Live data from Hacker News

Credit cards have a privacy problem

washingtonpost.com

161–170 of 178 posts

Re: Credit cards have a privacy problem

#161
post #81
post #15

Earlier quoted context omitted.

Did anyone else notice Mastercard's easily breakable captcha? It's just unmodified text with the same noise filter added to all codes. Perhaps there's opportunity here for someone to be Robinhood here and improve the privacy of a lot of people...

I'm pretty sure that's a good way to get the endpoint flagged as a target of abuse, and the page pulled until they can figure out what's going on, resulting in anyone who wants to opt-out after that point either running into a temporary or permanent problem, depending if they ever bother to put it back online. How about instead of fraudulently providing someone else's credit card because "we know best", we just make…

> I understand the impetus to help, but it's important to consider that what one person views as helping another might view as terribly invasive in itself.

This is a sense of decency that the surveillance companies didn't share. People didn't make any sort of educated choice to be surveilled - the surveillance companies arrogantly "opted" them in. Opting them out is much lesser transgression onto their will.

I do agree from the practical perspective - surveillance companies will parry any legible bulk activity into an excuse to continue surveilling. Fine point white text at the bottom of the homepage: "Due to an attack from scary hackers, all opt out requests from 2019 have had to be discarded. If you had submitted a request during that time, please resubmit your request. To protect yourself in the future, buy our nonsensical "identity insurance" for only $10/mo."

Re: Credit cards have a privacy problem

#162
post #71

Plaid is the most terrifying company in SV. The fact so many people are comfortable sharing their online banking creds with a third party, and in turn authorizing Plaid to share years of transaction data, your balances, emails, phone numbers, addresses etc scraped from your bank account is insane.

The worst part is that certain banks won't let you link an account that Plaid claims is supported based upon the routing number/account number. So for example when I attempted to link based upon routing/account number at Simple, it told me I can't continue because I should hand over my account information for the other bank to Plaid instead. I've done it, and then immediately changed my account info. So yes, technica…

I'm not arguing against the general idiocy of this, but the net effect should be to keep money away from such banks.

My understanding of the ACH system is that it's best used in a "pull" manner, as if you're writing a check. Link your Simple account from another bank and initiate the pull from there. (Then work on transitioning your activity to the better bank while you're at it).

Re: Credit cards have a privacy problem

#163

Earlier quoted context omitted.

privacy.com comes up on HN a lot, and every time they do I try to take the time to point out they require a binding arbitration agreement with no opt-out. Arbitration agreements are bad in general, but not necessarily uncommon. What makes privacy.com different is that they have access to your bank account. They're in a position where they have direct access to your funds, and you can't bring them to court if they wro…

> What makes privacy.com different is that they have access to your bank account. In my understanding, they have the account numbers and can do ACH withdrawals - just like someone who has your debit card number (but against a checking account, not a card). So I believe it's like every other transaction (or check) - there's an intentional (as I get it) processing period for a day or two, and you can always call your b…

One can't use the technical situation to escape the legal situation. If you dispute the ACH transaction, privacy.com could still claim you owe them that debt.

They likely won't, being still subject to the court of public opinion. But it doesn't bode well that they're trying to escape the more direct avenue of accountability.

(IMO the FAA is blatantly illogical and should be judicially nullified. But until that happens, we're stuck being on guard for these offensive customer-hostile terms)

Re: Credit cards have a privacy problem

#164
This article is severely deficient and written to draw clicks.

It doesn't go far enough (or at all, really) to explain that the credit card issuer doesn't see the data. They see a transaction amount. There's no banana.

The current top comment about Google linking online to B&M purchases isn't a leak of privacy: it's strictly private both to Google and the merchant. You are being tracked, but not in a privacy-revealing way, just in an uber-annoying I'm-still-being-targetted so-it's-creepy-and-annoying way.

That retail merchants are tracking you is a huge, huge problem. The CC facilitates this by linking all your purchases into a single history, but it isn't the CC per se that is the problem. eg the store's own rewards card specifically does this. They don't even care if you give your actual PII up to signup for the rewards card, all they care about is that they can [even anonymously] identify the purchase stream tied to an individual.

