Live data from Hacker News

“Privacy”.com–Yeah Right

ersei.net

121–130 of 172 posts

Re: “Privacy”.com–Yeah Right

#121
post #34

Onfido is state of the art service for ID verification and very trustworthy.

Then why do they have all those incredibly questionable things in their privacy policy? What makes them "trustworthy"? I've never heard of them, but from reading this blog post it seems like yet another evil company trying to suck up PII from unsuspecting victims and sell it.

And that's why you shouldn't trust a random blog. They completely misrepresented that paragraph. Here's the full quote:

"As part of a business transfer. Onfido may disclose your personal information to an actual or potential buyer, investor or partner (and its agents and advisers) in relation to any actual or proposed divestiture, merger, acquisition, joint venture, bankruptcy, dissolution, reorganization, or any other similar transaction or proceeding"

Re: “Privacy”.com–Yeah Right

#122
post #121

Earlier quoted context omitted.

Then why do they have all those incredibly questionable things in their privacy policy? What makes them "trustworthy"? I've never heard of them, but from reading this blog post it seems like yet another evil company trying to suck up PII from unsuspecting victims and sell it.

And that's why you shouldn't trust a random blog. They completely misrepresented that paragraph. Here's the full quote: "As part of a business transfer. Onfido may disclose your personal information to an actual or potential buyer, investor or partner (and its agents and advisers) in relation to any actual or proposed divestiture, merger, acquisition, joint venture, bankruptcy, dissolution, reorganization, or any oth…

how is that different from what the blogpost said?

edit: to be clear, the blog post has listed, among other complaints:

> Onfido may disclose your personal information to an actual or potential buyer (note "potential")

which you seem to be confirming from your own review of their policy. What did the blog post misrepresent?

Re: “Privacy”.com–Yeah Right

#123
post #23

Ahhh FFS, this post is complaining about third party KYC providers. Give me a break, in what world can you get a visa or mastercard without KYC? They provide privacy not anonymity, payment privacy that is not hiding your identity privacy. Your payments are private. Your payment info can't be easily tracked across the different cards you create. That's it.

I agree that most of the comments here amount to handwringing (or not understanding what amount of "privacy" is legal), but also, what KYC is really necessary for a company like this? If I understand correctly, all they do is pass through transactions. They don't hold customer deposits or provide credit. Isn't all this third party verification a little much?

It is a legal requirement for their bank and for mastercard.

Re: “Privacy”.com–Yeah Right

#124
post #23

Ahhh FFS, this post is complaining about third party KYC providers. Give me a break, in what world can you get a visa or mastercard without KYC? They provide privacy not anonymity, payment privacy that is not hiding your identity privacy. Your payments are private. Your payment info can't be easily tracked across the different cards you create. That's it.

It's not the existence of KYC, it's that their KYC provider is slimey and not privacy respecting. Selling your data to potential bidders is a no go.

Pretty sure selling your passport pic is illegal, as far as name, address and IP all major banks are doing this already.

Re: “Privacy”.com–Yeah Right

#125
post #28
post #18

Earlier quoted context omitted.

You "believe" without any evidence? To the contrary my bank card purchases were resulting in targeted ads but privacy.com cards have not shown any sign of that after using them for over a year.

Belief kind of implies lack of evidence, more a feeling or a faith, after all.

I agree in this case

Re: “Privacy”.com–Yeah Right

#126
Lets break this abysmal post down into what appears to be the point:

  Privacy.com flagged you for some unknown reason and asked you to verify your identity. You learned that Onfido exists and googled the name and (LOL) decided you would spend 45s on Wikipedia and then read a privacy policy written not-for-you, and then post yourself on HN so you can "inform others."
Lets not even bother with the fact that flagging for further identification happens at every financial company that exists. People are flagged all the time for a number of reasons dictated by ML/AI that is not always right. "I've never had this happen before." That's not how math works.

  As I am not a lawyer, I probably missed some more bits as well.
We can tell. And you did. You missed the part where you have to read and comprehend more than three or four words at a time. That or you intentionally excluded the pieces that invalidated everything that got you to the front page of HN. I'd wager it's the former. Allow me to do the research you pretended to do:

First and foremost, there are regulations on how PCI/PII data can be stored. I'll assume you read about reading about or pretended to read about PCI so I won't go into the details you don't care to understand (but should).

  Each of Onfido’s and/or Provider’s third-party vendors may have access to the facial scan data 
When a company hosts with providers like AWS, GCP, etc, those are considered "third party." If you curl the onfido website you can see that it's hosted on S3 (or at least parts of it are). It's very likely that onfido is storing data in S3 which means a third party has access to store the data, make backups, etc. You also excluded THE IMPORTANT PART on previous line that said Onfido securely stores all selfies, videos, photos of identity documents, and facial scan data in an encrypted format.

