I should add that my teacher would think we couldn't understand the science or concept behind airflow going through the classroom to cool us off. He'd explain it over and over and get frustrated that so many students didn't seem to "get it." But really they did get it, it just wasn't working for them. I wonder if the arguments about scientific things nowadays aren't similar. It may not be that someone is stupid or doesn't get it, or even that they disagree, just that it's not working for them. The window kids understood that the room was supposed to be getting cooler, but it wasn't for them. They weren't against air flow, but it didn't seem to be working for them. Perhaps in theory the 2 fans in the classroom should have worked, but maybe the fans weren't strong enough, there were other places for the air to go (like the ceiling), etc. so that in practice it didn't actually work like the teacher claimed it would. Maybe there's a lesson there for public debates.
My 4rd grade teacher was convinced of the science of using two fans to cool off the classroom: one blowing cool air into the classroom from the hallway and one fan blowing hot air out of the classroom through a window. The kids that sat near the fan blowing in the room from the hallway were quite content, but the kids by the window were always complaining and they would secretly turn the fan in the window around so it was also blowing in. This would infuriate our teacher when he would discover it and he would claim that the reason the classroom is hot is because the fans were no longer arranged to create air movement through the classroom. But the window kids weren't buying it.
So if sweaty 4th graders are any indication, have the fans blow on you regardless of whatever air movement is supposed to be made.
"we must devise new business models and structural incentives that aren’t rooted in manipulation and coercion...In the short-term, that might be achieved by turning to basic subscription services, by paying for the things we use."
That's why we made RealPeople.io (https://realpeople.io) have no ads at all. Users pay to use, and there's no AI, no sharing your data. Rather than trying to just convince users to take our word for it, we just built it into our business model. Our financial incentives align with keeping user data private. And since we don't get paid based on how many pages the user views or how long the user is on the system, there's no financial incentive to getting the user addicted.
The business model of using targeted advertising as the main source of revenue will always be at odds with protecting user data privacy, and same goes for not making users addicted to the service. These companies may say they will protect privacy and not make you addicted, but that goes against their financial interests.
"...but the solutions they are offering could just help the big players get even more powerful." That's why we should support startups from outside the valley, especially the smaller ones.
> I also don't trust handing "identity token" over to that site any more than I trust Facebook. What happens if/when they get hacked? Will they then have my bank card details? Will the be able to use my identity token to access other sites? These points matter to me because I know nothing about the company and they are gearing themselves up for being an obvious target for attackers.
A RealPerson code is not an access token. It's a unique code generated for a particular website. It's more like a coupon code and RealPerson.io will tell a website if it's valid. The website still handles creating the account and authentication etc., like it has before and does it however it wants, using whatever authentication it wants. But now the website can make a backend call and ask RealPerson.io if the code given is valid, meaning someone (who knows who) generated a code for this site. That's it. Then the website can validate that no other user has used that code when signing up on their website. The website doesn't know what account on RealPerson.io has the code. The website doesn't know what other websites the user uses (the codes are unique to each website). So RealPerson.io just knows codes and websites, and websites just know if the codes are valid. Nothing else is shared.
Stripe processes the payment and credit card details are not stored in RealPerson.io. There are no identity tokens to steal. You have codes but you generate those on demand when you are signing up on websites. Once they are used, then there's nothing more you can do with them.
RealPerson.io doesn't have any personal details on you besides the payment token from Stripe. No bank details. No usernames or passwords for other sites. No usage on other sites.
Yes I am affiliated. I'm arguing why we built RealPeople.io and RealPerson.io to solve the problems listed in the article. I don't think I've tried to hide that.
At first maybe for most people they won't want to pay the cost. What (hopefully) will happen is that smaller sites who have problems keeping bots and fake accounts at bay will decide it's worth it to them to require all their users to use RealPerson. And then (hopefully) over time users face no additional cost using RealPerson on other sites because they already have an account.
Incidentally, this is how RealPeople.io (https://realpeople.io) is able to have no ads because the revenue from RealPerson.io subsidizes it since they're owned by the same company.
> I also don't think it's possible to prevent bad actors from automation while allowing the good actors to do the same things on the cheap. The problem is the same controls that are used to make it difficult for bad actors will also make it difficult for the good ones,
That's how RealPerson.io is different. It's pay to play so it doesn't try to out-tech the bad actors, and so it doesn't make it harder for the good actors.
