An Amazon seller tried to bribe me

I bought a suitcase from Amazon, partly because of its good reviews.

The suitcase

The suitcase is alright. It’s not the best I’ve ever seen, but the price was decent and it seems like it should last a while. A couple of weeks later, I got a postcard from the seller offering a bribe. If I sent them proof that I posted a 5-star review, they’d pay me $15.

Front of the suitcase postcard Back of the suitcase postcard

I followed Amazon’s instructions to report the bribe. No response. I left a review of the suitcase stating that the seller had offered to pay me for a good review. That action did earn a response from Amazon: they deleted it.

Amazon's response to my review

If I can’t talk about it on Amazon, I’ll talk about it here. Amazon doesn’t seem to care if sellers are paying for good reviews. They don’t want you talking about it, though. The takeaway is that Amazon’s reviews aren’t trustworthy. If that seller tried to bribe me, they surely paid other customers for their good ratings.

You can do better, Amazon. Your product ratings are a big part of why people buy things from you. If we know they’re literally paid ads, we’d be better off taking our business elsewhere.

Updated 2023-12-26

Same with a travel steamer:

Front of the steamer postcard Back of the steamer postcard

An acquaintance suggested writing the review, cashing in the reward, then updating the review with my genuine thoughts. That’s tempting. I don’t blame anyone who does that. I don’t want a sketchy vendor to be able to say that they’ve paid me for reviews, though.

macOS 14 Sonoma is out, and mostly OK

Apple release macOS 14 Sonoma today. I always install the major OS beta versions on my work Mac when they’re first released, to see if anything critical breaks before it affects my coworkers. That happens sometimes, like when macOS 11 Big Sur deprecated kernel extensions and affected some software we used. Sonoma and its 1st-party apps were in good shape from the start.

I stumbled across a few glitches with 3rd-party software:

Summary: Sonoma is a good upgrade and I’ve installed it on my Macs. You may need to upgrade some of your other software at the same time.

Newsom vetoed self-driving truck bill

California governor Gavin Newsom vetoed a bill that would have required self-driving vehicles to have a human driver.

“Considering the longstanding commitment of my administration to addressing the present and future challenges for work and workers in California, and the existing regulatory framework that presently and sufficiently governs this particular technology, this bill is not needed at this time,” Newsom wrote. “For these reasons, I cannot sign this bill.”"

Good. I don’t see this as a safety issue so much as a make-work law. If a human would have to be in a self-driving truck at all times and ready to assume the controls at a moment’s notice, that’s basically human-driven with extra steps. Either the tech is good enough to be autonomous, or it’s not good enough to replace a human driver in the first place. And as a driver, I don’t think I’d want to be legally responsible for whatever boneheaded move a truck might take in the moments before I could regain control over it. “Hey, I know it was the AI that decided to swerve into the crowd of toddlers, and you only had 300ms to respond, but you were the one sitting in the driver’s seat…”

I’m not thrilled with ending human jobs without giving those people a way to survive. Even if I weren’t sympathetic to those hard-working people who are ready and willing to do the tough jobs that keep society running (and I hope it’s obvious that I am), enlightened self-interest means that I don’t want all of them to be unemployed and hungry. That’s bad for everyone. I also wish we shipped more freight via train, which is cheaper and way more environmentally friendly. Making it easier and cheaper to carry even more via truck is probably the wrong process to optimize.

Still, I think this bill was a well meaning but ultimately wrong solution. Frankly, it seems like it’d be cheaper and more efficient to pay those drivers to stay home than to pay them to perch in a self-driving truck.

TriNet shares employee PII without controls

My employer’s HR department asked me to validate a coworker’s identification documents and attest that they’re legitimate, for government tax form purposes.

I got an email from our payroll vendor, TriNet, with a link to attest to those documents’ authenticity. Clicking it took me to a page with scans of my friend’s driver’s license and Social Security card without requiring me to log in first. My coworker hadn’t entered their driver’s license number into the form, so I used the scanned image to enter it for them.

That’s pretty messed up. Good thing TriNet didn’t send that link to the wrong person, or they would have shared my colleague’s personally identifiable information with random strangers.

If your company uses TriNet, ask them for more information about this terrible, horrible, no good, very bad process, and how it got past design review. Their whole job is managing private payroll information. They’re not very good at it.

Veilid in The Washington Post

I’ve been helping on a fun project with some incredibly brilliant friends. I found myself talking about it to a reporter at The Washington Post. The story just came out. My part was crucial, insightful, and far, far down the page:

Once known for distributing hacking tools and shaming software companies into improving their security, a famed group of technology activists is now working to develop a system that will allow the creation of messaging and social networking apps that won’t keep hold of users’ personal data. […] “It’s a new way of combining [technologies] to work together,” said Strauser, who is the lead security architect at a digital health company.

