5 ms·
The way the Internet is built, it's very difficult (maybe impossible) to ever tell if a client app is being operated by a human or a bot. There are various ways
by tobyjsullivan 4y ago
The way the Internet is built, it's very difficult (maybe impossible) to ever tell if a client app is being operated by a human or a bot. There are various ways to make automation harder, and there are heuristics to guess if the operator might be a bot, but neither are absolute.
The best we can build today is an environment that "feels" like everyone is human but where we don't actually know and where that's almost certainly not true. (Think about Snapchat's "no screenshot implementation" as a real-world parallel.) The only bots on the platform would be the most nefarious actors who are willing to invest in the arms race.
Any platform that solves this problem will have to take a different approach - probably assuming there are bots and then providing tools to allow humans to only interact with other humans they can reasonably trust.
- alias_neo 4y agoYou have a very "positive/optimistic" outlook on how this would go down; My immediate thought was that an implementation of this platform would be using legal identification to prove humans, allowing for one a huge depository of highly-accurate personally identifying information; a security and privacy nightmare in my opinion. This already happens in many places, but those are regulated companies, banks etc, I couldn't imagine a social platform holding the crown jewels like this ever not being a disaster.
- deleted 4y ago[deleted]
- worldsayshi 4y agoYou don't have to have the social networking site handle the privacy information. You could integrate eId as identity providers and for a site like Twitter only provide guarantee that this is a human and this identity is unique for this human on this service. You wouldn't be anonymous but you could be anonymous towards everyone but the identity providers.
- alias_neo 4y agoGood point, I had totally forgotten about identity providers. I've only had to use one, which I totally disagree with; I can't remember which one, but some government site here in the UK required an IDP and the options were things like the "Post Office"; Not the sort of organisation I want to be trusting with my identity/login for any government site.
- borbulon 4y agoThat’s not completely true; you would be anonymous towards everyone but the identity providers and any government or organization powerful enough to wield influence over the identity providers. Which completely defeats the most important reason people choose to remain anonymous.
- worldsayshi 4y agoAh, yeah I implicitly meant that the identity providers basically have to be government owned so yes. I don't really see a way around this if the aim is to prove human-ness though.
- borbulon 4y agoRight, but the identity providers being government owned exacerbates the problem I'm talking about. I don't personally care if Joe the random person has access to an anonymous account*, but I do care if Joe the Russian dissident—whose entire ability to safely post points of view which disagree with his government relies upon it—has access to an anonymous account. * I am not saying there aren't other valid reasons, including entertainment reasons, to have an anonymous account. But those aren't part of my main point
- tobyjsullivan 4y agoThe only thing legal identification proves is that a human created the account. It does not prove that a human is posting or reading/scraping content. And even then, what does a photo of ID from some foreign country prove? That the person signing up had something that looked like legit ID? Or do we start building a global database of IDs of every human that is "government approved" and somehow not subject to corruption in certain countries?
- klabb3 4y ago> The way the Internet is built, it's very difficult (maybe impossible) to ever tell if a client app is being operated by a human or a bot. Indeed, I'm leaning towards it's not possible: - Even if you required government id, you'd get a market of people selling their unused accounts, or access to them. - You can use end-to-end DRM, like iMessage, to rate limit and complicate access to accounts, but it prevents access to legitimate actors. - Even if you magically solve it, it still prevents legitimate bot access, such as those that keep track of when Elon musks private jet is being used. The older I get, the more I think we're all just holding it wrong. Like the war on drugs, you can't just hunt down the bad actors. Instead, social networks simply become what they incentivize. If you make "followers" and "influence" your inofficial currency, the spam and impersonation isn't exactly a mystery. In fact, I'm pretty sure that engagement optimization contributes to making spam much worse (think clickbait). I don't think our current generation of social networks was designed with a solid understanding of game theory. Or perhaps it was, but the important findings were ignored because it tends to interfere with growth.
- zimpenfish 4y ago> If you make "followers" and "influence" your inofficial currency, the spam and impersonation isn't exactly a mystery. How would that translate to, e.g., email where spam and impersonation is a huge decades-long problem but there's no "followers" or "influence" to be gamed?
- friendzis 4y ago> to only interact with other humans they can reasonably trust. Remember when key exchange parties were supposed to be a thing ad we would build a network of trust and so on?