Live data from Hacker News

Chase did a bad thing, so we did a good thing

chaseoptout.com

101–110 of 246 posts

Re: Chase did a bad thing, so we did a good thing

#101
post #29

Assuming that you're completely legit and utterly competent, there's still a big security problem here: it's encouraging people to put their PII and CC info into arbitrary Web sites . On top of that, it's further identifying them as both Chase CC holders and receptive to scams, qualifying them as leads for further phishing/scamming.

Unfortunately this is the problem that Chase created ... we give users a way to download a form letter instead, but were just trying to make it as easy as possible for customers to opt out if they would like to do so

>we give users a way to download a form letter instead

But you don't just let them download it. You make them give you their email address first.

Edit: Haha! No wait, you have to click through two levels of "Don't want to give us your info? Click here to get the letter". The first one asks for you email, only after the second do you actually get the letter. Why? They already said "dont want to...". Just give it to them!

Edit2: Also the form letter, prepopulated with the Chase customer service P.O. box address, is another scam pitfall. Anyone using this kind of form letter should always check the address with the financial institution before sending any forms, especially that include PII/financial information.

Re: Chase did a bad thing, so we did a good thing

#102
Any advantages or downsides to opting out of Chase’s arbitration if Chase sues you for credit non-payment? I read the sites FAQs (only mentioned class action and if one or more people sue Chase) and appears that situation is likely not relevant for this opt-out?

Re: Chase did a bad thing, so we did a good thing

#103
post #79

Earlier quoted context omitted.

Oh dang. So this whole thing is just a big data grab. Even if they aren't going to make fraudulent charges, that's a clear ulterior motive.

not at all! We explicity ask if you want to opt in to future communications on our form - we are NOT using them to communicate with users if they do not opt in.

[deleted]

Re: Chase did a bad thing, so we did a good thing

#104
For me the red flag is them willing to send this letter to Chase, via snail mail at no charge to you. Nobody gives something for nothing. So I thought, why would they do this? after reading through the form, at the bottom, it looks like one of the companies, who sponsors this site, "Radvocate" seems like they are in the "class action" lawsuit business. https://myradvocate.com/

This site is about having enough potential clients are able to sue Chase at some point in the future, whenever a class action lawsuit comes up - and heck, they even will have a customer list and a relationship with you from sending this "free" letter for you in the past.

Usually in those kinds of cases, the end recipient gets very little - perhaps some subscription to a ID protection service or a few bucks but the firm who runs the class action makes a lot.

On the one hand, maybe it helps keep them honest (they cite Wells Fargo) so its good to be able to. But clearly there is some vested interest here on the part of Radvocate.

Re: Chase did a bad thing, so we did a good thing

#105
post #6

Earlier quoted context omitted.

Hey there, Maker of the site here! Our servers don't touch any of this data, it goes straight to Very Good Security and lives in a PCI compliant vault ... We ourselves are building a new kind of bank so we take security very seriously and are not phishing. Happy to talk through in more details but the FAQs do a pretty good job of that too!

FYI - there is some duplicated content under the "How does this site work?" heading.

Thanks for catching that! fix should be pushed now!

Re: Chase did a bad thing, so we did a good thing

#106

Earlier quoted context omitted.

We also give you the ability to just download the form and mail it yourself! Unfortunately Chase forces customers to mail a letter with this information on it so there's not much we can do

> there's not much we can do Open-source a script I can run locally to generate PDFs with the information your form uses.

Geez, or just send a letter.

Re: Chase did a bad thing, so we did a good thing

#107
post #29

Assuming that you're completely legit and utterly competent, there's still a big security problem here: it's encouraging people to put their PII and CC info into arbitrary Web sites . On top of that, it's further identifying them as both Chase CC holders and receptive to scams, qualifying them as leads for further phishing/scamming.

"And who even has stamps lying around anymore?"

People who order stamps online?

If the problem is writing the letter or stamps, then why not just send the user a postage-paid envelope, pre-addressed to Chase, with a generic letter that she can fill in with her personal information and deposit into the mail?

You should now be wondering how this "service" can be "free". As someone else has figured out, this is a company that wants lists of Chase customers to which they can market their consumer arbitration-related services.

This is interesting since the whole point of opting out here is that consumers want to avoid arbitration and reserve their rights to sue.

Other websites are offering a more sensible solution for those who cannot be bothered to write a letter: templates for a simple letter a customer can just print out, fill in her information, sign and mail.

Re: Chase did a bad thing, so we did a good thing

#108

Earlier quoted context omitted.

totally fine if you don't! we also allow you to just download the form so you can fill it out and mail it yourself

You shouldn't even be collecting this info.

Perhaps they should discuss that in an FAQ, but let's face it, they are literally saying "We know you're out of the loop probably, and we know you are too lazy to write the letter yourself, so we'll do it for you".

Other than "user training", if it's legitimate, it is not unethical.

Re: Chase did a bad thing, so we did a good thing

#109

For me the red flag is them willing to send this letter to Chase, via snail mail at no charge to you. Nobody gives something for nothing. So I thought, why would they do this? after reading through the form, at the bottom, it looks like one of the companies, who sponsors this site, "Radvocate" seems like they are in the "class action" lawsuit business. https://myradvocate.com/ This site is about having enough potenti…

> Usually in those kinds of cases, the end recipient gets very little - perhaps some subscription to a ID protection service or a few bucks but the firm who runs the class action makes a lot.

This suggests to me you feel that class action judgments do not adequately compensate claimants. This shouldn't dissuade us from fighting back against businesses who treat their customers unfairly.

The problem isn't the class action lawsuit or Radvocate. It goes much deeper. It's goes to the core of businesses (e.g, banks) who provide critical access to the financial system forcing you, the consumer, to resolve disputes through their shadow justice system in which they pay the arbiters, which have a history of siding more frequently with the corporation.

Re: Chase did a bad thing, so we did a good thing

#110

Cool service. A concern is that scammers can use variations of the domain (chaseoptout.co optoutchase.com etc) and use adwords to get on top of search results to trick people and steal personal identifying information if this thing gets popular enough.

Well, its the same concern with any eCommerce website that takes your CC, or really, just about any website that has a form input field. Few people in my office click on pretty much any link random people email them. I've even told friends/co-workers to reset their PW because they've been breached based on HIBP, but people never seem to care unless they personally get affected. I've given up..
Post reply on HN