Live data from Hacker News

Credit cards have a privacy problem

washingtonpost.com

171–178 of 178 posts

Re: Credit cards have a privacy problem

#171

Earlier quoted context omitted.

The person in question has a relationship with the credit card company, in that they have requested and use the credit card (and if they aren't using it, nothing is being collected). I agree that opting into collection automatically is less than ideal, and I don't want it to happen, but this isn't some third party getting between some other nefarious third party and myself, it's them injecting themselves into an ongo…

Due to the constraints on understanding, I believe "fine print" in contracts carries zero moral weight. In order for Visa and Mastercard to credibly claim people have opted in, there needs to be an overt choice (no default already-checked option) as part of the direct card relationship, as well as specific consideration for that specific aspect of the relationship to remove any incentive to downplay the choice. Furth…

> Furthermore, I do not view a person's associating with Visa/MC in today's society to be in any way voluntary - opting out is only possible at significant personal expense.

Hardly. There are other creditors, and if you aren't worried about credit at all (and there are other ways to build credit), then you can use cash, buy gift card variants of their products which don't link to you, use some other provider (paypal), or some other form of payment entirely in some cases (e.g. cryptocurrency). There are more choices now than ever before.

> Taken together, these put "abuse" of a "business relationship" is in the exact same category as interjected actions by "third" parties - unwanted transgressions. > I wouldn't personally do such a thing, but that doesn't mean I wouldn't applaud someone who did.

The only way I can read this is as you condoning additional violations of someone's privacy just because you think it's for the best this time. As I've noted, I don't think your value judgements have any place in my life, nor my interactions with other parties.

This has nothing to do with whether the whether the credit card company was justified in doing what they did, it has to do with people minding their own business and not violating other people's privacy. If you think the credit card companies are going too far, then calk to the authorities for legal action or legislative remedy. I applaud that action, but I don't want your vigilante activism, and I don't condone breaking the law by people that think they're more special than other people because they're doing it for "a good reason" or because "it's really just helping people".

I guess it's nice that you wouldn't do it yourself, but why would you applaud someone doing something that you wouldn't do yourself? It's real simple, if you can't or don't want to ask for permission to do something for someone else, then you shouldn't be doing that thing.

Re: Credit cards have a privacy problem

#172
post #15
post #3

Will leave these here, just one small step to help you regain your privacy: * https://marketingreportoptout.visa.com/OPTOUT/request.do * https://www.mastercard.us/en-us/about-mastercard/what-we-do/...

Did anyone else notice Mastercard's easily breakable captcha? It's just unmodified text with the same noise filter added to all codes. Perhaps there's opportunity here for someone to be Robinhood here and improve the privacy of a lot of people...

Sometimes when I get debt collector calls or car warranty scams I find their website and they usually have an opt out form, never seen a captcha. I have been really tempted to just hammer the endpoint with every valid phone number. Probably won’t accomplish anything but will give someone a fun surprise.

Re: Credit cards have a privacy problem

#173

Earlier quoted context omitted.

Due to the constraints on understanding, I believe "fine print" in contracts carries zero moral weight. In order for Visa and Mastercard to credibly claim people have opted in, there needs to be an overt choice (no default already-checked option) as part of the direct card relationship, as well as specific consideration for that specific aspect of the relationship to remove any incentive to downplay the choice. Furth…

> Furthermore, I do not view a person's associating with Visa/MC in today's society to be in any way voluntary - opting out is only possible at significant personal expense. Hardly. There are other creditors, and if you aren't worried about credit at all (and there are other ways to build credit), then you can use cash, buy gift card variants of their products which don't link to you, use some other provider (paypal)…

The issue isn't credit, but payment processors. Add Paypal and ACH to Visa/MC and you rule out basically every web retailer. If Monero/Zcash get to the point where they are well-adopted practical choices this judgement can change, but we are nowhere near that state of affairs.

> additional violations of someone's privacy

I've agreed that flipping that surveillance preference flag is a type of violation, just of territory that has already been trodden on. It's like if someone breaks into your house while you're away, then a neighbor comes along to put a tarp over your window before it rains, and you're complaining that the neighbor has trespassed. In a sense you'd be technically correct, but most people would consider that action to have been reasonable.

There is also the aspect where someone leaving this preference flag unmaintained is contributing to a larger attractive nuisance.

> why would you applaud someone doing something that you wouldn't do yourself?

Because I simply wouldn't want to take on the legal risk.

Re: Credit cards have a privacy problem

#174

Earlier quoted context omitted.

> Google buys your credit card data for advertising purposes How do they connect my credit card data to my Google activity? My Google account isn't connected to my personally identifiable information in any way. I.e. they don't have my phone number, nor do I use Google Pay.

>My Google account isn't connected to my personally identifiable information in any way. Which personally identifiable information? The time of day you use your devices? Which languages you use? Which websites you visit? The type of medical conditions you search for? Information being PII or non PII isn't binary. It's relative shades of how shannon entropic it is. You need about 33 bits to identify someone, you likel…

> Information being PII or non PII isn't binary.

It is binary in Google's data structures (marked as annotations on protobufs), and in law. Things you listed aren't considered PII.

Re: Credit cards have a privacy problem

#175

While I do love me some privacy.com, unfortunately they only allow you to tie payments to bank accounts, not credit cards. So, it's a virtual debit card, not a virtual credit card. Now, they do let you set transaction limits, and daily/weekly/monthly limits, as well as either locking the card to the first merchant to use it or to make it a "burner" one-time only card. So, there's lots of additional controls there. Th…

privacy.com comes up on HN a lot, and every time they do I try to take the time to point out they require a binding arbitration agreement with no opt-out. Arbitration agreements are bad in general, but not necessarily uncommon. What makes privacy.com different is that they have access to your bank account. They're in a position where they have direct access to your funds, and you can't bring them to court if they wro…

I believe you can opt-out of binding arbitration in california.

Re: Credit cards have a privacy problem

#176
post #142

Earlier quoted context omitted.

Oh, I wouldn't even mind if they served me ads. But what they're saying is: We won't let you read our stuff unless we can track you (and see exactly what you read how long from where using which device, etc.)

"... unless you are willing to pay us for reading this content. In which case you've already paid for it so browse however you like"

If you're signed in as a subscriber then they can track you though.... So you can't without being tracked period.

Re: Credit cards have a privacy problem

#177

Earlier quoted context omitted.

The worst part is that certain banks won't let you link an account that Plaid claims is supported based upon the routing number/account number. So for example when I attempted to link based upon routing/account number at Simple, it told me I can't continue because I should hand over my account information for the other bank to Plaid instead. I've done it, and then immediately changed my account info. So yes, technica…

I was able to get around this by typing in a junk/non-existent bank name, which dropped me into the manual routing/account number option.

Yeah, I tried that... and then when I entered the manual routing number it's like "Hey, you need to login instead because this bank is known to us"

Re: Credit cards have a privacy problem

#178

Earlier quoted context omitted.

The worst part is that certain banks won't let you link an account that Plaid claims is supported based upon the routing number/account number. So for example when I attempted to link based upon routing/account number at Simple, it told me I can't continue because I should hand over my account information for the other bank to Plaid instead. I've done it, and then immediately changed my account info. So yes, technica…

I'm not arguing against the general idiocy of this, but the net effect should be to keep money away from such banks. My understanding of the ACH system is that it's best used in a "pull" manner, as if you're writing a check. Link your Simple account from another bank and initiate the pull from there. (Then work on transitioning your activity to the better bank while you're at it).

Yup... that's what I have been doing.
Post reply on HN