Rendered at 23:52:59 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
stevoski 14 hours ago [-]
I once met an Irish person who was detained at Beirut Airport when (trying to) leave the country, and who then disappeared into the Lebanese prison system. Really, he just disappeared.
Luckily he was allowed to make a call just after being detained, to his friend who worked for the British Council in Beirut. The friend was tirelessly in searching for him and seeking his release. It wasn’t easy.
(I met him just after his release, while he was building the courage to try again to leave the country.)
Why was he detained? Because his common Irish first name and common Irish surname matched someone on an Interpol list.
darkhorn 14 hours ago [-]
Let me guess, he was living in his home address and he was employed. He had no visits by police but when he tried to leave the country no one was bothered who he really was but they were bothered that a not so much friendly UI message has appeared on the screen.
snickerer 14 hours ago [-]
Oh, the classic Tuttle <-> Buttle name confusion!
I always remember the movie Brazil when I have to interact with a stupid cybernetic apparatus like every big company, where simple programs are the brain and low-paid humans are the actuators.
dcminter 13 hours ago [-]
Brazil is one of the scariest films I've ever seen.
This is one of the obvious consequences of not having a national identity number assigned to everyone at birth, which exist in most developed countries, except for anglosphere, for some reason.
pibaker 16 hours ago [-]
Objection to ID numbers as a concept aside, I don't think it actually solves the problem this author faced.
Fake identities are dime a dozen. It is not exactly hard for an illicit entity to just put some random ID numbers it bought off the dark web on its books. And now you have just made it even harder for the people who had their identities stolen to clear themselves. How do you convince some company drone doing sanction compliance that you didn't actually work for Sanction Circumvention Ltd when your ID number matches the one on their company's payroll files?
Not to mention the sanction list is full of foreigners. The American authorities compiling the list aren't going to know what's the national ID of a random Russian or Iranian guy running an import business. So what is going to happen if your name matches someone who's on the list with a blank ID field? Probably the same thing that happened to the author, I guess.
larsnystrom 15 hours ago [-]
If they put an ID on a sanction list, there’s a possibility to verify it. They could verify that it actually belongs to the person they want to sanction before putting it on the list. Failing that, the actual person can prove that they don’t belong on the list by verifying their identity.
Verifying identity is a much simpler problem than establishing identity.
vlovich123 6 hours ago [-]
From the article which clearly wasn’t read:
> In both cases the courts called for better matching. Compare the date of birth. Compare the middle name.
> There is no version of that available to me. The listing has no date of birth to compare. No middle name and no passport number, because the person doesn’t exist. A screening system that does its job perfectly will still flag me, forever, on the only two facts the record contains: a common Irish name and a country.
These systems operate by matching as much information as possible. If the information isn’t there but the rest matches (even if it’s just a name) it flags in the system.
> Failing that, the actual person can prove that they don’t belong on the list by verifying their identity.
Sounds like you should tell the author. They’ve been living with this problem for 6 years but I’m sure your zero experience with these systems or trying to deal with it will help him immensely.
pibaker 15 hours ago [-]
> If they put an ID on a sanction list, there’s a possibility to verify it
They didn't care to figure out if the Sean Byrne of County Sligo actually existed before putting the name on the list. I doubt they would bother verifying an ID number.
Plus, going back to my point about the list being full of foreigners, how do you verify the validity of a foreign ID number and address? Maybe Ireland is going to comply with a US request, but many other countries won't, and you are now back to square one.
larsnystrom 14 hours ago [-]
Don’t let perfect be the enemy of good. As you said, Ireland might comply, which would’ve solved this particular issue.
msandford 9 hours ago [-]
Yes it's true we shouldn't let perfect be the enemy of good. But good also has to be good enough to solve the problem without creating more problems faster than it solves them.
It's fine to propose a solution but if people aren't convinced just throwing an aphorism grenade at them isn't productive.
okayishdefaults 8 hours ago [-]
I like to tack on "good enough" when throwing this particular aphorism grenade
fairlyaday 13 hours ago [-]
The courts obviously never had an id document for the US to find. Is the US going to omit all partial identities to avoid false positives or is Ireland going to illegally investigate lists for the US from extra judicial processes that likely involve non-extraditable crimes? Will the US believe every country that says these investigations found no real citizen?
Not bending to the US might be less convenient at times but if you bend for them you will eventually be bending for China.
JSR_FDED 8 hours ago [-]
Testing a new Markov chain? What is this incoherent drivel?
chrisjj 12 hours ago [-]
> It is not exactly hard for an illicit entity to just put some random ID numbers it bought off the dark web on its books. And now you have just made it even harder for the people who had their identities stolen to clear themselves.
The idea is you largely prevented the theft, and made it easier to prove, by linking to a physical verifiableb address.
matherial 14 hours ago [-]
How so? The article is talking about a fictitious person that's listed by name only on a sanctions list despite the government knowing the person doesn't exist. There is no possibility of the real Sean Byrne presenting a government number that is a negative match against the list because the fake Sean Byrne has no known ID to match against. The essence of the entry is just "here's a name to avoid".
The real Sean Byrne can produce a government-issued passport number, but that's clearly not enough for Apple.
I think it's more of a problem of all these "hyperscale" platforms where the cost of not being zealous enough is long litigation and devastating fines, while the cost of losing a single customer (or a thousand) is basically nil. This leads to all kinds of opaque, customer-hostile outcomes like this, also if you trip some filters not related to sanctions / mistaken identities. There's a recurring theme of HN posts along the lines of "an automated process at Google cut my business off, HN plz help".
Aozora7 14 hours ago [-]
In this particular case, it would be harder to produce a fake signature from a non-existent person if the signatures in questions were digital and backed by a national identity number. The kind of that I'm submitting when signing documents at work.
layer8 12 hours ago [-]
Aside from the fact the entry in question was added to the list almost two decades ago, it’s naive to assume that people would only be put on these lists if they have a verified identity number. If that was a rule, the easier rule of requiring a birth date would already have helped. Because while not everyone has a national ID number, pretty much everyone has a birth date.
necovek 10 hours ago [-]
There are people whose birth date is not really known (babies left at doorsteps, people from war-torn countries with no official record who had no parents to tell them of their birth date...).
I do not know how are they handled, but they probably get assigned one plausible date and it probably depends on the country.
In a sense, a birth date can be just as much an assigned number as an ID is. An ID can also have a checksum in it, potentially even a cryptographic one that only government can sign.
yassa9 16 hours ago [-]
in Egypt, every person is born with a universal national ID number , which is standardized everywhere here, but it created some problems, it became extremely valuable to attackers.
If leaked, it can be reused across completely different services ( and you can never change it under anycase )
Having the full name + national ID was enough to bypass verification and activate various services, and many people weren't tech savvy enough to realize how dangerous it was to share or leak that info
Terr_ 3 hours ago [-]
Right, people and organizations failing to (care to) distinguish between "highly distinctive" versus "true" is not a data design problem, it's a social/political one.
foxglacier 15 hours ago [-]
Clearly it was the services that weren't tech-savvy using a non-changeable non-secret ID as some kind of authentication. Can't blame the users here.
ramraj07 15 hours ago [-]
This is the SSN in the US too though.
