Live data from Hacker News

“PayPal has demanded that we monitor data traffic as well as customers’ files”

seafile.de

251–260 of 348 posts

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#251
post #242
post #65

Earlier quoted context omitted.

> Takes a few days though Typically 24h in the SEPA.

That's a bit optimistic. I've encountered 48hrs between my own accounts within Germany. I wish I still had the luxury of almost instant UK transfers.

In the Netherlands, within the same bank it can be within an hour or so, but to other banks up to two days. Internationally from/to NL can still take a week in my experience.

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#252
post #235
post #232

Earlier quoted context omitted.

Ah the incorrect assumption is that what the filesystem and dropbox scanners see must equal what the torrent client talks about, which isn't actually true. A preselected and stored in a dotfile or windows equivalent 9 digit number, or the bottom nine decimal digits of a MAC address, or some chunk of a UUID, or whatever. You could salt which bit is gonna get flipped by adding in the filename, or the partial timestamp…

All that sounds a lot of effort when the reality would be they'd just check the file in a different way than full-file md5 hashes as soon as this appeared.

Perfect being the enemy of good enough, etc.

Also its a bit unfair. Given this attack, design a perfect defense. OK here's an easy one. Oh OK well that works, but they'll just try a different attack. Well yeah, but that wasn't the initial challenge provided.

Also precomputed rainbow tables aren't so funny when you have gig wide columns instead of hash wide columns. For that alone its an entertaining idea.

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#253

Earlier quoted context omitted.

>Agreed; with both of you. Maybe it won't be crypto-currencies, but Paypal Has To Go®. Let them screw up two or three more times. They've already screwed up and screwed people over publicly dozens of times. Paypal does have to go, but I don't think paypal will die until someone offers an equivalent service.

> They've already screwed up and screwed people over publicly dozens of times. Dozens of times means absolutely nothing considering the billion that uses them. Do you many how many thousands of times banks and insurance companies actually screw people -- and yet nobody bats an eye? Besides the big assumption is that this is due to PayPals incompetence or malice, and not due to BS regulations (that anybody else will h…

Younger kids might not remember how incredibly painful it was to do credit card transactions in the 1990s. It wasn't just filling out a form or getting a bank to agree to it. Being told "monitor what your users upload in exchange for 3%" would have been something to kill for.

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#254

Earlier quoted context omitted.

I used to accept PayPal as a payment method when I was doing freelancing, ran hundreds of thousands of dollars through my account over the many years of having it. One client refuted a payment SIX MONTHS later, and they granted it to him based on the fact that it was a digital service and there's no way to verify it was successfully transferred. I immediately closed my bank account (PayPal wouldn't let me remove it w…

You could get together all your documentation with respect to that transaction and dispute that negative credit item directly with the three credit bureaus.

Exactly right, up to now the dispute existed in PayPal's walled garden and played out under their rules. PayPal's dispute resolution process has some serious flaws - with many high-profile examples - and often drags out to just slightly longer than the time limit for chargebacks (funny that, huh?).

I would raise the stakes a bit more and send PayPal a hard copy of supporting documentation and tell them that you will be disputing any negative report. Send this by a recorded delivery method like registered mail or courier. This means you can go to court and prove that PayPal had clear evidence of fraud and failed to take appropriate action. It also proves that they had knowledge of these facts prior to making the negative report to the credit agencies, which puts them in a bad spot if this all ends up in court. In the USA, the Fair Debt Reporting Act covers this scenario but similar laws exist in other countries.

Keep good documentation and send everything by a trackable method and never let these companies get away with ignoring you when you have a legitimate issue. Just make sure you are sure you have proof that you are correct, otherwise keep better documentation next time.

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#255

I wonder if legal action can be taken against PayPal for demanding this kind of information. PayPal blackmailed them into breaking a law (they didn't break it but they suffered financial loss from not doing it). If I told a customer who absolutely depends on my business to harass/attack somebody, I would certainly hold liable as well.

Or can PayPal take legal action against them for violating ToS? Did they properly disclose they were a file sharing site (as required by PayPal) before signing up to take payments? If they can't meet PayPal's ToS, they shouldn't have signed up. [Paypal sucks, but this doesn't seem like a cause for legal remedy]

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#256
post #213

Earlier quoted context omitted.

I worked for a financial services related startup for a while and was involved in implementing KYC/AML protections and AFAIK there isn't any relation between this and those laws. KYC is simply identifying your customers (nothing related to what they are doing) e.g. drivers license info, home address, etc. AML has to do with financial instruments passing through a business' account from customer (a) to customer (b) (i…

I don't know if you want to advertise lack of enforcement so loudly. Your practices would leave you to vulnerable to litigation if one of your customers were laundering money or committing crimes through your service. You've done enough to survive an audit if there have been no issues, but you'd be found negligent if there are.

To be fair, boldfield did say "worked for ... for a while" which implies they're no longer with the company (which might be a story in its own right). Still, it's good advice for others chiming in who may presently be in the same position.

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#258

Earlier quoted context omitted.

> Welcome to the world of financial regulations! > You may have not realised but banks and any financial institutions have been deputised by the regulators to be the financial police. They need to endure that none of their client use financial services to commit crimes or launder the proceeds of a crime, under the penalty of heavy (up to multi billions) fines. Particularly in the US. While I fully agree with this sta…

Paypal seems to have a long and ugly history of aggressive-yet-incoherent legal interpretations. They lock down donations to any unpopular group, and refuse to release already-held funds. They freeze Kickstarter campaigns as soon as someone says the word "fraud", and cause the exact damage they're trying to prevent by tying up all the funds so neither backers nor creators can get the money. They're incredibly caprici…

Paypal has lost tons of money to fraud, and with the margins they have it's not surprising they err on the side of caution.

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#259

I don't think they need regulation. I think they need to carry on like they are for a few more years so I can watch them be eaten alive by crypto currencies and other fintech innovations.

We detached this subthread from https://news.ycombinator.com/item?id=11944105 and marked it off-topic.

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#260

I don't think they need regulation. I think they need to carry on like they are for a few more years so I can watch them be eaten alive by crypto currencies and other fintech innovations.

> so I can watch them be eaten alive by crypto currencies and other fintech innovations

If crypto currencies become an even remotely threatening actor in finance, I'm sure you'll witness how quickly governments (being in the pocket of Big Finance) will crack down on them (i.e. you won't have any legal CC to nonCC trading).

Right now, of course, CCs are more of a practical joke.

Post reply on HN