Live data from Hacker News

“Privacy”.com–Yeah Right

ersei.net

111–120 of 172 posts

Re: “Privacy”.com–Yeah Right

#111
post #56

Sooner or later we're going to need a federal dept of is-this-guy-who-he-says-he-is. No startup can solve this; it's not profitable enough to do right. The last resort for authentication will always be "go to a place and talk to a human" and the gov't is the only entity who is willing/able to staff a brick-and-mortar office in reach of everyone in the country. I know some people are afraid of the feds having a centra…

This is what Notaries are for. Maybe we could find a way to more efficiently utilize their services instead of creating yet another federal agency to intrude on our lives?

You've misunderstood the problem we're trying to solve.

Right now, N companies have N partial records of my identity, with varying ages and accuracy levels. Company A has my name and phone number, company B has my email and name and my previous phone number, company C has a copy of my driver's license from two years ago, etc. N partially accurate versions of my identity, floating around, getting bought and sold and merged together with buggy perl scripts, forever. Notaries do nothing to solve this.

Whence comes this fear? How would the government having an accurate list of the citizenry, and storing a key for you so you can attest your identity, intrude on your life? Doesn't having to scan a copy of your ID and send it to your [bank/insurer/crypto account/hosting company/employer/etc] intrude on your life more?

Re: “Privacy”.com–Yeah Right

#112
post #101
post #94

Earlier quoted context omitted.

> Making it harder, rather than easier, to chargeback fraudulent uses is not what I'm looking for. Honestly I'm still confused by the whole thing. I told them that it was a fraudulent transaction that I didn't approve, they then kept asking me for tracking numbers and finally closed the support ticket, and would close any further ones instantly on me with this reply. https://i.imgur.com/EyjCGiU.png Never mind the fac…

>is a complete disregard for visa's rules Visa is probably easier to deal with in the case of fraud than what it sounds like privacy.com is like. I use a single CC for everything (that I'm willing to pay with a CC for.) It's been compromised to the point that charges went through 2-3 times over the past decade and a half. CC company caught the fraud each time, automatically charged-back each of the fraudulent transac…

> They also moved all of my recurring charges to my new card (somehow.)

If you're curious about how this works, read up on "Visa Account Updater".

Re: “Privacy”.com–Yeah Right

#113

Earlier quoted context omitted.

It's definitely a problem in the US. When setting up an account with treasury.gov there's a good chance you'll have to verify your identity, and the only way to do that is to go to a bank that you do business with that has a "Medallion Guarantee." I wish we could get to the point of having government issued smart cards for verifying identity. I would be elated if my US passport also functioned as a smart card.

ID.me's trying, but it should really be a government run service and not a private corporation.

In my preferred alternate reality, Keybase was (somehow) purchased by the feds instead of Zoom and used for exactly this purpose.

Re: “Privacy”.com–Yeah Right

#114
post #82

Earlier quoted context omitted.

That is the definition of phishing. This is why "vishing" is "voice phishing", etc. Phishing is stealing information. It's not a "semantic angle" - it's the definition of phishing. You're free to consulting a dictionary to fact check me. Plaid is not phishing, by any true definition of the word.

Like I said, pretend I said "Plaid pretends to be the users' banks in order to trick users into giving Plaid their bank credentials and stores those credentials without their knowledge or consent" if it makes you feel any better. I'm content with my comment if you agree Plaid's behavior matches phishing with the only exception being how they use the credentials afterwards.

But it's how they use the credentials afterwards that's core to the disagreement over your use of the word phishing. Which is to say, you don't like or trust them, fine, but Plaid isn't a scam that's going to try and steal your money with those credentials it's gotten. Which makes it not phishing. Phishing involves an attacker trying to get those credentials in order to steal yo shit. Plaid is trying to perform a service on your behalf.

If I go to a store and pick up some items and leave with them is that stealing? How about if I pay for them?

Re: “Privacy”.com–Yeah Right

#115

Earlier quoted context omitted.

What makes you think OnFido is sketchy? It’s a pretty popular platform for ID verification. 3rd party verification has become a standard in the fintech/insuretech industries since its very hard and risky to do KYC on your own. Also personally I don’t trust having all the random companies I transact with maintain my KYC info. At least in theory, the experts at ID verification have strong enough incentives, motivation…

Check the article. It has quotes from their ToS that can be roughly summarized as "we'll sell all your data to whoever pays and you have no control over this".

No, that's not what they are saying at all. The quote on the blog is misleading and leaves out important pieces. Here's the full thing:

"As part of a business transfer. Onfido may disclose your personal information to an actual or potential buyer, investor or partner (and its agents and advisers) in relation to any actual or proposed divestiture, merger, acquisition, joint venture, bankruptcy, dissolution, reorganization, or any other similar transaction or proceeding"

Re: “Privacy”.com–Yeah Right

#116
post #41

Earlier quoted context omitted.

No it’s just the ability to generate new credit card numbers on demand If you want various virtual cards with varying limits I also noticed my Citi card allows me to do this. It’s just a little clunkier but it’s actually more robust than Apple’s feature if you wanted a unique number per website.

Oddly, my Citi card does not seem to have this. Guess I need a new card.

It's not for all account holders: https://www.cardbenefits.citi.com/Products/Virtual-Account-N...

Re: “Privacy”.com–Yeah Right

#117
post #5

Privacy.com was a perfect expression of “Your business is our feature”. Practically every major card issuer provides native virtual numbers now.

Younger audiences may not remember, but yes: major card providers used provide virtual card numbers back in the day. This is a feature of the past, and most providers don't do it anymore. The only one I know of is Capital One's Eno: https://www.capitalone.com/digital/eno/virtual-card-numbers/

Citi does: https://www.cardbenefits.citi.com/Products/Virtual-Account-N...

Bank Of America retired theirs (and lost the retirement page): https://webcache.googleusercontent.com/search?q=cache:-9i6Vr...

Re: “Privacy”.com–Yeah Right

#118

Privacy.com is a great service. I use them all the time to generate 1 time use card numbers for sites & then cancel the card so they cannot mysteriously charge me. I've been with them for years & their CEO is a wonderful & smart person. When you're allowing strangers to perform financial transactions - you're taking on risk that the money that is sent needs to actually be funded. They need to conform to KYC laws like…

But they apparently require government photo ID that gets sent off into the cloud? You can most certainly get a regular credit card without that, so it doesn't seem analogous. They also intentionally hide this requirement so that you don't find out about it until after you've signed up, which is a pretty devious dark pattern.

Re: “Privacy”.com–Yeah Right

#119
I absolutely love Privacy.com for the service they provide. It's fantastic to be able to create a one time use card for a web purchase. I even have one connected to my Walmart app that allows me to pay in store via the QR code.

Re: “Privacy”.com–Yeah Right

#120

Sooner or later we're going to need a federal dept of is-this-guy-who-he-says-he-is. No startup can solve this; it's not profitable enough to do right. The last resort for authentication will always be "go to a place and talk to a human" and the gov't is the only entity who is willing/able to staff a brick-and-mortar office in reach of everyone in the country. I know some people are afraid of the feds having a centra…

If you think about it, there is a way this is done already in the real world - using Notaries. Notaries verify your ‘documents’. Not that’s they are experts at sensitive data storage, but there could be something to learn from the ‘distributed’ system of notaries.

Notaries already exist. The proof that they are not a good solution to this problem is that they're not currently being used to solve it. All the companies doing hokey things like asking people to take a picture of themselves holding their ID and so forth could just start asking them to find a notary instead. AFAIK none of them do and I'm not clear on why you're thinking they would or should.
Post reply on HN