CqtGLRGcukpy 1 day ago

Non-cloudflare link that basically says the same thing: https://mstdn.social/@stux/117186158784673388

  • totallymike 1 day ago

    Why is cloudflare a problem?

    • zbrozek 1 day ago

      Because they slow down and often block access to websites, particularly for people that try to avoid being fingerprinted or otherwise tracked. Pretty evil behavior.

      • esseph 1 day ago

        > Because they slow down and often block access to websites, particularly for people that try to avoid being fingerprinted or otherwise tracked. Pretty evil behavior.

        Bots and scrapers and hackers also try and avoid being tracked, which is by far a bigger problem for them and most websites than the 15 of us using tons of antifingerprinting techniques. Evil? No, that's silly.

      • nickff 1 day ago

        It is very challenging to distinguish individuals interested in privacy from bots acting maliciously or with reckless indifference. If you devise a way to do this more effectively than Cloudflare, you should start a business to sell this as a service.

        • lynx97 1 day ago

          Sure, I am practicing understanding for the tyranny around me everyday when I wake up, as a meditation exercise.

          Answers like yours kill the little remaining faith I have in people.

          This same argument has been used to defend sloppily implemented CAPTCHAS destroying accessibility since what, 20 years.

          • nickff 1 day ago

            My employer is a small business that has an e-commerce website that is attacked by fraudsters trying to validate stolen credit cards or obtain customer information hundreds of times per day. Operations like CloudFlare are the only way to foil these actors. Just trusting you is not a viable strategy.

            • karmakurtisaani 23 hours ago

              The people who downvote could propose how to solve the fraudster problem instead of shooting the messenger.

              • gib444 22 hours ago

                That isn't the done thing here, lamentably. Downvote is a de facto disagree button

              • lynx97 20 hours ago

                "We removed the wheelchair ramp because it was used by rodents to enter our building."

                "Don't shoot the messenger!"

                Security can't be a reason for discrimination.

                • karmakurtisaani 13 hours ago

                  So keep the ramp then. Now your business is full of rats and even the disabled don't want to shop there. What do you do now?

                  Edit: The downvotes have spoken! This view is simply wrong with no justification!

            • salawat 23 hours ago

              Your rate limits on adding and removing credit cards? Your input sanitization? Designing your system to not just disclose details around anything but that relevant to a logged in/authenticated user?

              There are many practical ways to handle that sort of thing that isn't Cloudflare. It just requires thinking and a bit of dev time.

              t. Been there, done that, cartels used an app to try to launder money through loyalty programs. Management was deadset against doing the one single thing that would make it impossible to do that at scale.

              Ulterior motives abound everywhere but especially behind people claiming X is the only answer. Fingerprinting is far more intrusive than just only allowing one to add at max 2 cards a day per user.

              • yetihehe 22 hours ago

                > Your rate limits on adding and removing credit cards?

                All those requests will appear from different ip's and different browsers, made by someone who can spend months on trying to defraud you. How do you differentiate this from valid customer who happens to try to buy something between 20 tries by bots?

                > Your input sanitization?

                All those fraud requests will give you valid credit cards which will work perfectly, but then defrauded people or banks will try to chargeback later.

                > Designing your system to not just disclose details around anything but that relevant to a logged in/authenticated user?

                They can register as normal buyers.

                > It just requires thinking and a bit of dev time.

                And they can spend months trying to outthink you, then will drain your service in 4 hours when you are asleep.

                > Management was deadset against doing the one single thing that would make it impossible to do that at scale.

                So, did you actually ever implemented and checked a good solution? Cloudflare isn't perfect, but not everyone has resources to implement their own solution that is better than cloudflare.

                > Fingerprinting is far more intrusive than just only allowing one to add at max 2 cards a day per user.

                The fraudsters will appear as completely new users each time, adding only one card and making one purchase.

                • happymellon 22 hours ago

                  > All those fraud requests will give you valid credit cards which will work perfectly, but then defrauded people or banks will try to chargeback later.

                  How are they getting pass 3D-S?

                  If they are able to get past it, then your liability drops off.

                  Yes it could be designed better, but that is a separate discussion.

                  • nickff 8 hours ago

                    It doesn’t matter that they can’t get past 3D-S, because the whole point of what they’re doing is checking what security features are enabled for a card, and whether their address and other validation data will pass. The fact that the scammers are testing so many cards that fail gets you banned from those payments providers, whether or not any payments go through. And this is ignoring all the attackers using bots for other purposes such as taking control of the website to obtain user or client data.

