Live data from Hacker News

Privacy – Forget Your Credit Card

privacy.com

251–260 of 367 posts

Re: Privacy – Forget Your Credit Card

#252

Earlier quoted context omitted.

Yeah, the TWiET podcast made a big deal recently about how chips are finally making their way to their cards. I couldn't help but laugh. IIRC, Norway had those since the late 80s. And in Australia, Paypass/Paywave is near ubiquitous now. I think the US is way behind in their banking infrastructure.

I used to work at the largest merchant acquirer in the US and it's funny to see people claim these features just now making it to the US were signs of innovation lacking within the US. However, the reason these features were necessary outside the US is because the risk model was more severe outside the US; there was no need to implement them here. I have a presentation from Mastercard somewhere from 2006 that showed…

Weird, because most of the data I can find shows that the US has one of the highest rates credit card fraud in the developed world. Australia being very far down the list typically, and yet we got chip & pin and Paywave/Paypass well before most other places

Re: Privacy – Forget Your Credit Card

#253
post #26

It's an interesting idea. However, I'm not comfortable with a third party having all that information. Some banks issue "corporate" cards, with numerous "employee" cards. I already trust the bank, after all. So what else does Privacy.com provide that's worth the risk? They're still subject to KYC, right? So there's no strong privacy. Or am I missing something?

We are still subject to US AML / KYC laws. But the cool thing about these cards is you can use any name or billing info you want with them, so don't have to worry about your info getting leaked if some website you bought an indie game / song / whatever from 6 months ago got hacked.

What response do you provide to an AVS request when the fake name and billing info is sent to you?

Re: Privacy – Forget Your Credit Card

#254
post #234

Earlier quoted context omitted.

Privacy uses Plaid on the back-end for this and does not store user credentials.

Don't care, use my ach info

ABA/DDA are inherently less secure than online access credentials. An account can be directly debited if ABA/DDA are compromised, and they cannot be rotated without closing the account. Plaid tokenizes all this to avoid any potential issues -- and further, if credentials are somehow compromised they can be rotated very easily.

Re: Privacy – Forget Your Credit Card

#255
post #161

In case anyone didn't catch what this actually costs, the answer is: 1.5-2%, which is the rate you could get cash back (or airline miles/etc) with good credit. Because this service draws directly from your bank account, and takes what would otherwise be your rewards from the credit card fees their banking partners charge, it provides a nice business model for them at the cost of you getting 0% rewards back. Not worth…

Yea I'd agree with that. Was bummed this couldn't be set up with a credit card, and didn't bother asking after realizing it'd break their business model.

All online transactions are processed as credit - even if the card used is debit/prepaid debit - and the card issuer earns 1-3% for each transaction. Some of this fee is rebated back to people through cashback/travel rewards cards, but I am assuming Privacy & Customer's Bank will be using it to fund their business.

Pretty cool idea! And even cooler website!! Would be interesting to see some sort of loyalty/rewards program implemented, although that doesn't really jive with your anti-marketing pitch.

I'll be sticking with my credit cards for now. They're worth a lot more than their rewards, and it's a shame so many people choose to stick with debit...

Re: Privacy – Forget Your Credit Card

#256

I think people are over-thinking this offering a little too much. People who are asking if the company will resist a subpoena, or if all customer data will be irreversibly encrypted, are expecting too much. The main purposes of this product are to be able to mask your marketing data (name, address, phone) to businesses, and to mitigate damage in the event of a data breach (any stolen card numbers are useless). It's n…

This is a very fair point. Still, I would hope that it would make it harder to link a purchase to an identified individual.

If I assume the US is a country where the laws and constitution is respected, then only a formal subpoena would link the credit card transaction to the individual. Hopefully snooping would not.

Re: Privacy – Forget Your Credit Card

#257
Privacy.com This site uses a weak security configuration (SHA-1 signatures), so your connection may not be private.

They not even using a secure signature for their SSL Cert and they want to be your trusted payment proxy?

Re: Privacy – Forget Your Credit Card

#258
Privacy.com This site uses a weak security configuration (SHA-1 signatures), so your connection may not be private.

They not even using a secure signature for their SSL Cert and they want to be your trusted payment proxy?

Re: Privacy – Forget Your Credit Card

#259

I think people are over-thinking this offering a little too much. People who are asking if the company will resist a subpoena, or if all customer data will be irreversibly encrypted, are expecting too much. The main purposes of this product are to be able to mask your marketing data (name, address, phone) to businesses, and to mitigate damage in the event of a data breach (any stolen card numbers are useless). It's n…

That's fair, if you're doing something illegal that may result in a subpoena, this is not the product for you.

However, that doesn't mean what we're doing isn't meaningful. We just think that you just shouldn't have to share your personal info with a random merchant you want to buy something from.

This notion that passing along your billing info is going some how substantially cutting down on fraud is ridiculous. It's anti-privacy in the guise of being anti-fraud.

And yes, it's fair, if you skip out on a gym contract, you do risk getting taken to collections. We're mostly talking more about the ticky tack, deceptive recurring billing fraud. We can do better. We'll make the language clearer on our home page.

Re: Privacy – Forget Your Credit Card

#260

I think people are over-thinking this offering a little too much. People who are asking if the company will resist a subpoena, or if all customer data will be irreversibly encrypted, are expecting too much. The main purposes of this product are to be able to mask your marketing data (name, address, phone) to businesses, and to mitigate damage in the event of a data breach (any stolen card numbers are useless). It's n…

>Finally, I am very skeptical of their claim about walking away from subscriptions and trials. Sure, in theory, you make it much harder for vendors to track you down, but by law, you're agreeing to pay for the company's services when you accept their agreement.

I am not sure about this. One could argue that you by signing up for the recurrent payment (or the free trial with automatic payed renewal), you merely consented for the company to automatically sell you another months subscription. If they are unable to do so, then they have every right to cancel your subscription, but it is not obvious that they have any right to require you to buy it. This becomes even more clear when you relize that, even if you used your real card, you would still be able to cancel before they charge you, and they would have no recourse.

Post reply on HN