Live data from Hacker News

Chase did a bad thing, so we did a good thing

chaseoptout.com

71–80 of 246 posts

Re: Chase did a bad thing, so we did a good thing

#71
post #29

Assuming that you're completely legit and utterly competent, there's still a big security problem here: it's encouraging people to put their PII and CC info into arbitrary Web sites . On top of that, it's further identifying them as both Chase CC holders and receptive to scams, qualifying them as leads for further phishing/scamming.

IANAL, so can someone help me understand how bullet proof their privacy policy is (https://www.chaseoptout.com/PrivacyPolicy.pdf)?

It seems to me that it's pretty flimsy? In particular:

> To conduct research and to improve and promote our services . We use the information wecollect to conduct research and to improve or enhance and promote our Services.

Both promotion and research are pretty damn broad terms, right?

Re: Chase did a bad thing, so we did a good thing

#76
post #52

Earlier quoted context omitted.

Edit: dumb question from me. I didn't follow the flow because I don't have a chase account, so I wasn't aware it was a multi-part form. Original comment below: --- I'm likewise not an attorney, but how hard would it be to do a simple "Type your name here to represent your signature" type of deal? This is the most common lay practice I've seen, with the more common CYA practice for electronic records being e.g. what D…

If you fill in your info on the page and click the buttom, this happens as the final part of the flow before it submits.

"By checking this box, I certify that my account information is accurate and I want to e-sign and mail this document to chase to opt out of binding arbitration."

The document is not actually present.

Re: Chase did a bad thing, so we did a good thing

#78
post #29

Assuming that you're completely legit and utterly competent, there's still a big security problem here: it's encouraging people to put their PII and CC info into arbitrary Web sites . On top of that, it's further identifying them as both Chase CC holders and receptive to scams, qualifying them as leads for further phishing/scamming.

Yes but it’s your Chase account number. If it gets leaked through this service, Chase precipitated that leak through their unethical use of arbitration.

Idk but I only have Chase through Amazon. Chase might get effed, but my Amazon account will probably always be fine.

Re: Chase did a bad thing, so we did a good thing

#79
post #71
post #29

Assuming that you're completely legit and utterly competent, there's still a big security problem here: it's encouraging people to put their PII and CC info into arbitrary Web sites . On top of that, it's further identifying them as both Chase CC holders and receptive to scams, qualifying them as leads for further phishing/scamming.

IANAL, so can someone help me understand how bullet proof their privacy policy is ( https://www.chaseoptout.com/PrivacyPolicy.pdf )? It seems to me that it's pretty flimsy? In particular: > To conduct research and to improve and promote our services . We use the information wecollect to conduct research and to improve or enhance and promote our Services. Both promotion and research are pretty damn broad terms, right?

Oh dang. So this whole thing is just a big data grab. Even if they aren't going to make fraudulent charges, that's a clear ulterior motive.
Post reply on HN