Live data from Hacker News

“Privacy”.com–Yeah Right

ersei.net

41–50 of 172 posts

Re: “Privacy”.com–Yeah Right

#41
post #33

I have the Apple credit card. If you just want to generate 1-time credit card numbers to use once it's the best experience imo - can easily do it in the Wallet app. Also lots of these subscription websites now detect card generated from something like a Privacy.com is prepaid and will prevent you from using it which defeats the purpose. Not the case with Apple.

Privacy.com also allows setting monthly/yearly spending limits, or even setting the card as single-use. Does Apple have anything like that?

No it’s just the ability to generate new credit card numbers on demand

If you want various virtual cards with varying limits I also noticed my Citi card allows me to do this. It’s just a little clunkier but it’s actually more robust than Apple’s feature if you wanted a unique number per website.

Re: “Privacy”.com–Yeah Right

#42
post #39

Earlier quoted context omitted.

I agree that most of the comments here amount to handwringing (or not understanding what amount of "privacy" is legal), but also, what KYC is really necessary for a company like this? If I understand correctly, all they do is pass through transactions. They don't hold customer deposits or provide credit. Isn't all this third party verification a little much?

> what KYC is really necessary for a company like this? If I understand correctly, all they do is pass through transactions. Products like this are particularly susceptible to fraud, especially given that they're charging your bank account directly. Without any KYC, if I as a fraudster get access to your bank login, I can basically drain your account. That opens up a ton of liability to Privacy. Also, the card networ…

Ok yes, I can see that they would want to have some insulation from having banks charge them back on whole user accounts. That makes sense.

Re: “Privacy”.com–Yeah Right

#43

Earlier quoted context omitted.

Privacy.com also allows setting monthly/yearly spending limits, or even setting the card as single-use. Does Apple have anything like that?

> Does Apple have anything like that? Not that I can find, which is why I use Privacy.

Citi does this.

Re: “Privacy”.com–Yeah Right

#44
post #32

Earlier quoted context omitted.

The point of KYC is to make money laundering harder (and other transactions that the various governments want to track/police). To that extent, yes, they need to be able to show a regulator who was making those transactions. The actual funding source/bank behind them won't see any detail beyond "privacy.com". Any card issuer (or virtual card issuer) has to do this.

My point is that privacy doesn't need to do KYC because there is no possibility of the customer evading regulators. Assuming that privacy answers subpoenas, they would be able to give the government detailed transaction info and a bank account which would identify the customer. KYC at this level of abstraction doesn't seem to solve any kind of legal problem. I'm glad to be educated by an expert, though. Edit: A sibli…

How do you validate that they own the bank accounts if you don't know who the user is?

Re: “Privacy”.com–Yeah Right

#45

I worked in domain registrations in the early 2000s and it's funny how we used to put stock into what sort of TLD a domain used. Like .com would clearly be a commercial entity, while .org would be more non-profits, open source, public domain and stuff like that. Anyways, they're probably harvesting your payments and selling that info. I've noticed that since the card issuers have such high security requirements, and…

That might be true if they weren't also the card issuer[0]. The main way they make money is on interchange, which for a card issuer is a kickback of up to 2% from Visa/Mastercard/etc [1].

[0] - https://techcrunch.com/2021/05/20/privacy-com-rebrands-to-li...

[1] - https://www.adyen.com/blog/interchange-fees-explained

Re: “Privacy”.com–Yeah Right

#46
post #3

Privacy.com is not about hiding your identity from authorities. It's mostly about hiding the fact that the same person, you, are paying to merchant A and merchant B. It allows you to easily have a card per merchant, and lock it to the merchant so that when its number is stolen, it can't be used anywhere else. The domain name is a bit lofty, yes.

>It's mostly about hiding the fact that the same person, you, are paying to merchant A and merchant B.

What merchants out there are cross-correlating credit card numbers to deanonymize people? Can you even do it in a way that's PCI compliant? If you're actually interested in preventing random merchants from tracking you, I think credit card numbers are the least of your worries. Your billing/shipping information, which is almost always collected is much more revealing about you and can't be anonymized. Given this I do think the name of "privacy".com is misleading. At best it's stopunauthorizedcharges.com.

Re: “Privacy”.com–Yeah Right

#47
post #6

Earlier quoted context omitted.

“Phishing” implies fraudulent deception.

I think their growth numbers would have looked much differently if they had transparently disclosed the reality on their login form from day one: “Plaid will store your plaintext password and use it to periodically access your bank account.” Burying truth deep in a TOS is seen by some as deceptive.

> “Plaid will store your plaintext password and use it to periodically access your bank account.”

That's terrifying.

I'm looking into privacy.com as an alternative to using my real debit card number online because it gets stolen at least once a year. Having my bank account itself compromised does not sound like an improvement. Then again, how often do banks get hacked and have their credentials compromised? At least as often.

Re: “Privacy”.com–Yeah Right

#48
post #6

Earlier quoted context omitted.

“Phishing” implies fraudulent deception.

I think their growth numbers would have looked much differently if they had transparently disclosed the reality on their login form from day one: “Plaid will store your plaintext password and use it to periodically access your bank account.” Burying truth deep in a TOS is seen by some as deceptive.

I believe plaid has oauth integration with the larger banks now. I remember using it with chase and chase showing me an auth and permission approval request screen.

Re: “Privacy”.com–Yeah Right

#49

Privacy.com is a great service. I use them all the time to generate 1 time use card numbers for sites & then cancel the card so they cannot mysteriously charge me. I've been with them for years & their CEO is a wonderful & smart person. When you're allowing strangers to perform financial transactions - you're taking on risk that the money that is sent needs to actually be funded. They need to conform to KYC laws like…

KYC does not require the use of sketchy 3rd parties who leak data like a sieve.

What makes you think OnFido is sketchy? It’s a pretty popular platform for ID verification.

3rd party verification has become a standard in the fintech/insuretech industries since its very hard and risky to do KYC on your own. Also personally I don’t trust having all the random companies I transact with maintain my KYC info. At least in theory, the experts at ID verification have strong enough incentives, motivation and expertise to keep my data safe, reducing the attack surface area.

Not affiliated with either party.

Re: “Privacy”.com–Yeah Right

#50

Sooner or later we're going to need a federal dept of is-this-guy-who-he-says-he-is. No startup can solve this; it's not profitable enough to do right. The last resort for authentication will always be "go to a place and talk to a human" and the gov't is the only entity who is willing/able to staff a brick-and-mortar office in reach of everyone in the country. I know some people are afraid of the feds having a centra…

If you think about it, there is a way this is done already in the real world - using Notaries. Notaries verify your ‘documents’. Not that’s they are experts at sensitive data storage, but there could be something to learn from the ‘distributed’ system of notaries.
Post reply on HN