14 ms·
No user accounts, by design
- nonrandomstring 5y agoWhat we used to call "Need to know" is making a comeback. You don't need to know. I don't need to know. And in most cases the less we do know the better. Glad that GDPR is spreading this fundamental security principle again. Most websites could and should dispense with sign-in. Even those that have something to sell can compartmentalise that function these days. That's why I like Gemini, because of its regression to more or a less stateless web that is about words, roles, knowledge, links, things and places, but not so much about people and "identity". That's where we've gone wrong with WWW.
- hinkley 5y agoI have been experimenting with trying to draw a line between wants and consequences where I work. It's tough, and I'm only barely making headway, but on a large project what you often end up with is people adding costs to the system without a clear payoff, and without cost accounting. I am trying to get telemetry in place to demonstrate how much of our capacity is going to particular features, so that we can say, okay, that wizbang thing is costing us $100k a year. Our profit is 1:X (we make $X for every dollar we spend). Is this lowering or raising our profit margin? I think we are completely disconnected from opportunity costs and the entire center of most orgs I've been in are all about covering your own butt and telling stories. Until the layoffs happen and then we discover that the investors, advisors and some of the C suite actually care about whether spending $1 for the prospect of making $1.50 is a complete waste of time and energy. And I often wonder if some of the narratives I hear about who got laid off and why are not seeing this calculus in the results.
- neonate 5y agohttps://archive.is/DcvFS https://archive.is/DcvFS
- a_c 5y agoI have been thinking how we can incentivize people building netizen friendly website/app. Creating users, cookies, javascripts heavy, paywall, analytics, etc all share a common incentive of ease of monetization. Privacy, usability, performance, all important stuff, but apparently not important enough, as a result plummeted. Would love to learn the options!
- deleted 5y ago[deleted]
- Kwpolska 5y ago> Mozilla has taken this idea a step further with Firefox Klar (also known as Firefox Focus similar to Firefox Klar but with less private default settings). Nope, Klar == Focus in German-speaking markets, the rename was caused by an existing trademark: https://support.mozilla.org/en-US/kb/difference-between-firefox-focus-and-firefox-klar https://support.mozilla.org/en-US/kb/difference-between-fire... Speaking of which, Focus fits my flow of incidental, one-off browsing quite well — it’s my default browser. If I need a more serious or stateful interaction, I might have the service’s/whatever’s app installed, or use Chrome or full Firefox.
- kuschku 5y agoIt’s actually not that simple – Firefox Focus and Firefox Klar are two different apps, with different packages. The official Firefox Klar builds originally contained slightly less tracking than the official Firefox Focus builds. Nowadays it might be only the trademark that keeps them separate, but originally there were clear differences in code.
- awinter-py 5y ago'anonymity is a great way to ensure privacy' is a strong argument IMO if (if) you assume that it's impossible for consumers to account for how sites use and share userdata, requiring businesses to allow anonymous transactions is the only policy solution to privacy tricky to balance a 'right to anonymous transaction' against other policy goals like financial KYC, fraud protection, but IMO our current KYC approach has been taken too far at the cost of consumer welfare, and there's an unexplored middle ground
- politelemon 5y agoApp developer's perspective. I have a few apps on all major places, including F-Droid. The 'no user accounts' thing makes developing and distributing on F-Droid a freeing experience, as compared to the G/A 'jails'. There is no pressure to meet arbitrary undocumented restrictions, you are not subject to the whims of dehumanizing AI routines, there are no ratings and reviews (the feedback is direct). The build and deployment process is not really my problem, as part of their Reproducible Builds, even that aspect is taken care of. https://f-droid.org/en/docs/Reproducible_Builds/ https://f-droid.org/en/docs/Reproducible_Builds/
- sneak 5y agoI find the distributor-does-the-building-and-signing to be problematic from a security point of view. I would much prefer that each developer does a build, signs it, and a notarization of some kind is added by the distributor. It seems to me that if you can compromise the f-droid infrastructure you can compromise millions of handsets.
- progval 5y agoF-Droid already supports this. From GP's link: > This means that F-Droid can verify that an app is 100% free software while still using the original developer’s APK signatures
- bduerst 5y agoHow do you solve problems arising from bad actors without an object representing the user?
