Live data from Hacker News

“PayPal has demanded that we monitor data traffic as well as customers’ files”

seafile.de

211–220 of 348 posts

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#211

I'm once again astonished with how much control of our businesses is simply out of our hands. When looking at practices these financial institutions use it makes me wonder what can't they do? Everyone cites "regulations", but as far as I understand, they make the regulations. Directly or indirectly. Take for example the known cases where PayPal freezes accounts holding people's money. If I take someone else's money a…

Accept payment in cash only. Oh, now you want to say that these vendors were providing you an important service after all? Hmm, how interesting.

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#212
post #141

Earlier quoted context omitted.

As a german that's not my experience at all. Credit cards aren't that common here and SEPA transfers are slow as hell and always a minor hassle, that I tend to avoid as long as I can. Without Paypal a lot of european customers wouldn't be able to buy from international vendors.

What about debit cards? I mean, you don't carry cash around all the time do you?

I do now that I live near Nuremberg, which is one of the safest cities in the world, but it was a hard thing to get used to, as I went to college in a US city rather infamous for its crime.

Surprisingly large restaurants in Nuremberg do not take credit cards. A lot of German and Austrian small business owners see no good reason to pay the credit card companies the ~3% fee when most of their customers are perfectly happy to settle a 500 EUR bill in cash. Always pay your hotel bill in rural Austria the night before you leave to prevent an emergency dash to the village ATM :)

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#213
post #56

Earlier quoted context omitted.

Welcome to the world of financial regulations! You may have not realised but banks and any financial institutions have been deputised by the regulators to be the financial police. They need to ensure that none of their client use financial services to commit crimes or launder the proceeds of a crime, under the penalty of heavy (up to multi billions) fines. Particularly in the US. I am pretty sure this is what is forc…

I worked for a financial services related startup for a while and was involved in implementing KYC/AML protections and AFAIK there isn't any relation between this and those laws. KYC is simply identifying your customers (nothing related to what they are doing) e.g. drivers license info, home address, etc. AML has to do with financial instruments passing through a business' account from customer (a) to customer (b) (i…

I don't know if you want to advertise lack of enforcement so loudly. Your practices would leave you to vulnerable to litigation if one of your customers were laundering money or committing crimes through your service. You've done enough to survive an audit if there have been no issues, but you'd be found negligent if there are.

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#214

Earlier quoted context omitted.

The reason PayPal continues to be provided with the opportunity to fuck people over is primarily due to their low financial/technical barriers to entry. A website can be configured to accept PayPal payments in less than half a day, and setting up a new PayPal account is a very straightforward process. Compare this with setting up a merchant account to take payments (here in the UK), which takes weeks, involves findin…

> Fortunately companies like stripe.com The sad truth is that Stripe is behaving exactly like PayPal. What's worse is that Stripe's fraud protection is non-existing. In other words, Stripe is actually worse than PayPal, as you risk the same account freeze, closing etc, but in addition, you will be swamped down with fraudulent purchases and chargebacks.

Ouch - that's a shame as I was hoping our next startup would use Stripe. I'd better do some more due diligence on them before we commit.

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#215

Earlier quoted context omitted.

>Agreed; with both of you. Maybe it won't be crypto-currencies, but Paypal Has To Go®. Let them screw up two or three more times. They've already screwed up and screwed people over publicly dozens of times. Paypal does have to go, but I don't think paypal will die until someone offers an equivalent service.

> They've already screwed up and screwed people over publicly dozens of times. Dozens of times means absolutely nothing considering the billion that uses them. Do you many how many thousands of times banks and insurance companies actually screw people -- and yet nobody bats an eye? Besides the big assumption is that this is due to PayPals incompetence or malice, and not due to BS regulations (that anybody else will h…

They probably mean either big screw ups, or hundreds of thousands of little ones. Eg, trying to circumvent banking laws, allowing donations to the KKK while refusing to cater to wikileaks, seizing funds from well known legitimate businesses, UX anti patterns (eg fake endorsements from the site), Braintree not understanding why you'd want to use CSP to stop someone stealing credit card details, etc.

I don't want to victim blame, but if you work in tech, and still involve PayPal in your business in any way you shouldn't be surprised about the outcome. Use Stripe, use GoCardless. Paypal Has To Go®.

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#216
post #56

Earlier quoted context omitted.

