15 ms·
“Privacy”.com–Yeah Right
- RVRX 4y agoThey actually don't let me use my primary email as they specifically don't allow accounts to use a Yandex email. They said the reasoning was to prevent non-US citizens from creating accounts, and that I would have to use another email address...
- buildbuildbuild 4y agoThe use of third party KYC services like Onfido is widespread in the cryptocurrency space as well, where over-compliance is the norm right now. Consumers are given little choice as to which provider stewards their ID scans, bank statements, biometric data, etc. This user experience has trained the most vulnerable, non-tech-savvy audiences to provide just about anything requested when asked for ID verification. Including to phishers. If you push back too hard against arbitrary, invasive KYC requests, you start down a path towards becoming unbanked. The USA is badly in need of modern consumer privacy regulations.
- cmeacham98 4y agoIf you think this one is bad: look at Plaid, which literally phishes users bank credentials as "fintech".
- anamexis 4y ago“Phishing” implies fraudulent deception.
- buildbuildbuild 4y agoI think their growth numbers would have looked much differently if they had transparently disclosed the reality on their login form from day one: “Plaid will store your plaintext password and use it to periodically access your bank account.” Burying truth deep in a TOS is seen by some as deceptive.
- jefftk 4y agoI doubt this would have affected signups that much: most people interested in their service don't care much. (Though instead of "access", which could imply "take money out" to some people, they'd probably use a more descriptive term)
- PainfullyNormal 4y ago> “Plaid will store your plaintext password and use it to periodically access your bank account.” That's terrifying. I'm looking into privacy.com as an alternative to using my real debit card number online because it gets stolen at least once a year. Having my bank account itself compromised does not sound like an improvement. Then again, how often do banks get hacked and have their credentials compromised? At least as often.
- dawnerd 4y agoI believe plaid has oauth integration with the larger banks now. I remember using it with chase and chase showing me an auth and permission approval request screen.
- 2Gkashmiri 4y agowhy can't banks have oath like authentication so this BS doesnt happen?
- twelve40 4y agobecause there are close to 20000 of them in the US, and while chase has the resources to do oauth properly, not every junky credit union can afford that
- jrochkind1 4y agoFew/no small credit unions (or banks) have their own bespoke online portal they developed just for them. They use a vendor. I bet a few vendors would cover a pretty large % of those 20K banks.
- cmeacham98 4y agoI believe they've improved it now, but their login page literally used to say "Plaid" nowhere, and at least for my bank (Bank of America) looked almost identical to the official login. Here's an example: https://d1hzvs60s6jsjg.cloudfront.net/IMAGES-1/208624076/plaid3.png https://d1hzvs60s6jsjg.cloudfront.net/IMAGES-1/208624076/pla... Does this look like it's going to be shipping your credentials off to be stored by a third party?
- edgineer 4y agoLast I checked, privacy.com uses Plaid, too. When privacy.com had asked me to use Plaid to add a payment method, Plaid's privacy policy talked of gathering transaction information and using it for advertising among other things. I think Plaid's stance was that if the host service (the one asking you to use Plaid) wanted to be invasive then it's up to them, or if this host would be upstanding and maintain your privacy, that could happen, too. It was up to the customer to check their policies. But this limitation was not spelled out nor promised that I could see. Their policy may have changed since then.
- junon 4y ago"Phishing" does not mean what you think it means. Blame the banks for Plaid's need to exist.
- cmeacham98 4y agoPhishing generally means "pretend to be X to get user's info/credentials for X", do you have a different definition?
- junon 4y agoPhishing is typically tricking an individual into divulging sensitive information. Credential stealing is typical, but still a subset. Plaid uses banking credentials on a user's behalf. Yes, it's similar to using stolen credentials because... it's the same thing, except consent, audits, insurance, etc. all play a role whereas with criminal activity they do not.
- cmeacham98 4y agoThis seems to be some weird semantic angle where because Plaid is audited that makes what they're doing not phishing? I'm not sure I agree with that definition or that it is particularly common. That said, if it makes you feel better, pretend my comment read "Plaid pretends to be the users' banks in order to trick users into giving Plaid their bank credentials and stores those credentials without their knowledge or consent".