There were some bad actors in the 90s, but the scale is different now. And the effect is now raised to the level of concern that elections are affected. Some people are even talking about how it is threatening democracy. We don't think an arms race of technology with the bots and bad actors is going to work long-term. We need to change the economics so that bad actors go broke trying to act bad, while real people have to pay very little and not have to give up privacy. Government regulation might solve some problems, but it might also just put Big Social Media in bed with politicians and then little guys will be prevented from playing, and/or the control over online speech will just flip back and forth between opposing ideologies every election.
Right. Bots aren't going to pay. But a user might pay $9/year for all websites. Websites don't have to pay for the service either. The more websites that use the service, the more cost effective it is for users (since they pay once for all sites), and for websites (since the likelihood that the user signing up already has a RealPerson account and doesn't need to pay anymore).
This is the primary way to prevent bots, but there still are secondary means like IP address, credit card, behavior pattern than can be used to detect bots. But with estimated millions of bots operating on Twitter and Facebook and elsewhere, the bot operators are not going to spend millions of dollars on RealPerson accounts.
It doesn't really guarantee uniqueness. It also doesn't verify identity (that this is really "John Smith"). It essentially verifies that the user has paid for an account on RealPerson.io, which is currently $9/year. This was to strike a balance between having to divulge too much personal info to RealPerson.io (like an identity verification service), but at the same time making it highly unlikely that the user is a bot. RealPerson.io doesn't try to drive the percentage to 0 that the user is a bot, but rather make it cost prohibitive for bots, while at the same time making it cost effective for real people, and still protect privacy.
Also, a user only gets one RealPerson code per website, so a user can't create multiple codes for a website and hence create multiple accounts on that website. And if that website bans the user, that user would need to get a new code for that website, which would mean creating a second account on RealPerson and paying again and face the scrutiny of RealPerson detecting that the user has two accounts on RealPerson.
I agree that having a few walled gardens is a problem, but having more smaller walled gardens probably won't change much. Bad actors can still sign up, post, spam, harass, etc. on several small walled gardens. What we need is a way to better identify and handle bad actors.
The internet in the 90s seemed more fun and more open. Perhaps it's because the only people really participating were not interested in abusing sites or people. It was mostly nerds sharing nerdy things. Once money got involved, and free everything was available, it turned into this soup of bots, trolls, AI, fake this and that, big money, swaying public opinion, and gross content.
Smaller sites and discussion boards have been at a disadvantage recently trying to fend off spam, bots, and sock accounts and very often lose out to the big sites. Effectively controlling abuse and doing it a cost-effective way can be very hard.
RealPerson.io (https://realperson.io) was created as a way for websites to verify that a user is a real person, but without disclosing personal details about the user. Each person can create a single account on RealPerson.io and then can create separate, randomly-generated codes for each site they use. Websites register on RealPerson.io and then for each user signup on their website they simply asks the user for their RealPerson code for their website. A backend REST call to RealPerson.io with the user code for the site returns "yes" or "no." Sites don't share codes so you can't track across websites. No shared logins or authentication code. Bots would have to pay for a code for each account which would be cost prohibitive to run a bot farm.
The first implementation of this approach was done with RealPeople.io (https://realpeople.io) which uses RealPerson.io to verify that the user is real.
What if there were a trusted third-party that periodically audited the business to see if they were protecting your privacy of not. Would people value or trust that? And who would people trust to do the audit?
Exactly why RealPeople.io (https://realpeople.io) was created. The business model of using targeted advertising needs to go away. With ads, platforms have the incentive to sell user data and keep users online as much as possible to maximize ad impressions. AI creates and uses phycological profiles of users and not only shows them targets ads but decides who sees what.
We need to support social media that use paid subscriptions with no ads. And we need to support platforms that make it core to their offering that they are not going to share user data, and which have a business model that will align with that.
There is a lot of discussion around this nowadays which is good, but it's time for people to actually take action and be leader and make the change themselves.
Rather than banning it, why not support platforms that don't use ads? RealPeople.io doesn't have ads, or allow third parties access to any data. No bots, no AI either. Users pay to use. https://realpeople.io