site banner

Culture War Roundup for the week of June 17, 2024

This weekly roundup thread is intended for all culture war posts. 'Culture war' is vaguely defined, but it basically means controversial issues that fall along set tribal lines. Arguments over culture war issues generate a lot of heat and little light, and few deeply entrenched people ever change their minds. This thread is for voicing opinions and analyzing the state of the discussion while trying to optimize for light over heat.

Optimistically, we think that engaging with people you disagree with is worth your time, and so is being nice! Pessimistically, there are many dynamics that can lead discussions on Culture War topics to become unproductive. There's a human tendency to divide along tribal lines, praising your ingroup and vilifying your outgroup - and if you think you find it easy to criticize your ingroup, then it may be that your outgroup is not who you think it is. Extremists with opposing positions can feed off each other, highlighting each other's worst points to justify their own angry rhetoric, which becomes in turn a new example of bad behavior for the other side to highlight.

We would like to avoid these negative dynamics. Accordingly, we ask that you do not use this thread for waging the Culture War. Examples of waging the Culture War:

  • Shaming.

  • Attempting to 'build consensus' or enforce ideological conformity.

  • Making sweeping generalizations to vilify a group you dislike.

  • Recruiting for a cause.

  • Posting links that could be summarized as 'Boo outgroup!' Basically, if your content is 'Can you believe what Those People did this week?' then you should either refrain from posting, or do some very patient work to contextualize and/or steel-man the relevant viewpoint.

In general, you should argue to understand, not to win. This thread is not territory to be claimed by one group or another; indeed, the aim is to have many different viewpoints represented here. Thus, we also ask that you follow some guidelines:

  • Speak plainly. Avoid sarcasm and mockery. When disagreeing with someone, state your objections explicitly.

  • Be as precise and charitable as you can. Don't paraphrase unflatteringly.

  • Don't imply that someone said something they did not say, even if you think it follows from what they said.

  • Write like everyone is reading and you want them to be included in the discussion.

On an ad hoc basis, the mods will try to compile a list of the best posts/comments from the previous week, posted in Quality Contribution threads and archived at /r/TheThread. You may nominate a comment for this list by clicking on 'report' at the bottom of the post and typing 'Actually a quality contribution' as the report reason.

8
Jump in the discussion.

No email address required.

so it's not like this was providing any real security benefit to my account against intruders

Yes, it is providing an excellent security benefit -- that from here on out the account will be protected by association to an additional factor.

Obviously it's not retroactively possible to add that as a factor for this specific login. But that doesn't mean it's of no benefit.

but doing it to someone who remembers literally every single piece of identity information associated with their account is a whole new level of bastardry.

You have as much information as a well-motivated attacker might have. In fact, you went to great efforts to make yourself so uncorrelated with the original login, that you are indistinguishable from an attacker.

On some level, sure, this is a failure of the technology to have more factors that the real count has that an attacker wouldn't (although see above -- you got mad when they tried to add more factors)

I immediately went back to Protonmail and created a new account then returned to Discord signing up for another shiny new account with my shiny new email.

Please, I don't want to look like abuse but I'm going to do everything I can to look like abuse!

Our system has flagged third-party service registration emails shortly after your account creation, which goes against the intended use of our service and may indicate disposable account usage.

Obviously. You made the account just to get past various other registrations. Of course that's gonna flag you.

Think of the alternative: if ProtonMail (or whoever) allowed this shit, then Discord (et al) wouldn't accept a ProtonMail account as a verification.

WTF???????? The fact that you knew this was a registration email from Discord implies that you have scanned my email

No, they don't scan. Discord and others explicitly insert metadata into the email header saying "this is a service registration request, please ensure that only established accounts can read it". No scanning necessary, because Discord actively tags it. You can read it yourself in the SMTP headers.

intense burning hatred inside of me for the way these big companies operate

This is maybe understandable, but at the same time this is niche-of-a-niche kind of user behavior.

The social question of whether the systems that we put in place need to accommodate the needs of tiny minorities of people rather than being aligned to the larger majorities is well trod.

The social question of whether the systems that we put in place need to accommodate the needs of tiny minorities of people rather than being aligned to the larger majorities is well trod.

Privacy is incompatible with Gattaca's "Valid world" or Shadowrun's SIN. If we still believe it's a right - as it has been for most of history and is official policy in most Western countries - SINs as a prerequisite of existing in society can't be allowed. If we don't, we should go the whole hog, abandoning all restrictions on government surveillance (there is a lot more social good in police surveillance than corporate surveillance!), ripping out the "three felonies a day" from the criminal code*, and possibly going the full Geodesica-Bedlam route of "privacy is against the law; everyone gets to access the telescreen cameras and run spy drones".

*Laws that everyone breaks + no privacy = police state, since everyone is always provably guilty and thus prosecutorial discretion is ultimate power. And, indeed, we're sliding in that direction at the moment.

What about zero knowledge proofs?

What is to be zero-knowledge proven?

The current ideas around the application of the technology are precisely that you could use it to build a digital identity system that still retains privacy.

The usual example involves medical records: instead of having some centralized authority store all of your information and reveal select parts of it to people of interest, which has the properties you decry, you could hold this information encrypted (and even public to some degree) and require the signature of the individual to verify any property of this shared encrypted data without ever even exposing the data itself.

You could have your pharmacy check that a doctor prescribed a particular drug to you without knowing what your illness is, who the doctor is or any other information about you and none of that information be handled in the clear by any state authority.

Whether it's realistic that such a system would be made is another question, but the raw technical impossibility you speak of is, at least, being questioned right now.

OP's usecase doesn't seem amenable to zero-knowledge-proof, though; you could certainly prove that you have access to a SIN, but everyone has such access (including spammers) so there's not much point.

Maybe i'm being too literal, but SR SINs are specifically about what social categories you're part of in the RPG, not mere individual identification.

That assumes that the phone number is there for security. It's actually there so that Google can collect information about you and correlate it with other information about you that uses the phone number. The claim that it's there for security is a lie.

Why would it not just be both? They make money on it and it also improves security for most people most of the time. They're willing to take the hit of angering a few weirdos that want to spoof and aren't actually doing anything sketchy if it makes them money and improves the user experience for people that don't care to hide their location or identity. Being able to correctly identify the owner of the account seems like an almost perfect alignment of interests between security and profit.

Seconded and endorsed across the board.