- junon 4y agoThat is the definition of phishing. This is why "vishing" is "voice phishing", etc. Phishing is stealing information. It's not a "semantic angle" - it's the definition of phishing. You're free to consulting a dictionary to fact check me. Plaid is not phishing, by any true definition of the word.
- cmeacham98 4y ago
- collegeburner 4y agoahahahaha man who do you think is the one who added all this KYC shit and who scares companies into over compliance... and you want more regulation as a solution. we could start by removing all KYC requirements and fighting crime as crime instead of imputing some criminality to a financial transaction. like even if it's part of a criminal enterprise the transaction itself isn't the "wrong" part.
- jcz_nz 4y agoUmm. Removing KYC requirements just makes it easier to launder dirty money. Why would we do that? As it is the US is considered a safe-heaven for dirty money - google South Dakota trusts. “Fighting crime as crime” is meaningless.
- collegeburner 4y agoumm removing KYC requirements also allows people to transact privately. yes bad people can do bad things with freedom, news at 5. i'm aware of south dakota trusts and intend to use one in the next few years to protect my assets and operate privately. fighting crime as crime isn't meaningless, it's how we're supposed to do things.
- jcz_nz 4y agoLol no. Your desire to avoid taxes is not a “right”, it’s a criminal intent. Oh, and newsflash - a SD trust is an absolute red flag, and will just mark you for “Enhanced Due Diligence”, where you will be asked to prove the source of funds. And chances are that info will be then shared with your local financial crimes agency - and without your knowledge. And if you think your lawyer or accountant don’t make those reports… heh.
- nine_k 4y agoPrivacy.com is not about hiding your identity from authorities. It's mostly about hiding the fact that the same person, you, are paying to merchant A and merchant B. It allows you to easily have a card per merchant, and lock it to the merchant so that when its number is stolen, it can't be used anywhere else. The domain name is a bit lofty, yes.
- DerekBickerton 4y agoThe name is doublespeak and not concerned with privacy as an ideal, it's really just to manage CCs in a sane way, like using a CC once and then disposing of it so you don't get unexpected charges. Also it limits the blast radius if a vendor gets breached and your legal name is not exposed. (So you need to sacrifice your privacy to privacy.com to get privacy on other vendors). They need to rebrand as 'SaneCard' or something similar.
- junon 4y agoNo, they don't. One of the main features is being able to put in any billing information you want and they'll accept it. Typically a bank will validate the name and sometimes the address against your account on file. Privacy ignores it. This IS a privacy enhancement in many cases.
- twelve40 4y agoNope. You have to go through KYC with them, give them your address, last 4 of social, dob, and yes, I got stuck on identity check too. Just because it didn't happen to you, doesn't mean it doesn't exist.
- junon 4y agoYou misread my comment. When I check out on a website using a card generated by Privacy.com, I can put any billing information into the checkout form on the site.
- ramesh31 4y agoPrivacy.com was a perfect expression of “Your business is our feature”. Practically every major card issuer provides native virtual numbers now.
- rectang 4y agoHow does one go about getting such numbers? Do a web search for "$BANK_NAME virtual credit card number"?
- nathancahill 4y agoReally? Visa/MasterCard/Amex have Click To Pay but it's on the merchant to offer it. This is the opposite of Privacy.com where the customer can choose to use it.
- public_defender 4y ago1) I have three different major credit cards and none of them have this feature. Your comment is still true in the abstract though, so I hope the amex product team is reading. 2) For a knowledgeable consumer, there is huge incentive to use services like this to prevent the credit companies from being a single point of financial data aggregation. But—and here I guess I'm talking to amex again—if disposable or per-merchant card numbers are widely offered by card providers, I'd expect most people would just use those instead of a more robust provider like privacy.com.
- zcmack 4y agoi have quite a few credit cards and haven't seen this feature on a single one. discover eliminated this feature years back.
- groovybits 4y agoYounger audiences may not remember, but yes: major card providers used provide virtual card numbers back in the day. This is a feature of the past, and most providers don't do it anymore. The only one I know of is Capital One's Eno: https://www.capitalone.com/digital/eno/virtual-card-numbers/ https://www.capitalone.com/digital/eno/virtual-card-numbers/
- jqpabc123 4y agoThe first step to getting an account at privacy.com is to surrender your privacy --- including private access to your bank account login credentials. To paraphrase Nancy Reagan, "Just say no".
