Hacker Newsnew | past | comments | ask | show | jobs | submit | davidmurdoch's commentslogin

How are you planning to turn this off remotely when telemetry off?

If it’s like other CC features that depend on telemetry being enabled, disabling telemetry will turn off the feature.

"You can't hide secrets from the future" - MC Frontalot

I had heard of MC Frontalot but never listened to any of his raps - But I should have:

https://www.youtube.com/watch?v=yVm8oZx9WSM

Also relevant to today's AI concerns:

https://www.youtube.com/watch?v=lWnV3HVro_0


Wow, a blast from the past about the future.

- MC 900 Foot Jesus


I'm partly to blame. I accidentally ran an illegal unregulated money transference service over Google Play.

It let users cash out their Google Play Credits for real cash, which I automatically wired them.

Someone then hacked in to a major bookstore chain, stole piles of Google Play Gift cards, activated them using their access, and used my app to get cash for them.

Luckily, the whole thing blew up on me before I got in serious trouble, rightfully so, and the app was removed by Google, then an investigation followed. A ton of copycat apps popped up immediately after, then a few months months later Google announced their app review process.


I love how casually you're dropping this incredible piece of internet lore as if somebody asked you how's the weather.

Haha. I used to have some blog posts detailing things a bit more, but I let it die when Heroku cancelled their original free tier years ago.

A domain is only ~$12/year if you don't buy it through a scammy site like godaddy that adds fake fees or quadruples the cost after a year. WordPress is easy for blogs, or you can just vibe code something in an afternoon if you don't care to have comments. Even embedding forms or an emailing tool can be done statically. Heck, there's probably a free option out there for simple posting that I don't know about.

The biggest costs are not the money, but the work and cognitive load of the thousand cuts it takes to not only bring all of this up, but keep it running, not to mention migrating the content.

However/also, "only" $12 to some is a considerable amount of money to others.


If its a static or client-side website, GitHub Pages is free and allows you to use whatever domain you have already own. Almost all of the websites I run are hosted on GitHub Pages. No maintenance required, and updates are as easy as `git push`.

Having done this for multiple sites, there's still a lot of friction and gotchas in the setup process, and it's also not guaranteed to not break/rot (e.g. have to renew the domain.)

You didn't use the word "just", but I still want to link this article:

https://alistapart.com/blog/post/the-most-dangerous-word-in-...


If you're inspired to rehash it here or another blog you'll have at least this additional reader.


what was the url? asking for a wayback friend


Wow! You managed to break almost every financial law and regulation in one go. That's amazing!

Reminded me of Arrested Development's George Bluth's "Light Treason".

What did you do with all the Google Play Credits?

When you "spend" Google Play Credits in an app, Google Play treats those credits the same as if you paid with real money: they took 30% (their take isn't so steep today), I took 10%, and then I sent the user/buyer the remaining 60% directly from my bank account (I used Dwolla back then).

It was risky because I didn't actually receive any money from Google until about a month later.


What you did was money laundering. And big chance for getting in trouble if let’s say ton of credits come from fraud/stolen and then google pays out to you and then crawl back once they realize is fraud.

I’m curious how you didn’t get into money laundering problems.


Technically it was an unregulated money transference service without KYC. The user that stole the cards from the bookstore was the one doing the money laundering part. I just enabled it (which is probably worse, legally).

I was investigated and cooperated fully.

Edit: I just remembered, the bank I used for the transference did do KYC for all users who were sent funds. This makes it more like "money dirtying", since the account is tied directly to a real identity.


Thanks for your detailed answer. Could you tell me what other things you had to deal with? Any prison, bad credit, fees, lawyer fees ?

This is not laundering, it is in fact exactly as the service was meant to be used. As long as you save where the money comes from and where it goes you are at worst operating a discount pseudo-bank. But that's what google is also doing, so we can infer that this is okay.

How did you "accidentally" do something that was so obviously not allowed?

I didn't know what a "money transference service" was, and certainly didn't know this service that I didn't know about was highly regulated.

I only created it because I had Google Play Credits that were gifted to me. I built an app to "convert" them to cash for myself. I had never built an app before. I was proud of it and tried to make it pretty and professional and useful for others, and used it as a learning experience. The listing on the Play Store was clear about what it was.

I had to answer questions about what the API was being used for when I signed up for Dwolla (an actual regulated money transference service). I answered honestly. They approved it.

The app sat unused with no downloads for years before someone on Reddit's `r/churning/` posted about it.


Right but... You've used gift cards before right? The whole point is that you can't convert them to cash. Not only that but Google/Apple gift cards are notorious for being used in fraud.

I guess if you're young...


Sure.

I created it back in 2011 or 2012.

It wasn't a gift card that personally motivated me to make this. It was credits from an online referral program I was gifted. I guarantee I did not read the fine print at that time.


> You've used gift cards before right? The whole point is that you can't convert them to cash.

This is very untrue - there's a ton of services that do this and while it is against the ToS sometimes, there's plenty of place where ToS of this type are not legal and so you are perfectly within your rights to resell a gift card for money.


It's obvious that you can convert them to cash, because merchants accept cash and do not want to pay their employees in gift cards.

The process is just not obvious and usually not accessible to everyone.


Most people dont read the fine print on the back of gift cards. So I can easily see someone never running into a situation where it’s actually explained that is not allowed face to face.

There are multiple companies dedicated to turning gift cards into cash.

It isn't some new idea, he just didn't follow all the rules doing it!


I mean people in poor neighborhoods do the same thing with laundry detergent or anything else you can buy with SNAP benefits.

You can’t buy laundry detergent with SNAP benefits, since it isn’t food.

