Live data from Hacker News

Chase did a bad thing, so we did a good thing

chaseoptout.com

211–220 of 246 posts

Re: Chase did a bad thing, so we did a good thing

#211

For me the red flag is them willing to send this letter to Chase, via snail mail at no charge to you. Nobody gives something for nothing. So I thought, why would they do this? after reading through the form, at the bottom, it looks like one of the companies, who sponsors this site, "Radvocate" seems like they are in the "class action" lawsuit business. https://myradvocate.com/ This site is about having enough potenti…

Radvocate here: We do have a vested interest. Over time, we want to be the place you come when you have a dispute against a big company because we'll fight hard for you. We're excited to partner on this project partly because it is very "on brand" for us from that perspective — we can help people, get our name out there, and shine light on an issue that matters to us. We're a business, but we're also all in this busi…

Good transparency here, an appreciated and professional online reaction to criticism.

Re: Chase did a bad thing, so we did a good thing

#212

Earlier quoted context omitted.

They could have raised awareness to the problem and provided detailed instructions on how anyone can go about resolving it, in a manner that's consistent with best practices of protecting yourself. It's a false dichotomy to say its either this web site or Chase wins. Promoting risky and insecure behavior is just wrong. period. That's independent of whatever Chase or any other company is putting in their agreements. I…

> It's a false dichotomy to say its either this web site or Chase wins. But it's not! No one is going to mail in a form. Chase specifically chose that go that route because they know nobody nobody is going to mail in a form. The only way to get around this is to make the process easier. How else do you do that? It strikes me as a very shortsighted to say "this behavior is wrong in all circumstances, period," while ig…

fair enough. You're putting more weight on the harm of arbitration agreements, whereas I'm putting more weight on the harm of identity theft and phishing/online scams.

I would say that more broadly speaking the harm of arbitration agreements is solvable in other ways, such as government or advocacy actions. I'm guessing that's what led to this letter/form in the first place: some regulator, or litigation resulted in Chase having to provide an "opt out", and they fulfilled their requirement by making it a mail-in form to discourage opt-out. If the harm persists then consumer advocates, elected representatives, and regulators can take another crack at it.

Educating people to be wary and careful with personal information is trickier. It's hard enough to spot a very well crafted spear-phishing attack, even when you know better and are generally vigilante. I don't know how else to deal with that except hyper-vigilance, and yes "this behavior is wrong in all circumstances, period," But again, I guess I'm weighing that risk higher than you are.

Re: Chase did a bad thing, so we did a good thing

#214

Earlier quoted context omitted.

Good points and I appreciate what you write here. And an interesting business concept - to help consumers pursue individual arbitrations. That could be really cool especially against large corporations when they are abusive. What do you charge as people go through their individual arbitration process/ how does the profit model work? I really have mixed feelings about the legal system - on Also, Radvocate, wondering i…

Hi, thanks for the response. On the business model – we charge a commission currently set at 15% of whatever compensation you recover. Hopefully that's from a negotiated settlement with the company before a full arbitration process is necessary. (More details at bottom). We currently process against 20+ cable / ISP / wireless companies. Re: PII, first I want to make clear that I can't speak with legal standing about…

I don't think you've come close to adequately addressing the PII issue here. The information you're collecting, if it ends up in the wrong hands, could lead to some nightmarish identity theft.

Surely you're aware of massive and prevalent data breaches[1]. You're collecting sensitive information to help people, but not providing any convincing bonafides on information security, let alone an actual plan for how sensitive information goes in your web form, then (many technical/logistical steps later) ends up in Chase's P.O. box, without leaking out to some unintended party. I don't think anyone should feel comfortable with "all we plan to store is an e-mail address"

1 - https://haveibeenpwned.com/

Re: Chase did a bad thing, so we did a good thing

#215
post #205

Earlier quoted context omitted.

I'd love to see HN or Reddit or someone work with the feds on how to investigate and prosecute astroturfing/sockpuppets/shilling, perhaps as unauthorized computer access and/or fraud.

Except it's not really unauthorized access if the owner of the account allows you to publish in his/her name, is it?

I suspect lawyers could figure out the ToS so that it is.

Re: Chase did a bad thing, so we did a good thing

#216
post #205

Earlier quoted context omitted.

This sort of activity and behavior is common on sites like reddit. It's used by media companies and brands, especially as the reach is much bigger than HN comments. Astroturfing is big business and can be very profitable. An account itself isn't worth much, it's the overall execution that matters.

I'd love to see HN or Reddit or someone work with the feds on how to investigate and prosecute astroturfing/sockpuppets/shilling, perhaps as unauthorized computer access and/or fraud.

Astroturfing and shilling isn’t illegal. Unless an account was hacked, no crime has been committed. Even lying generally isn’t a crime. In terms of fraud, there has to be a determination of unlawful gain or to deprive a victim of a legal right. Astroturfing isn’t fraud, nor is shilling.

Re: Chase did a bad thing, so we did a good thing

#217
post #215

Earlier quoted context omitted.

Except it's not really unauthorized access if the owner of the account allows you to publish in his/her name, is it?

I suspect lawyers could figure out the ToS so that it is.

That wouldn’t be “criminal” — a TOS violation isn’t “prosecuted” as its civil. And, the aggrieved party would have to prove actual damages.

Re: Chase did a bad thing, so we did a good thing

#218

Earlier quoted context omitted.

Good points and I appreciate what you write here. And an interesting business concept - to help consumers pursue individual arbitrations. That could be really cool especially against large corporations when they are abusive. What do you charge as people go through their individual arbitration process/ how does the profit model work? I really have mixed feelings about the legal system - on Also, Radvocate, wondering i…

Hi, thanks for the response. On the business model – we charge a commission currently set at 15% of whatever compensation you recover. Hopefully that's from a negotiated settlement with the company before a full arbitration process is necessary. (More details at bottom). We currently process against 20+ cable / ISP / wireless companies. Re: PII, first I want to make clear that I can't speak with legal standing about…

I am not sure why I want to sue Chase. I bank with them and they have provided the agreed services. What exactly has Chase done to harm someone like me? If I don’t like something they do, I simply bank elsewhere.

Re: Chase did a bad thing, so we did a good thing

#219
post #29

Assuming that you're completely legit and utterly competent, there's still a big security problem here: it's encouraging people to put their PII and CC info into arbitrary Web sites . On top of that, it's further identifying them as both Chase CC holders and receptive to scams, qualifying them as leads for further phishing/scamming.

Unfortunately this is the problem that Chase created ... we give users a way to download a form letter instead, but were just trying to make it as easy as possible for customers to opt out if they would like to do so

Chase didn’t set up a website asking for account numbers. So how did Chase create this problem? What exactly have they done wrong? If someone disagrees with the policy, they can opt-out, so what’s the problem that causes someone to need to give a bank account number to a random website? Why not just disclose in big letters what the site is all about: lead generation for a law firm? This isn’t some kind of “we like to help people,” project any more than ambulance chasers seek “justice.” There is a place for lawsuits certainly, but let’s not pretend this is about “helping,” it’s about lead generation.
Post reply on HN