Welcome to the world of financial regulations! You may have not realised but banks and any financial institutions have been deputised by the regulators to be the financial police. They need to ensure that none of their client use financial services to commit crimes or launder the proceeds of a crime, under the penalty of heavy (up to multi billions) fines. Particularly in the US. I am pretty sure this is what is forc…

I worked for a financial services related startup for a while and was involved in implementing KYC/AML protections and AFAIK there isn't any relation between this and those laws. KYC is simply identifying your customers (nothing related to what they are doing) e.g. drivers license info, home address, etc. AML has to do with financial instruments passing through a business' account from customer (a) to customer (b) (i…

It's not about onboarding/general KYC since this isn't about end users.

Paypal does it's own risk assessment for business partners, what I'm pretty sure this is is a simple "classification" case.

Paypal classifies the type of business you are and if you belong to certain types of businesses they put some requirements on you based on regulations and their own internal requirements usually produced by their legal department.

Paypal has probably seen what happened to file sharing websites like Mega and if you are tagged as a file sharing service they want to ensure that you do everything to prevent it being used for piracy, including being able to audit it themselves and to be able to either put pressure on you or cut off their services if they think they are at too much of a risk.

Now I understand that Seafile isn't anything like Mega but It's also not exactly on the scale of dropbox this also means that most likely no one at Paypal really knows what it is, or where they are heading business wise and so they just stick some additional requirements on them.

Also (this is true for 2-3 years ago, I don't know if it is still the case) filesharing websties and other sites that you can buy "premium currency" such as various online games, vidoe chat apps (usually porgnography) etc. are the main source of fraud for compromised accounts as far as Paypal goes this on it's own can bring on additional requirements from Paypal.

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#217

Earlier quoted context omitted.

For me part of the reason is that Paypal is available in more countries than Stripe. For example, here I can withdraw money from PayPal to my local bank account. I dont think its possible with Stripe.

Last time I used Stripe it was directly connected to a bank account. They would sit on funds for a couple of days I guess this was to allow the transaction to clear whatever batch cycles happen behind the scenes (debits cards were typically faster than credit charges) but the deposits came directly into the account. Has that changed?

I think it varies by country. Also Stripe isn't available in nearly as many markets as PayPal, two big ones that immediately pop out are Estonia and Hong Kong.

Another thing to bear in mind is lots of people outside the "main Western" countries (for lack of a better term) still don't have credit or debit cards that can be used to pay online. PayPal accepts a lot of local payment methods and even lets you transfer funds from your bank account.

I live in Lithuania (part of the EU since 2004, and Euro since 2015) and only this year have major retailers started to accept cards online. Before that you would receive an invoice and have to make a bank transfer (each bank had their own online payment system merchants could integrate to make it more streamlined) before goods were dispatched. Even now most cards need to be opted in for online payments.

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#218

Earlier quoted context omitted.

Sure, using PayPal as a buyer is great as long as you never get into a dispute with a seller. It took about 4 months for me to get PayPal to refund my money when a seller on eBay ripped me off. PayPal support was so inept they claimed that I had not returned the merchandise despite giving them the DHL tracking number and shipping receipt multiple times and eventually they closed my case in favor of the merchant. I ha…

I used to accept PayPal as a payment method when I was doing freelancing, ran hundreds of thousands of dollars through my account over the many years of having it. One client refuted a payment SIX MONTHS later, and they granted it to him based on the fact that it was a digital service and there's no way to verify it was successfully transferred. I immediately closed my bank account (PayPal wouldn't let me remove it w…

You could get together all your documentation with respect to that transaction and dispute that negative credit item directly with the three credit bureaus.

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#219
post #171

Earlier quoted context omitted.

This is not possible. The torrent protocol works by checking the hash of each file that it downloads so it can reseed the file. If these files were changed by even 1 bit then they couldn't be reseeded back into the torrent network.

unless the "corruption" is reversible by the torrent client, which it would be

If the corruption is reversible then the people doing the checking can also reverse it. They'll have both the corrupt version and the reverse-fixed version and just have to check an extra hash per thing they're scanning for

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#220
post #161

Earlier quoted context omitted.

And then DropBox runs that on every file, so you you have the normal md5 and the torrent-obfuscation-reversed md5. They check both. We have now achieved nothing.

Hashes, even md5, are pretty good about going nuts when even one bit is changed in the input. And video codecs (speaking very broadly) are tolerant of a bit error rate like 1e-9 or they'd be useless over the air or on optical media. So simply have your torrent client randomly flip 1 in a billion bits as it downloads. The md5 will never match and the movie quality will be unimpaired.

so if a billion people were to download it, lucky number one-billion would receive a completely garbage file.

Ok, ok. That's not statistically likely to happen. But you do have the problem then of other files being shared via bittorrent, it's not all movie files. You'd also have to re-start basically the entire BT network too, as all clients would no longer be backwards compatible - Good luck too getting every single torrent client dev to implement this at the same time!

Post reply on HN