Hm, maybe that loophole was closed recently? Definitely used to be a thing, people with benefits would buy something nonperishable and marketable. Tide detergent was the example. That could then be sold for cash, or traded for cigarettes or booze or something that the benefits program would not allow, and resold to people who needed laundry detergent. Everyone taking a cut along the way of course, but hey it's free to start with so who cares?

I went ahead and did a web search on this, and found that I misremembered it. It wasn't that the laundry detergent was initially purchased with a public benefit program, it was outright stolen.

https://reason.org/commentary/sound-money-tide-as-gold-stand...

Still, variations on the scam with benefit programs are still run.


I’m really wondering how you confused “things that thieves steal” with “things people buy with food stamps”. Food is rarely shoplifted in America.

He accidentally got caught.

I responded to others with more details if you're interested

I’ll never understand people so desperate to find villains in the world.

Anyone interested in this topic should check out https://www.bitsaboutmoney.com/archive/gift-card-marketplace...

> It let users cash out their Google Play Credits for real cash, which I automatically wired them.

I really want to know what the intended design or use case was for this? This is why people usually only let you turn credits into in app balances right


Cashing out unwanted gift cards

Meta's new muse.ai locks down its VM in various ways. But Muse LLM the accesses it really wants to do what the user wants... so it will find a way (tailscale and cloudflare zero don't work out of the box, because sentinel blocks them, but there are other ways).

Unfortunately it's bandwidth is limited to 20Mbps up, so web hosting isn't ideal. Down is actually slightly faster, but not by much.

They also restart the VM often, wiping everything but your home directory. And Docker doesn't work at all, and Muse can't find a way around it.


Jellyfin works just fine with remote access and multiple users.


I don't trust Jellyfin to be secure enough to be put on the public Internet.


Why is that? Did you have an issue with how it's set up? Or does it not do enough out of the box and leaves security for the administrator?


They can only send the marketing emails if you have the "send me marketing emails" checkbox checked when you type in your email address. Dark pattern, yeah.


That has never stopped companies from spamming me with marketing even when I didn't agree or even explicitly disagreed (unchecked). Not a single company has been or ever will be held accountable so they just keep doing it.


Shopify 's "abandoned cart" emails are legally considered transactional emails, not marketing, which is probably what you're getting. It's a feature built in to Shopify. If the email isn't related to your abandoned cart contents, you can report it to Shopify. Shopify will investigate reports of abuse and eventually will terminate a store account for blatant abuse.


No, I've received it just from entering my e-mail and nothing else. So many companies don't care, or don't know.

Either way, if I enter my e-mail, decide "nah" and quit, that should be that. It shouldn't be sending my details in the background


The checkbox is usually checked by default (it's a Shopify setting), in many jurisdictions (like the USA). "It" was probably an "abandoned checkout" email, which is a transactional email, and is legally allowed.

I use this Shopify feature as a buyer to get discount codes, as abandoned cart emails often come with them.


Isn't the email at the top of the form and the marketing checkbox at the bottom? It's an awful dark pattern and makes me want to not use any company that uses shopify.

They require your full address to show you shipping prices as well (vs just letting you estimate with country and postal code alone), so I have to punch in a ton of details before I nope out at awful shipping costs, and I end up with these emails.


No. For Shopify's checkout, it's directly beneath the email input.

You're probably getting the "abandon cart" emails, which is legally considered a "transactional email", and doesn't require consent.


Imagine the scenario where you end up hiking within earshot and in the same direction as another group.


Tip: Take a small break and within 60 seconds you'll be out of earshot. Also, I realize we're not going to agree on this and that's okay.


The same thing works for terrible drivers on the road, pushy customers at the supermarket, and all kinds of other bothersome interpersonal situations.

They can be optional. Just grant yourself a moment to let them go away.

Out of sight, out of mind.


Isn’t it unlikely that both groups share the same hiking speed for a while? And even if you have the same speed, take a break or pass them quickly.


That's not it. It's Apple. They are crippling the web on purpose.

We can't even have haptic vibration on Safari. And when we did for a little while earlier this year, it was because of a "bug" that that they promptly fixed.

Apple is not interested in making with apps as seamless and integrated as native because: money.


I agree that Apple has been awful here. But there are countries deeply dominated by Android that still heavily use apps when they could be using PWAs. I don’t mean to let Apple off the hook but I also don’t think they’re the only ones to blame.


Again, this is Apple's work. Developers don't make good web apps when they cant work on iOS.

https://infrequently.org/series/browser-choice-must-matter/


As an iPhone user: good. There is no good that can come from some dipshit website product manager being able to make my phone vibrate on a website. None at all.


An installed PWA should be able to do all the same things an installed app should do. The general web should not, and no one is arguing for that.


Parent comment is talking about PWA APIs that only show up when the PWA is added to the Home Screen, not via safari.


Is there any good that can come from a dipshit mobile product manager being able to make your phone vibrate on an app? Is there actually a meaningful difference?


Games are the usual reason in an app. Being able to do it as a “drive by” on a website though: absolutely hell no.


Sounds like it would be ideal to add it to Home Screen webapps only, just like web notifications. And yet…


Yes, because visiting a website is much easier to do even unintentionally. The last thing I want is my phone to vibrate as I scroll past an ad


Which is why things like permission prompts exist.


I don't even have "Priority" (2.5x speed) in my Pro account, only Standard and Fast (1.5, speed). I actually didn't even know their was a level above Fast till now. I don't imagine non enterprise users will get the "UltraFast" mode option why time soon.


How do you keep your phone out of data leaks?


Not sure! Used the same one for well over 10 years.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: