Live data from Hacker News

Chase did a bad thing, so we did a good thing

chaseoptout.com

41–50 of 246 posts

Re: Chase did a bad thing, so we did a good thing

#41

This seems sketchy as fuck - your website, I mean Might as well leave a box for the SSN while you're at it

Again, I wish we did not have to do this but this is what Chase is forcing customers to do. We also give customers a way to just download the form without giving us the info but then of course we can't mail it for them ... we were just trying to make this easier for customers to opt out with the shitty options we were given

Can you make the link for the download more obvious and less dark-pattern-y? I found it only after scouring the page (somehow the text under the form didn't catch my eye easily), and then it popped up a modal that unnecessarily asks for my email address. I closed it, annoyed, just barely noticing the small-font link to download without entering my email address.

If you actually care about privacy and claim to not be using or selling our information for anything, why don't you make it easier to avoid giving information entirely?

Having said that, thank you for creating this. I had left Chase's email about the terms change in my inbox, starred, so I'd remember to take care of this, but not having to formulate my own letter makes things so much easier.

Re: Chase did a bad thing, so we did a good thing

#42
post #27

Under the "What is the actual language in the agreement sent by Chase?" FAQ item, it says -- "Can I (the customer) reject this agreement to arbitrate? Yes. You have the right to reject this agreement to arbitrate if you notify us no later than 8/9/2019. You must do so in writing by stating that you reject this agreement to arbitrate and include your name, account number, address and personal signature . Your notice m…

[deleted]

Re: Chase did a bad thing, so we did a good thing

#44
post #4

Wait, you want me to put my credit card number and my personal info?

We also give you the ability to just download the form and mail it yourself! Unfortunately Chase forces customers to mail a letter with this information on it so there's not much we can do

> there's not much we can do

Open-source a script I can run locally to generate PDFs with the information your form uses.

Re: Chase did a bad thing, so we did a good thing

#45

Link to the "full privacy policy" 404s, which is not a good thing, given you are asking people to enter their full names, addresses, CC numbers.

Hi, site creator here - link is here and is not 404'ing for me

https://www.chaseoptout.com/PrivacyPolicy.pdf - let me know if you mean something else?

Re: Chase did a bad thing, so we did a good thing

#46
What did your legal counsel say about liability here? For example, what happens if a cardholder who used your opt-out service has a dispute with Chase, and Chase claims they did not receive the opt-out?

What has counsel advised about any risk of federal authorities investigating you as possible CC phishing operation (perhaps initiated by monitoring for bank-phishing-like domain name)? (Obviously you have some defense, but the best case might cost you money and misery.)

Also, do you expect to keep the domain name past an ICANN dispute?

Re: Chase did a bad thing, so we did a good thing

#47
It mentioned that the opt-out requires a specimen signature (from the FAQ as well What do I need to do to opt-out?). How would you be able to ensure that the opt-out process for the customer will be valid / accepted by Chase if there's no actual human signature?

From Chase's perspective, wouldn't they be asking for more details especially if their business hinges on retaining people into their business as much as they can?

Update: Additional wording

Re: Chase did a bad thing, so we did a good thing

#49
post #6

How secure is this website? What prevents a phishing site from pretending to be an opt-out site?

Hey there, Maker of the site here! Our servers don't touch any of this data, it goes straight to Very Good Security and lives in a PCI compliant vault ... We ourselves are building a new kind of bank so we take security very seriously and are not phishing. Happy to talk through in more details but the FAQs do a pretty good job of that too!

With a better understanding of how VGS works I really just fall back to my weakest link in the chain questions:

Does Lob hold any PCI level certifications? It appears they hold HIPAA but I see no mention of PCI?

Does Lob provide any interface that shows sent mail and the content (it appears they do)? If so and they don't hold any PCI certifications what benefit do we really have with ever getting a VGS token?

What stops you from scraping this data from Lob's API?

---

Original comment below.

I'm confused on how this data lands at Lob with an account number if you never get it.

Correct me if I'm wrong but the letter you send includes the account number and not the VGS token?

All of my following questions assumes an affirmative answer.

How is the account number landed in Lob? It appears something must be calling the Lob API with an unencrypted account number? What is making that call?

Does Lob hold any PCI level certifications? It appears they hold HIPAA but I see no mention of PCI?

Does Lob provide any interface that shows sent mail and the content? If so and they don't hold any PCI certifications what benefit do we really have with ever getting a VGS token?

Re: Chase did a bad thing, so we did a good thing

#50
post #29

Assuming that you're completely legit and utterly competent, there's still a big security problem here: it's encouraging people to put their PII and CC info into arbitrary Web sites . On top of that, it's further identifying them as both Chase CC holders and receptive to scams, qualifying them as leads for further phishing/scamming.

Note that there is a PDF for those who don't want to enter their information: https://www.chaseoptout.com/ChaseOptOut.pdf

I don't see how that's relevant to what I said. The problem I was citing was the encouragement to put this info into a Web form on an arbitrary site. You should always be discouraging that.
Post reply on HN