JuniperMesos 13 hours ago [-]
One good reason to introduce a national ID system in the US would be in order to replace and deprecate the Social Security Number, which is a terrible system that never should have been used as a de-facto national ID system.
lmz 6 hours ago [-]
Something tells me the people misusing the SSN would just misuse this new national ID number too. Wasn't the issue that people were treating knowledge of the (de facto public) ID number as proof of identity? Nothing is stopping them from doing the same with any future ID number.
Terr_ 3 hours ago [-]
Ironically, a certain level of secrecy is worse than having them fully public, because it leads people to (wrongly) design systems and processes that trust it or assume something from it.
All else being equal, I'd rather see national ID numbers which are so incredibly obviously un-secret that, at least on their own, they're nothing except a tool for avoiding overlaps and collisions.
5 hours ago [-]
smsm42 4 hours ago [-]
So, instead of SSN dumps on the darknet, we'd have national ID dumps, which will be stolen within months (either from the government itself, or from credit bureaus or data brokers). How did that improve anything exactly?
7 hours ago [-]
smsm42 4 hours ago [-]
How the identity number would help? It's not like terrorists tell each other their identity numbers. So if the LEOs learn about a terrorist guy that goes around under the name "Sean Byrne", how would they know which ID number that is? And even if I needed some ID number to put on my fake documents, it's easy to download one of the dozens data dumps on the darknet now, and just use any of the IDs there. The LEOs then have a choice - put that number into their ban database (therefore banning some innocent person whose only fault is that he made a mistake of participating in the economy) or go just by the name (which is not better). Don't see how it changed anything.
numpad0 59 minutes ago [-]
That doesn't work unless everyone is always referred to by that number. All it takes is a "credible" information on some database that says you're the other Sean Bryne, now with the related national ID.
YeGoblynQueenne 12 hours ago [-]
I'm from Greece, where I have a national identity number. In fact I've had several (maybe half a dozen?) national identity numbers. You see, the national identity number is, literally, the number on your national identity card, or in other words the serial number of the document; not the person. When the document changes, the number changes with it.
Same as with passports. Even in the Anglosphere people have passports with passport numbers. They could be used to uniquely identify the passport holder, except of course there are many passports, and therefore, many numbers, for each passport holder.
Small problem? Just update whatever database is holding the information for sanctionted persons (or, indeed, persons who should not be sanctioned)?
Turns out, that is not a small problem.
eru 10 hours ago [-]
> You see, the national identity number is, literally, the number on your national identity card, or in other words the serial number of the document; not the person. When the document changes, the number changes with it.
In Singapore, your number is fixed, even when they give you a new document.
neximo64 16 hours ago [-]
Its not as if it even helps since the numbers can be leaked and stolen and then abused & the situation ends up even worse since it is so centralised.
Aozora7 16 hours ago [-]
Identity numbers being abused is a consequence of them being misused. And as far as I can tell, this happens more often with american SSNs than anywhere with actual national identity numbers.
All that these numbers do is uniquely identify people. They aren't private. To actually prove your identity, you present your ID, passport, or a digital signature tied to that identity number.
lotsofpulp 16 hours ago [-]
The abuse only happens because US courts deemed a third party liable for a lender’s error/cost cutting in attempting to verify a borrower’s identity.
larsnystrom 16 hours ago [-]
You’re talking about different things. Sweden has personal identity numbers and they’re public information. It protects you from being mixed up with someone with the same name. Not from identity theft though.
trollbridge 11 hours ago [-]
Making them explicitly public is better than the US situation where they’re treated like a password - a password you can’t change if it gets disclosed, and that lots of people feel entitled to get.
ramraj07 15 hours ago [-]
In most countries you cant do anything with a single number id of a person. Except ironically the US so youre doubly so off.
nkrisc 13 hours ago [-]
Unique identifiers should be public. There shouldn’t be any leaking.
That also means they should be used simply as an identifier and not as any for of authentication or secret knowledge.
unixhero 16 hours ago [-]
It helps. Period.
chrisjj 12 hours ago [-]
We just need untheivable unlosable numbers /i
Macha 14 hours ago [-]
Ireland has a PPS number which everyone who’s ever had a job or claimed government benefits has. The union of those sets is basically everyone. Clearly that hasn’t helped.
basilikum 13 hours ago [-]
That is far from everyone.
boxed 14 hours ago [-]
Well.. yea, because it's the US that creates the list, and they don't know or understand that systems like ID numbers exists.
dghlsakjg 7 hours ago [-]
Or they understand that ID numbers are a less than perfect way to identify people.
I’m applying for a second citizenship. That means that I can have two national ids that are unlinked. In the US, you can petition to have your SSN number changed, as well, so that doesn’t work. If you are willing to commit crimes and lie, it isn’t that hard to spin up an entirely new identity. Some people are born to parents that don’t notify the government. The real world is incredibly messy.
If I were to be placed on a list with one passport/id, I could just use a different one.
The bigger issue is that the list is meant as a risk alert, but companies treat a match as truth because the penalty for doing business with a sanctioned entity is far higher than whatever they might lose by not hiring someone mistakenly.
What you need, at minimum, if you are going to make these lists is an easy way for false positive people to prove they aren’t the person named (tsa/homeland security have a “redress number” you can provide if you have the same name as someone on their list). Then a legal requirement that anyone checking this list must also ask for additional documentation if they are making a decision based on a hit.
nevdka 14 hours ago [-]
Americans use their social security numbers like id numbers in all sorts of systems. This problem has nothing to do with id numbers.
bagels 15 hours ago [-]
He has a passport with a number on it. Why isn't that sufficient? There are also multiple countries involved in this story.
Aozora7 15 hours ago [-]
When you renew your passport, the new one will have a new serial. Not matching a passport serial doesn't mean anything. Not matching a national identity number does.
7 hours ago [-]
Georgelemental 4 hours ago [-]
No, the problem is the due-process-free list of government-designated undesirables
hdgvhicv 14 hours ago [-]
America has social security numbers. U.K. has national
Insurance numbers, Ireland had a PPS and Canada has an SIN
graemep 16 hours ago [-]
National ID numbers will not help with cross border situations like this.
nephihaha 15 hours ago [-]
Don't worry, I don't doubt it will be turned into an international system like phone numbers.
dgellow 14 hours ago [-]
Isn’t that already the case?
tonfa 12 hours ago [-]
I guess ITINs are already pretty cost to this.
KronisLV 12 hours ago [-]
UUIDv7 for all!
karel-3d 6 hours ago [-]
Tony Blair joined the chat
thetimewotitis 11 hours ago [-]
I mean in theory, it doesn't have to be a serial number, and I think that's better. Something about it suggests being enlisted in a national army.
It says the state assigns "A body" a number.
-vs-
The state is made up of us as individuals.
So while the serial keyfield is a data engineers dream, politically I'd welcome something more personal.
Time of birth/parents and other identifying information is on our birth certificates in the UK. Concatenate some of that.
Location of Birth like an airport code - MRI (Manchester Royal Infirmary), Parent(s)... i mean we can use their birthdates too.
I actually quite like the idea of it. It seems intrinsically validating to a person to identify them in this way.
necovek 10 hours ago [-]
The problem with that is that it leaks too much information to anyone seeing it — this is bad if it needs to be used with any party you might not trust (or not trust their security). Serbia (former Yugoslavia) already does something similar since 1970s, and your Unique Citizen Number (JMBG) is derived from your date of birth and county of issuance (usually birth county) and sex at birth, a couple of digits and a single digit checksum.
