The other Sean Byrne doesn't exist
conic.alMercury unblocked my accounts because their founder is a very kind man who bothered to verify what the document actually says rather than falling back to, "Computer says no." But everywhere else? De nada. Computer says no.
And it's not even me. It's a fuzzy match with someone in their 50s. Doesn't matter. Computer says no.
And I can't "get off the list" because it's not me who's on the list. The computer will always say no.
In the long run, I'll be fine. I think. But I'll pay $100k+ by the time it's over. These systems are being steadily expanded, as the dumbest incarnations of themselves. We've gone from Thin Thread https://en.wikipedia.org/wiki/ThinThread to crappy fuzzy matches on shoddy data executed on with 0 diligence. It's the stupidest possible timeline.
I think many, many other people will be sharing our fate soon, which is partly why I've been writing about this slow rolling train wreck in motion in bits and pieces.
I remember, after the Snowden leaks, when anyone warned that governments could use the patriot act and the various other "intelligence" power grabs to destroy democracy and implement totalitarian dictatorship, they would be deemed insane conspiracy theorists. The hilarious part is most of them (including me) were warning about a distant future... yet it barely took a decade for America to collapse into fascist populism, declare ANTI-FAscists the real terrorists, and turn the surveillance apparatus against them.
You need a Monero. It's the only damn cryptocurrency that's used.
https://www.cbsnews.com/news/ted-kennedys-airport-adventure/
The simplest solution is to change my phone number. But
a) why should I have to? it’s my number, dammit!
b) how many accounts have 2FA? if I changed my number, what if I miss updating one that’s important?
c) it could happen again
If I change my number, however, that is the simplest way to solve the problem. It’s just, do I want to?
TOTP is portable and can be backed up.
I went a little bit off on a tangent, the stupidity of SMS 2FA is a pet peeve of mine.
I walk to the local phone shop and get a replacement sim for my number with a few of bits of ID and I regain sms access. Totp access is gone forever.
It’s clearly not worse that totp in every way.
You vans I may be able to manage a backup and understand how these codes are generated. The average person does not.
From memory most totp apps don’t even migrate when you move from one phone to another - at least on iPhone. I haven’t done that for 5 years but I seem to remember having to create new entries.
> I walk to the local phone shop and get a replacement sim for my number with a few of bits of ID and I regain sms access.
Or someone else gets access to your SIM by sim swapping you, which is not as stupidly easy as it used to be, but still SMS remains insecure. Building an authentication system on it is just a bad idea from virtually every angle.
Think of how manny John Smiths there are?
How can this be the company started by Wozniak and Jobs ...
It isn’t. The institutions involved simply don’t care whether they are destroying the lives of random people. At all.
And why should they? They are completely unaccountable in practice, sometimes even in theory.
The same Jobs that routinely denied publicly that he was the parent of his daughter, even though he knew? The same Jobs that cheated Wozniak financially? The same Jobs that led to a change in legal legislation on how organ transplants work?
The world needs to move on from this marketing bs that he was somehow a "great" man who is morally solid and must be doing the right thing. Apple is precisely the company founded by Jobs.
Firstly you have the issue that many terrorists are going by a nom de guerre rather than their legal or birth name.
Then, of course, your terrorists will have common names. How many Mohammeds are you gonna list?
Lastly is transliteration. Your no-fly list is in Latin characters. But your terrorists have Arabic and Persian and Hindi and Cyrillic names. So what do you do. Transliteration is an inexact science, and there are often many branching methods of doing it.
So no-fly lists are based on fuzzy matching common pseudonyms. It's a farce, really it is.
Also, sold his soul to the devil at a crossroads, so you gotta be careful.
I appreciate the humor and musical knowledge
And I'm surprised that your joke didn't get more laughs or comments on HN. There is life outside of screens ;)
did he die, or call anyone a "bastard!"
The reason is there. It's no big secret. Pick up a history book.
