Authorisation vs. Consent An Article by Terence Eden shkspr.mobi I recently read this interesting, and distressing, story of a man who was drugged and robbed. A form of crime which has been going on for centuries. But the 21st Century twist is that the thieves forced him to transfer large sums of money via his phone's banking apps. While under the influence, the victim used his usernames, passwords, PINs, and biometrics to send money to the criminal's accounts. Is there a "technological" way to stop this? His banks initially refused to refund the stolen money. Only once the press stepped in did they relent. One bank, Revolut, said: This was an unusual case where the payments were authorised by the customer but, as is now clear, without his consent. Upstream Color crime
Rethinking Twitter Verification An Article by Terence Eden shkspr.mobi The main problem, I think, is that no one knows what "Verified" means. If I were in charge (which I'm not) there would be various types of ticks. 🤖 is a bot 🆔 proved their legal identity 🏭 is run by a brand ⚖ is run by a government department 👮 Official law enforcement 😎 Celebrity And so on. iconographyidentity
Metrics have a strange hold on the imagination A Fragment by Shawn Wang www.swyx.io Once in place, metrics have a strange hold on the imagination: I've seriously had a CTO carelessly reject my genuine idea out of hand because "it doesn't help OKRs", the same OKRs we previously agreed should not describe all that we do. I agree with Amir Shevat that we should "do the right things over the easy to measure things." metricsux