Showing posts with label FACEBOOK. Show all posts
Showing posts with label FACEBOOK. Show all posts

2020-12-26

Facebook portal oddness

Obviously, as it was Christmas day, I ended up spending an hour helping a friend with tech support. Their Facebook portal was being a tad odd. So I post here in case anyone has any suggestions - as I was stumped!

She had factory reset and re-setup it anyway to try and get it working, and we tried resetting several times, and clearing the logins on the Facebook app (which also resets the portal). Here are the symptoms:

  • During set up, we connected to Facebook and it showed on the Facebook app as logged in, all sensibly. We selected some "favourites" as normal during set up (i.e. it showed contacts with check boxes as you would expect).
  • The home screen shows suggested contacts of the person themself! Not any actual contacts!
  • Trying to add a favourite shows an empty screen - no contacts to add!
  • Searching a contact shows not found.
  • However, incoming calls work, but they do not then show in "recent" after the call - it says no calls!
  • Saying "Hey portal, call Adrian" (or any other contact) correctly shows the contact or contacts matching, with name and picture, but selecting one does not actually make the call - just nothing happens.
  • Installing the portal app on the phone shows the favourites that we selected on set up of the portal.

Over all, it is just plain weird. We cannot see any sort of privacy settings blocking contacts (and if there were, the fact the "Hey portal" shows them would a be a bug).

Suggestions welcome!

2019-02-03

An interesting scam (I wonder how Amex will cope).

I am no expert on scams, honest, but I thought this was interesting.

I saw an advert (on Facebook) for a handheld inkjet printer. This looks cool, and I have previously seen some article on them. I vaguely recalled that they cost several hundred pounds, and the advert was for $44, which seemed very cheap. To be fair, many printers you can buy are stupidly cheap as they sting you on the consumables - so very possible. This is what the printer looks like: https://youtu.be/Va3A7QcBlLE

I decided to order one. My reasoning was that :-
  • If it is real, it is a cool gadget at a good price.
  • Not totally implausible I guessed (turns out I had mis-remember the cost of these).
  • I rashly assumed Facebook would have taken down a scam advert, LOL.
  • I assumed Amex would not deal with scammers.
  • I assumed Amex would be good at handling a dispute if it was a scam.
  • It is only $44 so not the end of the world and worth a shot, even though I kind of guessed it was a scam.

So how did I fair?

Well, it was a scam - what a surprise! Shame, as it would have been cool.

Basically, I got an email confirmation of my order, but it said it would ship in a few weeks. The first step in causing delay.

After nothing arrived, I put in a dispute with Amex.

Out of the blue (and perhaps because of dispute) the scammer sent an email saying it had been shipped! I did not hold out much hope, and I assume another delaying tactic.

The advert on Facebook popped up several more times, with different company names, and I complained to Facebook. They would not take action even though clearly a scam - the comments made it clear too. Also, it seems, these printers are normally around $8000 or something crazy so obviously a scam, had I bothered to check.

A while later, something arrived in the post... Signed-for, from China:-


They have the right description, but what they sent was a paper tape for a dymo labeller! As it happens, I had just got a Dymo labeller for my grandson, so it did not go to waste.

So, what next?

The "dispute" on Amex showed as complete, and no credit, and no contact from Amex. I did wonder if it had gone in spam and been deleted (spam not held for long). Seems not, as emails now from Amex are not going in to spam.

I raised a dispute again, and now even that has vanished, not showing a dispute complete or anything. Both were via the Amex app, which seemed to make raising the dispute quite easy!

I ended up doing a chat on their web site - apparently the dispute was stuck somehow, which is odd. He cleared it and made a new one and gave me a link to upload documents (e.g. above image). It would not take a jpeg but would take a PDF with a jpeg embedded! Crazy!

One issue is they wanted details of what the merchant had advertised. They were sneaky as the original advert was a video on Facebook and not there any more, and I did not even have a screenshot. Later Facebook adverts were different company name, so I could not use that. The confirmation email just had the description "Handheld Portable Printer" and even the "view my order" link (which no longer works) only had that description and not more detail nor an image.

So the evidence to Amex that I can provide is somewhat limited. Indeed, only the description on the label is in my favour. I wonder if they will claim that there is something lost in translation and a paper tape is all they were trying to sell? Oddly, such a tape is not even worth $44.

I hope Amex do not deal with scammers - we will see.

