Live data from Hacker News

“Privacy”.com–Yeah Right

ersei.net

71–80 of 172 posts

Re: “Privacy”.com–Yeah Right

#71
post #53

Earlier quoted context omitted.

The name is doublespeak and not concerned with privacy as an ideal, it's really just to manage CCs in a sane way, like using a CC once and then disposing of it so you don't get unexpected charges. Also it limits the blast radius if a vendor gets breached and your legal name is not exposed. (So you need to sacrifice your privacy to privacy.com to get privacy on other vendors). They need to rebrand as 'SaneCard' or som…

No, they don't. One of the main features is being able to put in any billing information you want and they'll accept it. Typically a bank will validate the name and sometimes the address against your account on file. Privacy ignores it. This IS a privacy enhancement in many cases.

Nope. You have to go through KYC with them, give them your address, last 4 of social, dob, and yes, I got stuck on identity check too. Just because it didn't happen to you, doesn't mean it doesn't exist.

Re: “Privacy”.com–Yeah Right

#72
post #54

In defense of Privacy.com, they've helped prevent me from being defrauded multiple times. I use them any time I'm buying from a website where I don't trust they will keep my CC secure (like paying local utility bills). Sure enough someone tried to use my one-time-use utility card multiple times. Once they charged it for 16 cents which how card runners test the cards to see if they are valid. Normally those won't show…

> Normally those won't show up on any alerts you may have, because most banks don't alert below $1.

My Chase credit card is set to text me on any charge over $0. I have received alerts for under a dollar.

Also, I have been using a credit card extensively for 20 years, and I don’t take many precautions (other than having text alerts for all purchases). I will put that number anywhere I want to buy something without even thinking about it.

I have had many fraud ATTEMPTS over the years, but I have never once lost money because of it. Having to change my credit card number has been annoying, but I am not sure it has been more annoying than it would be if I had to use a different number for every purchase.

Re: “Privacy”.com–Yeah Right

#73
post #65

Earlier quoted context omitted.

Not directly at fault? Privacy.com chose to use Onfido. I don't think the author's complaint is misplaced.

Using a company and having proper contracts and agreements with them to be properly protected is not malice, especially since the company is well known and assumedly adheres to regulation. I'm not sure what you want privacy.com to do differently.

I think the ask was pretty clear: not to share confidential identification information with sketchy companies that are clearly sharing that information with everyone.

Re: “Privacy”.com–Yeah Right

#74
post #3

Privacy.com is not about hiding your identity from authorities. It's mostly about hiding the fact that the same person, you, are paying to merchant A and merchant B. It allows you to easily have a card per merchant, and lock it to the merchant so that when its number is stolen, it can't be used anywhere else. The domain name is a bit lofty, yes.

Yeah, my main use of Privacy.com has been with web payment portals that look old/unmaintained or otherwise untrustworthy (surprisingly common with state government sites).

If there’s a better option for this use case I’m all ears, though. Reading sibling comments that Privacy won’t actually stop charges past set limits is disconcerting.

Re: “Privacy”.com–Yeah Right

#75
post #63

Earlier quoted context omitted.

Phishing generally means "pretend to be X to get user's info/credentials for X", do you have a different definition?

Phishing is typically tricking an individual into divulging sensitive information. Credential stealing is typical, but still a subset. Plaid uses banking credentials on a user's behalf. Yes, it's similar to using stolen credentials because... it's the same thing, except consent, audits, insurance, etc. all play a role whereas with criminal activity they do not.

This seems to be some weird semantic angle where because Plaid is audited that makes what they're doing not phishing? I'm not sure I agree with that definition or that it is particularly common.

That said, if it makes you feel better, pretend my comment read "Plaid pretends to be the users' banks in order to trick users into giving Plaid their bank credentials and stores those credentials without their knowledge or consent".

Re: “Privacy”.com–Yeah Right

#76

Earlier quoted context omitted.

I think their growth numbers would have looked much differently if they had transparently disclosed the reality on their login form from day one: “Plaid will store your plaintext password and use it to periodically access your bank account.” Burying truth deep in a TOS is seen by some as deceptive.

why can't banks have oath like authentication so this BS doesnt happen?

because there are close to 20000 of them in the US, and while chase has the resources to do oauth properly, not every junky credit union can afford that

Re: “Privacy”.com–Yeah Right

#77
post #53

Earlier quoted context omitted.

No, they don't. One of the main features is being able to put in any billing information you want and they'll accept it. Typically a bank will validate the name and sometimes the address against your account on file. Privacy ignores it. This IS a privacy enhancement in many cases.

Nope. You have to go through KYC with them, give them your address, last 4 of social, dob, and yes, I got stuck on identity check too. Just because it didn't happen to you, doesn't mean it doesn't exist.

You misread my comment. When I check out on a website using a card generated by Privacy.com, I can put any billing information into the checkout form on the site.

Re: “Privacy”.com–Yeah Right

#78
post #8
post #3

Privacy.com is not about hiding your identity from authorities. It's mostly about hiding the fact that the same person, you, are paying to merchant A and merchant B. It allows you to easily have a card per merchant, and lock it to the merchant so that when its number is stolen, it can't be used anywhere else. The domain name is a bit lofty, yes.

Author here. My concern wasn't that Privacy.com knows who is using their service, but with rather how they choose to know that information through a third party (Onfido) and how terrible Onfido's privacy policy is.

Recently I've signed up with Paddle, and they have opted to verify user identities with Onfido, so they have asked for a government ID and a selfie. I have contacted Paddle and refused to provide a selfie, so they eventually asked me to upload my ID too in place of a selfie and manually approved the submission.

Paddle has no excuse for collecting selfies, they are providing services to businesses that can be verified in more humane and secure ways, such as an electronic signature.

Verifying people with selfies is a degrading and insecure practice, especially when you encounter Onfido during the installation process of a bank's app that you already have an account with, opened in person at a local branch in the EU. This bank also asks you to create a video of yourself and submit your speech to configure their mobile banking app. I'm sure the data will be useful for someone when Onfido eventually gets hacked, or just sells your biometric data.

My hope is that biometric data collection for online account verification will become illegal once all EU member states have intoduced electronic IDs which have an NFC chip. The verification should consist of a person holding their ID next to their phone, and the online service would only receive the minimum amount of personal data to complete the verification.

Re: “Privacy”.com–Yeah Right

#79
post #65

Earlier quoted context omitted.

Using a company and having proper contracts and agreements with them to be properly protected is not malice, especially since the company is well known and assumedly adheres to regulation. I'm not sure what you want privacy.com to do differently.

I think the ask was pretty clear: not to share confidential identification information with sketchy companies that are clearly sharing that information with everyone.

So you're saying Privacy should reinvent the wheel with an incredibly difficult, terrible-to-manage process, itself requiring an entire company worth of people and a huge support staff, laden with insane amounts of red tape, just to perform a small function of their business, instead of contracting out another company that specializes in doing this exact thing?

This seems like a larger security/privacy surface area than the latter approach.

Re: “Privacy”.com–Yeah Right

#80
post #52
post #8

Earlier quoted context omitted.

Author here. My concern wasn't that Privacy.com knows who is using their service, but with rather how they choose to know that information through a third party (Onfido) and how terrible Onfido's privacy policy is.

Then why drop a steaming pile of shit on the company who's not directly at fault via the title? For clickbait? I've used privacy.com for years. Never had an issue. Never had to validate my identity. Never had any issues with support. If used as prescribed (setting limits on cards etc) it fits in directly to where it belongs in my threat model. What a strangely charged article.

[deleted]
Post reply on HN