Live data from Hacker News

Privacy – Forget Your Credit Card

privacy.com

41–50 of 367 posts

Re: Privacy – Forget Your Credit Card

#42
post #10

I understand why you need it, and I want this service in a big way, but I'm just baulking at giving you my online banking username and password. Why should I trust you with that?

We already trust mint.com with this information. I don't see the big issue.

On the contrary, this is why I don't use Mint...

Re: Privacy – Forget Your Credit Card

#43
post #26

It's an interesting idea. However, I'm not comfortable with a third party having all that information. Some banks issue "corporate" cards, with numerous "employee" cards. I already trust the bank, after all. So what else does Privacy.com provide that's worth the risk? They're still subject to KYC, right? So there's no strong privacy. Or am I missing something?

We are still subject to US AML / KYC laws. But the cool thing about these cards is you can use any name or billing info you want with them, so don't have to worry about your info getting leaked if some website you bought an indie game / song / whatever from 6 months ago got hacked.

Re: Privacy – Forget Your Credit Card

#44
post #4

Hey HN - Privacy.com co-founder here. I'm really excited to share what we've been working on for the past year and a half or so. We've been neck-deep in payments stuff on the card issuing side (getting a BIN sponsor, ACH origination, etc), so happy to answer any questions on that front as well. P.S. For new users, your first $5 donation to watsi.org is on us :)

Are you planning anything for B2B?

I’m working on an idea that will need to pay hundreds of vendors for the services they perform for our customers. We want to pay the vendors electronically where possible so having unique card numbers for each vendor would be a great thing.

After looking at Privacy.com I want to take it a step further by generating a unique card number for each of our customers. We’d need higher spending limits and the ability to manage the cards via API. Other than that, what you’ve built sounds like a perfect fit for our use case.

Re: Privacy – Forget Your Credit Card

#45

My biggest question with Privacy, and of any one-time use credit card numbers service, is always: Will it affect my rewards? Will businesses still show up unaffected with the same categories on my credit card statement? (I have a travel rewards only card, so breaking the rewards flow is a deal-breaker for using a higher level service.) Edit: I misunderstood the service as being able to be layered on top of normal cre…

Debit cards are something we're looking towards in the near term, credit cards probably will have to be a premium feature (due to how we make money right now).

The numbers can be one-time use (burners) or re-usable at the same merchant.

Re: Privacy – Forget Your Credit Card

#47
post #9

Any way this works without a browser extension? I'm assuming such an extension has full access to every single page in order to do its job, which is a huge security risk. You don't need to be reading my emails or passwords.

It does :), you can create directly from your dashboard without an extension. The current onboarding flow pushes you towards creating a card first, but we'll patch that.

Good to hear! Bring this to Europe and I can see it being very popular, credit cards aren't as common or easy to get here and ordering outside of your local country often requires one. I imagine that's still a long way away though :).

Re: Privacy – Forget Your Credit Card

#48
post #36
post #14

Earlier quoted context omitted.

Many virtual cards before you have ran into issues of being flagged as prepaid or single use cards and having their BINs blacklisted by merchants. How will you be combatting this?

>ran into issues of being flagged as prepaid or single use cards I generate Citi's virtual credit card numbers every month for numerous online shopping payments and I haven't run into issues. It seems that it's not possible to determine if a card is a virtual number by parsing the digits.[1] Do you have other information stating that merchants know how to reject virtual cc numbers? [1]"As there is no way for a mercha…

Citi and BOA get away with it because they can allocate out of a large pool of BIN numbers that are otherwise regular use debit/credit cards. These guys will have to figure out how to get a similar "mix" to avoid being flagged as prepaid/single use. This was the issue that ultimately caused PayPal to kill the service they had that was almost exactly the same as Privacy.com.

Re: Privacy – Forget Your Credit Card

#49
post #3

> STEP TWO When you check out on any website, the Privacy icon will appear in the card form. Click it to create a new card, and auto-fill the card form. Use any name and billing address you like. > STEP THREE After the card is charged, we withdraw the money from your chosen funding account, similar to a debit card. Not sure I get this. Do you have to fund an account on Privacy.com? So it's like a Paypal where you gen…

Well, technically they can but a split key system is a PCI-DSS requirement. The advantage is that no single employee can gain access to sensitive data - they would have to collude with each providing their key to decrypt any data.

It is mainly designed to prevent employees from selling off sensitive data, but I think in practice with the right audit controls it's pretty effective.

I guess if there was a system in place where the two employees didn't know who the other employee was then it would mitigate risk.

Makes me wonder what sort of auditing system could be used that guarantees total transparency around when the keys are requested by both parties, by whom and for what reason without disclosing the employees? More interestingly I'd be really interested in a system that ensured that nobody knew who the two employees were but the keys could still retrieved.

Then on top of this it would awesome to have a way of revoking keys.

Probably impossible, but that would be the ultimate in security!

Post reply on HN