- psanford 5y agoWe're just talking about software delivery here. Its the same as Debian not requiring you register before using `apt` to install packages (or every other linux distro).
- bduerst 5y agoThe article gives specific examples like virtual meeting software that doesn't have users, just URLs. It's more than that.
- hedora 5y agoThe solution for that is easy: Don't share the new URL with someone that was a jerk in the past. (And don't make it easy to guess meeting URLs)
- bduerst 5y agoHow do you share a URL without a user representation to share with? How do you prevent others from sharing URLs with bad actors? Or meeting passwords? https://en.wikipedia.org/wiki/Zoombombing https://en.wikipedia.org/wiki/Zoombombing
- tedunangst 5y agoYou send the url to your friends however you like. Email, chat, QR code. You don't send it to people who aren't your friends.
- bduerst 5y ago> How do you prevent others from sharing URLs with bad actors? Sure, but then the student who shares their interactive class URL (w/ or w/o password) on 4chan still isn't accounted for.
- 2OEH8eoCRo0 5y agoI've always wished that mobile app "stores" worked more like Linux package managers.
- encryptluks2 5y agoStill hopeful to get a proper Linux phone someday.
- imiric 5y agoThe PinePhone (Pro) and its ecosystem looks promising, no? I'd say we're closer than ever to it being a capable daily driver, certainly by the next iteration.
- fsflover 5y agoOr Librem 5, whose software is developed not by volunteers but by a company.
- charcircuit 5y agoNote that the Librem 5 is practically a scam. There are still people who ordered in 2017 who have not received their phone. Requesting a refund takes hundreds of days to be issued.
- fsflover 5y agoIt's not a scam. Did you hear about supply chain problems in CPUs? See here about delivery progress: https://forums.puri.sm/t/estimate-your-librem-5-shipping/11272 https://forums.puri.sm/t/estimate-your-librem-5-shipping/112.... Every time Purism can get the CPUs, they deliver another bunch of the phones.
- charcircuit 5y ago>See here about delivery progress That thread is backing up what I said. 4 days ago someone from the original crowdfunding campaign in 2017 is being shipped his Librem 5. If someone were to order a Librem 5 today (for $1200, double what people in 2017 paid) they too may have to wait years to get it. >Did you hear about supply chain problems in CPUs? Purism had years to procure the CPUs they needed. >Every time Purism can get the CPUs, they deliver another bunch of the phones. Sure, but the amount they are able to make is not enough. Purism's timeline constantly slips. Your money is stuck in an interest free loan to Purism that they won't let you get out of. It is not hard to find people complaining about not getting refunds or refunds taking hundreds of days to go through. It seems like they want to get as much money as possible while delivering as few phones as possible. This may not be their intention, but this is what it feels like to a lot of people.
- deleted 5y ago[deleted]
- Liquix 5y agoLove the sentiment & love F-Droid. Vote for non-dark patterns with your patronage wherever possible! It's a bit sad how a website not employing a dark pattern inspires explicit praise these days...
- wpietri 5y agoI tried something like this once and it worked surprisingly well, even for a UGC site. Years back we were doing something that included users documenting TV shows. We had a big meeting where people put every feature they wanted on index cards. We laid the cards out a founder's dining room table. The host got their change jar and each person got a certain number of pennies to mark features they thought were vital for first launch. After the first round of token-voting, the "user accounts" card had no votes. At first it seemed impossible. But after some discussion, we realized that viewing users didn't need accounts for launch. For people who wanted to edit, we let them type in a name to take credit for their contributions if they wanted, but with no verification. At worst, we figured we could add something more robust if the need were stronger. It turned out fine. The launch got out earlier and we got to test a number of key product hypotheses without having to build any sort of user account system. Months later it did eventually become the highest priority. But not having accounts worked way longer than I expected.
- sneak 5y agoWhat about abuse/vandalism? If the whole web has edit privileges, what's to stop someone from scripting changing all of the titles to random strings every hour? Do you do a captcha on every edit or something? I think the main idea around user accounts is that they centralize a point of applying captchas as well as a tiny bit of data collection (some form of contact information) that can be used for antispam (e.g. banning certain email address domains from creating accounts, or banning certain email addresses, etc).
