Live data from Hacker News

No user accounts, by design

f-droid.org

131–140 of 147 posts

Re: No user accounts, by design

#131
post #72
post #35

Earlier quoted context omitted.

Comcast has a portal for law enforcement to request subscriber information at https://lea.comcast.com . That IPv6 address, plus the current date and time, uniquely identifies you by name and service address. Any edits you make to Wikipedia from that address are not anonymous.

This is a use of "anonymous" that is unfamiliar to me. Do you mean something like "untraceable"? For example, when non-profits credit an anonymous donor, they know who the person is. In that more common sense of the word, Wikipedia's anonymous edits are indeed anonymous: they are published without a name attached. Anyhow, that seems besides the point. All HTTP requests come with IP addresses. That the police might be…

You are confusing anonymous and pseudonymous. Tor for example can afford you request-level anonymity.

Re: No user accounts, by design

#132
post #82
post #79

Earlier quoted context omitted.

Absolutely. I think your last point is especially good. Facebook consumes a ton of cash for what many people feel are disappointing results. Are they vulnerable to a competitor who is less about what users want than what they need ? A competitor who can do that for 1/10th or 1/100th as much money? That could be very hard for the me-me-me companies to keep up with.

The thing with fads, and adoption cycles in general, is that what people 'want' can be figured out pretty quickly, but as far as I'm concerned, The Trough of Disillusionment is what happens when people figure out that what they need is something else. So what you're asking is can someone come into the ToD and introduce a new product that steals people away? It's plausible and if I were in a better headspace I could p…

Sorry, I shouldn't have phrased that as a direct question. I meant it in a more rhetorical sense.

Oh, sure. It's a very tough field, and would be even if the incumbents didn't have billions to throw at the problem. I definitely don't believe that the better product wins; I only need Microsoft as a counter-example.

But it does strike me as a zone of opportunity. Maybe Substack is a good partial example here. Before the web, we had magazines. Then we basically had magazines on the web, preserving much of the old structure in the new medium. With lots of flailing as people tried to find sustainable business models.

And then Substack came along with an extremely bare-bones implementation mostly using 1980s technology and a lot of writers and readers are very happy with it.

So it's more that I'm asking myself. What are the products that cost 1/100th as much that might be as satisfying for my Facebook-ish needs?

Re: No user accounts, by design

#133
post #72

Earlier quoted context omitted.

This is a use of "anonymous" that is unfamiliar to me. Do you mean something like "untraceable"? For example, when non-profits credit an anonymous donor, they know who the person is. In that more common sense of the word, Wikipedia's anonymous edits are indeed anonymous: they are published without a name attached. Anyhow, that seems besides the point. All HTTP requests come with IP addresses. That the police might be…

You are confusing anonymous and pseudonymous. Tor for example can afford you request-level anonymity.

I really don't think I am. Look, for example at this project that is on the front page of HN: https://docs.taler.net/

They describe it as an anonymous payment system. That matches the first definition here: https://www.dictionary.com/browse/anonymous

Re: No user accounts, by design

#134

Earlier quoted context omitted.

Note that the Librem 5 is practically a scam. There are still people who ordered in 2017 who have not received their phone. Requesting a refund takes hundreds of days to be issued.

It's not a scam. Did you hear about supply chain problems in CPUs? See here about delivery progress: https://forums.puri.sm/t/estimate-your-librem-5-shipping/112... . Every time Purism can get the CPUs, they deliver another bunch of the phones.

I mean regardless of what the reason is, a 5 year delay is a 5 year delay, and if the refund process isn't near-perfect, I would call that scummy at the very least.

Re: No user accounts, by design

#135
post #82

Earlier quoted context omitted.

The thing with fads, and adoption cycles in general, is that what people 'want' can be figured out pretty quickly, but as far as I'm concerned, The Trough of Disillusionment is what happens when people figure out that what they need is something else. So what you're asking is can someone come into the ToD and introduce a new product that steals people away? It's plausible and if I were in a better headspace I could p…

Sorry, I shouldn't have phrased that as a direct question. I meant it in a more rhetorical sense. Oh, sure. It's a very tough field, and would be even if the incumbents didn't have billions to throw at the problem. I definitely don't believe that the better product wins; I only need Microsoft as a counter-example. But it does strike me as a zone of opportunity. Maybe Substack is a good partial example here. Before th…

Way back in the long dark ago I ran into some abandonware for incorporating third party data onto web pages via a shared server. Nobody I knew understood how it was meant to work, but I got the impression it was meant to be a tool where a group of people could host commentary about a website that was not their own.

I keep wondering why nobody has really tried that again. Slashdot sort of filled in that space, and then Digg and now Reddit. Or Facebook for the 'all-in' solution. I keep thinking there was something I was missing about why that would be difficult to pull off.

