>U.S cardholders may opt out of Visa So is the rest of the world not covered by this data collection effort or are they just denied the opportunity to opt out at all?
In EU you would have to opt in since there are actual data protections for consumers (that's if it is abusing user specific data which I have to assume it is)
Visa Advertising Solutions (VAS) Opt Out
241–250 of 253 posts
Re: Visa Advertising Solutions (VAS) Opt Out
#242Earlier quoted context omitted.
The cert appears to be DV, and is issued to and by Cloudflare. Issuer: C=US, O=Cloudflare, Inc., CN=Cloudflare Inc ECC CA-3 Subject: C=US, ST=CA, L=San Francisco, O=Cloudflare, Inc., CN=marketingreportoptout.visa.com The cert for visa.com is similar.
This certificate is actually OV. It has a Certificate Policy OID inside it, which is 2.23.140.1.2.2 for OV This is set side in section 7.1.6.1 "Reserved Certificate Policy Identifiers" of the Baseline Requirements, although you could just Google it because OIDs are unique. Cloudflare, as issuer, have confirmed that Cloudflare, the certificate subscriber, are really Cloudflare, because they're the same entity. That's…
Ah yes, thanks for pointing that out.
I'm not sure there's a practical distinction between EV and non-EV certs any more anyway. Browsers no longer show any indication of difference, and customers are not likely to inspect certs.
From a risk perspective, it looks like Visa is all-in on Cloudflare for consumer-facing infrastructure:
* Cloudflare terminates visa.com TLS, so it would be easy to swap an origin server without attracting notice, even if the cert was pinned or otherwise monitored
* Cloudflare also operates registered nameservers for visa.com, so they could issue DV certs at will
It looks strange, but it makes some sense. Visa deals with imperfectly-compliant handlers of cardholder data as their business, and they obviously have all sorts of risk modeling built into those relationships.
I'm sure they require Cloudflare to certify to a high level of PCI-DSS, and have carefully-apportioned liability in all of the paperwork.
Re: Visa Advertising Solutions (VAS) Opt Out
#243Here's an equivalent form for MasterCard: https://www.mastercard.us/en-us/vision/corp-responsibility/c...
Re: Visa Advertising Solutions (VAS) Opt Out
#244Earlier quoted context omitted.
I use physical cash at every opportunity already. How do you buy airline tickets that way? How do you purchase things online for delivery during a pandemic?
you can go to an airport, which has never closed, and buy a ticket in cash you can purchase things in cash at Walmart, Target, etc. which has never closed during the pandemic
This has not been true for some time. Ticket counters require payment cards.
I asked about purchasing things online because it's not safe to shop in person at the moment.
Re: Visa Advertising Solutions (VAS) Opt Out
#245Earlier quoted context omitted.
> What processing companies are available to use that don't sell your transaction data by default? Thankfully merchants are generally opaque in terms of the metadata provided to the payment processors. I for one am thankful my card statements have "Amazon purchase" instead of the specific item purchased, for instance.
There may be more data associated with your transaction than just what you see on the statement.
Re: Visa Advertising Solutions (VAS) Opt Out
#246Earlier quoted context omitted.
> What processing companies are available to use that don't sell your transaction data by default? Thankfully merchants are generally opaque in terms of the metadata provided to the payment processors. I for one am thankful my card statements have "Amazon purchase" instead of the specific item purchased, for instance.
I anticipate more and more merchants to use Level 3 data (or be forced to use it): https://tidalcommerce.com/learn/what-is-level-3-data/ I know staples.com, many hotel chains, and airlines already use this.
I could see companies whose lines of business tend to have higher fraud rates take advantage of providing more data in exchange for cheaper fees.
Re: Visa Advertising Solutions (VAS) Opt Out
#247Earlier quoted context omitted.
