Live data from Hacker News

“Privacy”.com–Yeah Right

ersei.net

51–60 of 172 posts

Re: “Privacy”.com–Yeah Right

#51
> There must be a way to follow local laws and regulations to prevent financial fraud without violating their privacy to this extent, right?

Sadly no, there really isn't, unless you lobby congress. These laws were written with law enforcement in mind, not privacy.

Re: “Privacy”.com–Yeah Right

#52
post #8
post #3

Privacy.com is not about hiding your identity from authorities. It's mostly about hiding the fact that the same person, you, are paying to merchant A and merchant B. It allows you to easily have a card per merchant, and lock it to the merchant so that when its number is stolen, it can't be used anywhere else. The domain name is a bit lofty, yes.

Author here. My concern wasn't that Privacy.com knows who is using their service, but with rather how they choose to know that information through a third party (Onfido) and how terrible Onfido's privacy policy is.

Then why drop a steaming pile of shit on the company who's not directly at fault via the title? For clickbait?

I've used privacy.com for years. Never had an issue. Never had to validate my identity. Never had any issues with support. If used as prescribed (setting limits on cards etc) it fits in directly to where it belongs in my threat model.

What a strangely charged article.

Re: “Privacy”.com–Yeah Right

#53
post #3

Privacy.com is not about hiding your identity from authorities. It's mostly about hiding the fact that the same person, you, are paying to merchant A and merchant B. It allows you to easily have a card per merchant, and lock it to the merchant so that when its number is stolen, it can't be used anywhere else. The domain name is a bit lofty, yes.

The name is doublespeak and not concerned with privacy as an ideal, it's really just to manage CCs in a sane way, like using a CC once and then disposing of it so you don't get unexpected charges. Also it limits the blast radius if a vendor gets breached and your legal name is not exposed. (So you need to sacrifice your privacy to privacy.com to get privacy on other vendors). They need to rebrand as 'SaneCard' or som…

No, they don't. One of the main features is being able to put in any billing information you want and they'll accept it. Typically a bank will validate the name and sometimes the address against your account on file. Privacy ignores it.

This IS a privacy enhancement in many cases.

Re: “Privacy”.com–Yeah Right

#54
In defense of Privacy.com, they've helped prevent me from being defrauded multiple times. I use them any time I'm buying from a website where I don't trust they will keep my CC secure (like paying local utility bills).

Sure enough someone tried to use my one-time-use utility card multiple times. Once they charged it for 16 cents which how card runners test the cards to see if they are valid. Normally those won't show up on any alerts you may have, because most banks don't alert below $1.

But privacy.com does.

I actually prevented about 1000 stolen cards from being used because I was able to inform the local utility that their database had been breeched before they even knew about it, and they were able to let the CC companies know before the card runners could use them.

Re: “Privacy”.com–Yeah Right

#55
post #46
post #3

Privacy.com is not about hiding your identity from authorities. It's mostly about hiding the fact that the same person, you, are paying to merchant A and merchant B. It allows you to easily have a card per merchant, and lock it to the merchant so that when its number is stolen, it can't be used anywhere else. The domain name is a bit lofty, yes.

>It's mostly about hiding the fact that the same person, you, are paying to merchant A and merchant B. What merchants out there are cross-correlating credit card numbers to deanonymize people? Can you even do it in a way that's PCI compliant? If you're actually interested in preventing random merchants from tracking you, I think credit card numbers are the least of your worries. Your billing/shipping information, whi…

That's not what it's about. It's the same reason why you use many passwords across all your sites. If one is breached, using privacy.com means your card information is not globally vulnerable to the point you have to get a new card, invalidate all your old ones, worry about personal information being correlated etc.

Re: “Privacy”.com–Yeah Right

#56

Sooner or later we're going to need a federal dept of is-this-guy-who-he-says-he-is. No startup can solve this; it's not profitable enough to do right. The last resort for authentication will always be "go to a place and talk to a human" and the gov't is the only entity who is willing/able to staff a brick-and-mortar office in reach of everyone in the country. I know some people are afraid of the feds having a centra…

This is what Notaries are for. Maybe we could find a way to more efficiently utilize their services instead of creating yet another federal agency to intrude on our lives?

Re: “Privacy”.com–Yeah Right

#57

The use of third party KYC services like Onfido is widespread in the cryptocurrency space as well, where over-compliance is the norm right now. Consumers are given little choice as to which provider stewards their ID scans, bank statements, biometric data, etc. This user experience has trained the most vulnerable, non-tech-savvy audiences to provide just about anything requested when asked for ID verification. Includ…

If you think this one is bad: look at Plaid, which literally phishes users bank credentials as "fintech".

"Phishing" does not mean what you think it means. Blame the banks for Plaid's need to exist.

Re: “Privacy”.com–Yeah Right

#58

Sooner or later we're going to need a federal dept of is-this-guy-who-he-says-he-is. No startup can solve this; it's not profitable enough to do right. The last resort for authentication will always be "go to a place and talk to a human" and the gov't is the only entity who is willing/able to staff a brick-and-mortar office in reach of everyone in the country. I know some people are afraid of the feds having a centra…

It's definitely a problem in the US. When setting up an account with treasury.gov there's a good chance you'll have to verify your identity, and the only way to do that is to go to a bank that you do business with that has a "Medallion Guarantee." I wish we could get to the point of having government issued smart cards for verifying identity. I would be elated if my US passport also functioned as a smart card.

Re: “Privacy”.com–Yeah Right

#59
post #6

Earlier quoted context omitted.

“Phishing” implies fraudulent deception.

I think their growth numbers would have looked much differently if they had transparently disclosed the reality on their login form from day one: “Plaid will store your plaintext password and use it to periodically access your bank account.” Burying truth deep in a TOS is seen by some as deceptive.

why can't banks have oath like authentication so this BS doesnt happen?

Re: “Privacy”.com–Yeah Right

#60
post #57

Earlier quoted context omitted.

If you think this one is bad: look at Plaid, which literally phishes users bank credentials as "fintech".

"Phishing" does not mean what you think it means. Blame the banks for Plaid's need to exist.

Phishing generally means "pretend to be X to get user's info/credentials for X", do you have a different definition?
Post reply on HN