- wpietri 5y agoI'm familiar with the theory. But accounts just aren't a big barrier to determined bad actors. Note that the world's biggest content site, Wikipedia, allows anonymous edits and always has. And note also that some of big tech companies, despite having all the money in the world, still have problems with fake accounts. So at best, requiring user accounts is one possible anti-abuse step, but it's neither necessary nor sufficient to prevent abuse.
- 5y ago
- seppoonbi 5y agoThere is also midground which takes good/bad parts of both worlds. Users have id’s but no username or password. Some imageboards use this.
- jkaptur 5y agoI've been thinking a lot about this for https://www.diffdiff.net https://www.diffdiff.net. After convenience, privacy is the core of the value proposition - the text to diff doesn't get sent to the server. On the other hand, though, if you want to publish/share a diff, then, you know, privacy is the core of the value proposition, so you probably don't want to share it with the whole world, much less let the whole world edit or delete it! It's possible to design a scheme with hard-to-guess URLs, URL parameters with "secret edit tokens" and so on, but that feels hard to use and different from how other sites work. I'm quite torn.
- syrrim 5y agoThe way mega.nz works is the sharable url contains a decryption key in the hash. The server only sees encrypted data, the client requests that data then decrypts it. This design ensures they have no ability to see user content, while still enabling users to share links on the web.
- m1sta_ 5y agoThey still have the ability to see user content, but it would require them to make a change to their codebase. If they did such a change silently...
- hansel_der 5y agojust like whatsapp encryption
- nobodywasishere 5y agoWhat if you embedded the diff in the html link itself, like PlantUML does for their web version?
- tgsovlerkhgsel 5y agoF-droid gets many things right (e.g. verifiable builds), but it's just not usable in practice. Installing applications is a rare event, updating them is frequent, and needs to disrupt the user as little as possible. Android used to not allow alternative app stores to update apps without user interaction, but now supports this through UPDATE_PACKAGES_WITHOUT_USER_ACTION, which doesn't seem to be supported by F-droid. So it's manual clicking for each update. F-droid also somehow gets the regular update flow wrong and often (always?) shows an error when you try to install the update from the notification. That has remained unfixed for years. So you have to manually open it, initiate the update, then click through the dialogs. Additionally, the official repos update so slowly that they're useless for fast-moving stuff like NewPipe. Together with Android bugs like https://issuetracker.google.com/issues/204233247 https://issuetracker.google.com/issues/204233247 (resetting all "open with" URIs on update), this makes using packages installed through F-Droid a nightmare.
- simcop2387 5y agoI believe this is a result of fdroid wanting to support older android versions for longer than google does. They could probably make two versions to allow this though but that would require more maintenance
- btdmaster 5y agoIssue tracking here: https://gitlab.com/fdroid/fdroidclient/-/issues/2316 https://gitlab.com/fdroid/fdroidclient/-/issues/2316
- staindk 5y agoNot really a counter point because you mention a lot of other issues with f-droid that sound valid (I haven't used it myself) - but as a tangent regarding auto updates, I disable them basically everywhere because I seem to have buggy experiences too often if I allow stuff to update all the time. I then go through the list of updates in the Play Store once a week or so and install those that I think might improve app functioning/stability. I look over and install Windows updates once a way-too-long (need to work on this). Feel like everyone is skimping on QA these days or something else fishy is going on. In the last handful of years there have been 2 or 3 Windows updates that either permanently erased data or caused some other insane issues. I didn't get them (tbf I understand that most people didn't), partially thanks to having auto updates disabled.
- lifeisstillgood 5y agoThe thing that F-droid are getting right here is "if we don't track you, you have privacy from us". But privacy is not secrecy. If f-droid tracked my every waking move, and then just never bother to look at that data, I would still have privacy from them. What they are doing here is a form of guaranteeing their future good behaviour. Which is nice, but there are other methods. For example I am happy to announce my plans to not rob a bank. But there are means in place to ensure I do not - At least not twice. So while it is nice to find ways to avoid having user accounts at all, most hospitals will have to have other means to keep their users privacy. Most of the time we are going to need to rely on regulation, where PII data (which lets face it is 98% of all data) will both legally and culturally have to be protected at levels hardly dreamed of today.
