Live data from Hacker News

“PayPal has demanded that we monitor data traffic as well as customers’ files”

seafile.de

331–340 of 348 posts

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#331
post #3

> PayPal has demanded that we monitor data traffic as well as all our customers’ files for illegal content. They have also asked us to provide them with detailed statistics about the files types of our customers sync and share on https://app.seafile.de That's a pretty big WTF right there. I know PayPal has a on overall pretty scummy reputation, but I still I cannot imagine PayPal doing this because they themselves th…

Paypal has been acting like this of their own accord for some time now. More than a decade ago a friend of mine sold cold filter bags for herbal extracts online using Paypal. The product was completely legal and didn't allude in any way that it was designed for illegal use (read marijuana hash making). Paypal decided, about 9 months in, to close their account in a similar fashion to the service here and deny them acc…

I've never absolutely needed Paypal. What situations have you run across where you have to use them? Just curious.

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#332
post #56
post #3

> PayPal has demanded that we monitor data traffic as well as all our customers’ files for illegal content. They have also asked us to provide them with detailed statistics about the files types of our customers sync and share on https://app.seafile.de That's a pretty big WTF right there. I know PayPal has a on overall pretty scummy reputation, but I still I cannot imagine PayPal doing this because they themselves th…

Welcome to the world of financial regulations! You may have not realised but banks and any financial institutions have been deputised by the regulators to be the financial police. They need to ensure that none of their client use financial services to commit crimes or launder the proceeds of a crime, under the penalty of heavy (up to multi billions) fines. Particularly in the US. I am pretty sure this is what is forc…

One of the highlights to the Banking Secrecy Act update in 2014 is listed in the first spot:

- Suspicious Activity Reporting

http://www.occ.treas.gov/news-issuances/bulletins/2014/bulle...

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#333
post #56

Earlier quoted context omitted.

Welcome to the world of financial regulations! You may have not realised but banks and any financial institutions have been deputised by the regulators to be the financial police. They need to ensure that none of their client use financial services to commit crimes or launder the proceeds of a crime, under the penalty of heavy (up to multi billions) fines. Particularly in the US. I am pretty sure this is what is forc…

Have they been deputized into service or pressed into mandatory service? My understanding is that the Know Your Client (KYC) laws are mandatory, with multi-billion dollar fines for companies who violate them. (HSBC has gotten into trouble with this recently)

Correct, it's mandatory service.

I think what the grandparent meant to say with being "deputized to be the financial police" is that the extent of this mandatory service has become so substantial that financial institutions often are left with the feeling that they are performing work (at their own expense) which feels like work that law enforcement should be doing.

It used to be that law enforcement pointed out the bad guys, or even just suspects, to you. Now, you're supposed to identify and report possible bad guys to law enforcement.

There's nothing wrong with that on principle, of course, but in practice, every bank must now train some personnel to detect not only suspicious individuals or transactions, but even suspicious patterns of transactions.

And that's when you start feeling like you've been deputized -- it feels like you are performing a criminil investigation on behalf of others.

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#334
post #328

Earlier quoted context omitted.

Yes, you were, of course, it's none of your damn business what your customers use your product for as long as they pay for it and it's not obviously illegal. If you are concerned about resource usage, limit the resources that you sell per account, and then enforce that limit if you like, but don't stick your nose into other people's lives. And I must say I find it particularly strange that you seem to find it somehow…

How can it be "not obviously illegal" if you're not checking. Side note, piracy is illegal in a lot of countries. If my account was accessed from 20 different countries in a day you can be damn well sure I'd want to be given a heads up too, as it's likely my account has been compromised.

> How can it be "not obviously illegal" if you're not checking. Side note, piracy is illegal in a lot of countries.

How could something be obvious if you have to check? Lots of stuff you can do in an appartment is illegal, too. That's still no reason for a landlord to install cameras to check. It's just none of their damn business.

It's obvious if a potential customer asks whether your service is good for warez hosting, or if a potential tenant ask whether your appartment is well-suited for getting rid of bodies. Anything where you have to violate their privacy in order to find out just is not obvious, and it's not your job to monitor people's private lives for possible illegal activity (and it is highly unethical to do so--it's what totalitarian regimes do, read up on the GDR's Stasi if you want to know what living in such a society is like).

> If my account was accessed from 20 different countries in a day you can be damn well sure I'd want to be given a heads up too, as it's likely my account has been compromised.

If you want to monitor your own account (or want to have someone, like the hoster, monitor it for you), feel free. It's still none of the hoster's business to investigate it any further without your explicit instruction to do so.

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#335

Earlier quoted context omitted.

The reason PayPal continues to be provided with the opportunity to fuck people over is primarily due to their low financial/technical barriers to entry. A website can be configured to accept PayPal payments in less than half a day, and setting up a new PayPal account is a very straightforward process. Compare this with setting up a merchant account to take payments (here in the UK), which takes weeks, involves findin…

> Fortunately companies like stripe.com The sad truth is that Stripe is behaving exactly like PayPal. What's worse is that Stripe's fraud protection is non-existing. In other words, Stripe is actually worse than PayPal, as you risk the same account freeze, closing etc, but in addition, you will be swamped down with fraudulent purchases and chargebacks.

