Live data from Hacker News

Visa Advertising Solutions (VAS) Opt Out

marketingreportoptout.visa.com

191–200 of 253 posts

Re: Visa Advertising Solutions (VAS) Opt Out

#191
post #136

Earlier quoted context omitted.

I believe it is the standard free level, "Universal SSL" cert that Cloudflare will provide sites on free tier, if they opt for proxying through Cloudflare.

So all credit card numbers submitted by the form are viewable by Cloudflare? That does not inspire confidence

Does CloudFlare specifically matter? Most services you use are not SSL-terminated on own servers, so most of the time there’s a third party that can theoretically access your data.

Re: Visa Advertising Solutions (VAS) Opt Out

#192
post #147
post #142

Earlier quoted context omitted.

Often you get the data in aggregate, bought and sold as an “audience”. It’s a Boolean flag if a person in the audience. Basically an array of IDs for people in the audience (true). Almost always the data seller masks the ID of people in the audience to the buyer. This then creates opportunity for third party “matching services” or “identity resolution” who can de-anonymize, link, and re-anonymize. Link audiences toge…

This is correct. I worked at oracle, who is the go between for advertisers/agencies and vendors like visa who sell data but don’t do the “client facing” kind of stuff.

Aren’t Oracle (and Salesforce) currently dealing with a class action suit in Europe because of these services?

Re: Visa Advertising Solutions (VAS) Opt Out

#193
post #145

Earlier quoted context omitted.

I would easily pay 0.0005 per solve if it meant I don't have to deal with a captcha again when browsing.

There is buster: https://github.com/dessant/buster Wasn't something I mentioned earlier but using the reCAPTCHA audio is also another solution for gcap. I haven't ever used it personally but always seemed like a cool idea.

I'll try that, thanks! I can confirm audio CAPTCHAs are much easier, I always use those.

Re: Visa Advertising Solutions (VAS) Opt Out

#194

Earlier quoted context omitted.

It doesn’t exist. VAS is a US product offered by Visa US, supporting US cardholders only.

"supporting" as a european I'm totally ok without this support.

They still aggregate and sell insights from their collected data.

https://www.markiteconomics.com/Public/Home/PressRelease/d18...

Re: Visa Advertising Solutions (VAS) Opt Out

#195

The form doesn't require any sort of authentication, so I imagine someone could write a script to submit all (or a large portion of) the set of card numbers to this API. Might need to work around rate limiting and so on, but seems feasible?

Also, if there is any sort of timing difference on valid/invalid card numbers. Boom... timing attack / CC oracle :)

Which would give you worthless information

Re: Visa Advertising Solutions (VAS) Opt Out

#196
> your opt out will be honored for five years. After five years, you will need to resubmit your card number.

This requirement seems very easy to abuse. Annoying and inconveniencing users into submission already works wonders, people accept all kinds of EULAs, cookie conditions and privacy policies. I wouldn't want expiring user choices to become another tool in this arsenal.

Re: Visa Advertising Solutions (VAS) Opt Out

#197
post #63

Earlier quoted context omitted.

I try to opt-out whenever I can but I’m pretty sure there are several other blind-spots I haven’t blocked. Pi-hole does that for both the US and worldwide. I just need to figure out how to proxy my phone web requests home through VPN or WireGuard.

I've found it easier to use NextDNS rather than maintaining a Pi-hole and routing everything through my home connection.

I can vouch for this also, they are a partner of Firefox DOH feature so good enough for me

Re: Visa Advertising Solutions (VAS) Opt Out

#198

Earlier quoted context omitted.

Haven't people been sent to jail for doing this much or less? I recall something happening to a guy who probed AT&T's phone number registry or something?

How is this illegal? You make a form that says “XYZ” and buy a domain “abc.com” and if someone enters a random submission they go to jail for it? Maybe I’m misunderstanding.

Hmm, this one is surprisingly dangerous under Computer Fraud and Abuse Act. VISA is certainly a financial institution and as such this site is a protected site. And this likely falls under "knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer;"

Act of DOS could be considered damage, not to even metion opt-out from revenue source...

Re: Visa Advertising Solutions (VAS) Opt Out

#199

Earlier quoted context omitted.

Is it just me, or is the wording hugely misleading? > To opt-out from our anonymization of your personal information to perform data analyses, please provide your Mastercard or Maestro payment card number What we're opting out from is the use of the data, right? I guess the charitable interpretation is that this was written by somebody incompetent, not by someone trying to be deliberately obfuscatory...

Even Apple makes opting out of sharing data with advertisers (IDFA) confusing[0] > Allow apps to ask permission to track you across apps and websites owned by other companies. [0] https://blog.gingerlime.com/2020/does-ios-14-protect-your-pr...

If Apple made that say “allow apps to track you” and everyone set it to off and they didn’t mention that apps that don’t ask will still try to track you they’d be exposing themselves to a lawsuit when a company tracked Apple users without the IDFA.

I think it could be better stated, but changing to to “allow apps to track you” would not be a setting they could actually offer.

Post reply on HN