Earlier quoted context omitted.

Not affiliate marketers are thieves

The whole industry is based upon on nonconsensual surveillance and other taking of personal information, so yes they are.

Less theft, more stalking.

Re: Honey's Dieselgate: Detecting and tricking testers

#115
post #76

Earlier quoted context omitted.

Capitalism is great at washing its hands of evil. I don't know how much slavery went into making the smart phone that I'm posting this from, but I'm sure it's not zero. I'm ethically complicit in the whole scheme. The C in ACAB stands for Capitalists. Which unfortunately, is all of us.

All of us? I don't own any capital and don't have employees who I trim profits off of.

You don't have a pension?

Re: Honey's Dieselgate: Detecting and tricking testers

#116

Earlier quoted context omitted.

That's not how malware is defined - Windows ain't malware just because they occasionally make Edge open instead of what you thought were your default browser. The malware definition is way more specific than simply software that doesn't always follow user intent.

It actually does fall under the definition malware. Specifically, Honey hijacks affiliate marketing tags and replaces them with their own. This falls under the definition of the “spyware” category of malware.

Spyware is software that sends information about the user (browsing history, etc) to a 3rd party.

Many affiliate browser extensions do indeed do this, as an extra revenue stream. In fact, I'd recommend never installing a coupon browser extension. But replacing one number with another does not meet the above definition of spyware.

Re: Honey's Dieselgate: Detecting and tricking testers

#117
post #80

Earlier quoted context omitted.

It's not malware. Marketing companies stealing commission from each other isn't malware. Giving the user less than the best possible deal isn't malware. It doesn't even upload your cookies to see if you're a tester - it does that on the client.

If I click on an affiliate link that I want to use and the extension changes that without me knowing, that’s malware for me. The intent of the user may be to use a specific affiliate link.

What's the ratio of people deliberately clicking affiliate links, to people who just click links and have no clue what an affiliate link even is?

I already thought Honey was scummy so I never used it in the first place, but I honestly don't get the particular outrage over these specific practices. You're already using the extension to effectively scam online stores, by using coupons the company gave to somebody else, not you. I see it as barely more ethical than doing that old trick of generating your own manufacturer coupons. Probably it's a lot more legal, but ethically it's in the same ballpark.

Re: Honey's Dieselgate: Detecting and tricking testers

#118

Original MegaLag video: https://www.youtube.com/watch?v=qCGT_CKGgFE You'd think that if you were an engineer building and maintaing a system like this, you'd have an "are we the baddies?" moment, but guess not.

Capitalism is great at washing its hands of evil. I don't know how much slavery went into making the smart phone that I'm posting this from, but I'm sure it's not zero. I'm ethically complicit in the whole scheme. The C in ACAB stands for Capitalists. Which unfortunately, is all of us.

Culpability is not a binary thing, it’s a scale. A small number of people are far and away the most culpable for much of the evil in the world, and they know it (and don’t care).

Re: Honey's Dieselgate: Detecting and tricking testers

#119
post #59
post #51

The entire affiliate "ecosystem" is cancer. I'd love to see Amazon turn it off entirely.

As consumer I would love to see lower prices directly. Or at least have available some official store affiliate discount code which would give me same discount which would be win win for everyone.

You cannot due to Amazon's stipulations that to list on Amazon.com, it must be the same as your advertised price on other retailers, including your own website. This raises overall costs, as Amazon.com sellers pay additional fees for placement, ads, etc. which get rolled into the price. As a workaround, you can have a MSRP on your website, with "coupons".

Re: Honey's Dieselgate: Detecting and tricking testers

#120

Earlier quoted context omitted.

From my experience, it’s more likely that the engineers who got far enough in the company to be working on this code believed that their willingness to work on nefarious tasks that others might refuse or whistle-blow made them a trusted asset within the company. In industries like this there’s also a mindset of “Who cares, it’s all going to corporations anyway, why not send some of that money to the corporation that…

Do you know of anyone declining to work on a project For ethical in their view ( non military non killing) ? I’ve led a sheltered life and never met one, people have told me they wouldn’t apply for a role with a company for ethical reasons maybe they even believed they would get the job

I quit a job on contract with a major insurance provider because they asked me to perform a truncate instead of a rounding operation in a formula without any mathematically sound reason for choosing the truncate over the rounding. I figured out they wanted truncating because it would lead to more people being denied flood coverage than rounding would.
Post reply on HN