Ideally, government could issue a cryptographically signed ID, so anyone with access to countries' public key can verify authenticity (with revocation mechanism built-in for both individual keys and all keys signed with one government — this is where it gets tricky). Obviously, governments become new CAs, and people in them can provide fakes when they want if they are corrupt, but anyone can easily validate it.
oasisbob 9 hours ago [-]
Names and even dates of birth aren't consistent enough in records for this.
You're reinventing a natural key with a bunch of identifiers which aren't stable enough.
functionmouse 9 hours ago [-]
Yes. And they should be tattooed onto the person's arm, so there can be no mistake. Maybe a bar code?
UltraSane 13 hours ago [-]
I wish people were assigned a identity certificate with public and private key at birth.
defrost 13 hours ago [-]
Multiple distinct sets of such things would be better.
sneak 11 hours ago [-]
What happens when they lose it? What happens when someone else gets a copy of the private key?
What happens when every app, website, and mobile OS requires a signature for every single post or message, tying all communication to an identity that the government can retaliate against?
This creates many more problems than it solves.
necovek 10 hours ago [-]
I agree and believe revocation is the most important problem.
With services requiring it, you can just not use them: as long as it does not get mandated (unfortunately, a direction we are heading in), hopefully market self-regulates and privacy conserving options win.
Yes, we all know that's not how that movie plays out :)
UltraSane 8 hours ago [-]
The private key would be generated and stored on the most secure hardware security modules like how AWS stores many billions of symetric and asymmetric keys.
chrisjj 12 hours ago [-]
For the 0yr-old to keep private?
UltraSane 11 hours ago [-]
Private key would be stored on a government HSM obviously
chrisjj 8 hours ago [-]
Unfortunately so. Any solution would rely on trust and for that reason alone would be unworkable.
UltraSane 1 hours ago [-]
I wonder if you could leverage etherium smart contracts to reduce the need for trust.
reaperducer 16 hours ago [-]
for some reason.
The reason is there. It's no big secret. Pick up a history book.
Extropy_ 16 hours ago [-]
Care to be a little less vague? Maybe a little more helpful?
rendall 16 hours ago [-]
A government may have entirely benign reasons for creating a comprehensive population database, but you cannot guarantee who will control that database later. You have to trust the people who control it, not only now, but at all times in the future, but history does not support that.
Nazi Germany and occupied forces used census data, municipal population registers, etc., to identify and track down targeted people. The United States, during World War II, used census information to assist in the removal and incarceration of citizens with Japanese, Italian, and German heritage. The Rwanda population database explicitly classified people as Hutu, Tutsi, or Twa. This became the mechanism to target Tutsi during the Rwandan genocide. In China today, these databases are used to surveil and imprison Uyghurs.
Those are examples of official policy turned to dark purposes. It did not even include malfeasance for malfeasance or criminality by individuals or cartels who somehow gain access.
Aozora7 15 hours ago [-]
A government won't give up on malicious acts just because it lacks accurate census. The United States does a lot more surveillance and oppression than EU countries that have national ID and mandatory ID documents.
The lack of a comprehensive population database only seems to hinder the actual useful civilian bureaucracy, not law enforcement, intelligence services, or ICE. The latter just grab anyone who looks brown enough.
wizzwizz4 14 hours ago [-]
In the US, where race is entirely defined by skin pigmentation and there's heavy segregation ("redlining") of living quarters, sure: databases aren't necessary. But in places where race is defined by heritage or culture, things which can be disguised by the targets of a regime, these databases are a vital part of any serious ethnic cleansing operation. I don't remember the statistic in IBM and the Holocaust that compares Jew survival rates in occupied countries with versus without digitised censuses, but the difference was stark.
dgellow 14 hours ago [-]
Are you aware that pretty much every developed country has such database? Even the US, its guaranteed US 3 letters agencies have such comprehensive population databases
toasty228 16 hours ago [-]
Uh? The reason is that the constitution doesn't explicitly allow the federal gov to do it, so it's a state power.
It's not like you care about all the thing you enumerated, they literally ask you for your "race" when getting a driver's license, which is the defacto ID document anyways. You're installing flock cameras everywhere and gargling palantir's balls while they implement the surveillance state.
po1nt 15 hours ago [-]
Yeah and that's exactly what shouldn't happen. Government's should not have a power to ask a private company for data under any circumstances and they should not make "race" a compulsory data to submit, so that you could exercise your rights.
tonfa 12 hours ago [-]
In some European countries government (and private entities) isn't allowed to collect ethnicity information.
po1nt 9 hours ago [-]
Unfortunately ethnicity isn't the only thing you can discriminate on. You can figure out the ethnicity from surname a lot of the times.
po1nt 15 hours ago [-]
Attaching numbers to people is unbelievably creepy. My identity is not a number. We recoil at the idea of having assigned and tattooed numbers on our bodies and I don't feel it's okay to do it, just so you could maybe avoid misidentification.
Almondsetat 15 hours ago [-]
You are the one somehow conflating an identity card with your actual identity as a self, which seems extremely strange and spurious.
pibaker 15 hours ago [-]
The one conflating the two isn't the author, but the state. A fixation on the state sanctioned representation of someone's identity instead of the actual, living person himself is exactly what caused TFA's author troubles.
Almondsetat 12 hours ago [-]
You could ask every company to have a specialized department to handle investigations for these nuanced cases... or you could rely on the state/nation to give you some actual assuranced. National ID solves this. Does Apple have the budget? Yes, but then are smaller companies justified for fucking up? Wouldn't a more objective, verifiable, and automatable procedure be preferred to level the playing field?
goobatrooba 13 hours ago [-]
The problem seems to be that the state has no other way to really identify them differently, also as one of them doesn't exist. An actual identity identifier would have solved this from ever occurring.
ramraj07 15 hours ago [-]
Why did it need to go to tattooed numbers?
Also the implication that cultures and countries which have happily accepted id numbers are filled with non individualistic people is it?
pibaker 15 hours ago [-]
> Why did it need to go to tattooed numbers
Many countries have laws about having to carry an ID on you all the time. Not as bad as a tattoo, but still not acceptable IMO.
> Also the implication that cultures and countries which have happily accepted id numbers are filled with non individualistic people is it?
Are we really gonna keep pretending there are no differences between cultures?
Aozora7 15 hours ago [-]
Very few countries require you to carry an ID. Many countries require you to own one and keep it up to date, but don't care whether you carry it outside.
Also, I find the point kind of moot for the US where a driving license is essentially an ID card, you have to carry it to drive, and you have to drive to go anywhere in most places.
8n4vidtmkvmk 6 hours ago [-]
In the US, permanent residents technically have to keep their green card on them at all times.
po1nt 15 hours ago [-]
So that you could not impersonate some other identity. Same in the spirit of carrying a plastic card, just without somebody touching you by force.
Either way you are branded forever.
esikich 15 hours ago [-]
Is your identity a string of letters? Don't be ridiculous.
po1nt 15 hours ago [-]
Yes, if there is a set of strings that can uniquely identify you, and you can't have it removed, nor act like somebody else, it's your identity.
Even GDPR admits it
skywhopper 14 hours ago [-]
So, your name is also this sort of identifier. But an “identifier” is not an “identity” in the way you mean it. Sometimes words are used in multiple ways.
shelled 12 hours ago [-]
This scares me! Denial of service (in some cases you may not even have an alternative), in some cases custody, et cetera and that too based on a false positive or a flimsy match. And no one doubles checks it, no one bothers to make sure, and they are allowed to do that! All this is actual legal and no one pays for it once it's found out, and even if you have suffered. None.
