Live data from Hacker News

Dear Dash Users – A message to all Dash users from the Kapeli Blog

blog.kapeli.com

51–60 of 110 posts

Re: Dear Dash Users – A message to all Dash users from the Kapeli Blog

#51
post #22

This whole thing has taught me a lesson. I initially sided with the weaker side because I own a copy of Dash, and it is great software, and because one tends to side with the underdog. After listening to the recording of the conversation, my feeling is that Apple is handling this in a very fair and professional way, and that I was too quick to take sides. I think it is not unreasonable to assume that: same credit car…

I generally agree with you but wanted to point out that: > same credit card + same hardware = same developer is fine as a pseudo-identifier for fraud detection...but I don't think is actually an identifier. It's kind of like someone knowing my social security number and birthday but not actually being me. IMO, Apple should have immediately reinstated the account once contacted about a potential edge case rather than…

If I had to guess, the combination of matching CCs + matching test devices (i.e. when _both_ are the same) has a fairly low false positive rate for identifying fraudulently-linked accounts.

This type of probabilistic inference is how fraud detection works in everything from Apple to Paypal to world banks.

I would even go so far as to call that aforementioned combination a smoking gun.

Re: Dear Dash Users – A message to all Dash users from the Kapeli Blog

#52

Earlier quoted context omitted.

And given that nugget of actual evidence, I can decisively say that he definitely screwed himself over. This is how the business world works. Sometimes you can't get the best deal, but it's still in your best interest to accept it regardless. You have to act rationally; you can't just defect (to borrow some game theory parlance -- this literally resembles Prisoner's Dilemma) in the name of "principles." One moderatel…

It's not a fact that had he written a blog post admitting guilt that his account would have been reinstated. That's just a carrot dangled by Apple, without a hard contractual obligation to follow through. If anything, actually writing that something wrong happened would make it easier for them to justify their decision. It could be a trick representatives sometimes use when they assume the party they are dealing with…

Okay, then you release your recorded call AFTER they defect (I'm not saying he shouldn't have covered his ass by recording the call, that's the smart thing I would've also done). Imagine how bad that would look for Apple.

If I had to guess, Phil & co. wouldn't want to risk that nuclear scenario (and they are definitely smart enough to know better).

Re: Dear Dash Users – A message to all Dash users from the Kapeli Blog

#53
post #17

There feels like no right side in this story. * Apple terminated both accounts because of fraudulent activity, but only one account was contacted to let them know of this activity. * Kapeli shared financial information and test devices with this other account, whether it was a relative or not. * Apple said "Hey, write a post telling the whole story and all will be cleared. Just don't say we were at fault." * Kapeli a…

Generally, I don't get this: * Kapeli shared financial information and test devices with this other account, whether it was a relative or not. The assumption here is that for some reason a credit card number and device identifiers (unclear where they come from...but maybe mac address?) are enough for Apple to "link" accounts. I contest this for the same reason I think someone knowing my birthday and social security n…

If it's his credit card, then the account is his responsibility. And it's not a stretch to link accounts that are the responsibility of the same person.

Re: Dear Dash Users – A message to all Dash users from the Kapeli Blog

#54

Earlier quoted context omitted.

Generally, I don't get this: * Kapeli shared financial information and test devices with this other account, whether it was a relative or not. The assumption here is that for some reason a credit card number and device identifiers (unclear where they come from...but maybe mac address?) are enough for Apple to "link" accounts. I contest this for the same reason I think someone knowing my birthday and social security n…

Even though I disagree with your post, I upvoted it to counter the people on this site who downvote merely because they disagree with somebody's comment.

Haha thanks.

Re: Dear Dash Users – A message to all Dash users from the Kapeli Blog

#55
post #22

This whole thing has taught me a lesson. I initially sided with the weaker side because I own a copy of Dash, and it is great software, and because one tends to side with the underdog. After listening to the recording of the conversation, my feeling is that Apple is handling this in a very fair and professional way, and that I was too quick to take sides. I think it is not unreasonable to assume that: same credit car…

I generally agree with you but wanted to point out that: > same credit card + same hardware = same developer is fine as a pseudo-identifier for fraud detection...but I don't think is actually an identifier. It's kind of like someone knowing my social security number and birthday but not actually being me. IMO, Apple should have immediately reinstated the account once contacted about a potential edge case rather than…

My point was that it is not unreasonable to assume same credit card + same hardware = same developer, not that it is an infallible method.

Apple offered some flexibility, to account for the remote possibility of an unfortunate misunderstanding, and offered a way forward that, in my view, was pretty reasonable, and that allowed both sides to safe face, and continue to do business together.

Re: Dear Dash Users – A message to all Dash users from the Kapeli Blog

#56
post #37

I14n is fun — to watch for the audience. Apple behaves as if everyone has a credit card and the mapping from credit card to (legal) person is unique. That isn't so in Romania and Apple's heuristics go boom. The same assumption shows up again a little later in the imbroglio: Apple asked him to admit some sort of wrongdoing, however gently, because credit card maps to person to the person they spoke to carries some res…

If you're going to put your credit card in, then you are responsible for the account. If fraud happens on one account you are responsible for, it's not a stretch to believe that fraud could happen on other accounts you are responsible for.