You bet I’m letting this go to my head.

At work: “Kirk, I think you’re wrong.” “Well, one of us was featured in WaPo, so we’ll just admit that I’m the expert here.”

At home: “Honey, can you take the trash out?” “People in The Washington Post can’t be expected to just…” “Take this out, ‘please’.

But really, Veilid is incredibly neat and I’m awed by the people I’ve been lucky to work with. Check it out after the launch next week at DEF CON 31.

Simply Sabotaging an Office

The US Office of Strategic Services, the precursor of today’s CIA, wrote the Simple Sabotage Field Manual in 1944. Its goal was clear:

The purpose of this paper is to characterize simple sabotage, to outline its possible effects, and to present suggestions for inciting and executing it.

The target audience was people living in countries occupied by foreign armies, and it aimed to give them tools to surreptitiously fight back against the invaders. You should go read it now. Go ahead. It’s not long, and the manual’s packed with clever and fascinating ideas for gumming up an organization’s plans.

But as I read it, some of its suggestions sounded a lot like things I’ve seen at the office. This is a great analogy for technical debt:

(1) Let cutting tools grow dull. They will be inefficient, will slow down production, and may damage the materials and parts you use them on.

By section 11, “General Interference with Organizations and Production”, the analogies became concrete behaviors we’ve all seen:

(a) Organizations and Conferences
(1) Insist on doing everything through “channels.” Never permit short-cuts to be taken in order to expedite decisions.

“Channels” are there for a reason, and large organizations have to have certain formal processes in place so they don’t devolve into chaos. However, don’t let hidebound processes block progress. They’re supposed to make work possible, not completely block it.

(3) When possible, refer all matters to committees, for “further study and consideration.” Attempt to make the committees as large as possible–never less than five.

When an excited and competent colleague asks to improve something, and it’s not going to require the rest of the department to change their plans, find a way to let them. Nothing kills enthusiasm like scheduling a preliminary pre-meeting planning session a month later.

(6) Refer back to matters decided upon at the last meeting and attempt to re-open the question of the advisability of that decision.

Settled business should say settled. If new information has come to light, then that’s a new discussion. Once a group has reached a decision and started making plans on top of it, it’s too late to re-litigate old complaints.

(7) Advocate “caution.” Be “reasonable” and urge your fellow-conferees to be “reasonable” and avoid haste which might result in embarrassments or difficulties later on.

That sounds like excellent advice, doesn’t it? How insidious! Saying “no” incurs less personal risk than saying “yes”, but it stops all progress. Find a way to say “yes, but make sure to…” instead.

(b) Managers and Supervisors
(2) “Misunderstand” orders. Ask endless questions or engage in long correspondence about such orders. Quibble over them when you can.

No one enjoys having to explain all their ideas repeatedly. Sometimes it’s better to say “fine, go build it and show me”. Painting a picture is more fun than writing encyclopedic descriptions of what it will eventually look like. Trust smart people to do smart things.

(7) Insist on perfect work in relatively unimportant products; send back for refinishing those which have the least flaw. Approve other defective parts whose flaws are not visible to the naked eye.

Is there a meaningless typo in internal documentation? Did the author give something a name that’s accurate but not the one you would have chosen? Is their style different from your own, yet reasonable and understandable by their coworkers? Resist the urge to “improve” their work. Let it go. Save that political capital for when something’s objectively wrong.

(11) Hold conferences when there is more critical work to be done.

There’s nothing I can add here.

And for individual contributors:

(d) Employees
(5) Do your work poorly and blame it on bad tools, machinery, or equipment. Complain that these things are preventing you from doing your job right.

Granted, some tools are genuinely awful. If that’s the case, speak up and suggest good alternatives. Better, whip up a demonstration. Endless kvetching has never improved the situation.

(6) Never pass on your skill and experience to a new or less skillful worker.

Ineffective employees sometimes purposefully worm their way into critical business processes. What a miserable way to live! If you’re the only person who can do a certain important thing, you’ll never get to fully leave your job behind. Who wants to get called on vacation? Do yourself, your coworkers, and your company a favor: teach other people how to do your job. Make yourself valuable by excelling at it, but let other people help you carry the load.

None of the behaviors above are inherently malicious. Most can be explained by well-meaning people trying to do their jobs. That’s what makes them each so dangerous to an organization. A coworker who regularly schedules vague meetings to rehash old problems when you’re trying to get work done probably isn’t a deliberate saboteur. And yet, they’re following the CIA’s best advice on how to grind work to a halt.

Read the manual. Remember it. And when you see those behaviors pop up in your office, put a quick end to them.

Happy 25th birthday, honeypot.net!

