Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • One option might be for the real Sean Byrne to move to the address in Sligo of the fictitious one, then ask to be removed from the Entity List on the grounds that he is a real person. I think that wouldn't work, and could be life-changing in a bad way, but it's an idea.
  • Sligo's not _that_ bad.
  • It might result in his address and birth date being added to the entry on the Entity List, now that the authorities have gained knowledge of that additional information. ;)
  • Ah, yes, irreversibly linking himself to the same address and adding an impersonation criminal charge will improve his situation a lot!
  • Not exactly the same still i would like to share my horror story.

    Google decided to ban my many years old account. Reason: account created by computer program. Likely flagged me because i use multiple computer and connect from other wifi.

    Whats worse is i am a monetized youtube partner with million+ views. Youtube support (@TeamYoutube) just say "it is a google problem"

    All appeals are handled by bots, there is no way to reach an actual human being.

    We are being controlled by our ai overlords. Some bot on some cpu can ruin your life on a whim.

  • The recurring recipe for Jill Bearup has been after exhausting all the "appeal" and "support" processes which are hopeless and either can't or won't help, to ask for the underlying data so that you can understand their decision. In the EU [and because it was once a member of the EU when this rule was enacted, the UK] you're legally entitled to that data because you are its subject.

    So far, getting the data hasn't happened once AFAIK but magically she's unbanned/ unblocked/ whatever.

  • You can't seriously match people on first and last name and claim "fully matched".

    Think of how manny John Smiths there are?

    How can this be the company started by Wozniak and Jobs ...

  • No-fly lists are sort of bonkers in this way.

    Firstly you have the issue that many terrorists are going by a nom de guerre rather than their legal or birth name.

    Then, of course, your terrorists will have common names. How many Mohammeds are you gonna list?

    Lastly is transliteration. Your no-fly list is in Latin characters. But your terrorists have Arabic and Persian and Hindi and Cyrillic names. So what do you do. Transliteration is an inexact science, and there are often many branching methods of doing it.

    So no-fly lists are based on fuzzy matching common pseudonyms. It's a farce, really it is.

  • > How can this be the company started by Wozniak and Jobs ...

    The same Jobs that routinely denied publicly that he was the parent of his daughter, even though he knew? The same Jobs that cheated Wozniak financially? The same Jobs that led to a change in legal legislation on how organ transplants work?

    The world needs to move on from this marketing bs that he was somehow a "great" man who is morally solid and must be doing the right thing. Apple is precisely the company founded by Jobs.

  • You’re presenting this like a mistake born out of incompetence.

    It isn’t. The institutions involved simply don’t care whether they are destroying the lives of random people. At all.

    And why should they? They are completely unaccountable in practice, sometimes even in theory.

  • As a guy named Chris Smith, I can tell you, people do absolutely "match people on first and last name", and it causes me no end of trouble.
  • I used to own a very small, very niche retail business that produced a specific part for analog synthesizers. I had customers in literally nearly every nation on earth, and I was surprised by how many times I received returned package for shipping to a person who was “sanctioned” by the US Government. It was probably something like 1 out of every 100 packages. In each case, the person on the receiving end was surprised to hear about the sanction and I honestly believe most were mistaken identity like the article in this post. When it happens, it’s nearly impossible to do anything about it.
  • I believe this real Sean Byrne should move into Sligo for a while, just to spice it up a little. Then they can also ask to be removed from the list as the person on the list.
  • This has been going on for a long time. In the early 2000s I knew someone with the relatively common name Ian Smith who was routinely held up in airports because someone else with that name was on a watch list. I think in the end he managed to get some kind of stamp in his passport that officially said "not that Ian Smith", and it seems mad this isn't easier to resolve these days.
  • It looks like it will be a good idea to name a baby after those databases are checked so that he/she is less likely have a problem in the future.
  • The App Store as the only way to install apps is the worst part about iOS and why I'll never use it again.

    I'm always helping friends with piracy and I have to tell them they can't conveniently use a native app because it isn't listed on the App Store.

    And then there's the removal of ICE apps.

    It's too much control. On iOS, if the government banned Signal, Apple could enforce it. On GrapheneOS, you can use whatever app from anywhere no matter what.

  • Yes, the posted story has so many layers of wrongness in it — it's hard to pick just one.

    None of it would be a problem without the App store in its current form though.

  • If a government entity would work like this, all heck would break loose.