(Disclaimer: I work at Stripe) Stripe does have a fraud protection product, which is enabled by default for every user. It centers around a machine learning system, that uses static signals (e.g. card issuing country) and time-dependent, dynamic signals (e.g. "how many different devices have tried to use this card in the last N hours?") to analyze every charge that hits our systems. Transactions that are deemed almost certainly fraudulent are automatically declined (but can be reviewed in the dashboard or via the API.)

We're constantly working on product & performance improvements, but feel free to get in touch with me directly (tara@stripe.com) to ask questions or share feedback on our models (and fraud product in general).

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#336

Had to use Paypal today to make a payment to a company who can't otherwise find a reasonable way to take credit cards online. I feel their pain, having been in that position. Paypal randomly saw that it was reasonable to demand I answer a phone in another country (though I haven't been based there for perhaps 15 years) if I wanted to log in to my account. I had to work around this by having them send a payment reques…

(I'm listening!) I work at Stripe on our fraud protection tools and would love to help. I want to dig into this particular situation -- mind sending me an email at tara@stripe.com?

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#337

Another victim of Paypal here. I run Jumpshare, a file sharing and collaboration service for creative professionals. This is what Paypal sent us: "May 8, 2016: When you signed up for your PayPal account, you agreed to our User Agreement and Acceptable Use Policy. Because some of your recent transactions violated this policy, we've had to permanently limit your account. Please remove any references to PayPal from your…

Having read during the last few years about the endless horror stories businesses have endured with PayPal, I honestly don't understand why anyone would still use PayPal when there clearly are alternatives (be that US companies like Stripe or EU companies like Paymill).

Because in some countries - like, for example, the Netherlands - creditcards are not a universally used thing. That leaves you with roughly two options for processing payments in a reasonably-easy-to-integrate manner: PayPal and Bitcoin.

And not enough people use Bitcoin to remove PayPal entirely.

EDIT: Yes, I know we have iDeal in the Netherlands. Every single company that processes it alongside other methods is either a nightmare to integrate, charges ridiculous fees, requires significant volume, doesn't do payouts over SEPA, or is similarly problematic as PayPal.

In my particular case, an added problem is that most of them refuse to process donations.

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#338
post #331

Earlier quoted context omitted.

Paypal has been acting like this of their own accord for some time now. More than a decade ago a friend of mine sold cold filter bags for herbal extracts online using Paypal. The product was completely legal and didn't allude in any way that it was designed for illegal use (read marijuana hash making). Paypal decided, about 9 months in, to close their account in a similar fashion to the service here and deny them acc…

I've never absolutely needed Paypal. What situations have you run across where you have to use them? Just curious.

PayPal-only eBay transactions.

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#339
post #180

Earlier quoted context omitted.

Last year I saw a customer (not at Seafile) who accessed our (paid) service from 20 different countries on the same day. Do you think that customer travelled to all those countries on that day? Do you think we were wrong to look for such globetrotting customers? Do you think we were wrong, or Seafile would be wrong, to look for customers who share their account with their hundred best friends?

Yes, you were, of course, it's none of your damn business what your customers use your product for as long as they pay for it and it's not obviously illegal. If you are concerned about resource usage, limit the resources that you sell per account, and then enforce that limit if you like, but don't stick your nose into other people's lives. And I must say I find it particularly strange that you seem to find it somehow…

A streaming service, actually, and one which doesn't sell to teams. The T&C prohibit giving anyone the password, with an exception for household members, so concurrent use from 20 countries stretches credulity.

Re: “PayPal has demanded that we monitor data traffic as well as customers’ files”

#340
post #321

Earlier quoted context omitted.

"Live and let live" can absolutely be made to sound absurd by taking it to the extreme. Does the amount of taking-far-enough needed to make something sound absurd vary? Sure. But the post I replied to was doing a whole lot of taking-far-enough.

> ...needed to make something sound absurd vary? Sure. That is your point, not mine. I'm saying that you're focusing on the wrong part of the equation. Imagine a machine with two variables that you have influence over, calibration error and runtime. You are suggesting short runtimes in order to minimize the impact of calibration error, I'm suggesting recalibration. I'd love to hear an extreme for "Live and let live",…

> That is your point, not mine. I'm saying that you're focusing on the wrong part of the equation. Imagine a machine with two variables that you have influence over, calibration error and runtime. You are suggesting short runtimes in order to minimize the impact of calibration error, I'm suggesting recalibration.

Please stop with the extended metaphors and just say what you're trying to say directly.

> I'd love to hear an extreme for "Live and let live", but I'm guessing that whatever scenario you can imagine is based on a faulty premise like "How can we wreak revenge without a death penalty?!".

Whatever. Are you interested in a constructive discussion or not? There are plenty of silly extremes for "live and let live" - harming the environment in ways that don't kill anyone? Harming themselves in all the various ways that can happen? Harming their children?

Post reply on HN