Nazi Germany and occupied forces used census data, municipal population registers, etc., to identify and track down targeted people. The United States, during World War II, used census information to assist in the removal and incarceration of citizens with Japanese, Italian, and German heritage. The Rwanda population database explicitly classified people as Hutu, Tutsi, or Twa. This became the mechanism to target Tutsi during the Rwandan genocide. In China today, these databases are used to surveil and imprison Uyghurs.
Those are examples of official policy turned to dark purposes. It did not even include malfeasance for malfeasance or criminality by individuals or cartels who somehow gain access.
It's not like you care about all the thing you enumerated, they literally ask you for your "race" when getting a driver's license, which is the defacto ID document anyways. You're installing flock cameras everywhere and gargling palantir's balls while they implement the surveillance state.
The lack of a comprehensive population database only seems to hinder the actual useful civilian bureaucracy, not law enforcement, intelligence services, or ICE. The latter just grab anyone who looks brown enough.
All that these numbers do is uniquely identify people. They aren't private. To actually prove your identity, you present your ID, passport, or a digital signature tied to that identity number.
That also means they should be used simply as an identifier and not as any for of authentication or secret knowledge.
Having the full name + national ID was enough to bypass verification and activate various services, and many people weren't tech savvy enough to realize how dangerous it was to share or leak that info
All else being equal, I'd rather see national ID numbers which are so incredibly obviously un-secret that, at least on their own, they're nothing except a tool for avoiding overlaps and collisions.
Fake identities are dime a dozen. It is not exactly hard for an illicit entity to just put some random ID numbers it bought off the dark web on its books. And now you have just made it even harder for the people who had their identities stolen to clear themselves. How do you convince some company drone doing sanction compliance that you didn't actually work for Sanction Circumvention Ltd when your ID number matches the one on their company's payroll files?
Not to mention the sanction list is full of foreigners. The American authorities compiling the list aren't going to know what's the national ID of a random Russian or Iranian guy running an import business. So what is going to happen if your name matches someone who's on the list with a blank ID field? Probably the same thing that happened to the author, I guess.
Verifying identity is a much simpler problem than establishing identity.
They didn't care to figure out if the Sean Byrne of County Sligo actually existed before putting the name on the list. I doubt they would bother verifying an ID number.
Plus, going back to my point about the list being full of foreigners, how do you verify the validity of a foreign ID number and address? Maybe Ireland is going to comply with a US request, but many other countries won't, and you are now back to square one.
Not bending to the US might be less convenient at times but if you bend for them you will eventually be bending for China.
It's fine to propose a solution but if people aren't convinced just throwing an aphorism grenade at them isn't productive.
> In both cases the courts called for better matching. Compare the date of birth. Compare the middle name.
> There is no version of that available to me. The listing has no date of birth to compare. No middle name and no passport number, because the person doesn’t exist. A screening system that does its job perfectly will still flag me, forever, on the only two facts the record contains: a common Irish name and a country.
These systems operate by matching as much information as possible. If the information isn’t there but the rest matches (even if it’s just a name) it flags in the system.
> Failing that, the actual person can prove that they don’t belong on the list by verifying their identity.
Sounds like you should tell the author. They’ve been living with this problem for 6 years but I’m sure your zero experience with these systems or trying to deal with it will help him immensely.
The idea is you largely prevented the theft, and made it easier to prove, by linking to a physical verifiableb address.
Also the implication that cultures and countries which have happily accepted id numbers are filled with non individualistic people is it?
Many countries have laws about having to carry an ID on you all the time. Not as bad as a tattoo, but still not acceptable IMO.
> Also the implication that cultures and countries which have happily accepted id numbers are filled with non individualistic people is it?
Are we really gonna keep pretending there are no differences between cultures?
Also, I find the point kind of moot for the US where a driving license is essentially an ID card, you have to carry it to drive, and you have to drive to go anywhere in most places.
Either way you are branded forever.
Even GDPR admits it
The real Sean Byrne can produce a government-issued passport number, but that's clearly not enough for Apple.
