Live data from Hacker News

“Privacy”.com–Yeah Right

ersei.net

61–70 of 172 posts

Re: “Privacy”.com–Yeah Right

#61
post #54

In defense of Privacy.com, they've helped prevent me from being defrauded multiple times. I use them any time I'm buying from a website where I don't trust they will keep my CC secure (like paying local utility bills). Sure enough someone tried to use my one-time-use utility card multiple times. Once they charged it for 16 cents which how card runners test the cards to see if they are valid. Normally those won't show…

Completely the same experience here.

Re: “Privacy”.com–Yeah Right

#62
post #52
post #8

Earlier quoted context omitted.

Author here. My concern wasn't that Privacy.com knows who is using their service, but with rather how they choose to know that information through a third party (Onfido) and how terrible Onfido's privacy policy is.

Then why drop a steaming pile of shit on the company who's not directly at fault via the title? For clickbait? I've used privacy.com for years. Never had an issue. Never had to validate my identity. Never had any issues with support. If used as prescribed (setting limits on cards etc) it fits in directly to where it belongs in my threat model. What a strangely charged article.

Not directly at fault? Privacy.com chose to use Onfido. I don't think the author's complaint is misplaced.

Re: “Privacy”.com–Yeah Right

#63
post #57

Earlier quoted context omitted.

"Phishing" does not mean what you think it means. Blame the banks for Plaid's need to exist.

Phishing generally means "pretend to be X to get user's info/credentials for X", do you have a different definition?

Phishing is typically tricking an individual into divulging sensitive information. Credential stealing is typical, but still a subset.

Plaid uses banking credentials on a user's behalf. Yes, it's similar to using stolen credentials because... it's the same thing, except consent, audits, insurance, etc. all play a role whereas with criminal activity they do not.

Re: “Privacy”.com–Yeah Right

#64
post #52
post #8

Earlier quoted context omitted.

Author here. My concern wasn't that Privacy.com knows who is using their service, but with rather how they choose to know that information through a third party (Onfido) and how terrible Onfido's privacy policy is.

Then why drop a steaming pile of shit on the company who's not directly at fault via the title? For clickbait? I've used privacy.com for years. Never had an issue. Never had to validate my identity. Never had any issues with support. If used as prescribed (setting limits on cards etc) it fits in directly to where it belongs in my threat model. What a strangely charged article.

So it wasn't privacy.com who chose Onfido?

If your contractor chooses a bad subcontractor, who do you blame?

Re: “Privacy”.com–Yeah Right

#65
post #52

Earlier quoted context omitted.

Then why drop a steaming pile of shit on the company who's not directly at fault via the title? For clickbait? I've used privacy.com for years. Never had an issue. Never had to validate my identity. Never had any issues with support. If used as prescribed (setting limits on cards etc) it fits in directly to where it belongs in my threat model. What a strangely charged article.

Not directly at fault? Privacy.com chose to use Onfido. I don't think the author's complaint is misplaced.

Using a company and having proper contracts and agreements with them to be properly protected is not malice, especially since the company is well known and assumedly adheres to regulation.

I'm not sure what you want privacy.com to do differently.

Re: “Privacy”.com–Yeah Right

#66
post #64
post #52

Earlier quoted context omitted.

Then why drop a steaming pile of shit on the company who's not directly at fault via the title? For clickbait? I've used privacy.com for years. Never had an issue. Never had to validate my identity. Never had any issues with support. If used as prescribed (setting limits on cards etc) it fits in directly to where it belongs in my threat model. What a strangely charged article.

So it wasn't privacy.com who chose Onfido? If your contractor chooses a bad subcontractor, who do you blame?

Privacy.com is not a contractor, firstly. IMO that's a weak analogy at best. I've asked elsewhere - what do you want privacy.com to do differently?

Re: “Privacy”.com–Yeah Right

#68

Earlier quoted context omitted.

KYC does not require the use of sketchy 3rd parties who leak data like a sieve.

What makes you think OnFido is sketchy? It’s a pretty popular platform for ID verification. 3rd party verification has become a standard in the fintech/insuretech industries since its very hard and risky to do KYC on your own. Also personally I don’t trust having all the random companies I transact with maintain my KYC info. At least in theory, the experts at ID verification have strong enough incentives, motivation…

FWIW, they are at least willing to put this in their privacy policy:

> Whenever legally possible, we seek to protect the information we share by imposing contractual privacy and security safeguards on the recipient of the information. This is particularly important in cases where the recipient is located in a country that has different or lesser privacy laws than those of the country where the information was originally collected. In some cases, however, it’s not possible for us to do so — for example, when we have a legal obligation to disclose information to a government authority and that government authority isn’t willing to enter into such contractual safeguards.

Re: “Privacy”.com–Yeah Right

#69

Earlier quoted context omitted.

KYC does not require the use of sketchy 3rd parties who leak data like a sieve.

What makes you think OnFido is sketchy? It’s a pretty popular platform for ID verification. 3rd party verification has become a standard in the fintech/insuretech industries since its very hard and risky to do KYC on your own. Also personally I don’t trust having all the random companies I transact with maintain my KYC info. At least in theory, the experts at ID verification have strong enough incentives, motivation…

Check the article. It has quotes from their ToS that can be roughly summarized as "we'll sell all your data to whoever pays and you have no control over this".

Re: “Privacy”.com–Yeah Right

#70
post #44

Earlier quoted context omitted.

My point is that privacy doesn't need to do KYC because there is no possibility of the customer evading regulators. Assuming that privacy answers subpoenas, they would be able to give the government detailed transaction info and a bank account which would identify the customer. KYC at this level of abstraction doesn't seem to solve any kind of legal problem. I'm glad to be educated by an expert, though. Edit: A sibli…

How do you validate that they own the bank accounts if you don't know who the user is?

They only verify control. They do the method of making two small deposits and asking what they were.
Post reply on HN