And heaven's forbid if your actual ID and references (i.e you) have ended up in such places (or such list/s) by mistake or malice.
gwerbin 5 hours ago [-]
Also because there's no real due process associated with these various lists, they can be used to punish political enemies.
Mercury unblocked my accounts because their founder is a very kind man who bothered to verify what the document actually says rather than falling back to, "Computer says no." But everywhere else? De nada. Computer says no.
And it's not even me. It's a fuzzy match with someone in their 50s. Doesn't matter. Computer says no.
And I can't "get off the list" because it's not me who's on the list. The computer will always say no.
In the long run, I'll be fine. I think. But I'll pay $100k+ by the time it's over. These systems are being steadily expanded, as the dumbest incarnations of themselves. We've gone from Thin Thread https://en.wikipedia.org/wiki/ThinThread to crappy fuzzy matches on shoddy data executed on with 0 diligence. It's the stupidest possible timeline.
I think many, many other people will be sharing our fate soon, which is partly why I've been writing about this slow rolling train wreck in motion in bits and pieces.
praptak 16 hours ago [-]
Terrorism went from "kill one person to scare millions" to "stir shit up to cripple the adversary with the costs of prevention".
somat 14 hours ago [-]
That is the fundamental of guerrilla warfare. The guerrillas can't win but can loose with very little cost while the cost for the established side to "Win" is an order of magnitude more.
andai 8 hours ago [-]
"Encourage your adversary to do more of the thing they've been pushing for half a century."
Henchman21 6 hours ago [-]
“When your enemy makes mistakes, don’t stop them.”
TalkingCodeMonk 13 hours ago [-]
After 9/11 (and long before), the majority of historians and academia warned that the political response to terrorism — the destruction of civil liberties, implementation of mass surveillance, Islamophobia, populism — were a greater threat and risk to our freedoms than the terrorists ever were.
I remember, after the Snowden leaks, when anyone warned that governments could use the patriot act and the various other "intelligence" power grabs to destroy democracy and implement totalitarian dictatorship, they would be deemed insane conspiracy theorists. The hilarious part is most of them (including me) were warning about a distant future... yet it barely took a decade for America to collapse into fascist populism, declare ANTI-FAscists the real terrorists, and turn the surveillance apparatus against them.
psd1 17 hours ago [-]
"The evil, I can tolerate; but the stupidity..." -Hubert Farnsworth
darkhorn 13 hours ago [-]
May be you need to change your name to something unique like Ackfknetce. That will be cheaper.
layer8 11 hours ago [-]
Until Trump tweets it by mistake.
Henchman21 6 hours ago [-]
At least at that point you’re familiar with the name change process
mock-possum 16 hours ago [-]
How can you possibly afford to pay $100k for something like this? That’s so much money!
areoform 16 hours ago [-]
Can I afford to? No.
But will I have to? Yes.
shmeeed 11 hours ago [-]
Did you consider changing your name?
Cider9986 14 hours ago [-]
>It started rather innocuously. Someone couldn’t send me money.
You need a Monero. It's the only damn cryptocurrency that's used.
This has been going on for a long time. In the early 2000s I knew someone with the relatively common name Ian Smith who was routinely held up in airports because someone else with that name was on a watch list. I think in the end he managed to get some kind of stamp in his passport that officially said "not that Ian Smith", and it seems mad this isn't easier to resolve these days.
darkhorn 13 hours ago [-]
It looks like it will be a good idea to name a baby after those databases are checked so that he/she is less likely have a problem in the future.
flurdy 12 hours ago [-]
Now we know why Elon named his kid 'X Æ A-Xii'.
UUID names next? v7 so we get the age...
qingcharles 4 hours ago [-]
Having a single-letter first name is also a road to dystopian aggravation.
I knew someone with a single-letter name and good luck flying anywhere -- most ticket sales systems won't allow it because the devs didn't read those Falsehoods guides. So you expand the name, e.g. T -> Tee so you can buy the ticket, but when you get to the gate your ticket doesn't match your ID and now you're being escorted out of the building.
Henchman21 6 hours ago [-]
He named his children gibberish because he has a ketamine problem and is trying extra hard to “be cool”
necovek 9 hours ago [-]
I believe this real Sean Byrne should move into Sligo for a while, just to spice it up a little. Then they can also ask to be removed from the list as the person on the list.
Cider9986 14 hours ago [-]
The App Store as the only way to install apps is the worst part about iOS and why I'll never use it again.
I'm always helping friends with piracy and I have to tell them they can't conveniently use a native app because it isn't listed on the App Store.
And then there's the removal of ICE apps.
It's too much control. On iOS, if the government banned Signal, Apple could enforce it. On GrapheneOS, you can use whatever app from anywhere no matter what.
veeti 9 hours ago [-]
Once Android developer verification rolls out globally, Alphabet Inc. in Mountain View and the US sanctions and export controls list will become the sole arbitrer of accepted software publishers. Only minority platforms like GrapheneOS, Mac OS X, Win32, Linux remain as free general computing operating systems.
rzwitserloot 13 hours ago [-]
If a government entity would work like this, all heck would break loose.
Trying to contrast this to the EU's attempts to force only gatekeepers (those companies so large that there is no alternative to dealing with them) to open up systems, even at the cost of damaging e.g. apple's valiant and welcome attempts to protect the privacy of its customers, highlights to me that the EU is completely correct in doing so.
gwerbin 5 hours ago [-]
Government entities in the USA already work like this. That's how all this came about.
derbOac 12 hours ago [-]
Yes, the posted story has so many layers of wrongness in it — it's hard to pick just one.
None of it would be a problem without the App store in its current form though.
lbriner 5 hours ago [-]
What makes me kind of angry is this is a totally and easily fixable problem but for whatever reason, the people who could do something about it have no desire for improvement and would happily let the cost and inconvenience continue.
Not one single person in that system thinks the very obvious "A name without any other data is worthless, let's just delete it from the list".
If people lack agency then you already have an ineffective system but my guess would be that no-one person has the authority to take executive action and every change however daft takes 30 people in a meeting discussing it for an hour so it just gets left as it is.
saejox 13 hours ago [-]
Not exactly the same still i would like to share my horror story.
Google decided to ban my many years old account. Reason: account created by computer program. Likely flagged me because i use multiple computer and connect from other wifi.
Whats worse is i am a monetized youtube partner with million+ views. Youtube support (@TeamYoutube) just say "it is a google problem"
All appeals are handled by bots, there is no way to reach an actual human being.
We are being controlled by our ai overlords. Some bot on some cpu can ruin your life on a whim.
tialaramex 7 hours ago [-]
The recurring recipe for Jill Bearup has been after exhausting all the "appeal" and "support" processes which are hopeless and either can't or won't help, to ask for the underlying data so that you can understand their decision. In the EU [and because it was once a member of the EU when this rule was enacted, the UK] you're legally entitled to that data because you are its subject.
So far, getting the data hasn't happened once AFAIK but magically she's unbanned/ unblocked/ whatever.
kazinator 18 hours ago [-]
You can't seriously match people on first and last name and claim "fully matched".
Think of how manny John Smiths there are?