  Onfido may disclose your personal information to an actual or potential buyer (note "potential")
I'm going to go out on a limb here and assume you've never owned a company who's had an offer to exit. When company A purchases company B they first have to evaluate that business and decide if they want to buy it. Since you think like Twitter I'll clear something up for you: acquisitions don't happen by posting on twitter "I want to buy Twitter." This is a standard bullet point in every privacy policy. When you are approached by a potential buyer you sign a slew of NDA's and other legally binding documentation that prevents any party from sharing the details of the agreement.

Believe it or not, startups don't have enough time, money, energy, resources to rewrite every little feature required to run a business. Visa and Mastercard also have their own ways of sharing your private information. Does that also mean to start a privacy focused fintech company you need to write the entire american payment system?

  Onfido may disclose your personal information... or other third party where we believe disclosure is necessary... to protect your vital interests or those of any other person
Jesus Christ. I don't even know how you pieced that together so I'll _actually quote_ the document:

  To comply with laws. Onfido may disclose your personal information to any competent law enforcement body, regulatory, government agency, court or other third party where we believe disclosure is necessary (i) as a matter of applicable law or regulation, (ii) to exercise, establish or defend our legal rights, or (iii) to protect your vital interests or those of any other person; 
This is American and guess what: you have to comply with the law. I know in your fantasy world of impotence masquerading as activism you think you can "privacy" your way around it, but guess what? You can't. Any company operating in has to comply with the laws. "I use Proton and they are privacy." I'm sure you do, and they're privacy because the laws permit it until they don't.

So what do you do? You try to deprive a company who's actively trying to do what you pretend to do with your useless tantrum.

Re: “Privacy”.com–Yeah Right

#128

Earlier quoted context omitted.

If you think about it, there is a way this is done already in the real world - using Notaries. Notaries verify your ‘documents’. Not that’s they are experts at sensitive data storage, but there could be something to learn from the ‘distributed’ system of notaries.

Notaries already exist. The proof that they are not a good solution to this problem is that they're not currently being used to solve it. All the companies doing hokey things like asking people to take a picture of themselves holding their ID and so forth could just start asking them to find a notary instead. AFAIK none of them do and I'm not clear on why you're thinking they would or should.

You are right - current notary system may not be optimal for this use case. What I meant to say was that in my understanding, my main issue with 3rd parties such as OnFido etc is my lack in trusting them with my information and secondly storing that info in a central repository. If a bad entity gets access to that database, they now have very detailed information about me.

I would rather prefer a decentralized & secure way that can be accesses via an API by companies such as privacy.com etc. The distributed piece is solved by Notaries. Could we learn something from how the notary system works that can be leveraged to build out a modern distributed ID verification system.

Re: “Privacy”.com–Yeah Right

#129
post #100

Earlier quoted context omitted.

>I had a card number stolen from them, charged to the tune of $200+ I'm curious, how did this happen specifically? In my experience, all privacy.com virtual cards default to being merchant-locked to the first place you use them. Did the merchant run an unauthorized transaction on the card? I've had online payment info compromised once, and privacy.com caught it cold (and also clearly demonstrated that the vendor had…

Honestly no clue, different vendor than the card was setup for. This was during a big wave of unauthorized activity being attempted on their cards as well, a lot of friends reported blocked charges for random amounts at like a retirement/hospice home(?) at the time. This was like 3+ years ago, and my only guess now (read: can't remember if this is true) is that the card had never been charged to the merchant, only pr…

Interesting, looks like there was some kind of attack on privacy.com in 2020[0] that caused transactions to be run from vendors without them.

0. https://blog.privacy.com/a-different-type-of-card-fraud-anat...

Re: “Privacy”.com–Yeah Right

#130

Earlier quoted context omitted.

Younger audiences may not remember, but yes: major card providers used provide virtual card numbers back in the day. This is a feature of the past, and most providers don't do it anymore. The only one I know of is Capital One's Eno: https://www.capitalone.com/digital/eno/virtual-card-numbers/

Citi does: https://www.cardbenefits.citi.com/Products/Virtual-Account-N... Bank Of America retired theirs (and lost the retirement page): https://webcache.googleusercontent.com/search?q=cache:-9i6Vr...

Wow, I have a Citi card and I never knew! I don't think I've ever been promoted this feature before.

I remember BofA used to. When they closed it, I thought everyone else followed suite.

Post reply on HN