            • tobinfekkes 17 hours ago

              I had this problem too for all my clients e-commerce websites, then solved it 3 years ago with very little code changes.

              Happy to share it with you. Using small businesses for credit card testing is one of the most evil things on the Internet, so anything to stop it is worth it.

      • webdoodle 1 day ago

        Don't listen to these hecklers, you have every right to your privacy, and should demand it. Anonymity is paramount if people want to be able to talk without repercussions. Gaslighting, heckling and other forms of harassment are to convince you to self censor. Don't take the bait. Ignore them.

      • neya 1 day ago

        "Never attribute to malice that which is adequately explained by stupidity."

        • polotics 23 hours ago

          well in my experience mostly you get either:

          - stupidity

          - stupidity and malice

        • salawat 23 hours ago

          Hanlon's Razor is especially effective at getting Good people to put out their own eyes to keep them nice and soft targets for the malicious. I'll take being a harder to find likable by people I have no desire to be liked by to make myself a harder mark. The honest ones will understand. The malicious were never worth being close with, and I'm doing the world a service by getting the borderline enlightened.

          Sufficiently advanced stupidity being indistinguishable from malice is also something to keep in mind.

    • JohnFen 1 day ago

      Cloudflare doesn't reliably let me through.

      • dlcarrier 23 hours ago

        It regularly blocks me too. I've begun search Google for: what does [url] say about [search query]

        It'll make a Gemini summary of the page, and can be prompted for more details. It's really the only use for Gemini I've found reliable. I'd still rather directly view the output of the scraper bot, though.

        If anyone knows a good scraping bot that lets you view the output directly, without running it through an LLM, please let me know.

    • pibaker 15 hours ago

      Getting past cloudflare can be a problem if you are from a less reputable country or a VPN or if you use a less conventional browser.

      There is also a larger problem of a private entity being the MITM for a large portion of internet traffic. But i don't think this is the point GP was trying to make.

    • ranger_danger 10 hours ago

      Most CF sites I try to visit only give me an endless captcha loop, so I cannot visit them at all.

      I suspect it's simply because my ISP regularly rotates IPs, and so I unfortunately have to share "reputation" with other users who can't behave online.

artisinal 1 day ago

In the USA, is it really that easy to find the home address of a business owner?

The EU briefly had a similar registry but that got shut down quickly.

  • lotsofpulp 1 day ago

    Land records are public in most US locales. You can type in almost any residential address on homes.com and it will show you who owned it when and with what loan terms.

  • hattmall 1 day ago

    Not really, it looks like this guy originally registered the business at his personal residence which is not really common. Kinda surprised if he still lives there considering how FLOCK has expanded.

  • dlcarrier 23 hours ago

    Yes, but only for the business directly owned. In the US, it's perfectly legal to run things through shell companies that make things much more difficult. E.g. instead of directly owning the company, he could put his share in fully-owned shell company, based in a country that doesn't report the owner.

cocacola1 1 day ago

It’s been interesting to see this vitriol towards Flock increase over the past couple of months or so.

  • bamboozled 23 hours ago

    What is interesting about it ?

    • camillomiller 22 hours ago

      I think they spelled satisfying wrong

    • alexjplant 22 hours ago

      Because Flock is the first company to so brazenly violate the post-2011 social contract: if you're going to track somebody you need to give them coupons and content as compensation. They have failed to provide the people whose privacy they are violating with internet drama and buttcheeks videos. Other companies with many times greater reach and market cap collect GPS, cell tower, and 802.11 ESSID data to observe their users' movements; they track them across web sites and apps without explicit consent to serve personalized advertisements and adjust prices for durable goods and services depending upon user behavior. They do this with impunity because people enjoy short-form videos and image macros and will readily trade their privacy for easy access to them. Flock has nothing to offer in this regard. This is why they are shunned whereas other companies that understand how this game is played are forgiven for equivalent or worse sins.

      • aceazzameen 16 hours ago

        I agree with the post, despite the sarcasm. But the one thing it's missing is how Flock uses AI to pass user data directly to law enforcement without a warrant. At least (most?) of other companies that comply with the said social contract wait for the warrant.

    • cocacola1 11 hours ago

      The speed of the surge + people feeling strongly enough about it that they destroy the cameras + events like the grand jury that refused the indictment. I usually just see this kind of vitriol remain online. That it’s crossed into the real world like this is interesting to see.

platesmead 22 hours ago

"Doxxing is bad except when it's against people I dislike"?

If people don't want CCTV, campaign to make it illegal.