How can this be the company started by Wozniak and Jobs ...
cbsmith 18 hours ago [-]
As a guy named Chris Smith, I can tell you, people do absolutely "match people on first and last name", and it causes me no end of trouble.
projektfu 8 hours ago [-]
I failed a background check once because they even ignore middle name/initial. The record in the system had a different MI and I provided mine. Also, birthdate, location, race, etc., were all mismatched. Thankfully, in that case, I was able to provide documentation that I was not a match, but it is incredibly frustrating to have false positives and no "this is positive but it is obviously a partially incorrect match. In the OP's hypothetical about a pre-screening background check, you might never get the opportunity to clear your name.
qingcharles 4 hours ago [-]
And most systems and forms in the USA only provide for one middle initial, which makes things tricky for those coming from other cultures.
nephihaha 17 hours ago [-]
They do unfortunately. I know someone with a more unusual surname who was getting chased for the debt of someone with the same name. It happens.
17 hours ago [-]
p-e-w 16 hours ago [-]
You’re presenting this like a mistake born out of incompetence.
It isn’t. The institutions involved simply don’t care whether they are destroying the lives of random people. At all.
And why should they? They are completely unaccountable in practice, sometimes even in theory.
layer8 11 hours ago [-]
I think he’s presenting it as the shortcoming of not caring.
altmanaltman 16 hours ago [-]
> How can this be the company started by Wozniak and Jobs ...
The same Jobs that routinely denied publicly that he was the parent of his daughter, even though he knew? The same Jobs that cheated Wozniak financially? The same Jobs that led to a change in legal legislation on how organ transplants work?
The world needs to move on from this marketing bs that he was somehow a "great" man who is morally solid and must be doing the right thing. Apple is precisely the company founded by Jobs.
9 hours ago [-]
projektfu 8 hours ago [-]
TBF, the company of Wozniak would have a way around the App Store restrictions, so it's obviously not that anymore. Probably hasn't been since Sculley.
ButlerianJihad 11 hours ago [-]
No-fly lists are sort of bonkers in this way.
Firstly you have the issue that many terrorists are going by a nom de guerre rather than their legal or birth name.
Then, of course, your terrorists will have common names. How many Mohammeds are you gonna list?
Lastly is transliteration. Your no-fly list is in Latin characters. But your terrorists have Arabic and Persian and Hindi and Cyrillic names. So what do you do. Transliteration is an inexact science, and there are often many branching methods of doing it.
So no-fly lists are based on fuzzy matching common pseudonyms. It's a farce, really it is.
martinclayton 14 hours ago [-]
One option might be for the real Sean Byrne to move to the address in Sligo of the fictitious one, then ask to be removed from the Entity List on the grounds that he is a real person. I think that wouldn't work, and could be life-changing in a bad way, but it's an idea.
ricardobeat 13 hours ago [-]
Ah, yes, irreversibly linking himself to the same address and adding an impersonation criminal charge will improve his situation a lot!
layer8 11 hours ago [-]
It might result in his address and birth date being added to the entry on the Entity List, now that the authorities have gained knowledge of that additional information. ;)
soneil 3 hours ago [-]
Sligo's not _that_ bad.
dcminter 13 hours ago [-]
I got temporarily banned from the Sun Java Forums years and years ago because of something like this. I tried creating a few test accounts and it seemed to be the first name, not even the full name, that was the "match" ! I assume someone on the list had an alias of just "Dave" or "David" and whoever implemented the filter had just done the easiest thing possible.
Not really a life-altering inconvenience, and the other forum members got sufficiently uppity that they re-reviewed it and let me back in, but it was a good lesson in how big orgs have no innate common sense.
HtmlProgrammer 4 hours ago [-]
I assure you there are several Sean Byrnes in Sligo, and at least one in Drumcliff
soneil 3 hours ago [-]
Yeah it's pretty much a John Smith, which I assume was half the point, and is now most the problem.
zhivota 19 hours ago [-]
Honestly the best thing to do might be to change your name at this point. I'm glad my name is not common, this kind of issue is going to only get worse in the future.
kmoser 18 hours ago [-]
That is trading one problem for another: when the name on your birth certificate doesn't match the name on your government issued ID, certain other government entities tend to deny you services.
derriz 16 hours ago [-]
This is the case for me - since the age of 4 or 5. I don’t live in the US but have lived and worked in 3 different countries and the only time it was an issue was getting married. Everything else - bank accounts, drivers license, residency permits, employer background checks, etc were no problem.
gucci-on-fleek 18 hours ago [-]
I would think that changing the last name only should be fine though, since up until somewhat recently, most women changed their last names when they got married, so most systems should be equipped to handle this.
kmoser 10 hours ago [-]
You would think. But that's not always the case: Florida residents face driver’s license denials over mismatched documents https://www.youtube.com/watch?v=5FSwv_D8gxw (Now, it's Florida, which may partly explain the idiocracy.)
nephihaha 17 hours ago [-]
It used to be very common for migrants to change their surnames, although less so now. There used to be a person who wrote about Scottish Lithuanians called John Millar, who was born as Jonas Stepšys. Noam Chomsky had said that his family's surname was substantially altered after they went to the USA.
a57721 16 hours ago [-]
And older example: Warner brothers were born as Wonsal (or Wonskolaser), and they changed their names too (Hirsz became Harry, Aaron became Albert).
nephihaha 15 hours ago [-]
There are tonnes of them. Especially Eastern Europeans and Jews. Italians sometimes too. Still happens in entertainment, since Steve Carell and Nicholas Cage's real names are more Italian sounding.
netsharc 15 hours ago [-]
Hah. Cage changed his last name because he didn't want to be a "nepo-baby"... You should look up that Italian-sounding last name and see who it belongs to.
nephihaha 5 hours ago [-]
I know who he's related to, but he did go for a very un-Italian name.
basilikum 14 hours ago [-]
In some countries you can get a new birrh certificate with your new name.
deeplytroubled 16 hours ago [-]
[dead]
mproud 17 hours ago [-]
I get phone calls for a guy named Randy about his business. I can’t for the life of me figure out how to make the phone calls stop.
The simplest solution is to change my phone number. But
a) why should I have to? it’s my number, dammit!
b) how many accounts have 2FA? if I changed my number, what if I miss updating one that’s important?
c) it could happen again
If I change my number, however, that is the simplest way to solve the problem. It’s just, do I want to?
14 hours ago [-]
basilikum 14 hours ago [-]
2FA over SMS is stupidly bad. It's worse than TOTP in every aspect including this reason. It is also much less secure. You could start switching accounts to TOTP regardless of this and then decide if you want to switch your number later when you have the option.
TOTP is portable and can be backed up.
I went a little bit off on a tangent, the stupidity of SMS 2FA is a pet peeve of mine.
hdgvhicv 14 hours ago [-]
If I lose my phone I have no totp access or sms access
I walk to the local phone shop and get a replacement sim for my number with a few of bits of ID and I regain sms access. Totp access is gone forever.
It’s clearly not worse that totp in every way.
basilikum 9 hours ago [-]
Only if you don't backup your TOTP tokens. Just like you lose your photos when you lose your phone. One of the main advantages of TOTP is that it is portable and can be backed up.
> I walk to the local phone shop and get a replacement sim for my number with a few of bits of ID and I regain sms access.
Or someone else gets access to your SIM by sim swapping you, which is not as stupidly easy as it used to be, but still SMS remains insecure. Building an authentication system on it is just a bad idea from virtually every angle.
