Also, sold his soul to the devil at a crossroads, so you gotta be careful.
Think of how manny John Smiths there are?
How can this be the company started by Wozniak and Jobs ...
Mercury unblocked my accounts because their founder is a very kind man who bothered to verify what the document actually says rather than falling back to, "Computer says no." But everywhere else? De nada. Computer says no.
And it's not even me. It's a fuzzy match with someone in their 50s. Doesn't matter. Computer says no.
And I can't "get off the list" because it's not me who's on the list. The computer will always say no.
In the long run, I'll be fine. I think. But I'll pay $100k+ by the time it's over. These systems are being steadily expanded, as the dumbest incarnations of themselves. We've gone from Thin Thread https://en.wikipedia.org/wiki/ThinThread to crappy fuzzy matches on shoddy data executed on with 0 diligence. It's the stupidest possible timeline.
I think many, many other people will be sharing our fate soon, which is partly why I've been writing about this slow rolling train wreck in motion in bits and pieces.
It isn’t. The institutions involved simply don’t care whether they are destroying the lives of random people. At all.
And why should they? They are completely unaccountable in practice, sometimes even in theory.
The simplest solution is to change my phone number. But
a) why should I have to? it’s my number, dammit!
b) how many accounts have 2FA? if I changed my number, what if I miss updating one that’s important?
c) it could happen again
If I change my number, however, that is the simplest way to solve the problem. It’s just, do I want to?
The same Jobs that routinely denied publicly that he was the parent of his daughter, even though he knew? The same Jobs that cheated Wozniak financially? The same Jobs that led to a change in legal legislation on how organ transplants work?
The world needs to move on from this marketing bs that he was somehow a "great" man who is morally solid and must be doing the right thing. Apple is precisely the company founded by Jobs.
Fake identities are dime a dozen. It is not exactly hard for an illicit entity to just put some random ID numbers it bought off the dark web on its books. And now you have just made it even harder for the people who had their identities stolen to clear themselves. How do you convince some company drone doing sanction compliance that you didn't actually work for Sanction Circumvention Ltd when your ID number matches the one on their company's payroll files?
Not to mention the sanction list is full of foreigners. The American authorities compiling the list aren't going to know what's the national ID of a random Russian or Iranian guy running an import business. So what is going to happen if your name matches someone who's on the list with a blank ID field? Probably the same thing that happened to the author, I guess.
The reason is there. It's no big secret. Pick up a history book.
Having the full name + national ID was enough to bypass verification and activate various services, and many people weren't tech savvy enough to realize how dangerous it was to share or leak that info
All that these numbers do is uniquely identify people. They aren't private. To actually prove your identity, you present your ID, passport, or a digital signature tied to that identity number.
But will I have to? Yes.
https://www.cbsnews.com/news/ted-kennedys-airport-adventure/
Verifying identity is a much simpler problem than establishing identity.
Also the implication that cultures and countries which have happily accepted id numbers are filled with non individualistic people is it?
Nazi Germany and occupied forces used census data, municipal population registers, etc., to identify and track down targeted people. The United States, during World War II, used census information to assist in the removal and incarceration of citizens with Japanese, Italian, and German heritage. The Rwanda population database explicitly classified people as Hutu, Tutsi, or Twa. This became the mechanism to target Tutsi during the Rwandan genocide. In China today, these databases are used to surveil and imprison Uyghurs.
Those are examples of official policy turned to dark purposes. It did not even include malfeasance for malfeasance or criminality by individuals or cartels who somehow gain access.
Many countries have laws about having to carry an ID on you all the time. Not as bad as a tattoo, but still not acceptable IMO.
> Also the implication that cultures and countries which have happily accepted id numbers are filled with non individualistic people is it?
Are we really gonna keep pretending there are no differences between cultures?
They didn't care to figure out if the Sean Byrne of County Sligo actually existed before putting the name on the list. I doubt they would bother verifying an ID number.
Plus, going back to my point about the list being full of foreigners, how do you verify the validity of a foreign ID number and address? Maybe Ireland is going to comply with a US request, but many other countries won't, and you are now back to square one.
The lack of a comprehensive population database only seems to hinder the actual useful civilian bureaucracy, not law enforcement, intelligence services, or ICE. The latter just grab anyone who looks brown enough.
It's not like you care about all the thing you enumerated, they literally ask you for your "race" when getting a driver's license, which is the defacto ID document anyways. You're installing flock cameras everywhere and gargling palantir's balls while they implement the surveillance state.

Earlier this year Apple denied me access to App Store Connect after deciding that I matched someone on a U.S. government restricted-party list.
Their explanation was fairly definitive:
“The information you provided fully matches one or more restricted parties on the U.S. government consolidated screening list or another government’s sanctions list.”
They already had my passport.
