Jump to content
Seriously No Politics ×

Letter Regarding Name Submissions: Was It Read In Sacrament Today?


Recommended Posts

Posted

There's no such thing as no effort at all. What you meant was a little effort.

Regardless, you did not respond to my point. Creating a more restrictive system would be A) impractical and B) still possible to mess up, with nearly the same amount of effort.

You need to imagine the possible alternatives, and also imagine doing them yourself, before you start criticizing something. Otherwise, you will just end up creating pointless commotion, and for me, that is undesirable.

TAO,

I'm a software developer by training and worked for 15 years as a developer and a technical lead building some pretty sophisticated systems, some of which did require restricted accessibility.

What you are describing is not impossible. It's not something a kid in a basement could whip up, but a team of engineers and some money, it's a fairly common problem that is solved in a number of ways.

H.

Posted

I think we need to stick to the topic- not Harvey Milk.

All derails do is turn attention away from what has been done.

This is not an ordinary thread. I have never seen anything like this before, where someone brags about his attempt to embarrass the church, and has succeeded.

Posted

Any system can be circumvented, and the person doing it, will always plead that it was easy. Maybe it was, maybe it wasn't. But it does require a certain lack of integrity to undermine a system built on trust. The trust between members in a church that, while not perfect, has served we members well. I have made references to men of evil intent that where the sheeps clothing. One should always note who they flock with, who agrees with them. They wish the church ill, and they disdain the members. If being like them is what is required leave the church, I think I am much happier here. Integrity means something in the church, the definition is lost on those like LDS Toronto.

I do know the letter was brought up in bishops council, they decided to read it next week.

Posted

TAO,

I'm a software developer by training and worked for 15 years as a developer and a technical lead building some pretty sophisticated systems, some of which did require restricted accessibility.

What you are describing is not impossible. It's not something a kid in a basement could whip up, but a team of engineers and some money, it's a fairly common problem that is solved in a number of ways.

H.

Had you applied your experience in software development and produced some possible fixes for the supposed problem, rather than doing something you believed to be wrong and something you were told not to do, in pursuit of a fools errand, the results may have been a win-win instead of a lose-lose. But, what is the loss of your personal integrity when you've got the Church to flog?

Thanks, -Wade Englund-

Posted (edited)

TAO,

I'm a software developer by training and worked for 15 years as a developer and a technical lead building some pretty sophisticated systems, some of which did require restricted accessibility.

Well, then, perhaps you have a point.

Edited by Bob Crockett
Posted (edited)

Well, then, perhaps you have a point.

I liked it better before you edited it.

But I did the same thing earlier so I understand

Edited by mfbukowski
Posted

I liked it better before you edited it.

But I did the same thing earlier so I understand

No sense flogging a horse who painted his own sign, "Please Flog Me," and put it on his own behind.

Posted

No sense flogging a horse who painted his own sign, "Please Flog Me," and put it on his own behind.

LOL

It's really pretty incredible.

Posted (edited)

Did anybody bother to notice that the letter doesn't SAY it is SUPPOSED to be read??? That it's supposed to be POSTED?

Cheesh people.

...I'm sorry then I guess? Unless you're saying that with some sarcasm that I missed, tad bit of an over-reaction there my friend.

With the attention that's being drawn to this topic right now, I would think, in my opinion, that the letter from the First Presidency should be read and not just simply posted. That way more members could have an idea about what's going on with this.

EDIT: Because I guess some people need me to indicate that it's my opinion I'm expressing.

Edited by Gohan
Posted

Yes or no? Were you being deceptive when you claimed you received permission from a close relative to do the work for this man? Were you being deceptive when you claimed you read the church's policy and agreed to abide by it?

Posted
With the attention that's being drawn to this topic right now, I think that the letter from the First Presidency should be read and not just simply posted.

You would know best, whoever you are. :good:

Thanks, -Wade Englund-

Posted

The first step is admitting you have a problem. There seems to be sufficient software knowledge here on the board to help the Church fix the problems.Perhaps even the dasterdly LDST could assemble a team,for a small fee.I somewhat understand the desire to "kill the messenger" in this case,but that does not help solve the improper name submission situation. The sooner the Church gets the software to flag such submissions and submitters ,the sooner the media storm subsides and Radkey and her ilk start hunting for a new area to target. A call to Homeland Security might.... then again,forget that.

