3 ms·
An IP address being used in the course of providing the service is not surveillance. That's like saying "Amazon knowing where to ship my package is surveillance
by coder543 5y ago
An IP address being used in the course of providing the service is not surveillance. That's like saying "Amazon knowing where to ship my package is surveillance." It's a bad argument, in my opinion.
Regardless, consider a DDoS attack. If every new request is coming from a different IP address, how do you continue providing service to your legitimate customers while blocking that malicious attack? Knowing the attacker's IP addresses doesn't do you any good... because they can just keep using new IP addresses, and blocking the old ones doesn't do any good.
This is where heavily surveillance-based systems like Google CAPTCHA often come into play, and I have very mixed feelings about those.
There are some non-surveillance-based captchas like this one[0] that I saw on HN awhile back, and I hope those become successful.
[0]: https://friendlycaptcha.com/ https://friendlycaptcha.com/
- charcircuit 5y ago>That's like saying "Amazon knowing where to ship my package is surveillance." To complete the metaphor Amazon would use the address you gave them to help improve their business in some sense without asking you if it's okay. Similar to how web masters don't ask if it's okay if they write what pages we access into logs is okay. >Knowing the attacker's IP addresses doesn't do you any good... because they can just keep using new IP addresses, and blocking the old ones doesn't do any good. Then we should try to find any patterns with the traffic that we can use to try and filter it out. This is a place where fingerprinting is useful. >friendlycaptcha This just slows down bot spam instead of testing if someone is a bot. Someone posting spam to your site once a minute is still annoying.
- coder543 5y agoI've read your other replies to this thread and your argument does not seem to be made in good faith. This whole thread is about surveillance based advertising being bad. In no way is using an IP address in a firewall a form of surveillance. It isn't. The IP address isn't being associated with any other data, it's just some numbers floating in space, disconnected from any human being. There is no association with that IP address of what you like and don't like, what you have purchased, what links you have clicked, or anything else. It's just in a firewall, and that firewall rule could be blocking an entire CIDR block, especially in the case of IPv6. But even if it were surveillance, that's irrelevant to this discussion about the ethics of surveillance-based advertising. I'm not going to waste my time further on this thread after making this one last point. > This just slows down bot spam instead of testing if someone is a bot. Someone posting spam to your site once a minute is still annoying. Google CAPTCHA is trivially bypassed all the time. Do you really think it isn't? Sometimes using services like Amazon Mechanical Turk, sometimes using simple computer vision. It doesn't test whether someone/something is a bot either... it just tests whether they can pass the CAPTCHA. It certainly doesn't test whether they're part of a DDoS, nor does it test their intentions to find whether they are good or malicious. It's just a CAPTCHA, but it also uses a lot of surveillance... and as I said, I have mixed feelings about that. I didn't mean for this to become the point of the thread, it is definitely off topic. The idea of Proof of Work CAPTCHAs is that you can actually make it more expensive for an attacker to solve those than it would be for the attacker to solve Google CAPTCHAs. Obviously, this is still an area of debate and research.
- charcircuit 5y ago>your argument does not seem to be made in good faith I'm not exactly sure what this means. I used to be all for total privacy, but I found that future to not be sustainable. Perhaps I'm just jaded, but privacy just gets in the way. >This whole thread is about surveillance based advertising being bad. Well this part of the thread isn't. It's talking about how surveillance improves services by allowing them to deal with abuse. >In no way is using an IP address in a firewall a form of surveillance. It isn't. The IP address isn't being associated with any other data, it's just some numbers floating in space, disconnected from any human being. Wrong. I am using your IP as part of a scheme to fingerprint you. I want my rate limit to limit each person separately. An IP address is just a somewhat decent way to approximate that. >The idea of Proof of Work CAPTCHAs is that you can actually make it more expensive for an attacker to solve those than it would be for the attacker to solve Google CAPTCHAs. This has to be carefully balanced with the user experience. No user in going to want to wait 5 minutes to post when they can just have a Google account with a good reputation and just click a checkbox.
- danbruc 5y agoI used to be all for total privacy, but I found that future to not be sustainable. Perhaps I'm just jaded, but privacy just gets in the way. That's not your decision, I decide what matters to me, whether I want my privacy or this nebulous sustainability, whatever this is suppose to be. Wrong. I am using your IP as part of a scheme to fingerprint you. I want my rate limit to limit each person separately. An IP address is just a somewhat decent way to approximate that. Then let me turn this around, if using my IP address in this scenario is surveillance, then don't do it. If it is necessary, then ask me for permission, can we use your IP address to fight off attacks and ensure the availability of our website or do you prefer that the website might not always be available due to attacks? And the same applies if you want to rate limit all users, offer the choice between not using your website or opting in for IP based rate limiting. It's that easy.
- b3morales 5y agoAmazon using shipping addresses in isolation to improve their business is not what people are concerned about here. It's perfectly legitimate for Amazon to say "we're getting a lot of orders from this list of zip codes, let's open some warehouses there". That doesn't infringe on anyone's individual privacy; the action is not tied directly to a single person, and especially not to further data collection/collation.