• 0 Posts
  • 9 Comments
Joined 2 years ago
cake
Cake day: June 29th, 2023

help-circle

  • Yeah I totally agree that the whole ordeal is unnecessarily complex and confusing. The number of websites that have started mandating 2FA despite having complex, unique passwords that have never been shared annoys me regularly. It’s frustrating that because other people can’t figure out how to use a password manager, we can’t have nice things.

    My guess is that there is a certain number of account actions you’re allowed to take (changing password, email, etc) before they force you into a cool down period where you can’t delete your account for like a week. Maybe not, but this is one approach I’ve seen before.

    As for the video call, I totally see your train of thought. This is gonna sound dumb, but consider that nobody at LI knows you, so a video call is of limited value, especially in this world of ai models that can apply filters to video in real time. I’m not saying this is their rationale, but it could be part of it.

    I’m gonna nerd out here for a second but hopefully you’ll humor me. Authentication is tricky, especially if you want more than one factor for 2FA/MFA. The factors are often explained as something you know (password), something you have (perhaps a yubikey, in this case a state issued ID), or something you are (biometrics). The biggest issue as I understand it is that people reuse the same password over and over, so if your LI password were compromised then it isn’t too big of a leap to assume that your email was also compromised, meaning that any form of authentication relying on email cannot be trusted.

    If LI has a policy that any account deletion actions attempted within a month of changing the primary email require the account to have at least 2 factors, that would trigger the request for your ID, because they’re assuming that a threat actor is controlling all of the relevant accounts and they are no longer useful for authentication. State issued ID is one of the best ways to authenticate because when your state provides the ID, they are providing a level of guarantee that the information is both true and being provided without modifications (authentic).

    Having said all of that, could you not photoshop a state ID and provide that? Some in the comments have suggested that as an option. If I were designing the program then this third party, Persona, would have relationships with issuers of state ids and could do some level of validation that the ID being uploaded is authentic.

    I realize none of this solves your problem, but sometimes I feel better about “stupid” policies if I can work backwards and understand how they came to be in the first place and what they’re meant to accomplish. My advice is to wait a week or 3 and try to delete again, but obviously that is still no guarantee. Good luck!


  • Would you prefer that anyone be able to request that any non-verified account be deleted?

    I’d bet their security system saw you log in from a new IP, maybe even over VPN(?), then change the email and add 2fa, which are exactly the steps a malicious actor takes when securing an account acquired using credential stuffing. They presumably expect that your account has been compromised and are treating you as untrusted until you provide some form of validation that you are who you say you are.

    I suspect that if you were to seek legal action against them they would claim that you refused to take basic actions to positively prove your identity and throw out some statistics, ie (making this up) 98% of users are able to verify using their system without any issues.

    If you do seek to bring them to court under article 77, would you not then be putting into the public record a permanent association between your real identity and the account you seek to delete? Is that better than simply sending them a picture of your ID? With this in mind, is it worth the cost of legal representation to resolve the issue? I’m not sure where you’re from and you don’t need to answer me but I would encourage you to consider those questions when determining your path forward.


  • I understand where your anger is coming from here, as I was just recently raging about lies in modern day advertising, but I’m having trouble following the line here.

    Let’s say we “stamp out of existence” all activities relating to marketing. Practically speaking, does this make all products commodities? When I walk into a grocery store, is every shelf just a plain brown box with a minimal description of its contents? “cane sugar 1lb”, “laundry detergent”, “vegetable soup”? Further, marketing includes identification of where there is demand for a certain good, so we should be shipping ice melt to Florida in July and sun screen to Montana in January?

    Can I suggest that perhaps what we actually need is better regulations around marketing practices and enforced penalties when companies go over the line?