Re: Dear Dash Users – A message to all Dash users from the Kapeli Blog

#57
A lot of people here are switching over to Apple's side, but I wouldn't be so quick to throw Kapeli under the bus.

Imagine this scenario:

You buy your cousin a fancy sword for his birthday one year, which he later uses as a murder weapon against his girlfriend. The police look up the serial number and see that although it's registered under your cousin's name, your credit card was used to purchase it.

They arrest your cousin, give him a fair trial, convict him of murder, and place him on death row. You're not in touch with your cousin, so you are completely oblivious to everything which has happened. At this point, SWAT officers storm your home and arrest you, refusing to tell you why. You're thrown in a cell and told you have been placed you on death row, and that their decision is final and can’t be appealed.

Your only saving grace is the fact that you happen to be mildly influential in a small community with ties to the government, and you're able to get your side of the story out.

Articles are written about you. People are outraged at the government. Others come forward to tell of their dead relatives who had been wrongly executed as well.

The Attorney General reads one of these articles and scrambles to do PR damage control.

Se has her aid call you and demand that you make a public statement saying that The Government did nothing wrong, that you were the one who purchased the weapon so they were justified in their actions, and that they are so graciously working with you to clear your name. Of course, they completely ignore the part about their negligence and what would have happened if you were just some no-name.

---

I believe Apple desperately needs to change their policies. These statements like "We can't provide you with any more information.", "This decision is final.", and lack of communication are wrong. Sure, they are a private company and have the legal right to remove anything from their platform at any time for any reason without any notice or explanation, but that doesn't mean that their actions should be supported and endorsed by the communities of users and developers.

Their actions should have consequences in the form of diminished trust, which may be the straw the breaks the camel's back in many developer's and user's choices to continue developing for and using their platform.

I will say that it was not smart of Kapeli to publish the phone call; at least not yet. He should have waited a bit longer, and only published it if Apple didn't follow through on their word. However, I still believe Apple is in the wrong here, and Kapeli's only real crime is that of naivety.

Re: Dear Dash Users – A message to all Dash users from the Kapeli Blog

#58
post #17

There feels like no right side in this story. * Apple terminated both accounts because of fraudulent activity, but only one account was contacted to let them know of this activity. * Kapeli shared financial information and test devices with this other account, whether it was a relative or not. * Apple said "Hey, write a post telling the whole story and all will be cleared. Just don't say we were at fault." * Kapeli a…

Generally, I don't get this: * Kapeli shared financial information and test devices with this other account, whether it was a relative or not. The assumption here is that for some reason a credit card number and device identifiers (unclear where they come from...but maybe mac address?) are enough for Apple to "link" accounts. I contest this for the same reason I think someone knowing my birthday and social security n…

What makes you think they've shared all the ways that they were linked? The guy on the phone call may have just listed a couple of them when he was trying to establish with Kapeli what the ground truth was, that these accounts were linked.

Re: Dear Dash Users – A message to all Dash users from the Kapeli Blog

#59
post #56
post #37

I14n is fun — to watch for the audience. Apple behaves as if everyone has a credit card and the mapping from credit card to (legal) person is unique. That isn't so in Romania and Apple's heuristics go boom. The same assumption shows up again a little later in the imbroglio: Apple asked him to admit some sort of wrongdoing, however gently, because credit card maps to person to the person they spoke to carries some res…

If you're going to put your credit card in, then you are responsible for the account. If fraud happens on one account you are responsible for, it's not a stretch to believe that fraud could happen on other accounts you are responsible for.

You're equating "paying for" and "responsible for".

Re: Dear Dash Users – A message to all Dash users from the Kapeli Blog

#60
post #22

This whole thing has taught me a lesson. I initially sided with the weaker side because I own a copy of Dash, and it is great software, and because one tends to side with the underdog. After listening to the recording of the conversation, my feeling is that Apple is handling this in a very fair and professional way, and that I was too quick to take sides. I think it is not unreasonable to assume that: same credit car…

I generally agree with you but wanted to point out that: > same credit card + same hardware = same developer is fine as a pseudo-identifier for fraud detection...but I don't think is actually an identifier. It's kind of like someone knowing my social security number and birthday but not actually being me. IMO, Apple should have immediately reinstated the account once contacted about a potential edge case rather than…

Even though they only mentioned credit card and device identifiers, I'm sure Apple has much more information behind the scenes they don't make public, such as the account behavior, etc.

For example they could just look at the IP from which each account holder signed in, and may have found that they were coming from the same IP. In fact, it is very likely that they would have tried this, and if they did and found that the IP were different they probably wouldn't have been as confident about how they dealt with this case in my opinion.

Post reply on HN