I replied with my full legal name, Sean Joseph Byrne, uploaded my driver’s license, and pointed out the address on the government record they appeared to be matching me against. I’ve never lived at that address, never lived in County Sligo, and have no connection to the company involved. I asked them to escalate it to their sanctions compliance folks and make a proper non-match determination.
Apple still hasn’t replied.
Apple’s response after reviewing my identity information.
I knew what had happened because this wasn’t the first time.
Search the U.S. government’s Consolidated Screening List for Sean Byrne and you get exactly one result:
Sean Byrne
Cloonmull House
Drumcliffe, County Sligo
IrelandSource: Entity List, Bureau of Industry and Security
Added: July 21, 2009
License requirement: All items subject to the EAR
License policy: Presumption of denial
The Consolidated Screening List isn’t itself a sanctions list. It’s a U.S. government screening tool that combines a number of export-control, sanctions and other restricted-party lists maintained by the Departments of Commerce, State and Treasury.
The result comes from the Commerce Department’s Bureau of Industry and Security Entity List. “All items subject to the EAR” means the Export Administration Regulations, the rules governing what U.S. companies can ship abroad. “Presumption of denial” is a licensing posture: if someone applies for a licence to export something to this person, the default answer is no. That’s the entire purpose. It’s an export-control instrument but it says nothing about who can be employed, or who can sell shares.
The person in the search result isn’t me. More interestingly, it doesn’t appear to be anyone.
The entry came out of the prosecution of an Irish aircraft-parts business called Mac Aviation. In 2009, the Department of Justice described Sean Byrne as Mac Aviation’s commercial manager and charged him alongside Thomas and Sean McGuinn over the illegal export of U.S. aircraft equipment to Iran.
Except Mac Aviation had apparently invented employees to make the company look bigger than it was.
Mac Aviation was a father and son working out of a cottage on the edge of Drumcliffe village, Ben Bulben behind it. A Rolls-Royce official who came to visit was reportedly speechless. The company he had been selling helicopter engines to, and had taken for a global operation employing hundreds of professionals, was a house in Sligo.
Drumcliffe, County Sligo, with Ben Bulben in the background.
To keep up the impression of a much larger firm, the McGuinns signed documents with false names. Sean Byrne was one of them. John Mooney reported in the Sunday Times that the name appeared on so much company paperwork that the American authorities “became convinced Byrne existed and tried to indict him.”
When DOJ filed a superseding indictment in 2010, replacing the original, Sean Byrne was no longer a defendant. The defendants were Mac Aviation and Thomas and Sean McGuinn.
More importantly, the superseding indictment repeatedly describes Sean Byrne as an alias used by one or more co-conspirators. The phrase appears more than fifteen times, attached to specific invoices, emails and an ownership statement. Mac Aviation staff used the name with suppliers in the U.S. and customers in Iran.
At some stage the U.S. government appears to have worked out that Sean Byrne wasn’t actually a separate person. And yet the entry in the Entity List survived. Sixteen years later it still has no date of birth, passport number, middle name or other useful personal identifier. It’s basically a common Irish name, an address in Sligo and Ireland.
Cloonmull House in Sligo was Thomas McGuinn’s home, and the indictment gives it as Mac Aviation’s registered mailing address. So the entry isn’t a record of a man in Sligo. It’s a name attached to somebody else’s house. And I’ve never lived in Sligo.
Years before I moved back to Ireland, I was selling stock through a tender offer when Nasdaq stopped my order after a background check returned a match on my name.
Their Head of Account Management emailed me saying that the check had found a match associated with a previous incident and that he was confident it was a false positive, but compliance wanted additional proof of my California address. On the phone he gave me more detail and specifically asked me about Mac Aviation. I explained that I’d never had anything to do with the company, provided the extra documentation they wanted and the sale went through with an entertaining story to tell people.
Nasdaq’s response after a background check matched my name.
More recently I ordered a Starlink mounting pole from California. DHL, shipping on behalf of SpaceX, told me the problem was a restricted-party match and asked for my passport. I sent it, they cleared it and the pole arrived. DHL also wouldn’t send a hat I’d ordered in the U.S. on to me in Ireland without a copy of my passport.
The fake Sean Byrne was associated with attempts to procure helicopter engines, fighter-aircraft parts and other U.S. equipment for Iran. The real Sean Byrne occasionally needs to produce a passport before someone will send him a hat.
Apple is the odd one out. Nasdaq and the shippers both generated false positives, asked for enough information to resolve them, and then resolved them. Apple already had my passport, received my driver’s license and a fairly detailed explanation of exactly why the match was wrong, and still told me that I “fully” matched a restricted party.
None of this is novel. In October 2006, 60 Minutes found twelve American men named Robert Johnson who all had trouble boarding flights, and brought them to New York together. A politician, a soccer coach, businessmen and a serving member of the military.
