Helping Surfers Sidestep Site Registration
netbuzz writes, "PrefPass, a startup debuting at DEMO today, is looking to do for the onerous Web site registration process what Amazon has done for shopping: one click and you get the goods. If it catches on, sites requiring full registration may feel the heat." Looks like sites will have an incentive to implement PrefPass; it's not antagonistic to their interests in the way Bugmenot is.
Hasn't this been attempted before, with the likes of PassPort, and other numerous "universal" single-signon type things that have attempted to partner with commercial sites, and so on?
It says it's different from PassPort, and I agree, but I fail to see why this would have any more success.
I thought (correct me if I'm wrong) that the reason those sites want your age / sex / location was for demographics (for marketing and such).
If they just want to personalize your page, a cookie should be sufficient.
So, if this tool allows me to login to multiple sites, but with faked info, I don't see the sites going for it.
I hate sites that require registration to access "free" content. Either publish your content to your "free" website, or charge me for it. I shouldn't have to tell you anything about myself to get access.
I know I'm jaded and cynical, but how much of the information that is entered into web site registration pages is genuine, anyway?
Insisting on "correct" English is like saying that there is only one, definitive recipe for chili.
But when I do let you know something about me, then know that even though I'm a high school dropout
I am also a 22 year old 5"4 athletic blonde female and I just love the sex older men can give me and I'm
interested in dating and romance. I like Billy Graham, Zachariah Sitchen but I hate Prince Phillip and
I earn more than a hundred thousand dollars a year working as a pharma whore.
Can I use PrefPass to avoid registration for PrefPass?
For some reason, the article omitted a link to bugmenot. There's a Firefox extension that automates the process.
If you don't know what this is, it's a user-maintained list of usernames and passwords for sites that "bug" you for registration. Some sites block Bugmenot-listed usernames and passwords but most don't.
|/usr/games/fortune
I know it's weird, but...
I love the way you say "passport".
C'mon, won't you say it again?
mmmmmm.... passport... it's just such a beautiful word...
passport...
passport!
A Web-based service, the PrefPass registration itself requires only two pieces of information from a user: an e-mail address and the URL of a first Web site or feed in which the user is interested.
So if you're only identified by an already public identifier (that being your email address), what's to prevent people from messing around with other people's preferences? Cookies can be lost by the legitimiate user and spoofed by an attacker. IP-based filering doesn't work for different users behind a common firewall. I wonder how they can get by without some sort of password. I wish they had a technical FAQ to go along with their press release.
--
"Extra Anus Kills Four-Legged Chick" -- Headline
Just another vehicle to serve up even more advertising.
FTA: "In exchange, users agree to let PrefPass sites access their pref lists, thus allowing them to customize the experience, as well target advertising to the user."
I'll stick with BugMeNot, thank you.
Down With Slashdot BETA!!! I've been around the corner and seen the oliphant; you can only abuse me from your perspecti
Note that the submitters email address is "@nww.com" which resolves to networkworld. How much does it cost to get your product listed on slashdot these days?
PrefPass should be something like PassTheInfo, HandItOverToHackers or, maybe TARGET.
Because that's what it's going to become if the public and the corporations actually start using this thing.
One Big Target. Hackers start your engines...!
Lee Darrow, C.H.
I honestly don't see an easy way for spammers to cull this thing (unless they bust into the PrefPass servers, I suppose).
Quo usque tandem abutere, Nimbus, patientia nostra?
I could not care much less for what sites want when they try to collect my demographic information. More often then not, it is directly the opposite of my own desires and preferences. I go to a site to read an article, check a price, or a score, or the day's news. I will look at an advertisement under protest, but I will not willingly give them ammunition to bother me outside of my interaction with their site.
When a site asks for my personal information just so I can see their advertisements on my way to reading the morning's news, I have no problem at all about lying to them. I give a fake name, a fake zip code and a fake email.
If they require an email authorization, I use a spamcatcher account that is created with fake information.
Since when are we required to acquiesce to the wishes of the corporate world just for the privelege of purchasing and using their products? Since when do I have to provide correct personal information just to get the day's weather forecast?
It's the same thing when I go to a Best Buy or Radio Shack and they ask for my zip code or last name. Maybe down the line if they figure out that people are lying to them they'll stop asking.
I'm starting to believe that the next few decades will be marked by the traditional business/customer relationship being replaced by a much more combative, adversarial interaction between the individual and the corporation. It will be to nobody's benefit, but it seems that there are few ways to discourage real assholes. I'm sure those of us who still believe in the primacy of the individual and privacy in general will become inventive in coming up with more ways to thwart these "business" people who believe they have ownership rights over our lives. It's time to balance the scales a bit, I think.
You are welcome on my lawn.
There could be a standard HTTP header field defined.
Call it 'X-Demographics'
Contents would be of the form
"X-Demographics: Age/28, Location/Seattle, Sex/Male, Occupation/Programmer"
All free-form and user selected, with browsers offering a dialog where users can set common information, and choose when/where to send it.
Servers must not require the info, and must accept invalid data without dying ( "Age -1/Location The Moon/Sex Yes Please" ) but if provided, they can customize their content/advertising.
Sure, users might deliberatly provide false data, but they would do that anyway with a 'log on' form; and if you don't want to provide it, you don't (default in a browsers should be nothing sent without user approval) and browsers should be able to control which sites get sent what data. Even a simple mechanism, such as the first time you visit a site, do not send data, but if you return to the site later, then send it.
Details of parsing are trivial (I know, not really), once a standard basic layout and header field name is chosen, I'm going for something like the 'Accept:' field format.
I don't mind reasonable advertisments, but as an example, as a guy, I really have no interest in tampon ads, and I doubt the tampon companies want to spend their advertising dollars on me.
Whenever a site asks me to register before I can access content (and I don't mind my username/password being made public), I use http://www.mailinator.com/. You basically make.up.an.email.address@mailinator.com, and then head over to the site, type in your made up email address, and it shows you the last 5 (probably spam) messages it has received. Of course its totally unsecure (but that's sort of the point), so be careful what you use it for.