- nopenopenopeno 4y agoIt would have been funnier if they used privacy.org. I never expected them to provide any privacy of any sort, but I don’t think they could make matters worse. Privacy.com has been extremely convenient for me, private or otherwise.
- volandovengo 4y agoPrivacy.com is a great service. I use them all the time to generate 1 time use card numbers for sites & then cancel the card so they cannot mysteriously charge me. I've been with them for years & their CEO is a wonderful & smart person. When you're allowing strangers to perform financial transactions - you're taking on risk that the money that is sent needs to actually be funded. They need to conform to KYC laws like all fintech providers - so yes, they will require knowing a little bit about you to operate in the United States like all financial institutions.
- hirundo 4y agoThat part is fine. The part that isn't is where they require you to give your personal information to a third party who has very weak controls on how they share it. Your endorsement makes me interested in trying the service, but I have the same "nope" reaction to the non-privacy as the author of this post.
- vorpalhex 4y agoKYC does not require the use of sketchy 3rd parties who leak data like a sieve.
- fillskills 4y agoWhat makes you think OnFido is sketchy? It’s a pretty popular platform for ID verification. 3rd party verification has become a standard in the fintech/insuretech industries since its very hard and risky to do KYC on your own. Also personally I don’t trust having all the random companies I transact with maintain my KYC info. At least in theory, the experts at ID verification have strong enough incentives, motivation and expertise to keep my data safe, reducing the attack surface area. Not affiliated with either party.
- lcnPylGDnU4H9OF 4y agoFWIW, they are at least willing to put this in their privacy policy: > Whenever legally possible, we seek to protect the information we share by imposing contractual privacy and security safeguards on the recipient of the information. This is particularly important in cases where the recipient is located in a country that has different or lesser privacy laws than those of the country where the information was originally collected. In some cases, however, it’s not possible for us to do so — for example, when we have a legal obligation to disclose information to a government authority and that government authority isn’t willing to enter into such contractual safeguards.
- INTPenis 4y agoI worked in domain registrations in the early 2000s and it's funny how we used to put stock into what sort of TLD a domain used. Like .com would clearly be a commercial entity, while .org would be more non-profits, open source, public domain and stuff like that. Anyways, they're probably harvesting your payments and selling that info. I've noticed that since the card issuers have such high security requirements, and audits, a lot of little businesses have cropped up who are trying to act as middlemen to your payments. Because they just found a backdoor to getting all your payment history without hacking your card issuer. I believe privacy.com is one such business.
- _8j50 4y agoYou "believe" without any evidence? To the contrary my bank card purchases were resulting in targeted ads but privacy.com cards have not shown any sign of that after using them for over a year.
- bombcar 4y agoBelief kind of implies lack of evidence, more a feeling or a faith, after all.
- _8j50 4y agoI agree in this case
- INTPenis 4y agoYes I believed to be more specific, you've changed that belief with your facts. Thanks. But I still do believe this practice goes on here in Sweden where small businesses are offering services that act as man in the middle between the consumer and the card issuer. And therefore they're able to harvest your transaction data, which is gold.
- solumos 4y agoThat might be true if they weren't also the card issuer[0]. The main way they make money is on interchange, which for a card issuer is a kickback of up to 2% from Visa/Mastercard/etc [1]. [0] - https://techcrunch.com/2021/05/20/privacy-com-rebrands-to-lithic-raises-43m-for-virtual-payment-cards/ https://techcrunch.com/2021/05/20/privacy-com-rebrands-to-li... [1] - https://www.adyen.com/blog/interchange-fees-explained https://www.adyen.com/blog/interchange-fees-explained
- Raed667 4y agoCompanies using Onfido [0], Stripe Identity[1] or other similar services, just want to move the "trust/fraud" problem one layer away without throwing internal resources at it. It is a hard problem, and using a 3rd party service is more cost effective than staffing a department to do manual verification. [0] https://onfido.com https://onfido.com [1] https://stripe.com/en-fr/identity https://stripe.com/en-fr/identity
- _8j50 4y agoAhhh FFS, this post is complaining about third party KYC providers. Give me a break, in what world can you get a visa or mastercard without KYC? They provide privacy not anonymity, payment privacy that is not hiding your identity privacy. Your payments are private. Your payment info can't be easily tracked across the different cards you create. That's it.
