Live data from Hacker News

FSFE supporters affected: Payment provider Nexi cancelled us

fsfe.org

11–20 of 32 posts

Re: FSFE supporters affected: Payment provider Nexi cancelled us

#12
post #4
post #2

The FSFE justly drew the line at providing private information of supporters. How many other customers of Nexi simply handed over such data 'because audit'?

So this was not only about FSFE and payments for them but a general audit of their (Nexi's) customers ?

It seems unlikely that the FSFE is the first customer they have asked for this information.

Re: FSFE supporters affected: Payment provider Nexi cancelled us

#13
post #11

So what did Nexi really want, and how did it get mangled so badly that it came out as "specifically the usernames and passwords of our supporters"?

It's entirely possible that is actually what they wanted (at least what the people in the company they were talking to wanted). I suspect that "we understood to mean" is language carefully designed to avoid a lawsuit.

Re: FSFE supporters affected: Payment provider Nexi cancelled us

#14

Reminds me of the famous "Our security auditor is an idiot. How do I give him the information he wants? [1] [1] https://serverfault.com/questions/293217/our-security-audito...

Is there some part of PCI auditing requirements that is getting misinterpreted by some auditors to demand this? Though in my experience with standards like this what auditors want to see and what the standards say often have only loose overlap anyhow.

Re: FSFE supporters affected: Payment provider Nexi cancelled us

#15
post #7

> Over the past few months, our former payment provider Nexi S.p.A. (“Nexi”) requested access to private data, which we understood to be specifically the usernames and passwords of our supporters. I must be missing something, but why is there an expectation that clear text passwords would even be known?

Probably because most people haven't internalized how password hashing works.

Re: FSFE supporters affected: Payment provider Nexi cancelled us

#16

Reminds me of the famous "Our security auditor is an idiot. How do I give him the information he wants? [1] [1] https://serverfault.com/questions/293217/our-security-audito...

That is crazier than any old dailywtf stories, and that site felt like everyone tried to one-up each other.

Re: FSFE supporters affected: Payment provider Nexi cancelled us

#18
We work with MLS provider(s) that requires us to keep plaintext password for our users and provide it on request in case of `breach in the security of MLS Listing Information or a violation of MLS Rules`.

The user is accessing only copy of their data in _our_ systems, the user has no contact with MLS itself directly or indirectly.

Re: FSFE supporters affected: Payment provider Nexi cancelled us

#20
Sounds like someone is being "overenthusiastic" about interpreting the KYC/ALM regulations.

Combined with the FSFE not being your "usual" charitable or business organization so setting off auditor red flags and perhaps raising the risk profile of Nexi as a payment processor.

Post reply on HN