Peacefulz 13 hours ago [-]
I suggest exporting your password manager && your topt keychain onto an encrypted flash drive. I went through the horrors of having a phone die on me after migrating my topt to a local solution. Having a valid login cookie on bitwarden on my laptop was the only thing that saved me.
hdgvhicv 13 hours ago [-]
And that post is why sms is superior.
You vans I may be able to manage a backup and understand how these codes are generated. The average person does not.
From memory most totp apps don’t even migrate when you move from one phone to another - at least on iPhone. I haven’t done that for 5 years but I seem to remember having to create new entries.
Peacefulz 11 hours ago [-]
I've moved between three managers in the past two years and all of them supported importing and exporting your full lists. That could be a recent development, though. I admit, I haven't used an apple product in a long time, so you could be right. I don't trust SMS, because I don't trust cleartext over the air. Too many people have too much time on their hands and information is too readily available.
duskdozer 11 hours ago [-]
I agree but there are so many places that demand only SMS 2FA
nephihaha 15 hours ago [-]
We managed to get given a drug dealer's former landline, and had to get it changed after strange calls in the middle of the night. Then our neighbours got the same number after about a year and had the same issue.
grey-area 18 hours ago [-]
No, the best thing to do is get the press involved and make Apple and ideally the US gov fix their incompetent handling of this.
ben_w 18 hours ago [-]
Given a US senator was "on" the post-9/11 no-fly list for the same stupid reason, merely making noise and getting the press invlolved isn't enough to fix the deeper problem.
In Ireland you can use the Gaelic spelling and probably get away with it. Poof, no matches for Seán Ó Beirn.
18 hours ago [-]
duskdozer 10 hours ago [-]
Well, until they decide that a name change is inherently suspicious under these circumstances, and things get even worse.
dgellow 14 hours ago [-]
Its not always possible, some countries make it pretty hard to do a change of name
eterm 15 hours ago [-]
What name do you suggest they choose, "Roger Thornhill" perhaps?
bachmitre 3 hours ago [-]
Tim Cook should do, or Donald Trump, either one should get you removed from the list quickly
bitlad 15 hours ago [-]
Background check softwares do this too.
Some of the low cost options now a days do not have human in the loop. They often miss obvious red flags or do too much false positives.
bambax 13 hours ago [-]
The reason Apple or Google or Microsoft don't care one way or the other is their directors rarely if ever suffer from their policies. We should try to make them.
The way to retaliate against those stupid lists and the stupid way they are enforced by US companies could be to register a fake company with principals named Tim Cook, Satya Nadella, Donald Trump, etc. (and many other people with less well-known names, but high up in various organizations) and somehow get that company and all its employees' names on a sanctions list?
Not sure what it would take to work, but it would probably be fun.
anon7000 8 hours ago [-]
> Asked about it, the head of the FBI’s Terrorist Screening Center said Robert Johnson would never get off the list, and that anyone with the name would be inconvenienced every time they tried to check in.
(Said person was already in prison.)
So essentially, the federal government and three letter agencies are propagating the crime. The original person did something which presumably violated other people’s rights. Now the federal government continues to violate people’s rights by essentially lying about who’s actually a threat.
17 hours ago [-]
IAmGraydon 6 hours ago [-]
I used to own a very small, very niche retail business that produced a specific part for analog synthesizers. I had customers in literally nearly every nation on earth, and I was surprised by how many times I received returned package for shipping to a person who was “sanctioned” by the US Government. It was probably something like 1 out of every 100 packages. In each case, the person on the receiving end was surprised to hear about the sanction and I honestly believe most were mistaken identity like the article in this post. When it happens, it’s nearly impossible to do anything about it.
sneak 11 hours ago [-]
Imagine now incorrectly being on the no-fly list. It requires no conviction and has no appeal.
ButlerianJihad 12 hours ago [-]
I found some very intriguing/disturbing things while I was paying for full access on Ancestry.com. Those genealogy sites have powerful searches over a lot of public-records databases if you pay them enough. So naturally, I investigated myself.
One of the biggest mind-benders was finding a person with a string of addresses going back 25+ years. Now I've lived in this area for 27, and for some reason, this person's addresses all coincided with mine. They had lived near every residence I ever had; they lived within a stone's throw of every clinic, every church, my college, every place I had a relationship with. One such person's "last known address" was an exact match for my previous address: apartment number and all. I found a profile on Facebook but it is unknown if these are real persons, or fictitious entities in the public record for some purpose.
Then, I found a person who seems to be real (has a Facebook profile with photo, lists a real place of employment, etc.) She shared my exact surname and had a given name that matches my ethnicity. She lived at the same street address for a long time, albeit a different apartment number. I was receiving mail for her.
At some point, this phantom wife/sister was conflated with me in the public record. Obviously someone got her unit number wrong if I got her mail. But my phone number was eventually listed as hers. She has found herself in debt, and is sometimes referred to a collection agency. I've gotten no less than 3 separate inquiries for delinquent debts, that are clearly not mine, that start coming through because her contact info is utterly conflated with mine, and apparently no valid, current info is giving them any leads.
The crazy thing I learned last year is that a collection agency doesn't need to divulge any details of the debt they hold to the person they contact. It is incumbent on the contactee to verify whether they reached the wrong person. I began following CFPB instructions on disputing the debt, but the collections agency clammed up and refused to answer any questions until I answered theirs (registered on their website, divulged a lot of PII). However, the joke's on them, because it is very easy to review credit reports and determine whether a debt is or isn't on my own record.
bryanrasmussen 18 hours ago [-]
>The Robert Johnson they kept being confused with wasn’t a man named Robert Johnson. It was a known alias of someone convicted of plotting to bomb a Hindu temple and a cinema in Toronto
Also, sold his soul to the devil at a crossroads, so you gotta be careful.
morganf 15 hours ago [-]
Hahahahahaha
I appreciate the humor and musical knowledge
And I'm surprised that your joke didn't get more laughs or comments on HN. There is life outside of screens ;)
tclancy 14 hours ago [-]
Fellow traveler, my takeaway was that the author didn’t address the elephant in the room, which is that his name is within Soundex/ Levenshtein distance of “Sean Bean” who played a terrorist in Patriot Games, so I chalk this up as another win for our government’s incredibly well-designed security state keeping me safe from imaginary threats. Good reading for today: https://www.theguardian.com/books/ng-interactive/2026/aug/15...
bryanrasmussen 4 hours ago [-]
>“Sean Bean” who played a terrorist in Patriot Games
Luckily he was allowed to make a call just after being detained, to his friend who worked for the British Council in Beirut. The friend was tirelessly in searching for him and seeking his release. It wasn’t easy.
(I met him just after his release, while he was building the courage to try again to leave the country.)
Why was he detained? Because his common Irish first name and common Irish surname matched someone on an Interpol list.
I always remember the movie Brazil when I have to interact with a stupid cybernetic apparatus like every big company, where simple programs are the brain and low-paid humans are the actuators.
https://www.imdb.com/title/tt26657236/
Fake identities are dime a dozen. It is not exactly hard for an illicit entity to just put some random ID numbers it bought off the dark web on its books. And now you have just made it even harder for the people who had their identities stolen to clear themselves. How do you convince some company drone doing sanction compliance that you didn't actually work for Sanction Circumvention Ltd when your ID number matches the one on their company's payroll files?