In times of yore, my friends gave their computers cool cyberpunky names so that they sounded cool at LAN parties: “Hey, can you toss me an Ethernet cable for suntzu?” “Sure. Here’s the switch I’m using for chaosium.” My Amiga had a few hard drives to store all the, ahem, public domain music files that we traded around. I don’t know what prompted me to think of it as the honeypot full of music, but it stuck, and I christened it honeypot to be one of the cool kids.

I was working at an ISP and handling domain registration tasks for our customers. It struck me as a great idea to one-up my friends and turn my computer’s name into a full-blown domain name. The .org TLD didn’t feel right because I wasn’t an organization, and definitely didn’t identify with .org’s non-profit connotations. .com also felt wrong because I wasn’t some boring company that had decided to hop on to the Internet to see what the fuss was all about. .net had just the right about of geek cred, so honeypot.net it was.

It was the custom to have a cool and vaguely menacing desktop wallpaper to go with our cool and vaguely menacing handles. If you’ve seen “Hackers”, you’re familiar with those ideas. Here was my pre-honeypot.net background:

How cool was I, right?

That wasn’t good enough to show off my new domain, so I replaced it:

Obligatory Nine Inch Nails-style backward n.

I needed to change things a bit when I acquired a second computer. Instead of using the whole domain name for a single host, I decided on a whim to give each one a name from A. A. Milne’s Winnie-the-Pooh stories. First, Pooh was my childhood stuffed animal best friend, and I still like him. Second, Pooh loves honey, as in a pot of it – a honeypot. Finally, it was an ironic pushback against the scary hacker imagery that was common at the time.

When I registered honeypot.net, about 2 million domains existed. Today there are about 700 million. I wish I’d gotten on the Bitcoin or Apple stock bandwagons that early.

Happy 25th birthday, honeypot.net. We’ve had fun.

Twitter went dark. Now what?

Twitter is in a race with Reddit to see who can ruin their service more quickly. That’s the simplest explanation I have for Twitter’s change today that hides all of their users’ posts behind a login page. Until today, you could still view a favorite company’s messages, or a sport team’s highlights, or an interesting author’s opinions, without logging on to the site. If you wanted to interact with that page by liking a post or replying to it, you needed an account. It was free to view those posts, though. And now, it’s not.

For end users, this immediately devalues Twitter as a way to casually catch up with public figures. For those public figures, this immediately devalues Twitter as a way to broadcast messages to the world. The service still has many users today, of course, and those people won’t go away immediately. But most recent public estimates say that Twitter has about 400 million users, or about 1/10th of the world’s online population. Assuming that all of those accounts are real people, which is a giant assumption, that means about 90% of the world can’t see those messages anymore.

A couple of pieces of free advice for people and organizations still posting to Twitter:

  1. Investigate the alternatives that are open to readers by default. Facebook and friends also make it hard for casual visitors to see messages without logging in. Many brands have flocked to Mastodon, Micro.blog, and newer services like Bluesky.
  2. Track your engagement numbers. If Twitter still reports a similar number of views for your messages after making them inaccessible to 90% of the world, those statistics are probably fake.
  3. Blogs and newsletters still exist, and you have complete control over them. Consider communicating with your most loyal followers over open, easy-to-use channels that everyone can access.
  4. And finally, start working on your Twitter exit strategy. As the site continues to remove the guardrails that kept it relatively civil and brand-safe, it’s only going to become a worse place to hang out.

Quitting Reddit

I’ve spent way more time on Reddit than I should have. I justified it to myself by saying it was a great way to stay current on news and technology trends. Really, it was just a slow drip of tiny endorphin hits that felt good but ultimately didn’t make my life better.

Thanks to Reddit CEO Steve Huffman’s ham-fisted community management and the resulting moderator and user boycott, I deleted its apps off my devices and stopped visiting the site altogether. The first couple of days were difficult, not in the overwhelming craving way that quitting smoking was hard, but because muscle memory kept trying to open the apps the moment I found myself with a few seconds to spare. That, too, passed.

Thanks, Reddit, for breaking my unhealthy addiction to your site. I couldn’t have done it without you.

Fake landlord tried to scam my kid

My kid and their friend are looking for a house to rent. They found a perfect match, with a nice house in a pretty neighborhood and accommodating landlords, but there were a few red flags.

The last was when the landlords wanted kid and friend to send them money, supposedly because they live in a different state, and then they’d mail the house keys. The landlord also sent the kids a signed lease to sign and return. The signature on that lease didn’t match up with their name:

Signature from the lease

I did a reverse image search on the signature, and it was L. Ron Hubbard’s signature from his Wikipedia article:

Signature from Wikipedia

I took no joy in breaking the bad news to the kids, but I praised them profusely for talking to me about it first.