  • beAbU 17 hours ago

    Flock is not CCTV though. There's nothing 'closed circuit' about it at all, and that's the problem.

    • platesmead 17 hours ago

      Okay, reading car plates. Again, campaign to make it illegal.

Simulacra 19 hours ago

The irony is over the top with this guy. He says that Americans need to "compromise" on their privacy, but then absolutely loses it when the Panopticon is turned on him.

webdoodle 1 day ago

Ironically most of the people reading this are doing so on an always connected phone with a fused battery, that they can't trust, because they don't control it. It also has significantly more capabilities that a flock camera, and they likely pay for it too.

  • ethanwillis 1 day ago

    It's called choice. Maybe a dumb choice, but a choice!

  • HDBaseT 1 day ago

    false equivalence.

  • kadoban 1 day ago

    That's not ironic, that's _hey, look over there!_

yonran 1 day ago

The article is very one sided, implying without evidence that Flock is for recreational tracking of individuals. With San Francisco SFPD’s ALPR cameras at least, this would be an abuse of the cameras according to the policy linked from https://transparency.flocksafety.com/san-francisco-ca-pd. Here are the Authorized purposes:

Locate stolen, wanted, and or other vehicles that are the subject of investigation

To apprehend wanted persons subject to arrest warrants or who are otherwise lawfully sought by law enforcement.

To locate victims, witnesses, suspects, missing children, adults, and/or elderly individuals, including in response to Amber Alerts and Silver Alerts and others associated with a law enforcement investigation.

To assist with criminal investigations initiated by local, state and regional public safety departments by identifying vehicles associated with targets of criminal investigations.

Counter-terrorism: Identify potential threats to critical infrastructure sites.

For other law enforcement purposes as authorized by law: Investigations of major crimes.

Which of these uses do people not like? Or which other policies are people concerned with in other jurisdictions?

  • chews 1 day ago

    161 people in LA were stopped for bad data using flock cameras. The contract with them is canceled but the damn things are still up giving data to DHS probably.

  • defrost 1 day ago

    Not on the list, but documented:

    * Live monitoring of teenagers in gyms for sales purposes,

    * Multiple counts of stalking by LEOs,

    * Instances of unsecured access,

    * Multiple erroneous plate matching directly leading to "swatting" of women and children on day to day shopping trips.

    • yonran 22 hours ago

      The Dunwoody MJCC monitoring seems the worst incident in that Flock never issued a postmortem on how the terms of the sharing were violated.

      Abuses in violation of policy are a problem like in any organization that can be reduced through auditing, discipline, etc. And it seems that the ones that have been caught (Jarmarus Brown of Orange City, FL; Asad Zahir of Shively, KY; Emily Pacheco of New Bedford, MA) have been disciplined and/or charged.

      Insufficient security of devices is a problem but does not have to do with my comment about the intended uses.

      Officers have to be trained about OCR errors, just like we have to know when to trust an LLM. The SFPD policy I linked says officers shall “Visually verify the alphanumeric characters on the plate” before stopping a car identified by ALPR. And like LLM hallucinations OCR errors will go down over time.

  • soulofmischief 1 day ago

    The unwarranted mass surveillance and dragnet part. We have a thing called the fourth Constitutional amendment here in the United States. We also have the first amendment, which the Supreme Court has ruled in the past must not be subject to a "chilling effect".

    The Flock camera system, and any dragnet surveillance system, is a direct chilling effect to the rights to freedom of speech, freedom from religious persecution and freedom of assembly.

    The inalienable aspect of these rights means that literally no example or rationalization you can provide would justify impacting those rights for even a single individual or group.

    • sroussey 22 hours ago

      You carry a phone with you broadcasting constantly. Not sure why police just don’t buy your location data from data brokers. Maybe they do…

      • defrost 22 hours ago

        > You carry a phone with you broadcasting constantly.

        You know them personally?

        I can't speak for them but I, for one, don't.

        • sroussey 10 hours ago

          You don’t carry a phone with you?

          I aim to get there some day…

      • zingababba 16 hours ago

        Cast off your demoralization and join the resistance.

      • soulofmischief 2 hours ago

        Two wrongs don't make a right. I have dealt with multiple incidents of police harassment and gross misconduct and I don't trust them with my location data any more than I do a national camera network that pervades neighborhoods and intimate spaces.

  • lostlogin 22 hours ago

    > The article is very one sided

    Of course it is. If we want a Flock press release we can just read one.

    Plenty of things have lots of great upsides, and it’s the downsides that stop wider adoption and cause regulation and limits.