Not to mention the sanction list is full of foreigners. The American authorities compiling the list aren't going to know what's the national ID of a random Russian or Iranian guy running an import business. So what is going to happen if your name matches someone who's on the list with a blank ID field? Probably the same thing that happened to the author, I guess.
Verifying identity is a much simpler problem than establishing identity.
> In both cases the courts called for better matching. Compare the date of birth. Compare the middle name.
> There is no version of that available to me. The listing has no date of birth to compare. No middle name and no passport number, because the person doesn’t exist. A screening system that does its job perfectly will still flag me, forever, on the only two facts the record contains: a common Irish name and a country.
These systems operate by matching as much information as possible. If the information isn’t there but the rest matches (even if it’s just a name) it flags in the system.
> Failing that, the actual person can prove that they don’t belong on the list by verifying their identity.
Sounds like you should tell the author. They’ve been living with this problem for 6 years but I’m sure your zero experience with these systems or trying to deal with it will help him immensely.
They didn't care to figure out if the Sean Byrne of County Sligo actually existed before putting the name on the list. I doubt they would bother verifying an ID number.
Plus, going back to my point about the list being full of foreigners, how do you verify the validity of a foreign ID number and address? Maybe Ireland is going to comply with a US request, but many other countries won't, and you are now back to square one.
It's fine to propose a solution but if people aren't convinced just throwing an aphorism grenade at them isn't productive.
Not bending to the US might be less convenient at times but if you bend for them you will eventually be bending for China.
The idea is you largely prevented the theft, and made it easier to prove, by linking to a physical verifiableb address.
The real Sean Byrne can produce a government-issued passport number, but that's clearly not enough for Apple.
I think it's more of a problem of all these "hyperscale" platforms where the cost of not being zealous enough is long litigation and devastating fines, while the cost of losing a single customer (or a thousand) is basically nil. This leads to all kinds of opaque, customer-hostile outcomes like this, also if you trip some filters not related to sanctions / mistaken identities. There's a recurring theme of HN posts along the lines of "an automated process at Google cut my business off, HN plz help".
I do not know how are they handled, but they probably get assigned one plausible date and it probably depends on the country.
In a sense, a birth date can be just as much an assigned number as an ID is. An ID can also have a checksum in it, potentially even a cryptographic one that only government can sign.
Having the full name + national ID was enough to bypass verification and activate various services, and many people weren't tech savvy enough to realize how dangerous it was to share or leak that info
All else being equal, I'd rather see national ID numbers which are so incredibly obviously un-secret that, at least on their own, they're nothing except a tool for avoiding overlaps and collisions.
Same as with passports. Even in the Anglosphere people have passports with passport numbers. They could be used to uniquely identify the passport holder, except of course there are many passports, and therefore, many numbers, for each passport holder.
Small problem? Just update whatever database is holding the information for sanctionted persons (or, indeed, persons who should not be sanctioned)?
Turns out, that is not a small problem.
In Singapore, your number is fixed, even when they give you a new document.
All that these numbers do is uniquely identify people. They aren't private. To actually prove your identity, you present your ID, passport, or a digital signature tied to that identity number.
That also means they should be used simply as an identifier and not as any for of authentication or secret knowledge.
I’m applying for a second citizenship. That means that I can have two national ids that are unlinked. In the US, you can petition to have your SSN number changed, as well, so that doesn’t work. If you are willing to commit crimes and lie, it isn’t that hard to spin up an entirely new identity. Some people are born to parents that don’t notify the government. The real world is incredibly messy.
If I were to be placed on a list with one passport/id, I could just use a different one.
The bigger issue is that the list is meant as a risk alert, but companies treat a match as truth because the penalty for doing business with a sanctioned entity is far higher than whatever they might lose by not hiring someone mistakenly.
What you need, at minimum, if you are going to make these lists is an easy way for false positive people to prove they aren’t the person named (tsa/homeland security have a “redress number” you can provide if you have the same name as someone on their list). Then a legal requirement that anyone checking this list must also ask for additional documentation if they are making a decision based on a hit.
It says the state assigns "A body" a number.
-vs-
The state is made up of us as individuals.
So while the serial keyfield is a data engineers dream, politically I'd welcome something more personal.
Time of birth/parents and other identifying information is on our birth certificates in the UK. Concatenate some of that.
I could be.
DavidAndrewEvans-01011980-0036-MRI-JeanDavis-AlexEvans
Name-DOB-TOB-LocationCode-Parent(s)
Location of Birth like an airport code - MRI (Manchester Royal Infirmary), Parent(s)... i mean we can use their birthdates too.
I actually quite like the idea of it. It seems intrinsically validating to a person to identify them in this way.
Ideally, government could issue a cryptographically signed ID, so anyone with access to countries' public key can verify authenticity (with revocation mechanism built-in for both individual keys and all keys signed with one government — this is where it gets tricky). Obviously, governments become new CAs, and people in them can provide fakes when they want if they are corrupt, but anyone can easily validate it.
You're reinventing a natural key with a bunch of identifiers which aren't stable enough.
What happens when every app, website, and mobile OS requires a signature for every single post or message, tying all communication to an identity that the government can retaliate against?
This creates many more problems than it solves.
With services requiring it, you can just not use them: as long as it does not get mandated (unfortunately, a direction we are heading in), hopefully market self-regulates and privacy conserving options win.
Yes, we all know that's not how that movie plays out :)
The reason is there. It's no big secret. Pick up a history book.
Nazi Germany and occupied forces used census data, municipal population registers, etc., to identify and track down targeted people. The United States, during World War II, used census information to assist in the removal and incarceration of citizens with Japanese, Italian, and German heritage. The Rwanda population database explicitly classified people as Hutu, Tutsi, or Twa. This became the mechanism to target Tutsi during the Rwandan genocide. In China today, these databases are used to surveil and imprison Uyghurs.
Those are examples of official policy turned to dark purposes. It did not even include malfeasance for malfeasance or criminality by individuals or cartels who somehow gain access.
The lack of a comprehensive population database only seems to hinder the actual useful civilian bureaucracy, not law enforcement, intelligence services, or ICE. The latter just grab anyone who looks brown enough.
It's not like you care about all the thing you enumerated, they literally ask you for your "race" when getting a driver's license, which is the defacto ID document anyways. You're installing flock cameras everywhere and gargling palantir's balls while they implement the surveillance state.
Also the implication that cultures and countries which have happily accepted id numbers are filled with non individualistic people is it?
Many countries have laws about having to carry an ID on you all the time. Not as bad as a tattoo, but still not acceptable IMO.
> Also the implication that cultures and countries which have happily accepted id numbers are filled with non individualistic people is it?
Are we really gonna keep pretending there are no differences between cultures?
Also, I find the point kind of moot for the US where a driving license is essentially an ID card, you have to carry it to drive, and you have to drive to go anywhere in most places.
Either way you are branded forever.
Even GDPR admits it
And heaven's forbid if your actual ID and references (i.e you) have ended up in such places (or such list/s) by mistake or malice.
Mercury unblocked my accounts because their founder is a very kind man who bothered to verify what the document actually says rather than falling back to, "Computer says no." But everywhere else? De nada. Computer says no.
And it's not even me. It's a fuzzy match with someone in their 50s. Doesn't matter. Computer says no.
And I can't "get off the list" because it's not me who's on the list. The computer will always say no.