The Robert Johnson they kept being confused with wasn’t a man named Robert Johnson. It was a known alias of someone convicted of plotting to bomb a Hindu temple and a cinema in Toronto, who by then had served his sentence and been deported to Trinidad. The airline agents checking the twelve real ones against it had a name and nothing else. Not even a date of birth.
Asked about it, the head of the FBI’s Terrorist Screening Center said Robert Johnson would never get off the list, and that anyone with the name would be inconvenienced every time they tried to check in.
I’m not on the Entity List. I’m being misidentified as an entry on it. Apple didn’t make that distinction.
The consumer version of this has been litigated. In 2005 Sandra Cortez was held up buying a car in Colorado because TransUnion matched her against a woman on the Treasury Department’s sanctions list who was born 27 years after her. The credit bureau had compared first and last names only, not dates of birth. A jury awarded her damages and the Third Circuit upheld it, describing the failure to compare birth dates as reprehensible. Sergio Ramirez had the same experience at a car dealership six years later, and his case reached the Supreme Court in 2021.
In both cases the courts called for better matching. Compare the date of birth. Compare the middle name.
There is no version of that available to me. The listing has no date of birth to compare. No middle name and no passport number, because the person doesn’t exist. A screening system that does its job perfectly will still flag me, forever, on the only two facts the record contains: a common Irish name and a country.
Which is why arguing with companies one at a time is the wrong approach.
Remote hiring has developed a serious identity-fraud problem. It has also developed, somewhat unbelievably, a North Korea problem.
North Korean IT workers have been getting remote jobs at U.S. companies using stolen or fabricated identities, proxy interviewers and U.S.-based “laptop farms” that make workers overseas appear to be connecting from inside the United States. The FBI has been warning companies about it, and the DOJ has prosecuted schemes that successfully placed workers at more than 100 U.S. companies.
So if you’re hiring remote engineers, “is this person actually who they claim to be?” is now a legitimate security problem.
A new class of recruiting products is being built around that problem. They sit inside the software companies use to manage job applications, the applicant tracking system or ATS.
Tofu is one of them. Their pitch is that they screen every applicant across more than forty signals before a recruiter opens a résumé, and that when a screened applicant triggers a sanctions match the signal routes straight to compliance review. They are explicit that this has to happen early: screening at the background-check stage is, on their account, already too late, so it should run at application submission before any recruiter makes contact. They also say a candidate flagged by one of their customers is flagged across their whole customer network through their API. Brainner makes a similar case, checking applicants against 3.5 billion data points and flagging high-risk profiles before a recruiter reviews them.
Tofu says its database is built from analysed applicant profiles. Their homepage says more than 18 million. Most of their other pages say more than 5 million.
The sanctions screening these vendors describe is OFAC and the Specially Designated Nationals list, which is the right list for the risk they’re selling against: paying wages to a sanctioned person. I’ve no evidence that either company queries the BIS Entity List, and no idea whether any company I’ve applied to uses either product.
But screening my name against U.S. restricted-party data produces a false positive. It did at Nasdaq, at SpaceX, at DHL and at Apple. Four times in six years. And the industry’s answer to remote-hiring fraud is to run that class of check earlier, before a human is involved, and propagate the result across a network of employers.
Their whole thesis is that name screening produces false negatives: a North Korean operative using a stolen American identity passes an SDN check cleanly, because the check runs against the victim’s identity rather than the fraudster’s. That’s true, and it’s a good reason to build better tools. But it’s an argument that only points one way, toward more screening, earlier. Nobody is accounting for a real applicant who matches a listing for a person who was invented.
Mac Aviation fabricated an employee to make itself look like a bigger company. That fabricated employee ended up in an authoritative U.S. government database. Sixteen years later, an industry is being built to detect fabricated employees applying for technology jobs.
Has this cost me a job? I don’t know. I’ve spent my career in information security, much of it in the U.S., and I’m now applying for roles from Ireland. There have been jobs where I’ve a background that should at least get a conversation and I’ve heard nothing. That’s hardly remarkable on its own. Hiring is messy, roles get frozen, recruiters disappear and companies reject perfectly good candidates for reasons the candidate will never know. There is an entire website called Did They Ghost You?, so we’re not dealing with an unexplained phenomenon.
But Nasdaq told me it was Mac Aviation. DHL shipping on behalf of SpaceX asked for a passport and told me it was due to a hit against the restricted parties on the U.S. government consolidated screening list. Apple at least told me I’d matched something, even if it then stopped talking. An applicant tracking system will tell me nothing at all.
I asked the Bureau of Industry and Security’s End-User Review Committee to review the original Entity List entry. I’m not sure anything will come of it. The normal process is designed for a listed person asking to be removed, which creates an interesting problem here. I’m not the listed Sean Byrne, and the available evidence suggests that person may never have existed.
For now the U.S. government’s screening data still says Sean Byrne, Cloonmull House, Drumcliffe, County Sligo.
I’ve still never lived in Sligo.