Live data from Hacker News

Privacy – Forget Your Credit Card

privacy.com

61–70 of 367 posts

Re: Privacy – Forget Your Credit Card

#61
post #4

Hey HN - Privacy.com co-founder here. I'm really excited to share what we've been working on for the past year and a half or so. We've been neck-deep in payments stuff on the card issuing side (getting a BIN sponsor, ACH origination, etc), so happy to answer any questions on that front as well. P.S. For new users, your first $5 donation to watsi.org is on us :)

>Privacy.com co-founder here

Tell me about AVS please.

Existing virtual card services have me covered on the virtual card front - both cost and (limited) privacy. I want something that gets me past the virtual card + AVS issue. All the virtual card providers seem to suck on this front...

Re: Privacy – Forget Your Credit Card

#62

Earlier quoted context omitted.

This sounds awesome. I really hope you will be successful!! What do you do when you get subpoenaed? Do you link all the accounts to the real identity? Lavabit-style exit?

Thank you! We do have to abide by US AML / KYC laws as we are working with a sponsoring bank. We plan on releasing transparency reports on a regular basis.

Do the anti-fungibility regulations and/or your sponsored relationship require you to preemptively submit your transaction information (eg card#->bank# mapping) for surveillance, or only in response to a specific court order? If the latter, what is your retention period?

Do you have any plans to add batching+noise to foil global passive adversaries? For example, I opt to keep a running balance target of ~$50 and today's charge for $34.56 is debited as $31.37 a week later.

Re: Privacy – Forget Your Credit Card

#63
post #26

It's an interesting idea. However, I'm not comfortable with a third party having all that information. Some banks issue "corporate" cards, with numerous "employee" cards. I already trust the bank, after all. So what else does Privacy.com provide that's worth the risk? They're still subject to KYC, right? So there's no strong privacy. Or am I missing something?

We are still subject to US AML / KYC laws. But the cool thing about these cards is you can use any name or billing info you want with them, so don't have to worry about your info getting leaked if some website you bought an indie game / song / whatever from 6 months ago got hacked.

OK, so that would have protected Ashley Madison users. Because none of the likely interested parties (partners, private investigators, etc) would have leverage to get information from you. Same for users buying porn, unless they get investigated for child porn. That's not a KYC issue, but there will be a subpoena. And I'm assuming that you must comply with all subpoenas.

Edit: I wonder what your burden would be in bankruptcy cases.

Re: Privacy – Forget Your Credit Card

#64

Earlier quoted context omitted.

If this is true, then Privacy.com doesn't resolve this obligation. The temporary card number won't be chargeable by the merchant, but you'd still be on the hook for the renewed (and unpaid) service.

It certainly changes the burden of notification. A company can setup many hoops for canceling, forcing you to go through some asinine phone tree and drone script to stop charges to your card. Whereas lacking an established payment channel, they can no longer play dumb if you eg send them a simple email to cancel.

I think this is one of the best aspects of the product. The power is shifted to the customer.

Re: Privacy – Forget Your Credit Card

#65
post #25

Earlier quoted context omitted.

We already trust mint.com with this information. I don't see the big issue.

Not everyone does. And anyway it's owned by Intuit which has a much longer track record than this new company, so it's not the same thing.

This Intuit? http://krebsonsecurity.com/2015/02/turbotaxs-anti-fraud-effo...

Re: Privacy – Forget Your Credit Card

#66
post #63

Earlier quoted context omitted.

We are still subject to US AML / KYC laws. But the cool thing about these cards is you can use any name or billing info you want with them, so don't have to worry about your info getting leaked if some website you bought an indie game / song / whatever from 6 months ago got hacked.

OK, so that would have protected Ashley Madison users. Because none of the likely interested parties (partners, private investigators, etc) would have leverage to get information from you. Same for users buying porn, unless they get investigated for child porn. That's not a KYC issue, but there will be a subpoena. And I'm assuming that you must comply with all subpoenas. Edit: I wonder what your burden would be in ba…

Ashley Madison and porn users are easy targets. But broadly-speaking, we just think you just shouldn't have to share your personal info with a random merchant you want to buy something from.

It's anti-privacy in the guise of being anti-fraud.

Yes, we do have to comply with subpoenas.

Re: Privacy – Forget Your Credit Card

#67
post #4

Hey HN - Privacy.com co-founder here. I'm really excited to share what we've been working on for the past year and a half or so. We've been neck-deep in payments stuff on the card issuing side (getting a BIN sponsor, ACH origination, etc), so happy to answer any questions on that front as well. P.S. For new users, your first $5 donation to watsi.org is on us :)

Are you planning anything for B2B? I’m working on an idea that will need to pay hundreds of vendors for the services they perform for our customers. We want to pay the vendors electronically where possible so having unique card numbers for each vendor would be a great thing. After looking at Privacy.com I want to take it a step further by generating a unique card number for each of our customers. We’d need higher spe…

Take a look at Marqeta.com, this is their bread and butter.

Re: Privacy – Forget Your Credit Card

#68
post #10

I understand why you need it, and I want this service in a big way, but I'm just baulking at giving you my online banking username and password. Why should I trust you with that?

I wish banks would offer something like OAuth - a service-specific, revokable credential with access only to the stuff it needs. I'd be a lot more inclined to use a product like Mint, for example, if I could grant it ONLY read access to my transactions and I knew I could revoke that access at any time without having to change my primary credentials or disrupt any other services/apps I have connected.

Re: Privacy – Forget Your Credit Card

#69
post #2

Very useful - my citibank credit card used to have a feature like this many years ago (I believe called "virtual card numbers"), but they got rid of it for some reason. Though I am more likely to give my personal details to citibank than some startup. Trust is a big issue with payment startups.

Odd. My Citi cards have virtual numbers still.

Re: Privacy – Forget Your Credit Card

#70
post #61
post #4

Hey HN - Privacy.com co-founder here. I'm really excited to share what we've been working on for the past year and a half or so. We've been neck-deep in payments stuff on the card issuing side (getting a BIN sponsor, ACH origination, etc), so happy to answer any questions on that front as well. P.S. For new users, your first $5 donation to watsi.org is on us :)

>Privacy.com co-founder here Tell me about AVS please. Existing virtual card services have me covered on the virtual card front - both cost and (limited) privacy. I want something that gets me past the virtual card + AVS issue. All the virtual card providers seem to suck on this front...

For the confused: https://en.wikipedia.org/wiki/Address_Verification_System
Post reply on HN