Skip to content

Comment on One-Click Anonymous Loginparent

Comments

Also, goddamn, please stop using phone numbers as ID numbers.

No, I don't want to give every service my phone number.

humanID blocks automated accounts, cyber-bullies, trolls, and freeloaders

Yeah, stop right there. Please don't block automation. That blocks innovation in accessibility. Go after the bullies and trolls but please don't try to differentiate a human and robot user of your UI, because some humans need a robot to help them.

What externally-verifiable ID verification mechanism are you willing to participate, in order to demonstrate that you are not a sockpuppet? Phone numbers are crossed off the list, so at least we don't have to debate whether they're acceptable or not, and email addresses obviously aren't useful for preventing sockpuppets either. What else is left that is acceptable to you?

preventing sockpuppets

Focus on preventing abusive usage patterns, not sockpuppets or robots.

Sometimes I do want a sockpuppet to help me access information and reformat or deliver it to me in an alternative form that is better accessible to me.

There’s two ways to look at this.

First, we can say “let’s not verify identities, anyone can be as many people as they want”. We have that today. It’s killed a lot of businesses and has deeply harmed society. Swell. we can of course redouble our efforts and refuse to take other steps, which is certainly a popular choice.

Or we could discuss the pragmatic path: verifying identity. Phone numbers are popular. Email is a tire fire. SMS is simple to hack. So, what’s next to try? What should this startup be using instead of phone number verification? What platforms exist to build revenue with clearly-identified customers on the internet?

The folks refusing to consider the question here seem to only care about the former, but I’d like to see pragmatic verified-identity solutions that address the firestorm of hate that anonymity has brought down upon us, and I’d like to see someone make a billion dollars from it.

I’m here for a pragmatic discussion, not for another retread of the same boring “everything must tolerate sock puppets” that we’ve been living with for the past two decades, and I’m not going to waste productive time and energy in idealistic debates that have failed to deliver what they promised at ETcon’03. We owe society better. We owe ourselves better. At least this startup is trying.

In an ideal world, the governments of the world (or other trusted parties) would provide identity providers based on zero-knowledge proofs.

These would have the property that when a person joins a platform, the platform can check what other users on it is controlled by the same person, without revealing the meatspace identity of the person in question; and without revealing the usernames to the trusted entity. (Well, ideally the platform would only get to know the number of users, not who they are; but I don't think that can be done.)

Then a platform could just put a hard limit on how many users any given person can have, while still retaining the users' pseudonymity. Or it could place a soft limit, for that matter: every subsequent user receives an automatic penalty (e.g. 10 downvotes on every new message).

It wouldn't stop state actors, and it'd be horrible in places where the government isn't held accountable, but otherwise seems to solve most of the problems of anonymity.

Perhaps you could replace the trusted entity with something peer-to-peer, but it would have to be very carefully designed.

I've been thinking about the same albeit more limited:

it would still be useful in very many cases even if it wasn't so watertight.

As long as it is audited, I get a warning and it has to pass a judge to not be punished I'd be fine in most contexts even if it was technically possible to look me up.

Of course I am keenly aware that this is a privilege that not everyone has.

that address the firestorm of hate that anonymity has brought down upon us

I disagree with many (most?) of your underlying assumptions about social dynamics, but this one in particular stood out to me. Have you not seen the vile things that people post to Facebook under their legal name, typically to groups consisting almost entirely of people from the local community?

It isn't anonymity that's the problem. It's the intent behind and incentives provided by the social interaction in question. There are deep systemic issues (IMO) with the interaction models of most social media today.

Anonymity is a separate problem from immunity, but the former certainly is perceived as a successful route to the latter.

Those people posting to Facebook under their own name are living under the belief that their words are protected speech, and that no harm will come to them in their community for speaking them. So, too, do anonymous identities perceive themselves to be immune to harm. Communities in the southeast United States have been quietly passing racism and sexism by word of mouth for hundreds of years, and they are quite correct to think that posts on Facebook will do no significant harm to their lives, as long as they don’t stray far from their communities. They derive courage from seeing others say these terrible things, and they say them too. Anonymity is of no relevance to their concerns, because they have unity across community and authority to protect their cruel and malicious beliefs.

Anonymous identities present this problem at scale, where the community is “anonymous identities” and the authorities are the businesses that run the Internet. For decades we built these platforms, I helped build these platforms, and we’ve discovered that we’ve created a place that allows social evils of all sorts to coordinate and fester and grow and feed upon those who are vulnerable. The platforms have so many users that policing speech is impossible, and in the few cases such as Nextdoor or Yelp where locality narrows speech down to enforceable-scale communities, the platforms shy away from the simple human cost of moderating speech and applying principles, desiring instead to maximize daily active users and advertising views and paid subscriptions and minimize dollars spent on human oversight and moral compass wayfinding in these community bulletin boards they’ve created.