Posted

You would know best, whoever you are. :good:

Thanks, -Wade Englund-

Clearly I don't, since it wasn't my intent to express that. Edited my previous post for clarity, thanks for the sarcastic complement I suppose.

Posted (edited)

The first step is admitting you have a problem. There seems to be sufficient software knowledge here on the board to help the Church fix the problems.Perhaps even the dasterdly LDST could assemble a team,for a small fee.I somewhat understand the desire to "kill the messenger" in this case,but that does not help solve the improper name submission situation. The sooner the Church gets the software to flag such submissions and submitters ,the sooner the media storm subsides and Radkey and her ilk start hunting for a new area to target. A call to Homeland Security might.... then again,forget that.

I vote for waiting until LDST researches the software problem and attempts to come up with a fix before jumping to conclusions about what the Church should or should not do at this point. This way, if the Radkeys of the world continue their self-serving harangues on this issue, then LDST can blame himself instead of the Church and post a blog article demonstrating his failure.

Now there is a win-win if ever there was one. :good:

Thanks, -Wade Englund-

Edited by wenglund
Posted
Clearly I don't, since it wasn't my intent to express that. Edited my previous post for clarity, thanks for the sarcastic complement I suppose.

No problem. I was just reciting the Ark Steadier Creed.

Thanks, -Wade Englund-

Posted

Did the LDS church make a promise to the Jewish community that it could not keep?

The Church made a reasonable commitment that it has reasonably kept. That should have sufficed--except, perhaps, for those with an ax to grind or polemic points to score.

Thanks, -Wade Englund-

Posted (edited)

TAO,

I'm a software developer by training and worked for 15 years as a developer and a technical lead building some pretty sophisticated systems, some of which did require restricted accessibility.

What you are describing is not impossible. It's not something a kid in a basement could whip up, but a team of engineers and some money, it's a fairly common problem that is solved in a number of ways.

H.

Nah, I don't think you are understanding.

Let us say, for a moment, that the only possible vulnerability points to the system were the basic ones (in other words, let's assume the system could not be hacked).

Now let's look at all the possible ways to get around that. The first, and obvious one, is to enter in slightly wrong data. Change their birthdate. Change their birth location. Maybe even change their name by one or two letters. There are thousands of possible ways to alter the data so it is unrecongizable for the computer. And even the recognizable ones can generate alot of false positives. There are seven people precisely with my exact name, with my exact birthdate, that go to a certain place to get glasses, just in my state. If that's consistent, think about all the other possibilities. Even if names with close to if not resemblant names were flagged, then, somebody has to go through them all, because obviously, the system is going to pick up some wrong things. Considering how many people that is, that's going to cost something. And that is only with names. What about other slightly off information? There are so many different possible scenarios, that doing that would be somewhat of a nightmare. And all the while, people are looking for ways around your software. And there's many more people looking for ways around it than there are people fixing it.

There are other problems too. Let's say they removed the option to insert non-family members. How many people genuinely are inserted per year that are not family members? Alot. That means the work has to be done manually, and that's more paperwork, and thus, more money. Not to mention, that people can still insert people who aren't family members as family members. How do we check that? We can't set up any form of ID to check whether the person is actually a family member (that'd be a breach of privacy), so we have to do yet more flagging and more manual work, which costs yet more money.

Let's even say, for a moment, that they required voice permission inserts. What if someone faked the voice insert? How do you verify that? You can't go spying in on their home. And you'd still have to make sure people listened to it to make sure it wasn't garbage (yet more money). Or what if we required lots of background information, to be sure? Well, how are we sure that all people have alot of background information? We aren't. And even then, we'd have to check they didn't copy it from elsewhere, are we to perform a comparison check on every single entry in the database? That's a HUGELY expensive operation. You don't want your servers doing things like that. Even if we eliminate some of the unlikeliest ones, that's alot of data to check. The fact is, changing a few small things takes only a tiny bit of effort. Whereas, it takes the server (or humans) alot of effort to weed out.