- public_defender 4y agoI agree that most of the comments here amount to handwringing (or not understanding what amount of "privacy" is legal), but also, what KYC is really necessary for a company like this? If I understand correctly, all they do is pass through transactions. They don't hold customer deposits or provide credit. Isn't all this third party verification a little much?
- smachiz 4y agoThe point of KYC is to make money laundering harder (and other transactions that the various governments want to track/police). To that extent, yes, they need to be able to show a regulator who was making those transactions. The actual funding source/bank behind them won't see any detail beyond "privacy.com". Any card issuer (or virtual card issuer) has to do this.
- public_defender 4y agoMy point is that privacy doesn't need to do KYC because there is no possibility of the customer evading regulators. Assuming that privacy answers subpoenas, they would be able to give the government detailed transaction info and a bank account which would identify the customer. KYC at this level of abstraction doesn't seem to solve any kind of legal problem. I'm glad to be educated by an expert, though. Edit: A sibling explains a good liability reason for this, which makes sense but would not imply any legal reason.
- smachiz 4y agoHow do you validate that they own the bank accounts if you don't know who the user is?
- tempsy 4y agoI have the Apple credit card. If you just want to generate 1-time credit card numbers to use once it's the best experience imo - can easily do it in the Wallet app. Also lots of these subscription websites now detect card generated from something like a Privacy.com is prepaid and will prevent you from using it which defeats the purpose. Not the case with Apple.
- sholladay 4y agoPrivacy.com also allows setting monthly/yearly spending limits, or even setting the card as single-use. Does Apple have anything like that?
- CharlesW 4y ago> Does Apple have anything like that? Not that I can find, which is why I use Privacy.
- tempsy 4y agoCiti does this.
- tempsy 4y agoNo it’s just the ability to generate new credit card numbers on demand If you want various virtual cards with varying limits I also noticed my Citi card allows me to do this. It’s just a little clunkier but it’s actually more robust than Apple’s feature if you wanted a unique number per website.
- jrochkind1 4y agoOddly, my Citi card does not seem to have this. Guess I need a new card.
- fragmede 4y agoIt's not for all account holders: https://www.cardbenefits.citi.com/Products/Virtual-Account-Numbers https://www.cardbenefits.citi.com/Products/Virtual-Account-N...
- ex3ndr 4y agoOnfido is state of the art service for ID verification and very trustworthy.
- markovbot 4y agoThen why do they have all those incredibly questionable things in their privacy policy? What makes them "trustworthy"? I've never heard of them, but from reading this blog post it seems like yet another evil company trying to suck up PII from unsuspecting victims and sell it.
- Kiro 4y agoAnd that's why you shouldn't trust a random blog. They completely misrepresented that paragraph. Here's the full quote: "As part of a business transfer. Onfido may disclose your personal information to an actual or potential buyer, investor or partner (and its agents and advisers) in relation to any actual or proposed divestiture, merger, acquisition, joint venture, bankruptcy, dissolution, reorganization, or any other similar transaction or proceeding"
- markovbot 4y agohow is that different from what the blogpost said? edit: to be clear, the blog post has listed, among other complaints: > Onfido may disclose your personal information to an actual or potential buyer (note "potential") which you seem to be confirming from your own review of their policy. What did the blog post misrepresent?
- Kiro 4y agoOmitting the context very clearly makes it sound like they sell your personal information, when the paragraph is actually referring to disclosing the data in an M&A transaction. The "buyer" here is not a buyer of data but the buyer of the company. Even you said "from reading this blog post it seems like yet another evil company trying to suck up PII from unsuspecting victims and sell it".
- ineptech 4y agoSooner or later we're going to need a federal dept of is-this-guy-who-he-says-he-is. No startup can solve this; it's not profitable enough to do right. The last resort for authentication will always be "go to a place and talk to a human" and the gov't is the only entity who is willing/able to staff a brick-and-mortar office in reach of everyone in the country. I know some people are afraid of the feds having a centralized and accurate registry of citizens, but the alternative (that every company who takes payments must have their own separate, partial, and inaccurate registry) causes a lot of problems.
