8 ms·
Yubico sent marketing email to address submitted for product replacement
- jnxx 8y ago> Sadly I have no idea what is a viable alternative to Yubikeys, but at least we're not likely to buy any more any time soon. Nitrokey: https://www.nitrokey.com/ https://www.nitrokey.com/
- lowry 8y agoJust because they used your email in a marketing campaign? Yubico is a small business,I am sure the dude that did this will be heavily reprimanded. Hopefully, not fired. Oh, I see. Shameless self-primotion.
- detaro 8y agoHow do you link jnxx to nitrokey?
- reificator 8y ago`>` is used to denote a quote and it's been that way for decades at least. The article was asking for alternatives. Then jnxx responded with an alternative. This chain of interactions was perfectly reasonable until you showed up and started accusing people without even a shred of evidence. They only have 8 comments, you can read through all of them in the span of a minute. The only one that seems to be on one of their own projects is a link to this: https://gitlab.com/jnxx/check-trustpaths https://gitlab.com/jnxx/check-trustpaths
- rkho 8y agoI don't think you're making the objectively logical conclusion that you think you're making. GP quoted the linked post.
- Sir_Cmpwn 8y agoAlso check out U2F Zero https://www.u2fzero.com/ https://www.u2fzero.com/
- ecesena 8y agoMy preferred one is Vasco, also working on ios. I wrote a comparison a while ago: https://medium.com/@0x0ece/googles-advanced-protection-program-with-iphone-and-ipad-5f30802885e7 https://medium.com/@0x0ece/googles-advanced-protection-progr... On a related note, has anyone already tested a FIDO2 key? I'm looking to buy one, but still can't find any, including developer previews.
- ilikepi 8y agoAdam Langley did a couple round-ups of various security keys last year. Here's the links to each of their respect HN posts: * https://news.ycombinator.com/item?id=15042851 https://news.ycombinator.com/item?id=15042851 * https://news.ycombinator.com/item?id=15429831 https://news.ycombinator.com/item?id=15429831
- Fnoord 8y agoIf you got a Ledger Nano you can use that as well in some circumstances. Likely the same counts for other Bitcoin hardware wallets.
- ForHackernews 8y agoIn the pantheon of tech company misconduct, opting users into marketing emails when they open a support request seems pretty minor (especially if they can easily opt-out). This is at worst, a trivial annoyance. I don't see how we need regulation to outlaw this behaviour.
- baxtr 8y agoWell, it’s says a lot about their company values though. That you can take and extrapolate on anything else they might do or not do
- avoidwork 8y agothis says nothing about the company values; a person made the wrong decision. you’re blowing it up in a fantastical way, like the author of the editorial. i don’t make purposeful email addresses; i don’t have time for that.
- glax 8y agoIt's again like the social media issue. Lot of people don't care doesn't make it right thing to do. These type of things should be opt-in.
- eganist 8y ago> a person made the wrong decision …during the course of that person's work duties, for which the company, therefore, owns responsibility. Literally every single thing any company has ever done wrong boils down to "a person made the wrong decision." > i don’t make purposeful email addresses; i don’t have time for that. Yes, but security and privacy researchers make time for this specifically to validate whether companies follow their own privacy and usage terms as well as to quantify and gauge the risks in interacting with a company, such as the risk that the company will misuse that information or the risk that the company may be breached, resulting in user account details being used in attacks against the individual users themselves. It's fine if you don't do any of this or, for that matter, if you don't even care. But don't belittle the work when you don't understand the reasons for it.
- hadrien01 8y agoIsn't that illegal, at least in the EU and Canada?
- proactivesvcs 8y agoI believe the e-Privacy directive makes it illegal in the EU: https://en.wikipedia.org/wiki/Privacy_and_Electronic_Communications_Directive_2002 https://en.wikipedia.org/wiki/Privacy_and_Electronic_Communi...
- pluma 8y agoI'm fairly confident it will be illegal starting May 25th.
- ilikepi 8y ago> If you are a registered user of a Yubico website and have supplied your email address, Yubico may occasionally send you an email to tell you about new features, solicit your feedback, or just keep you up to date with what’s going on with Yubico and our products. If they made the author a "registered user" when he submitted his address to the replacement program, they should make it clear that's what is happening. Or they need to expand their TOS language a bit...
- zAy0LfpBZLC8mAC 8y agoYou cannot have ToS for a process you establish to correct a failure to perform for existing contracts, in this case for exchanging a defective product (other than what was part of the original contract).