In the novel Snow Crash and in many works prior, the Tower of Babel is an allegory for the risk of all humanity being able to thoughtlessly communicate. It’s not that different languages are unintelligible, but it’s simply that they slow communication, ensuring that one community cannot readily infect another with malicious beliefs and cultism. We have torn down the barriers between communities that kept the uncivilized, the evil, from metastasizing throughout the world. And so we who built blogs from the ashes of Fidonet and Usenet have created a perfect agar dish for a plague that threatens to kill us all.

Sock puppets are a unique feature of anonymity, that slow any single entity to represent themselves as a crowd, and human beings are extremely vulnerable to crowdthink manipulation by those actors. This can’t readily be done without anonymity, and is a problem unique to anonymity itself. 4chan could not have wielded an army of sock puppets in Gamergate and beyond, if users had been required to authenticate their true selves at each forum they coordinated attacks upon. Even if their identities were unpublished, they would be found and banned, and eventually the equivalent of Spamcop would be set up to coordinate disreputation tracking with published proof of the misbehavior of the identity in question. It isn’t necessary to publish the identity of an attacker to indicate that they attacked you, and the invaluable contribution of centralized Twitter blocklist subscriptions demonstrates that we are still very capable of silencing voices that are deemed beyond the pale.

It’s uncomfortable to consider the morality of when, if, voices should be silenced. But I’m tired of this world where consequence-free verbal abuse is taken for granted, and anonymity contributes uniquely to that in ways that cannot be assigned to the greater problem of community bulletin boards at worldwide scale. So, yes, I call for ways to verify identities that are sufficient to stop this army of manipulative sockpuppets that swarm any platform without active identity verification.

HN suffers these attacks too; witness how any post about ESR or China or gender inequity is guaranteed to have a freshly-registered account posting plausibly-formed comments that somehow always push the discussion towards a world with more bias, more inequity, more tolerances of abusive behaviors. We don’t see sockpuppets swarming discussions asking us to keep an open mind and be more civil towards each other and have empathy for the viewpoints of both sides. We see sockpuppets pushing authoritarianism and bigotry instead. They do so freely, knowing that their attacks are impossible to detect and stop with any algorithm.

MasterCard paid nearly a billion dollars today for an online identity verification startup, because they understand that the future we’re living is so terrible that it won’t be allowed to continue. Sockpuppets are an unprofitable drain upon the financial profits of capitalism. Tor and VPNs are frequently banned at a network level due to anonymous abusive behaviors committed upon them, and that simply won’t scale. Cloudflare’s own 1.1.1.1 VPN is blocked by Slice, a pizza delivery app, using Cloudflare’s own CDN firewall services, no doubt because the anonymity was abused for stolen credit card testing and in general abuse at scale. I wouldn’t be inclined to accept traffic from TOR if I ran a business, not unless I was doing live ID checks in some way that isn’t as trivial to falsify or hack as the weak solutions we’re offered by phone and email today.

If you are able to present a case that the sockpuppets problem is in fact common to anonymous communities (such as HN) and to identity-verified communities (I can’t name any, can you?), then I’d like an opportunity to consider your arguments along those lines. Your case is not yet compelling, but I’m open to hearing more.

Please note that HN basically works this way. Anyone can basically create an account anytime. Still HN is one of the nicest and most thoughtful places I am aware of on the internet.

Anyone can create one account for their use anytime, but if they create and use multiple accounts, they get shutdown by the site admins. HN became what you praise in part by emplacing defenses against sock puppets, an approach that’s loudly contested elsethread. That HN has remained at all nice is in part due to that “one account per person” enforcement, and the reason why is clearly stated in the guidelines:

Throwaway accounts are ok for sensitive information, but please don't create accounts routinely. HN is a community—users should have an identity that others can relate to.

I don’t mind if people keep their identity secret from the other users of the sites that verify identity. I don’t mind if people keep their identity secret from the site admins, as long as they only have one identity. Enforcing that is very hard at scale, and only works at HN due to the small size.

Someone made a billion dollars selling their startup in this identity verification niche today: https://news.ycombinator.com/item?id=26867448

demonstrate that you are not a sockpuppet

Why is this necessary in the first place?

Because spammers spams spam that ruins everything.

I do encourage you to post your comment further upthread with more details about your view, but I won’t be participating in that thread. My focus here is solely on the question of which ID verification mechanisms are acceptable, as the parent comment only rejects one method without completing the thought by specifying the acceptable alternatives.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.