- fillskills 4y agoIf you think about it, there is a way this is done already in the real world - using Notaries. Notaries verify your ‘documents’. Not that’s they are experts at sensitive data storage, but there could be something to learn from the ‘distributed’ system of notaries.
- ineptech 4y agoNotaries already exist. The proof that they are not a good solution to this problem is that they're not currently being used to solve it. All the companies doing hokey things like asking people to take a picture of themselves holding their ID and so forth could just start asking them to find a notary instead. AFAIK none of them do and I'm not clear on why you're thinking they would or should.
- fillskills 4y agoYou are right - current notary system may not be optimal for this use case. What I meant to say was that in my understanding, my main issue with 3rd parties such as OnFido etc is my lack in trusting them with my information and secondly storing that info in a central repository. If a bad entity gets access to that database, they now have very detailed information about me. I would rather prefer a decentralized & secure way that can be accesses via an API by companies such as privacy.com etc. The distributed piece is solved by Notaries. Could we learn something from how the notary system works that can be leveraged to build out a modern distributed ID verification system.
- jedberg 4y ago> There must be a way to follow local laws and regulations to prevent financial fraud without violating their privacy to this extent, right? Sadly no, there really isn't, unless you lobby congress. These laws were written with law enforcement in mind, not privacy.
- jedberg 4y agoIn defense of Privacy.com, they've helped prevent me from being defrauded multiple times. I use them any time I'm buying from a website where I don't trust they will keep my CC secure (like paying local utility bills). Sure enough someone tried to use my one-time-use utility card multiple times. Once they charged it for 16 cents which how card runners test the cards to see if they are valid. Normally those won't show up on any alerts you may have, because most banks don't alert below $1. But privacy.com does. I actually prevented about 1000 stolen cards from being used because I was able to inform the local utility that their database had been breeched before they even knew about it, and they were able to let the CC companies know before the card runners could use them.
- borski 4y agoCompletely the same experience here.
- cortesoft 4y ago> Normally those won't show up on any alerts you may have, because most banks don't alert below $1. My Chase credit card is set to text me on any charge over $0. I have received alerts for under a dollar. Also, I have been using a credit card extensively for 20 years, and I don’t take many precautions (other than having text alerts for all purchases). I will put that number anywhere I want to buy something without even thinking about it. I have had many fraud ATTEMPTS over the years, but I have never once lost money because of it. Having to change my credit card number has been annoying, but I am not sure it has been more annoying than it would be if I had to use a different number for every purchase.
- baseballdork 4y agoI think that this is a totally valid approach. I merely prefer using privacy because it locks a card to a vendor and I can set limits (or simply pause a card) per vendor trivially. In fact, this weekend I got a notice from wilsoncombat that their payment processor had been hacked and card info had been leaked, which I had suspected when I received a notification that a charge ($0.15) had been declined on the card I used with them in March. The charge was declined, and I was able to close that card and not have to redo my card info in every place I have a card linked.
- avipars 4y agoMainly about managing debit cards...
- bel_marinaio 4y agoprivacy.com is one of my favorite companies. They have saved me from fraud 2x in 3 years. Then I simply closed that "card" with the click of a button. No need to call my bank, cancel my debit card that I use at ATMs, and wait a week for a new card I don't have to worry about remembering to cancel free subscriptions. I set the card max at $1. This has saved me multiple times from the free trial scams that you need to opt out of. Free trials should be opt in after the trial. Opt out is a scam to trickle money into a company from non customers. They stopped a contractor from charging me over $2k when I specifically told them they needed to tell me how much before charging me. Of course they didnt tell me and tried to run the charge. Privacy put a stop to their BS. It is mostly automatic or easy to set up once you are using Privacy. Some banks have started to offer similar digital card numbers similar to Privacy.
- jiveturkey 4y agoNot starting, this kind of virtual card service has existed long before privacy.com came on the scene.
- aorth 4y agoPrivacy.com is great. I've been using it for years on the free plan. I use short-lived, vendor-specific cards a few times per month. The author is complaining about the service's name not matching their expectation of what the service is supposed to do. I don't think that's fair. The Privacy.com homepage summarizes the service very well in my opinion. You give Privacy.com your financial information so you don't have to give it to a dozen other companies, and you get to control when and how those companies use that information by setting limits on spending or card duration. The author was expecting this to be a cryptocurrency tumbler or what?
