Live data from Hacker News

Didn’t Homejoy Shut Down?

medium.com

321–330 of 361 posts

Re: Didn’t Homejoy Shut Down?

#321

I'm one of the founders of Homejoy. I'm still very passionate about the home service space. After leaving Homejoy, I started FlyMaids, where we're exploring a few different angles on the space. We recently acquired the customer and service provider data from Homejoy. We're a small team that has been focused on moving quickly while bootstraping. We tried to quickly test different approaches, but we realize now that we…

I wanted to follow up and address some concerns mentioned in this thread, and acknowledge that I definitely made mistakes. How did you get my information? We acquired Homejoy’s domain and customer information through an ABC process. Our intention is to improve and then relaunch Homejoy’s cleaning service. We were testing a new model using Fly Maids, one of our testing brands. As evidenced today, we made some mistakes…

Instead of posting the opt-out link on hn, shouldn't you send that out to all the former Homejoy users which were just emailed?

Re: Didn’t Homejoy Shut Down?

#322

Earlier quoted context omitted.

That's the head office of Nortons accountants, who I'd imagine are handling the liquidation. Changing the registered address is normal. http://www.nortonsgroup.com/uk/global-offices

The liquidators have the power to dispose of the assets as they wish, in an attempt to return as much money to creditors (and the taxman) as possible. It's entirely possible that they've decided to try and keep some parts of the company active and have outsourced the dev work to a shady 3rd party. Alternatively they might be moving the sellable assets into a separate company which can itself be sold soon/later. Odds…

In the UK the liquidators hold the assets in a kind of trust. It is their responsibility to try and liquidate the assets to return money to the creditors.

In my case one of our founders purchased the domain name and the "good will of the company", and continued to run the company under that name as a "trading name". The actual company entity going forward was completely different.

Re: Didn’t Homejoy Shut Down?

#323

What's the big deal? Homejoy is just hacking startup downfunding... (/s) I'd like to see some kind of stronger YC influence on ethics in the companies they fund. I realize that YC doesn't have any direct control over the companies, but it could be as simple as including good ethics in the traits they look for in startup founders. A while back I started compiling a list of YC companies that spammed or otherwise behave…

I'd like to see some kind of stronger YC influence on ethics in the companies they fund. Great idea, maybe you should take that up with Paul "Morally, [the founders we want to fund] care about getting the big questions right, but not about observing proprieties. That's why I'd use the word naughty rather than evil." Graham.

You say "lying", I say "exploring a few different angles on communication" /s

Re: Didn’t Homejoy Shut Down?

#324

I'm one of the founders of Homejoy. I'm still very passionate about the home service space. After leaving Homejoy, I started FlyMaids, where we're exploring a few different angles on the space. We recently acquired the customer and service provider data from Homejoy. We're a small team that has been focused on moving quickly while bootstraping. We tried to quickly test different approaches, but we realize now that we…

Thanks for clarifying what is going on. For me, however, the weasel-worded "we realize now that we did so in an unclear manner" is completely different than "we realize now we made a big mistake".

See the marvellous http://www.mcsweeneys.net/articles/an-interactive-guide-to-a... (discussed here at https://news.ycombinator.com/item?id=10449660)

Re: Didn’t Homejoy Shut Down?

#325
post #318

Earlier quoted context omitted.

That could just be the last four digits. When you create a token with Stripe, you do still get those back. Conceivably, they're showing 12 asterisks and the naked last four, while retaining the token Homejoy used with you so they can recharge -- although in order to do that, they would need Homejoy's Stripe API secret.

The last four digits are still plenty sensitive enough to make serving them over http blatantly irresponsible.

It's not just that - it allows you to update your credit card over unencrypted http.

Re: Didn’t Homejoy Shut Down?

#326

I'm one of the founders of Homejoy. I'm still very passionate about the home service space. After leaving Homejoy, I started FlyMaids, where we're exploring a few different angles on the space. We recently acquired the customer and service provider data from Homejoy. We're a small team that has been focused on moving quickly while bootstraping. We tried to quickly test different approaches, but we realize now that we…

I wanted to follow up and address some concerns mentioned in this thread, and acknowledge that I definitely made mistakes. How did you get my information? We acquired Homejoy’s domain and customer information through an ABC process. Our intention is to improve and then relaunch Homejoy’s cleaning service. We were testing a new model using Fly Maids, one of our testing brands. As evidenced today, we made some mistakes…

Uh! This is making things worse, not better!!!!

1. You now acknowledge you intentionally lied to customers by saying you were redirecting them to a "partner", but it's the same company under a different name.

2. You don't hold that data under a payment provider like Stripe, and yet you claim to have PCI-DSS compliance but are violating it and risking a lot of customer credit card data!

You now say you have deleted that data, but how are we meant to believe you? Where was that data stored? Locally or with Stripe? Why didn't you encrypt it?

How did you "acquire Homejoy’s domain and customer information through an ABC process"? How does that even work?!

Re: Didn’t Homejoy Shut Down?

#327
post #203

Earlier quoted context omitted.

If they were using stripe how did they pass details through onto HTTP? as far as I remember their webhook won't even communicate with an unsecure page. They must be using some other payment gateway.

I sure hope they don't gather the data via calls to Stripe's API then push it out via HTTP (and vice versa!)

Oh brother - surely they weren't storing that data themselves?!?

Re: Didn’t Homejoy Shut Down?

#328

Oh that's not shady at all. Assuming all this is legal (I doubt it, but hypothetically) how is this a good marketing tactic? Having all this info already stored comes off as way more creepy than convenient as evidenced by the author of the article. And yeah, I can't see this being legal in a thousand years.

> Having all this info already stored comes off as way more creepy than convenient as evidenced by the author of the article. If you're used to thinking about this from our side of things, sure. For Random Person, they might think, "gee, this is neat! And they've already got my card number and everything!"

No, random person thinks what we all think: "how the hell did they get my credit card details?!?!"

Re: Didn’t Homejoy Shut Down?

#329
post #320
post #278

Honest question, how is this #11 right now with 901 points? It's below a story with 199 points that was posted an hour before.

It must have been heavily flagged. It's been lower than it should have been from the start. Admittedly the title of the submission isn't great so - if I'm being charitable - it's because users flagged based on title only.

It's been on the front page for hours now.

Re: Didn’t Homejoy Shut Down?

#330

Earlier quoted context omitted.

But it is secure information. If I recall, last 4 digits were part of how the CIA chief's e-mail was hacked recently.

No, it's not secure information. Any time you use last-4 as something secure, you're doing it wrong. As mentioned above, last-4 is sent by email frequently, and email passes, unencrypted, through intermediate servers all over the Internet. Any compromised host can observe all of the email that passes through it. Any process that uses last-4 to unlock a password or otherwise as a secure token is broken by design.

Any time you use last-4 as something secure, you're doing it wrong.

It's not a question of what I use those digits for, it's a question of what everyone else uses them for.

Post reply on HN