They should go to length to better distinguish this problem because then they can get to the fact that every Apple Pay transaction is tokenized and not linkable to prior or future Apple Pay transactions.

Re: Credit cards have a privacy problem

#165

Yup, do-no-evil Google buys your credit card data for advertising purposes: https://www.bloomberg.com/news/articles/2018-08-30/google-an... Companies need to start thinking of this less in the lens of "evil" and more principle of least astonishment. Would users be surprised and angry to learn you do this? Then don't.

> Google buys your credit card data for advertising purposes How do they connect my credit card data to my Google activity? My Google account isn't connected to my personally identifiable information in any way. I.e. they don't have my phone number, nor do I use Google Pay.

I'll hazard a guess that it takes less than 4 other data points, gathered without your knowledge or consent (but very commonly gathered nonetheless), to associate your credit card with your google activity.

And 4 data points would be a lot more than usually required.

Re: Credit cards have a privacy problem

#166
post #81

Earlier quoted context omitted.

I'm pretty sure that's a good way to get the endpoint flagged as a target of abuse, and the page pulled until they can figure out what's going on, resulting in anyone who wants to opt-out after that point either running into a temporary or permanent problem, depending if they ever bother to put it back online. How about instead of fraudulently providing someone else's credit card because "we know best", we just make…

> I understand the impetus to help, but it's important to consider that what one person views as helping another might view as terribly invasive in itself. This is a sense of decency that the surveillance companies didn't share. People didn't make any sort of educated choice to be surveilled - the surveillance companies arrogantly "opted" them in. Opting them out is much lesser transgression onto their will. I do agr…

> Opting them out is much lesser transgression onto their will.

So, that makes it okay? They've been abused before, so what what's the big deal if we do it too? That's a troubling perspective to me. Two wrongs don't necessarily make a right.

I think this is very straightforward. You, as a third party, have no place making decisions for me without my consent in this case. If I have a relationship with Visa or MasterCard, please stay out of it. The appropriate way for this to change is for a) me or someone I've authorized to request it, b) the company in question deciding not to do it anymore, or c) a legislative body with jurisdiction mandating a change through law or regulation.

If you have access to my credit card number and I haven't given it to you, the only appropriate things you should do with it are to notify me, the company providing it, or the authorities that it's been exposed and should probably be changed. If I have given it to you to authorize a payment, you are authorized to use it for that payment (and possibly later payments that I agree to), not to keep it to use as you see fit later on without my consent.

If you have my card because I've given it to you and you show me a dialog letting me know you can opt me out and give me the choice, that's acceptable. But I view any action taken on my behalf without my consent with regard to this as a violation of my trust, privacy, and personal information. We are in a very scary place if we as random third partied think we're allowed to make decisions for people just because we think it's better for them.

Re: Credit cards have a privacy problem

#167

Earlier quoted context omitted.

> I understand the impetus to help, but it's important to consider that what one person views as helping another might view as terribly invasive in itself. This is a sense of decency that the surveillance companies didn't share. People didn't make any sort of educated choice to be surveilled - the surveillance companies arrogantly "opted" them in. Opting them out is much lesser transgression onto their will. I do agr…

> Opting them out is much lesser transgression onto their will. So, that makes it okay? They've been abused before, so what what's the big deal if we do it too? That's a troubling perspective to me. Two wrongs don't necessarily make a right. I think this is very straightforward. You, as a third party, have no place making decisions for me without my consent in this case. If I have a relationship with Visa or MasterCa…

My main assertion was merely "This is a sense of decency that the surveillance companies didn't share".

It's okay to acknowledge this as a vulnerability of your personal paradigm but still hold yourself to it. Just don't act like it's the only permissible way to interpret the situation, when the present state of affairs has been created by the surveillance companies not following the same moral requirement - already "[making] decisions for [everyone] without [our] consent".