Now, let me make an analogy to the independent flash game industry, which I am trying to get into. Now mind you, I don't have any multiplayer games. But I know (and talk to) alot of developers who do. Now, one of the major problems in these games is hackers. Now, we can provide a few checksums to see if they are accessing the correct data, and double check that the weapon stats are right. We can ensure that things are done on the client side, to make it harder to access (because data has to be inserted at precise moments). And we can do many other things to prevent hacking and manipulating of data to allow a fun multiplayer experience. Now, what does it all come up to? There are just less hackers. Not alot less, mind you, only some less. Why? Because hacking programs are distributable, and once one person makes one, many others use the same program. So there are still hackers, and the hackers don't even have to have a knowledge of hacking. They just have to have a knowledge of where a package you have to download is, and how to use it. Ultimately, the life lesson learned is that you can't prevent everything through code; computers aren't just smart enough. They only prevent people who don't have a truly compelling interest.

Now, there is another technique the developers use against hackers - reporting. This is the most effective technique, because people can learn and recognize patterns very quickly, while computers can't. If a hacker is reported, their IP is blocked, their account is deleted. This doesn't always stop them, of course, because they can change computers/networks, but, it does help alleviate the problem. The problem will still exist - and people will still hack - but the problem is always being solved, thanks to people reporting the hackers. Thus, this, is the best way to block hackers to date. It's alot less time consuming then rewriting the software to make their hacking programs not work. It isn't permanent. It ins't a catch all. But it works.

The thing is, I think the church is already doing this, right? They already let users report errors like this?

So to sum things up, here it goes:

1) Fixing these problems isn't going to stop people who are already sufficiently motivated to submit incorrect data. At most, it will stop ones who are either non-tech-savy, or are just doing it as a joke.

2) The amount of fixes and combinations of ways to make errors is gigantic, and just impractical to incorporate into a program. It'd make things very slow, and very expensive.

3) The church is already employing the most practical approach of the problem: letting users report data that has been incorrectly submitted

4) The more restrictive the system, the more of a hassle it is for the user base that is supposed to be accessing the software. You are a software developer, so you should know that making things difficult is not a good idea.

Conclusion: Regardless of your intentions, you have not created an appropriate solution for the problem (the ones I see are either expensive, hasslish, or impractial,and we can't use those =/). Thus, I do not see why you should be criticizing it. You need to come up with a truly practical solution, and then we can start talking, and most definitely will start talking =).

Edited by TAO
Posted

Yes or no? Were you being deceptive when you claimed you received permission from a close relative to do the work for this man? Were you being deceptive when you claimed you read the church's policy and agreed to abide by it?

Yes. I admit this in my article. By the way, this is the *only* safeguard that is in place. No others.

H.

Posted

The first step is admitting you have a problem. There seems to be sufficient software knowledge here on the board to help the Church fix the problems.Perhaps even the dasterdly LDST could assemble a team,for a small fee.I somewhat understand the desire to "kill the messenger" in this case,but that does not help solve the improper name submission situation. The sooner the Church gets the software to flag such submissions and submitters ,the sooner the media storm subsides and Radkey and her ilk start hunting for a new area to target. A call to Homeland Security might.... then again,forget that.

The Church runs an open-source program, enlisting some fairly bright individuals to do development work for free. There is no reason these talented people can't solve this problem. They don't need to pay someone like me to do what a competent team of people are capable of.

H.

Posted

The church has asked you not to do it you still do in defiance of the church wishes. Then you try to justify it. You are an apostate plain and simple.

Posted

Nah, I don't think you are understanding.

Let us say, for a moment, that the only possible vulnerability points to the system were the basic ones (in other words, let's assume the system could not be hacked).

Now let's look at all the possible ways to get around that. The first, and obvious one, is to enter in slightly wrong data. Change their birthdate. Change their birth location. Maybe even change their name by one or two letters. There are thousands of possible ways to alter the data so it is unrecongizable for the computer. And even the recognizable ones can generate alot of false positives. There are seven people precisely with my exact name, with my exact birthdate, that go to a certain place to get glasses, just in my state. If that's consistent, think about all the other possibilities. Even if names with close to if not resemblant names were flagged, then, somebody has to go through them all, because obviously, the system is going to pick up some wrong things. Considering how many people that is, that's going to cost something. And that is only with names. What about other slightly off information? There are so many different possible scenarios, that doing that would be somewhat of a nightmare. And all the while, people are looking for ways around your software. And there's many more people looking for ways around it than there are people fixing it.