I think it's more of a problem of all these "hyperscale" platforms where the cost of not being zealous enough is long litigation and devastating fines, while the cost of losing a single customer (or a thousand) is basically nil. This leads to all kinds of opaque, customer-hostile outcomes like this, also if you trip some filters not related to sanctions / mistaken identities. There's a recurring theme of HN posts along the lines of "an automated process at Google cut my business off, HN plz help".
I do not know how are they handled, but they probably get assigned one plausible date and it probably depends on the country.
In a sense, a birth date can be just as much an assigned number as an ID is. An ID can also have a checksum in it, potentially even a cryptographic one that only government can sign.
I’m applying for a second citizenship. That means that I can have two national ids that are unlinked. In the US, you can petition to have your SSN number changed, as well, so that doesn’t work. If you are willing to commit crimes and lie, it isn’t that hard to spin up an entirely new identity. Some people are born to parents that don’t notify the government. The real world is incredibly messy.
If I were to be placed on a list with one passport/id, I could just use a different one.
The bigger issue is that the list is meant as a risk alert, but companies treat a match as truth because the penalty for doing business with a sanctioned entity is far higher than whatever they might lose by not hiring someone mistakenly.
What you need, at minimum, if you are going to make these lists is an easy way for false positive people to prove they aren’t the person named (tsa/homeland security have a “redress number” you can provide if you have the same name as someone on their list). Then a legal requirement that anyone checking this list must also ask for additional documentation if they are making a decision based on a hit.
What happens when every app, website, and mobile OS requires a signature for every single post or message, tying all communication to an identity that the government can retaliate against?
This creates many more problems than it solves.
With services requiring it, you can just not use them: as long as it does not get mandated (unfortunately, a direction we are heading in), hopefully market self-regulates and privacy conserving options win.
Yes, we all know that's not how that movie plays out :)
Same as with passports. Even in the Anglosphere people have passports with passport numbers. They could be used to uniquely identify the passport holder, except of course there are many passports, and therefore, many numbers, for each passport holder.
Small problem? Just update whatever database is holding the information for sanctionted persons (or, indeed, persons who should not be sanctioned)?
Turns out, that is not a small problem.
In Singapore, your number is fixed, even when they give you a new document.
It says the state assigns "A body" a number.
-vs-
The state is made up of us as individuals.
So while the serial keyfield is a data engineers dream, politically I'd welcome something more personal.
Time of birth/parents and other identifying information is on our birth certificates in the UK. Concatenate some of that.
I could be.
DavidAndrewEvans-01011980-0036-MRI-JeanDavis-AlexEvans
Name-DOB-TOB-LocationCode-Parent(s)
Location of Birth like an airport code - MRI (Manchester Royal Infirmary), Parent(s)... i mean we can use their birthdates too.
I actually quite like the idea of it. It seems intrinsically validating to a person to identify them in this way.
Ideally, government could issue a cryptographically signed ID, so anyone with access to countries' public key can verify authenticity (with revocation mechanism built-in for both individual keys and all keys signed with one government — this is where it gets tricky). Obviously, governments become new CAs, and people in them can provide fakes when they want if they are corrupt, but anyone can easily validate it.
You're reinventing a natural key with a bunch of identifiers which aren't stable enough.
Some of the low cost options now a days do not have human in the loop. They often miss obvious red flags or do too much false positives.
UUID names next? v7 so we get the age...
I knew someone with a single-letter name and good luck flying anywhere -- most ticket sales systems won't allow it because the devs didn't read those Falsehoods guides. So you expand the name, e.g. T -> Tee so you can buy the ticket, but when you get to the gate your ticket doesn't match your ID and now you're being escorted out of the building.
I always remember the movie Brazil when I have to interact with a stupid cybernetic apparatus like every big company, where simple programs are the brain and low-paid humans are the actuators.
Luckily he was allowed to make a call just after being detained, to his friend who worked for the British Council in Beirut. The friend was tirelessly in searching for him and seeking his release. It wasn’t easy.