This certificate is actually OV. It has a Certificate Policy OID inside it, which is 2.23.140.1.2.2 for OV This is set side in section 7.1.6.1 "Reserved Certificate Policy Identifiers" of the Baseline Requirements, although you could just Google it because OIDs are unique. Cloudflare, as issuer, have confirmed that Cloudflare, the certificate subscriber, are really Cloudflare, because they're the same entity. That's…
> It has a Certificate Policy OID inside it, which is 2.23.140.1.2.2 for OV Ah yes, thanks for pointing that out. I'm not sure there's a practical distinction between EV and non-EV certs any more anyway. Browsers no longer show any indication of difference, and customers are not likely to inspect certs. From a risk perspective, it looks like Visa is all-in on Cloudflare for consumer-facing infrastructure: * Cloudflar…
I believe EV user interface treatment is still a thing in Internet Explorer, and for all I know the Chromium Edge has it too, I never run those browsers. Some minority browsers also distinguish, mostly using the CA/B reserved OID whereas historically Firefox and Chrome had a list of issuer specific policy OIDs flagged.
From the issuer's point of view, the generic EV OID is reserved by that same document for certificates which obeyed the BR rules for how to identify the name, business number (if appropriate) and location of the business, but that is not so different from OV. Private OIDs might correspond to some other (potentially stricter) policy.
There is another CA/B document about EV, but in practice reform has mostly taken place in the BRs and so rules there, or enacted by the trust stores (e.g Apple's 398 day rule) make most of the provisions of the CA/B EV rules obsolete.
The original goal of EV was to find a mutually satisfactory way to improve on the status quo at that time which was a price free fall for long-lived domain validated certificates using whatever method satisfied the issuer's needs to confirm control over the names issued. The browsers got issuers to do a better job (their main ask) and the issuers got a cool UI (the "green bar") to help sell expensive certificates.
The most important legacy of that was the standing meeting, the CA/Browser Forum, which means there is an ongoing dialog between the CAs and the browser vendors rather than them only talking when there's a grave and urgent problem. It took some work to design a structure that's legal, that gets the job done but isn't a cartel, because cartels are illegal (OPEC is/ was a cartel but its members are sovereign entities, and so they are immune to prosecution for running a cartel)
There's considerable value in being able to get the other participants in an ecosystem to agree (even if begrudgingly) that a policy change is necessary rather than forcing it upon them. Getting to 825 day certificate lifetimes was done by agreement, and not even so very long ago, while 398 day lifetimes was done by Apple's fiat after they struck out in negotiations.
Visa doesn't have to worry about PCI-DSS, unlike a retailer who is going to "stop" Visa from doing stuff that is prohibited by PCI-DSS? Nobody. Like the banks, the networks gave themselves the independent right to decide to just break the rules if they want to. For example if your e-commerce website uses SHA-1 that's a huge No-no right? But if Visa has a system that uses SHA-1 and replacing it to do SHA-256 would cost say $1M, they can decide actually it's fine as it is, they keep the $1M and that's OK under rules they helped write.
Re: Visa Advertising Solutions (VAS) Opt Out
#248Earlier quoted context omitted.
I get "System Error" when I submit my card number
Same here. I have a suspicion like they designed it for 5 queries/day and we just blew it.
Re: Visa Advertising Solutions (VAS) Opt Out
#249Earlier quoted context omitted.
you can go to an airport, which has never closed, and buy a ticket in cash you can purchase things in cash at Walmart, Target, etc. which has never closed during the pandemic
> you can go to an airport, which has never closed, and buy a ticket in cash This has not been true for some time. Ticket counters require payment cards. I asked about purchasing things online because it's not safe to shop in person at the moment.
Even Amtrak is now not accepting cash anymore:
https://www.amtrak.com/purchase-train-tickets
Looks like the only option left is drive a car and fill up at gas stations which accept cash (for the time being). I'm not super familiar with EV charging stations but I don't think I've seen one that accepts cash, if that's any hint as to where we are headed.
Dark times
Re: Visa Advertising Solutions (VAS) Opt Out
#250Earlier quoted context omitted.
They'll just throw out all the ones spammed from your IP. If you become obnoxious they will call the FBI because this would be a CFAA violation.
Not a lawyer - would it really be a violation of the CFAA? I'd also be surprised if Visa involved the FBI for someone excessively hitting their API...
Doing otherwise -> access in excess of authority -> CFAA violation
Just because you can easily walk through an unlocked door doesn’t mean doing so is always legal.