There are other problems too. Let's say they removed the option to insert non-family members. How many people genuinely are inserted per year that are not family members? Alot. That means the work has to be done manually, and that's more paperwork, and thus, more money. Not to mention, that people can still insert people who aren't family members as family members. How do we check that? We can't set up any form of ID to check whether the person is actually a family member (that'd be a breach of privacy), so we have to do yet more flagging and more manual work, which costs yet more money.

Let's even say, for a moment, that they required voice permission inserts. What if someone faked the voice insert? How do you verify that? You can't go spying in on their home. And you'd still have to make sure people listened to it to make sure it wasn't garbage (yet more money). Or what if we required lots of background information, to be sure? Well, how are we sure that all people have alot of background information? We aren't. And even then, we'd have to check they didn't copy it from elsewhere, are we to perform a comparison check on every single entry in the database? That's a HUGELY expensive operation. You don't want your servers doing things like that. Even if we eliminate some of the unlikeliest ones, that's alot of data to check. The fact is, changing a few small things takes only a tiny bit of effort. Whereas, it takes the server (or humans) alot of effort to weed out.

Now, let me make an analogy to the independent flash game industry, which I am trying to get into. Now mind you, I don't have any multiplayer games. But I know (and talk to) alot of developers who do. Now, one of the major problems in these games is hackers. Now, we can provide a few checksums to see if they are accessing the correct data, and double check that the weapon stats are right. We can ensure that things are done on the client side, to make it harder to access (because data has to be inserted at precise moments). And we can do many other things to prevent hacking and manipulating of data to allow a fun multiplayer experience. Now, what does it all come up to? There are just less hackers. Not alot less, mind you, only some less. Why? Because hacking programs are distributable, and once one person makes one, many others use the same program. So there are still hackers, and the hackers don't even have to have a knowledge of hacking. They just have to have a knowledge of where a package you have to download is, and how to use it. Ultimately, the life lesson learned is that you can't prevent everything through code; computers aren't just smart enough. They only prevent people who don't have a truly compelling interest.

Now, there is another technique the developers use against hackers - reporting. This is the most effective technique, because people can learn and recognize patterns very quickly, while computers can't. If a hacker is reported, their IP is blocked, their account is deleted. This doesn't always stop them, of course, because they can change computers/networks, but, it does help alleviate the problem. The problem will still exist - and people will still hack - but the problem is always being solved, thanks to people reporting the hackers. Thus, this, is the best way to block hackers to date. It's alot less time consuming then rewriting the software to make their hacking programs not work. It isn't permanent. It ins't a catch all. But it works.

The thing is, I think the church is already doing this, right? They already let users report errors like this?

So to sum things up, here it goes:

1) Fixing these problems isn't going to stop people who are already sufficiently motivated to submit incorrect data. At most, it will stop ones who are either non-tech-savy, or are just doing it as a joke.

2) The amount of fixes and combinations of ways to make errors is gigantic, and just impractical to incorporate into a program. It'd make things very slow, and very expensive.

3) The church is already employing the most practical approach of the problem: letting users report data that has been incorrectly submitted

4) The more restrictive the system, the more of a hassle it is for the user base that is supposed to be accessing the software. You are a software developer, so you should know that making things difficult is not a good idea.

Conclusion: Regardless of your intentions, you have not created an appropriate solution for the problem (the ones I see are either expensive, hasslish, or impractial,and we can't use those =/). Thus, I do not see why you should be criticizing it. You need to come up with a truly practical solution, and then we can start talking, and most definitely will start talking =).

My intent was not to solve the Church's problems. But let me give you a freebie solution:

1. Use a loose pattern matching algorithm to check submissions against a list of restricted names. Such lists are easily obtainable.

2. Sequester names that are flagged as possible matches.

3. Do a more thorough check on sequestered names. This can be done low-cost - have service missionaries do it. Create a protocol that checks for verifies proof of permission.

Yes, this system can be circumvented. But it would take much more effort to circumvent than the current system.

H.

Posted

The church has asked you not to do it you still do in defiance of the church wishes. Then you try to justify it. You are an apostate plain and simple.

Yes, I'm an apostate. And?

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...