2018-02-10

2D bar codes

I have done a lot on barcodes on my blog, and I am sure I have mentioned the URL shortener I made that is www.4.gg in the past.

It allows you to provide a URL and gives you a barcode for that in a variety of formats. Some time ago I changed from IEC16022 (DataMatrix) codes to IEC18004 (QR) codes simply because this is a tad like betamax vs VHS, and clearly QR codes have won. Shame, in my view, but they work. It's is even possible to script it to get codes for URLs from automated systems.

I was looking today at some of the stats on the site. It collects very few pieces of data - obviously it has a log of the mapping from an assigned code to a URL, it has to have that, and it records the date/time it was made, and the IP from which it was made and a hit count and latest time of use, and well, that is it.

It was never any attempt to collect data, personal or otherwise. I intended it to be useful, and well, we (A&A) use it for things like barcodes on invoices.

What makes it special is that the barcode is designed to fit the minimal QR code format, so is compact and/or easy to read. For example :-

That is the size of all of the barcodes it makes, the smallest allowed in normal IEC 18004 QR codes. But the URL shortener aspect means that can be any URL you like.

I checked, and was amazed that there are literally millions of hits on these codes now. It has been working for like 9 years now. We actually have over a 1000 new codes created a day now, which shocked me! When I started some camera phones had QR or data matrix readers, and even the Nokia phone had a bug that did not like a "z" in the code. These days phones have QR code readers in the camera apps, and iPhones just "see" QR codes when taking a picture...

So then comes GDPR, and I am concerned - we collect IP address when codes created and hit counts. Importantly we could collect way more if we wanted to. Some may count as "personal data" though that is questionable. So do I have to worry.

Well, best plan is make this an official free service by A&A and include in GDPR privacy statements. Annoying we have to do this crap in many ways, but let's do the right thing shall we.

BTW, the most popular code is some site that is now a parked domain, over 500k hits and even one today, so someone has put that barcode somewhere massively popular and I know nothing about it. Amazing how a free service I have not even advertised has taken off.

What is especially amusing is Facebook hampering my freedom of speech talking about it!


First time I have ever been accused of spamming... What is amusing is that I could post that screen shot on Facebook and a QR code of my post and the various comments and replies in QR code with no problem. Shows how effective Facebooks policies are in practice. LOL.

2017-10-30

Is there a role for social media to solve the "web of trust" issue?

Public key encryption is a great system - it allows private communications to someone simply by knowing their public key.

The issue is that of "identity". There is no real way to know that someone's public key is theirs. Yes, the key is accompanied with additional information such as name, and email address, and that is signed by the private key so we know it all goes together. However we don't know it is not all simply made up by someone else.

This is solved in many ways - I have a PGP key fingerprint on my business cards. This means that after a face to face meeting, someone can check the person they actually met matches a public key they find on the internet. They still do not know for sure that the person they met is Adrian Kennard, but they know they are communicating with the person they met (assuming I am not giving someone else's key out for some obscure reason).

The other way is a "web of trust" - when you meet someone, and by some means you confirm their identifying information in their public key matches up to them (check passport, driving licence, etc), then you counter sign their key. This is what happens at key signing parties (honest, that is all, it is not some euphemism).

The idea is that with people signing other people's keys you can create a chain of signatures from someone you know personally to the key you want to check. And indeed, by having multiple paths, and a score of "trust" in each signature, you can create a threshold for trusting the "web".

This ultimately allows you to trust people you do not know without the need for a trusted central authority model. Obviously, if trusted central authorities, like banks, and companies house, actually participated, that would help massively.

So how could we improve the web of trust?

Well, I wonder if this is actually a role the likes of Facebook could take on. This already creates a web of contacts, and most of my "friends" I know personally and can be sure the Facebook persona is the person I know. They would need to prompt people to confirm how well they know their friends, not when they follow but maybe a few months later. But ultimately that could mean allowing a signature chain to be created to join up digital keys...

I have not worked out the details - as one issue is that not everyone has keys, and I have not told Facebook my public key, but done right it could mean people that do put public keys on Facebook could get a load of addition signatures based on a web of social media trust.

I have also not tried to work out how the whole thing could be heavily trolled.

Comment?

Taxing home internet

There seems to be a proposal to change TV licensing to a tax on home internet! Thanks to this article from ISP review. I hope it goes nowhe...