In the long run, I'll be fine. I think. But I'll pay $100k+ by the time it's over. These systems are being steadily expanded, as the dumbest incarnations of themselves. We've gone from Thin Thread https://en.wikipedia.org/wiki/ThinThread to crappy fuzzy matches on shoddy data executed on with 0 diligence. It's the stupidest possible timeline.
I think many, many other people will be sharing our fate soon, which is partly why I've been writing about this slow rolling train wreck in motion in bits and pieces.
I remember, after the Snowden leaks, when anyone warned that governments could use the patriot act and the various other "intelligence" power grabs to destroy democracy and implement totalitarian dictatorship, they would be deemed insane conspiracy theorists. The hilarious part is most of them (including me) were warning about a distant future... yet it barely took a decade for America to collapse into fascist populism, declare ANTI-FAscists the real terrorists, and turn the surveillance apparatus against them.
But will I have to? Yes.
You need a Monero. It's the only damn cryptocurrency that's used.
https://getmonero.org
UUID names next? v7 so we get the age...
I knew someone with a single-letter name and good luck flying anywhere -- most ticket sales systems won't allow it because the devs didn't read those Falsehoods guides. So you expand the name, e.g. T -> Tee so you can buy the ticket, but when you get to the gate your ticket doesn't match your ID and now you're being escorted out of the building.
I'm always helping friends with piracy and I have to tell them they can't conveniently use a native app because it isn't listed on the App Store.
And then there's the removal of ICE apps.
It's too much control. On iOS, if the government banned Signal, Apple could enforce it. On GrapheneOS, you can use whatever app from anywhere no matter what.
Trying to contrast this to the EU's attempts to force only gatekeepers (those companies so large that there is no alternative to dealing with them) to open up systems, even at the cost of damaging e.g. apple's valiant and welcome attempts to protect the privacy of its customers, highlights to me that the EU is completely correct in doing so.
None of it would be a problem without the App store in its current form though.
Not one single person in that system thinks the very obvious "A name without any other data is worthless, let's just delete it from the list".
If people lack agency then you already have an ineffective system but my guess would be that no-one person has the authority to take executive action and every change however daft takes 30 people in a meeting discussing it for an hour so it just gets left as it is.
Google decided to ban my many years old account. Reason: account created by computer program. Likely flagged me because i use multiple computer and connect from other wifi.
Whats worse is i am a monetized youtube partner with million+ views. Youtube support (@TeamYoutube) just say "it is a google problem"
All appeals are handled by bots, there is no way to reach an actual human being.
We are being controlled by our ai overlords. Some bot on some cpu can ruin your life on a whim.
So far, getting the data hasn't happened once AFAIK but magically she's unbanned/ unblocked/ whatever.
Think of how manny John Smiths there are?
How can this be the company started by Wozniak and Jobs ...
It isn’t. The institutions involved simply don’t care whether they are destroying the lives of random people. At all.
And why should they? They are completely unaccountable in practice, sometimes even in theory.
The same Jobs that routinely denied publicly that he was the parent of his daughter, even though he knew? The same Jobs that cheated Wozniak financially? The same Jobs that led to a change in legal legislation on how organ transplants work?
The world needs to move on from this marketing bs that he was somehow a "great" man who is morally solid and must be doing the right thing. Apple is precisely the company founded by Jobs.
Firstly you have the issue that many terrorists are going by a nom de guerre rather than their legal or birth name.
Then, of course, your terrorists will have common names. How many Mohammeds are you gonna list?
Lastly is transliteration. Your no-fly list is in Latin characters. But your terrorists have Arabic and Persian and Hindi and Cyrillic names. So what do you do. Transliteration is an inexact science, and there are often many branching methods of doing it.
So no-fly lists are based on fuzzy matching common pseudonyms. It's a farce, really it is.
Not really a life-altering inconvenience, and the other forum members got sufficiently uppity that they re-reviewed it and let me back in, but it was a good lesson in how big orgs have no innate common sense.
The simplest solution is to change my phone number. But
a) why should I have to? it’s my number, dammit!
b) how many accounts have 2FA? if I changed my number, what if I miss updating one that’s important?
c) it could happen again
If I change my number, however, that is the simplest way to solve the problem. It’s just, do I want to?
TOTP is portable and can be backed up.
I went a little bit off on a tangent, the stupidity of SMS 2FA is a pet peeve of mine.
I walk to the local phone shop and get a replacement sim for my number with a few of bits of ID and I regain sms access. Totp access is gone forever.
It’s clearly not worse that totp in every way.
> I walk to the local phone shop and get a replacement sim for my number with a few of bits of ID and I regain sms access.
Or someone else gets access to your SIM by sim swapping you, which is not as stupidly easy as it used to be, but still SMS remains insecure. Building an authentication system on it is just a bad idea from virtually every angle.
You vans I may be able to manage a backup and understand how these codes are generated. The average person does not.
From memory most totp apps don’t even migrate when you move from one phone to another - at least on iPhone. I haven’t done that for 5 years but I seem to remember having to create new entries.
https://www.cbsnews.com/news/ted-kennedys-airport-adventure/
Some of the low cost options now a days do not have human in the loop. They often miss obvious red flags or do too much false positives.
The way to retaliate against those stupid lists and the stupid way they are enforced by US companies could be to register a fake company with principals named Tim Cook, Satya Nadella, Donald Trump, etc. (and many other people with less well-known names, but high up in various organizations) and somehow get that company and all its employees' names on a sanctions list?
Not sure what it would take to work, but it would probably be fun.
(Said person was already in prison.)
So essentially, the federal government and three letter agencies are propagating the crime. The original person did something which presumably violated other people’s rights. Now the federal government continues to violate people’s rights by essentially lying about who’s actually a threat.
One of the biggest mind-benders was finding a person with a string of addresses going back 25+ years. Now I've lived in this area for 27, and for some reason, this person's addresses all coincided with mine. They had lived near every residence I ever had; they lived within a stone's throw of every clinic, every church, my college, every place I had a relationship with. One such person's "last known address" was an exact match for my previous address: apartment number and all. I found a profile on Facebook but it is unknown if these are real persons, or fictitious entities in the public record for some purpose.
Then, I found a person who seems to be real (has a Facebook profile with photo, lists a real place of employment, etc.) She shared my exact surname and had a given name that matches my ethnicity. She lived at the same street address for a long time, albeit a different apartment number. I was receiving mail for her.
At some point, this phantom wife/sister was conflated with me in the public record. Obviously someone got her unit number wrong if I got her mail. But my phone number was eventually listed as hers. She has found herself in debt, and is sometimes referred to a collection agency. I've gotten no less than 3 separate inquiries for delinquent debts, that are clearly not mine, that start coming through because her contact info is utterly conflated with mine, and apparently no valid, current info is giving them any leads.
The crazy thing I learned last year is that a collection agency doesn't need to divulge any details of the debt they hold to the person they contact. It is incumbent on the contactee to verify whether they reached the wrong person. I began following CFPB instructions on disputing the debt, but the collections agency clammed up and refused to answer any questions until I answered theirs (registered on their website, divulged a lot of PII). However, the joke's on them, because it is very easy to review credit reports and determine whether a debt is or isn't on my own record.
Also, sold his soul to the devil at a crossroads, so you gotta be careful.
I appreciate the humor and musical knowledge
And I'm surprised that your joke didn't get more laughs or comments on HN. There is life outside of screens ;)
did he die, or call anyone a "bastard!"