- ilikepi 8y agoAre you summarizing particular laws regarding defective product replacement? This is not an area with which I'm really familiar. The way you phrase it, to me, suggests that it would be impossible (in practical terms) for a company to operate any sort of replacement program via the net, because they'd be required to collect and process personal information digitally, and they would be likely advised to not do so without defining the terms under which that information would be used. Another comment[1] suggests YubiCo implemented this replacement program by issuing coupon codes for their store. The checkout process requires consent to their terms. [1]: https://news.ycombinator.com/item?id=17059784 https://news.ycombinator.com/item?id=17059784
- guitarbill 8y ago> because they'd be required to collect and process personal information digitally, and they would be likely advised to not do so without defining the terms under which that information would be used. That's absurd. First, they should only collect the information they need to provide a replacement product. Second, they should only use that information to provide a replacement product. That would be the right thing to do, regardless of how anti-consumer the laws in whatever countries are. > The checkout process requires consent to their terms. You can't arbitrarily weaken people's rights via terms in most civilized countries. So if that was the only way to get a replacement, I don't think it'd be too difficult to make a case that the terms are null and void. Certainly in Germany, additional terms such as EULAs are invalid if presented after the purchase. --- However, while the store might have been the most convenient way to get a replacement, I don't know if it was the only way. If they made it clear in the email that there were other ways to get a replacement, well then it's still a shitty move by marketing and ethically questionable, but probably legally okay.
- MaupitiBlue 8y agoOMG. I would imagine you've been pretty shaken up by this. Perhaps it would be therapeutic to do a Reddit ama about the after effects of opening your email and seeing an email that says "Yubikey sale?"
- js4 8y agoTake a step back and look at the system. Venture backed companies are required to grow fast to be competitive. They do whatever they can to achieve this goal. Complain about that, not an individual. The individual is just trying to survive. Sad thing is that this tactic works. It’s likely that more people will end up buying because of this tactic then will care about it.
- mannykannot 8y agoI am not buying this excuse. It is individuals, making individual decisions, that create the environment, and the buck stops with them. This form of relativism can easily be extended to all sorts of fraud and corruption.
- js4 8y ago> This form of relativism can easily be extended to all sorts of fraud and corruption. You’re right, it can be, and it is for much of the world. Which is why you need to get the system right.
- llao 8y agoNo one is being forced to let their start-ups be dictated by venture capitalists. Everyone is responsible for their own actions.
- js4 8y agoAre you so sure? The cost of not having resources is not surviving. Name a big tech company that you could work for that didn’t take on venture funding.
- AdmiralAsshat 8y agoI've experienced similar issues with sites where someone else used my e-mail address to sign-up for something, I purposefully did not follow the authorization URL, and the companies have flatly refused to delete my fraudulent accounts or remove me from their mailing lists. One in particular tried to tell me to reset the password on the account so that I could sign in and opt-out of the mailing lists. I refused, saying that doing so would be acknowledging the account as mine and putting the onus on me to manage something I never signed up for. They refused to budge, despite numerous escalations. I swear I feel more like Hank Hill every day.
- thehnguy 8y agoLiked for the last line. Getting old is funny.
- Cacti 8y agoI registered my own domain and switched my email over to a service that lets me generate arbitrary email aliases. When I go to a site or have to otherwise give an email address, I create a new unique alias just for that service. This lets me track where they are leaking my email to, and lets me blackhole the whole site if needed. It’s great.
- icey 8y agoI've been doing a similar thing for year with the gmail feature that lets you add "+anything" to the end of your email address. If someone starts spamming myrealemail+thethingIusedforthatsite@gmail.com, it's easy to create a filter to trash it automatically. I've tried the catchall method on a domain I control, but got way too much spam people trying random addresses.
- ceejayoz 8y agoI'd imagine your average spam list purchaser removes the + stuff on Gmail addresses.
- 8y ago
- xmodem 8y agoYubico is a Swedish company, so you may want to consider filing a complaint with the Swedish data protection authority: https://www.datainspektionen.se/in-english/contact-us/ https://www.datainspektionen.se/in-english/contact-us/
- exabrial 8y agoMarketing teams really need to be kept in check. I get it they're pressed for results with often limited budgets and tools, but there needs to be some basic ethics at every company. To me, this is just as bad as bundling security updates with mandatory new features....
- davesque 8y agoWhat's the actual risk here? I'm not seeing it.
- acdha 8y agoThe HN title is misleading - it wasn’t a bug report but the Yubikey 4 replacement. The process by which it happened seems understandable: they used their existing store to process replacements (you got a coupon code for the same model as your old key) and notified all past customers when a major new standard shipped. They should have handled that better and made it clearer under which conditions you’d get email but it’s way down the list of annoying corporate email practices.
- rdiddly 8y agoCute. If I had a dime for all the times this has happened to me since the 90s...
- CryoLogic 8y agoMicrosoft and a few other companies have done this with the email I used when interviewing :/
- sajal83 8y agoMy policy: if email is interesting/relavent. Do nothing. If I remember subscribing and haven't attempted to unsubscribe in the past, attempt to unsubscribe. Spending max 10 seconds. All other situations, hit "mark as spam"