- hinkley 5y ago> I would still have privacy from them. No, they have an unexploited asset and you think you're safe because nobody has exploited it yet. This is false security. If money gets tight they'll exploit it. If they get bought out the new owners will exploit it. If they get hacked, the entire Internet will exploit it. I would highly recommend that you spend a little bit of time thinking about or working with groups of dissidents, other oppressed groups, even people who have been sexually harassed. I have seen so much wrong-thinking about what Security actually is and it's always people living in a privilege bubble, not thinking of actual, real life existential threat that exposure can represent until they have some user in hiding because they got death threats after being doxxed. Or just plain disappearing because their government black-bagged them over something they posted online.
- lifeisstillgood 5y agoYes, I do live a privileged life. I think I get it. And I do not want to spark some kind of fight here. I am interested in your views and would be interested in specific cases / archetypes of concern. But I do not want to be on the side of "we need a better way to hide". Staying hidden should not be the solution to death threats. Jail is the solution. I hate that we (western ? US/UK?) society has abandoned hope of properly funding a justice system, let alone a mental health system. In our society I do not want the response to death threats to be "hide better". It must be "police better". And that is expensive and difficult and long. In other societies, well, We are not going to bring the worlds dictators down with clever messaging protocols. That is going to be old fashioned politics (and by recent events war too). I have been very unsure about posting this - it's a very big wide topic that raises a lot of emotions. And that's because it is important - we have much to fix about our world.
- newaccount74 5y agoI try to follow this as much as possible, but at some point when providing a paid service you run into the problem that you need to track whether the user has paid for the software or not. So even though my software does not require user accounts, it requires a serial number to activate all features. That serial number can be linked to the purchaser, so in theory my app could do really invasive tracking. (It doesn't, but my users have to rely on my word) How can one fix this? I would love for my software to somehow anonymously check whether the user paid for it, and isn't running it on more than X devices, but I'm not sure how this could be done without revealing the users identity.
- 13415 5y agoMullvad allows Bitcoin purchases of tokens, which can then be used as a serial for the VPN that works for the time period you've purchased. Users can change tokens any time. That's probably close to what you're already doing.
- lucb1e 5y agoOr for those less blockchain-inclined, you can just send them cash as well... https://mullvad.net/en/pricing/ https://mullvad.net/en/pricing/ ctrl+f cash (the section has no anchor)
- trs-80 5y agoYep, came here to say this. It doesn't get any more anonymous than cash in the mail. :)
- newaccount74 5y agoI'm not sure how Mullvad does it, but I keep a record of who purchased what serial number. My number one customer support request is people asking for their serial numbers because they lost them, which is why I keep a record.
- nosedief 5y agoI'd like to point to my comment on another thread pointing out some poignant issues with F-Droid's design: https://news.ycombinator.com/item?id=30507185 https://news.ycombinator.com/item?id=30507185
- deleted 5y ago[deleted]
- pabs3 5y agoI note that F-Droid are hiring contractors right now: https://guardianproject.info/contact/android-python-contractor/ https://guardianproject.info/contact/android-python-contract...
- MomoXenosaga 5y agoF-droid reminds me there are still people out there making software for fun. Thank you Hendroid dev (a man of culture as well) whoever you are.
- langsoul-com 5y agoI feel that no user accounts just makes things harder. For some things it isn't required, like joining a video call. But user accounts helps reduce spam, save profiles and enable cross platform syncing. Sure you could do something like have a user account-like process, which involves unique ids and all that jazz. Except, at that point, you're making a user account with 10 more steps.
- Falkon1313 5y agoYeah, but I think a lot of things could do well with just a pseudonym and a passphrase. Sure, that's still a user account, but no email or phone number or other stuff required (unless you want notifications, or to be able to reset your passphrase). And maybe prefer procedurally-generated identicons rather than photo avatars if you want a visual aspect.
- mro_name 5y agoin meatspace a lot of things work without logging in – use cash, buy a hammer, make phonecalls from public booths, take a train etc. Actually showing your id was once rare and still is. In the 80s in UK a lot of people did well completely without one.