- whodev 4y agoI absolutely love Privacy.com for the service they provide. It's fantastic to be able to create a one time use card for a web purchase. I even have one connected to my Walmart app that allows me to pay in store via the QR code.
- notyourneighbor 4y agoLets break this abysmal post down into what appears to be the point: Privacy.com flagged you for some unknown reason and asked you to verify your identity. You learned that Onfido exists and googled the name and (LOL) decided you would spend 45s on Wikipedia and then read a privacy policy written not-for-you, and then post yourself on HN so you can "inform others." Lets not even bother with the fact that flagging for further identification happens at every financial company that exists. People are flagged all the time for a number of reasons dictated by ML/AI that is not always right. "I've never had this happen before." That's not how math works. As I am not a lawyer, I probably missed some more bits as well. We can tell. And you did. You missed the part where you have to read and comprehend more than three or four words at a time. That or you intentionally excluded the pieces that invalidated everything that got you to the front page of HN. I'd wager it's the former. Allow me to do the research you pretended to do: First and foremost, there are regulations on how PCI/PII data can be stored. I'll assume you read about reading about or pretended to read about PCI so I won't go into the details you don't care to understand (but should). Each of Onfido’s and/or Provider’s third-party vendors may have access to the facial scan data When a company hosts with providers like AWS, GCP, etc, those are considered "third party." If you curl the onfido website you can see that it's hosted on S3 (or at least parts of it are). It's very likely that onfido is storing data in S3 which means a third party has access to store the data, make backups, etc. You also excluded THE IMPORTANT PART on previous line that said Onfido securely stores all selfies, videos, photos of identity documents, and facial scan data in an encrypted format. Onfido may disclose your personal information to an actual or potential buyer (note "potential") I'm going to go out on a limb here and assume you've never owned a company who's had an offer to exit. When company A purchases company B they first have to evaluate that business and decide if they want to buy it. Since you think like Twitter I'll clear something up for you: acquisitions don't happen by posting on twitter "I want to buy Twitter." This is a standard bullet point in every privacy policy. When you are approached by a potential buyer you sign a slew of NDA's and other legally binding documentation that prevents any party from sharing the details of the agreement. Believe it or not, startups don't have enough time, money, energy, resources to rewrite every little feature required to run a business. Visa and Mastercard also have their own ways of sharing your private information. Does that also mean to start a privacy focused fintech company you need to write the entire american payment system? Onfido may disclose your personal information... or other third party where we believe disclosure is necessary... to protect your vital interests or those of any other person Jesus Christ. I don't even know how you pieced that together so I'll _actually quote_ the document: To comply with laws. Onfido may disclose your personal information to any competent law enforcement body, regulatory, government agency, court or other third party where we believe disclosure is necessary (i) as a matter of applicable law or regulation, (ii) to exercise, establish or defend our legal rights, or (iii) to protect your vital interests or those of any other person; This is American and guess what: you have to comply with the law. I know in your fantasy world of impotence masquerading as activism you think you can "privacy" your way around it, but guess what? You can't. Any company operating in <insert country> has to comply with the laws. "I use Proton and they are privacy." I'm sure you do, and they're privacy because the laws permit it until they don't. So what do you do? You try to deprive a company who's actively trying to do what you pretend to do with your useless tantrum.
- kornhole 4y agoI use and like the service for what it does. Has anybody found a competing service?
- rachel_lithic 4y agoRachel here, I lead Operations at Privacy.com. Wanted to clarify our data collection and retention process, and our position on privacy. Our goal is to make sure that customer data spends as little time as possible with third-party providers like Onfido. Onfido’s general policy is that they will not save customer data longer than a year but they set up different contractual agreements based on what customers stipulate. We've stipulated that they delete data after 30 days. The "Privacy" in our name is about making sure our customers’ personal and payment information is kept private from merchants and from fraudsters. We offer a financial service that comes with legal and regulatory requirements and we have to gather details like address, social security number, and phone number to authenticate a user’s account. If you know of other KYC providers that have more privacy-forward policies, we’re open to exploring. Happy to discuss more. You can drop me a note at rachel@lithic.com.
- Chalene34 4y ago