    Trying to contrast this to the EU's attempts to force only gatekeepers (those companies so large that there is no alternative to dealing with them) to open up systems, even at the cost of damaging e.g. apple's valiant and welcome attempts to protect the privacy of its customers, highlights to me that the EU is completely correct in doing so.

  • Once Android developer verification rolls out globally, Alphabet Inc. in Mountain View and the US sanctions and export controls list will become the sole arbitrer of accepted software publishers. Only minority platforms like GrapheneOS, Mac OS X, Win32, Linux remain as free general computing operating systems.
  • This scares me! Denial of service (in some cases you may not even have an alternative), in some cases custody, et cetera and that too based on a false positive or a flimsy match. And no one doubles checks it, no one bothers to make sure, and they are allowed to do that! All this is actual legal and no one pays for it once it's found out, and even if you have suffered. None.

    And heaven's forbid if your actual ID and references (i.e you) have ended up in such places (or such list/s) by mistake or malice.

  • Also because there's no real due process associated with these various lists, they can be used to punish political enemies.
  • This is one of the obvious consequences of not having a national identity number assigned to everyone at birth, which exist in most developed countries, except for anglosphere, for some reason.
  • He has a passport with a number on it. Why isn't that sufficient? There are also multiple countries involved in this story.
  • Ireland has a PPS number which everyone who’s ever had a job or claimed government benefits has. The union of those sets is basically everyone. Clearly that hasn’t helped.
  • How the identity number would help? It's not like terrorists tell each other their identity numbers. So if the LEOs learn about a terrorist guy that goes around under the name "Sean Byrne", how would they know which ID number that is? And even if I needed some ID number to put on my fake documents, it's easy to download one of the dozens data dumps on the darknet now, and just use any of the IDs there. The LEOs then have a choice - put that number into their ban database (therefore banning some innocent person whose only fault is that he made a mistake of participating in the economy) or go just by the name (which is not better). Don't see how it changed anything.
  • Its not as if it even helps since the numbers can be leaked and stolen and then abused & the situation ends up even worse since it is so centralised.
  • I'm from Greece, where I have a national identity number. In fact I've had several (maybe half a dozen?) national identity numbers. You see, the national identity number is, literally, the number on your national identity card, or in other words the serial number of the document; not the person. When the document changes, the number changes with it.

    Same as with passports. Even in the Anglosphere people have passports with passport numbers. They could be used to uniquely identify the passport holder, except of course there are many passports, and therefore, many numbers, for each passport holder.

    Small problem? Just update whatever database is holding the information for sanctionted persons (or, indeed, persons who should not be sanctioned)?

    Turns out, that is not a small problem.

  • in Egypt, every person is born with a universal national ID number , which is standardized everywhere here, but it created some problems, it became extremely valuable to attackers. If leaked, it can be reused across completely different services ( and you can never change it under anycase )

    Having the full name + national ID was enough to bypass verification and activate various services, and many people weren't tech savvy enough to realize how dangerous it was to share or leak that info

  • How so? The article is talking about a fictitious person that's listed by name only on a sanctions list despite the government knowing the person doesn't exist. There is no possibility of the real Sean Byrne presenting a government number that is a negative match against the list because the fake Sean Byrne has no known ID to match against. The essence of the entry is just "here's a name to avoid".

    The real Sean Byrne can produce a government-issued passport number, but that's clearly not enough for Apple.

    I think it's more of a problem of all these "hyperscale" platforms where the cost of not being zealous enough is long litigation and devastating fines, while the cost of losing a single customer (or a thousand) is basically nil. This leads to all kinds of opaque, customer-hostile outcomes like this, also if you trip some filters not related to sanctions / mistaken identities. There's a recurring theme of HN posts along the lines of "an automated process at Google cut my business off, HN plz help".

  • Objection to ID numbers as a concept aside, I don't think it actually solves the problem this author faced.

    Fake identities are dime a dozen. It is not exactly hard for an illicit entity to just put some random ID numbers it bought off the dark web on its books. And now you have just made it even harder for the people who had their identities stolen to clear themselves. How do you convince some company drone doing sanction compliance that you didn't actually work for Sanction Circumvention Ltd when your ID number matches the one on their company's payroll files?

    Not to mention the sanction list is full of foreigners. The American authorities compiling the list aren't going to know what's the national ID of a random Russian or Iranian guy running an import business. So what is going to happen if your name matches someone who's on the list with a blank ID field? Probably the same thing that happened to the author, I guess.