(I met him just after his release, while he was building the courage to try again to leave the country.)
Why was he detained? Because his common Irish first name and common Irish surname matched someone on an Interpol list.
I'm always helping friends with piracy and I have to tell them they can't conveniently use a native app because it isn't listed on the App Store.
And then there's the removal of ICE apps.
It's too much control. On iOS, if the government banned Signal, Apple could enforce it. On GrapheneOS, you can use whatever app from anywhere no matter what.
Trying to contrast this to the EU's attempts to force only gatekeepers (those companies so large that there is no alternative to dealing with them) to open up systems, even at the cost of damaging e.g. apple's valiant and welcome attempts to protect the privacy of its customers, highlights to me that the EU is completely correct in doing so.
None of it would be a problem without the App store in its current form though.
Not really a life-altering inconvenience, and the other forum members got sufficiently uppity that they re-reviewed it and let me back in, but it was a good lesson in how big orgs have no innate common sense.
Google decided to ban my many years old account. Reason: account created by computer program. Likely flagged me because i use multiple computer and connect from other wifi.
Whats worse is i am a monetized youtube partner with million+ views. Youtube support (@TeamYoutube) just say "it is a google problem"
All appeals are handled by bots, there is no way to reach an actual human being.
We are being controlled by our ai overlords. Some bot on some cpu can ruin your life on a whim.
So far, getting the data hasn't happened once AFAIK but magically she's unbanned/ unblocked/ whatever.
The way to retaliate against those stupid lists and the stupid way they are enforced by US companies could be to register a fake company with principals named Tim Cook, Satya Nadella, Donald Trump, etc. (and many other people with less well-known names, but high up in various organizations) and somehow get that company and all its employees' names on a sanctions list?
Not sure what it would take to work, but it would probably be fun.
And heaven's forbid if your actual ID and references (i.e you) have ended up in such places (or such list/s) by mistake or malice.
One of the biggest mind-benders was finding a person with a string of addresses going back 25+ years. Now I've lived in this area for 27, and for some reason, this person's addresses all coincided with mine. They had lived near every residence I ever had; they lived within a stone's throw of every clinic, every church, my college, every place I had a relationship with. One such person's "last known address" was an exact match for my previous address: apartment number and all. I found a profile on Facebook but it is unknown if these are real persons, or fictitious entities in the public record for some purpose.
Then, I found a person who seems to be real (has a Facebook profile with photo, lists a real place of employment, etc.) She shared my exact surname and had a given name that matches my ethnicity. She lived at the same street address for a long time, albeit a different apartment number. I was receiving mail for her.
At some point, this phantom wife/sister was conflated with me in the public record. Obviously someone got her unit number wrong if I got her mail. But my phone number was eventually listed as hers. She has found herself in debt, and is sometimes referred to a collection agency. I've gotten no less than 3 separate inquiries for delinquent debts, that are clearly not mine, that start coming through because her contact info is utterly conflated with mine, and apparently no valid, current info is giving them any leads.
The crazy thing I learned last year is that a collection agency doesn't need to divulge any details of the debt they hold to the person they contact. It is incumbent on the contactee to verify whether they reached the wrong person. I began following CFPB instructions on disputing the debt, but the collections agency clammed up and refused to answer any questions until I answered theirs (registered on their website, divulged a lot of PII). However, the joke's on them, because it is very easy to review credit reports and determine whether a debt is or isn't on my own record.
(Said person was already in prison.)
So essentially, the federal government and three letter agencies are propagating the crime. The original person did something which presumably violated other people’s rights. Now the federal government continues to violate people’s rights by essentially lying about who’s actually a threat.
Not one single person in that system thinks the very obvious "A name without any other data is worthless, let's just delete it from the list".
If people lack agency then you already have an ineffective system but my guess would be that no-one person has the authority to take executive action and every change however daft takes 30 people in a meeting discussing it for an hour so it just gets left as it is.