More generally, a sense of right and wrong cannot mean simply following low level axiomatic rules, but rather requires judging constructive behavior. I'd say an action that mainly undoes a wrong is a lot closer to being right than another wrong.

Re: Credit cards have a privacy problem

#168

Earlier quoted context omitted.

> Opting them out is much lesser transgression onto their will. So, that makes it okay? They've been abused before, so what what's the big deal if we do it too? That's a troubling perspective to me. Two wrongs don't necessarily make a right. I think this is very straightforward. You, as a third party, have no place making decisions for me without my consent in this case. If I have a relationship with Visa or MasterCa…

My main assertion was merely "This is a sense of decency that the surveillance companies didn't share". It's okay to acknowledge this as a vulnerability of your personal paradigm but still hold yourself to it. Just don't act like it's the only permissible way to interpret the situation, when the present state of affairs has been created by the surveillance companies not following the same moral requirement - already…

The person in question has a relationship with the credit card company, in that they have requested and use the credit card (and if they aren't using it, nothing is being collected). I agree that opting into collection automatically is less than ideal, and I don't want it to happen, but this isn't some third party getting between some other nefarious third party and myself, it's them injecting themselves into an ongoing business relationship between two parties.

You can label them surveillance companies all you want, and in some contexts it might be the most fitting description. In this context, I would say it's more fitting to say they are contractual partners abusing the looseness of the contract for their own benefit.

Just in case you missed where this particular thread started, the top level comment is about the opt out forms for data collection at Visa and MasterCard, and the reply's (possibly somewhat in jest) suggestion that since the CAPTCHA is so simple, someone just use whatever card numbers they have access to to opt people out automatically. All my comments are specifically in that context, which is one of random third parties using card numbers they shouldn't have direct access to anyway to alter the business relationship of others without authorization.

Re: Credit cards have a privacy problem

#169
post #67

Earlier quoted context omitted.

Your transaction data is never exposed to anyone outside of $corp. $corp provides it's marketing partners with insights gleaned from aggregated transaction data. And allows select partners to query an api for derived information about $corp's cardholders using a marketing identifier that tracks across multiple agencies including credit reporting, social media monitoring and customer intelligence analytics. Additional…

Yes it absolutely is exposed to whomever provided the processing. I've seen the data extensively. The amount of info provided is overwhelming.

Should have qualified it as; "never exposed to anyone outside of $corp or it's authorized contractors."

Re: Credit cards have a privacy problem

#170

Earlier quoted context omitted.

My main assertion was merely "This is a sense of decency that the surveillance companies didn't share". It's okay to acknowledge this as a vulnerability of your personal paradigm but still hold yourself to it. Just don't act like it's the only permissible way to interpret the situation, when the present state of affairs has been created by the surveillance companies not following the same moral requirement - already…

The person in question has a relationship with the credit card company, in that they have requested and use the credit card (and if they aren't using it, nothing is being collected). I agree that opting into collection automatically is less than ideal, and I don't want it to happen, but this isn't some third party getting between some other nefarious third party and myself, it's them injecting themselves into an ongo…

Due to the constraints on understanding, I believe "fine print" in contracts carries zero moral weight. In order for Visa and Mastercard to credibly claim people have opted in, there needs to be an overt choice (no default already-checked option) as part of the direct card relationship, as well as specific consideration for that specific aspect of the relationship to remove any incentive to downplay the choice.

Furthermore, I do not view a person's associating with Visa/MC in today's society to be in any way voluntary - opting out is only possible at significant personal expense. So the mere existence of a business relationship also cannot be a basis for general consent. (As an aside: people generally do not contract with Visa/MC directly)

Taken together, these put "abuse" of a "business relationship" is in the exact same category as interjected actions by "third" parties - unwanted transgressions. They only feel different because we've become fatigued to accepting these transgressions when they pad someone else's bottom line.

And yes I am aware of the context of the discussion. I wouldn't personally do such a thing, but that doesn't mean I wouldn't applaud someone who did.

Post reply on HN