Today I have a different answer for that - that ship has sailed. We are multi-device and it would be much more difficult for me to have a consistent experience across phone and personal (and sometimes work) machines.

But at the time perhaps it as an adoption thing. Just visiting a website is a cheap interaction that can lead to a habit. Having to do something special doesn't work the same way.

Re: No user accounts, by design

#136
post #33

Earlier quoted context omitted.

> How do you prevent others from sharing URLs with bad actors? Sure, but then the student who shares their interactive class URL (w/ or w/o password) on 4chan still isn't accounted for.

Your argument boils down to "I came up with one scenario where this is bad, so it can't work at all" and I find this dissatisfying. If this hypothetical student "shared" their user account and then disavowed giving it out, you would have the same issues.

My original question is:

>How do you solve problems arising from bad actors without an object representing the user?

In response to the argument that user objects are no longer needed, even for something like virtual meetings. The scenario of zoombombing isn't something "I came up with", it's a real life scenario that having a user object helps prevent bad actors with.

In the event of a user sharing their account, you would know who it was and be able to hold the bad actor accountable, as opposed to a meeting URL being shared. I think the better question is why you are so hostile to the idea of user accounts having utility.

Re: No user accounts, by design

#137
post #33

Earlier quoted context omitted.

> How do you prevent others from sharing URLs with bad actors? Sure, but then the student who shares their interactive class URL (w/ or w/o password) on 4chan still isn't accounted for.

You can easily generate individual share links for every pupil and sanction the one whose link was used by a hundred random people from all over the world to join the conference. Jitsi and Big Blue Button are both able to handle this special use case where users aren't trusted to act in good faith I believe.

The individual share links would be linked to what exactly? A non-user object with the student's name and email address?

Re: No user accounts, by design

#138
post #39

Earlier quoted context omitted.

Not really a counter point because you mention a lot of other issues with f-droid that sound valid (I haven't used it myself) - but as a tangent regarding auto updates, I disable them basically everywhere because I seem to have buggy experiences too often if I allow stuff to update all the time. I then go through the list of updates in the Play Store once a week or so and install those that I think might improve app…

Personally, I've found that disabling auto-updates just means either unnecessarily sticking with outdated/buggy versions (or versions that drift out of sync with backend services and acquire new bugs that way), or I spend way too much time manually maintaining my phone instead of actually using it. I don't have time to read release notes/research each new version, so I'd likely just spend 10 minutes hitting "update"…

> Personally, I've found that disabling auto-updates just means either unnecessarily sticking with outdated/buggy versions (or versions that drift out of sync with backend services and acquire new bugs that way),

I guess I don't care if my apps are "outdated" as long as they still do what I want. If there's something buggy about an app that annoys me enough I'll often just uninstall the buggy app and find an alternative.

I find that once I install an Fdroid app and I like it, it'll pretty much just keep working just the way I want it to. The only app I use that breaks if I don't update it is NewPipe and that's google's fault. It doesn't happen often enough, or take long enough to update to offset the benefits of using it.

Even most my regular google play store apps don't actually "need" to be updated, and many haven't been since the day they were installed with no bugs or issues.

Re: No user accounts, by design

#139

Earlier quoted context omitted.

You can easily generate individual share links for every pupil and sanction the one whose link was used by a hundred random people from all over the world to join the conference. Jitsi and Big Blue Button are both able to handle this special use case where users aren't trusted to act in good faith I believe.

The individual share links would be linked to what exactly? A non-user object with the student's name and email address?

You can just make your own list. Generate 20 links, paste them somewhere, have your list of students next to it. Delete the list if nothing happened, check which number offended if it went wrong.

If you can trust the platform, in cases where the school hosts the program itself, the names can be added to the links directly. You don't need a big db of students for this, just an ephemeral list of strings.

Re: No user accounts, by design

#140

F-droid gets many things right (e.g. verifiable builds), but it's just not usable in practice. Installing applications is a rare event, updating them is frequent, and needs to disrupt the user as little as possible. Android used to not allow alternative app stores to update apps without user interaction, but now supports this through UPDATE_PACKAGES_WITHOUT_USER_ACTION, which doesn't seem to be supported by F-droid.…

Just FYI, NewPipe has their own F-Droid repo with faster updates. https://newpipe.net/FAQ/tutorials/install-add-fdroid-repo/ So does Bromite browser. https://www.bromite.org/fdroid

That, in itself, is another nice feature of F-Droid. It allows you to add additional repositories of your own choosing.

It's so refreshing, especially compared to $megacorp control freak, er, security measures, yeah that's it!

Post reply on HN