Live data from Hacker News

“Privacy”.com–Yeah Right

ersei.net

151–160 of 172 posts

Re: “Privacy”.com–Yeah Right

#152
post #25

Earlier quoted context omitted.

>It allows you to easily have a card per merchant, and lock it to the merchant so that when its number is stolen, it can't be used anywhere else. In my experience even that can fail. I had a card number stolen from them, charged to the tune of $200+, and their support refused to even entertain the idea of it being fraud, and when I mentioned a chargeback they basically said "we don't do those, because we have contrac…

Hey @flutas, I'm sorry to hear about your experience. Send me a note at rachel@lithic.com and I'll look into this further for you.

As somebody who doesn't use any of these services, your request for somebody to contact you at a lithic.com address in response to concerns about privacy.com issues is uh.... well, it reads like the 3rd slide in a corporate SCORM annual "phishing awareness" training.

Re: “Privacy”.com–Yeah Right

#153
post #143

Earlier quoted context omitted.

Omitting the context very clearly makes it sound like they sell your personal information, when the paragraph is actually referring to disclosing the data in an M&A transaction. The "buyer" here is not a buyer of data but the buyer of the company. Even you said "from reading this blog post it seems like yet another evil company trying to suck up PII from unsuspecting victims and sell it".

It actually wasn't that particular line that made me think they were selling personal information, it was mostly the other three points in that list which you seem to be ignoring: * Each of Onfido’s and/or Provider’s third-party vendors may have access to the facial scan data * Onfido is in no way linked to or responsible for the practices of other Providers. Onfido encourages you to read Company’s privacy policies a…

And I replied to "how is that different from what the blogpost said?", not the other points but you got me curious so here goes:

* "Each of Onfido’s and/or Provider’s third-party vendors may have access to the facial scan data"

This is actually "Each of Onfido’s and/or Provider’s third-party vendors may have access to the facial scan data to store the data, to maintain backup copies, and to service the systems on which such data is stored.".

Completely standard and another misrepresentation by the blog trying to paint it like they send the stuff everywhere when it's just about their storage and backup solution.

* "Onfido is in no way linked to or responsible for the practices of other Providers. Onfido encourages you to read Company’s privacy policies and terms and conditions, as well as those of other Providers, which may apply to the use of facial scan data extracted from photos and videos."

Nothing strange whatsoever. Again completely standard in GDPR that you need to have to to acquit yourself.

* Onfido may disclose your personal information... or other third party where we believe disclosure is necessary... to protect your vital interests or those of any other person

This is actually "To comply with laws. Onfido may disclose your personal information to any competent law enforcement body, regulatory, government agency, court or other third party where we believe disclosure is necessary (i) as a matter of applicable law or regulation, (ii) to exercise, establish or defend our legal rights, or (iii) to protect your vital interests or those of any other person; and"

Wow, probably the worst misrepresentation. This blog is straight-up misinformation and slander. Thanks for highlighting it.

Re: “Privacy”.com–Yeah Right

#154

Earlier quoted context omitted.

Hey @flutas, I'm sorry to hear about your experience. Send me a note at rachel@lithic.com and I'll look into this further for you.

As somebody who doesn't use any of these services, your request for somebody to contact you at a lithic.com address in response to concerns about privacy.com issues is uh.... well, it reads like the 3rd slide in a corporate SCORM annual "phishing awareness" training.

hey jimmy grapes, sorry to hear you had a bad experience with a Lithic employee. Please email us at lithic@gmail.com with your SSN and mothers maiden name and we'll have this dealt with shortly

Re: “Privacy”.com–Yeah Right

#155
post #145

Earlier quoted context omitted.

Like I said, pretend I said "Plaid pretends to be the users' banks in order to trick users into giving Plaid their bank credentials and stores those credentials without their knowledge or consent" if it makes you feel any better.

Plaid does none of that. They don't trick you. Having used plaid software before, it's pretty clear what's happening.

I've (been conned into) using Plaid too! Here's the login screen I saw: https://d1hzvs60s6jsjg.cloudfront.net/IMAGES-1/208624076/pla...

Please describe to me how I can figure out from this that my bank credentials will be sent to and stored by a third party that isn't my bank.

Re: “Privacy”.com–Yeah Right

#156
post #101

Earlier quoted context omitted.

>is a complete disregard for visa's rules Visa is probably easier to deal with in the case of fraud than what it sounds like privacy.com is like. I use a single CC for everything (that I'm willing to pay with a CC for.) It's been compromised to the point that charges went through 2-3 times over the past decade and a half. CC company caught the fraud each time, automatically charged-back each of the fraudulent transac…

> They also moved all of my recurring charges to my new card (somehow.) If you're curious about how this works, read up on "Visa Account Updater".

Any way to deactivate that feature?

Re: “Privacy”.com–Yeah Right

#157

The use of third party KYC services like Onfido is widespread in the cryptocurrency space as well, where over-compliance is the norm right now. Consumers are given little choice as to which provider stewards their ID scans, bank statements, biometric data, etc. This user experience has trained the most vulnerable, non-tech-savvy audiences to provide just about anything requested when asked for ID verification. Includ…

ahahahaha man who do you think is the one who added all this KYC shit and who scares companies into over compliance... and you want more regulation as a solution. we could start by removing all KYC requirements and fighting crime as crime instead of imputing some criminality to a financial transaction. like even if it's part of a criminal enterprise the transaction itself isn't the "wrong" part.

Umm. Removing KYC requirements just makes it easier to launder dirty money. Why would we do that? As it is the US is considered a safe-heaven for dirty money - google South Dakota trusts. “Fighting crime as crime” is meaningless.

Re: “Privacy”.com–Yeah Right

#158

Sooner or later we're going to need a federal dept of is-this-guy-who-he-says-he-is. No startup can solve this; it's not profitable enough to do right. The last resort for authentication will always be "go to a place and talk to a human" and the gov't is the only entity who is willing/able to staff a brick-and-mortar office in reach of everyone in the country. I know some people are afraid of the feds having a centra…

Other countries do this and manage (Australia, NZ, UK, etc). Companies outsource the KYC to vendors who carry ISO27001 etc and heaps of insurance. No sane IT people would want photos of so much personally sensitive data on their own systems.

The tech to do this well is nearly here - combination of ID on Apple/google wallet + decent on-device facial recognition tech and you can hugely reduce the risk profile of KYC.

Re: “Privacy”.com–Yeah Right

#159
post #145

Earlier quoted context omitted.

Plaid does none of that. They don't trick you. Having used plaid software before, it's pretty clear what's happening.

I've (been conned into) using Plaid too! Here's the login screen I saw: https://d1hzvs60s6jsjg.cloudfront.net/IMAGES-1/208624076/pla... Please describe to me how I can figure out from this that my bank credentials will be sent to and stored by a third party that isn't my bank.

I'm not clicking on your janky link, sorry.

Re: “Privacy”.com–Yeah Right

#160

Earlier quoted context omitted.

Hey @flutas, I'm sorry to hear about your experience. Send me a note at rachel@lithic.com and I'll look into this further for you.

As somebody who doesn't use any of these services, your request for somebody to contact you at a lithic.com address in response to concerns about privacy.com issues is uh.... well, it reads like the 3rd slide in a corporate SCORM annual "phishing awareness" training.

They rebranded to lithic from privacy last year.
Post reply on HN