9 ms·
I'd like to offer a cautionary tale that involves my experience after seeing this post. First, I tried enabling o3 via OpenRouter since I have credits with the
by 34679 1y ago
I'd like to offer a cautionary tale that involves my experience after seeing this post.
First, I tried enabling o3 via OpenRouter since I have credits with them already. I was met with the following:
"OpenAI requires bringing your own API key to use o3 over the API. Set up here: https://openrouter.ai/settings/integrations https://openrouter.ai/settings/integrations"
So I decided I would buy some API credits with my OpenAI account. I ponied up $20 and started Aider with my new API key set and o3 as the model. I get the following after sending a request:
"litellm.NotFoundError: OpenAIException - Your organization must be verified to use the model `o3`. Please go to: https://platform.openai.com/settings/organization/general https://platform.openai.com/settings/organization/general and click on Verify Organization. If you just verified, it can take up to 15 minutes for access to propagate."
At that point, the frustration was beginning to creep in. I returned to OpenAI and clicked on "Verify Organization". It turns out, "Verify Organization" actually means "Verify Personal Identity With Third Party" because I was given the following:
"To verify this organization, you’ll need to complete an identity check using our partner Persona."
Sigh I click "Start ID Check" and it opens a new tab for their "partner" Persona. The initial fine print says:
"By filling the checkbox below, you consent to Persona, OpenAI’s vendor, collecting, using, and utilizing its service providers to process your biometric information to verify your identity, identify fraud, and conduct quality assurance for Persona’s platform in accordance with its Privacy Policy and OpenAI’s privacy policy. Your biometric information will be stored for no more than 1 year."
OK, so now, we've gone from "I guess I'll give OpenAI a few bucks for API access" to "I need to verify my organization" to "There's no way in hell I'm agreeing to provide biometric data to a 3rd party I've never heard of that's a 'partner' of the largest AI company and Worldcoin founder. How do I get my $20 back?"
- 34679 1y agoFollow-up. I pasted the above into ChatGPT because I genuinely wanted to know how to get my 20 bucks back. That request is in and they say I'll get a response in 2-3 days. I then asked it "What are the potential risks of agreeing to their terms?" Here's the response: Agreeing to Persona’s terms, especially for biometric identity verification, involves both privacy and long-term data security risks. Here’s a clear breakdown of the main risks you should be aware of: 1. Biometric Data Collection Risk: Biometric identifiers (like facial recognition, voiceprints, etc.) are extremely sensitive and irreplaceable if compromised. What they collect: Persona may collect a selfie, video, and metadata, and extract biometric templates from those for facial comparison and liveness detection. If leaked or abused: Unlike passwords, you can't change your face. A future data breach or misuse could lead to permanent identity compromise. 2. Data Storage & Retention Risk: Persona says biometric data is kept for up to one year, but: You’re relying on their internal policies, not a legal guarantee. There’s no technical detail on how securely it’s stored or whether it’s encrypted at rest. Worst-case scenario: Poorly secured biometric templates could be stolen, reused, or matched against other data sets by bad actors or governments. 3. Third-Party Sharing and Surveillance Risks Risk: Your biometric and ID data may be shared with subprocessors (partners/vendors) that you haven’t explicitly vetted. Persona may transfer your data to cloud providers (like AWS, GCP), verification specialists, or fraud prevention services. Depending on jurisdiction, data could be subject to subpoenas, surveillance laws, or government backdoors (especially in the U.S.). 4. Consent Ambiguity & Future Use Risk: The fine print often includes vague consent for "quality assurance", "model improvement", or "fraud detection". This opens the door to retraining algorithms on your biometric data—even if anonymized, that's still a use of your body as data. Their privacy policy may evolve, and new uses of your data could be added later unless you opt out (which may not always be possible). Should You Agree? Only if: You absolutely need the service that requires this verification. You’re aware of the privacy tradeoff and are okay with it. You trust that Persona and its partners won’t misuse your biometric data—even a year down the line. If you’re uneasy about this, you’re not alone. Many developers and privacy advocates refuse to verify with biometrics for non-critical services, and companies like OpenAI are increasingly facing criticism for requiring this.
- stevage 1y agoHuh, I never considered using ChatGPT to read terms of serivce for me. Nice idea.
- nateburke 1y agoI don't recall Persona being in the mix last year when I signed up. Interesting development.
- gwhr 1y agoI think it was a recent thing [1], but I thought they were only considering it [1] https://techcrunch.com/2025/04/13/access-to-future-ai-models-in-openais-api-may-require-a-verified-id/ https://techcrunch.com/2025/04/13/access-to-future-ai-models...
- conradev 1y agoI was more excited by the process, like, there exists a model out there so powerful it requires KYC which, after using it, fair! It found a zero day
- __float 1y agoI think they're probably more concerned about fake accounts and people finding ways to get free stuff.
- abeindoria 1y agoWhat free stuff? It requires a paid API.
- DrammBA 1y agoWith no intention to tarnish your pure world view, paid services with low registration requirements are ideal for account laundering and subscription fraud with stolen credit cards
- conradev 1y agoI actually think they’re worried about foreign actors using it for… - generating synthetic data to train their own models - hacking and exploitation research etc
- gscott 1y agoChina is training their AI models using ChatGPT. They want to stop or slow that down.
- olalonde 1y agoWhy? It seems counterproductive given OpenAI's mission statement: "We are building safe and beneficial AGI, but will also consider our mission fulfilled if our work aids others to achieve this outcome."
- AstroBen 1y agoKYC requirement + OpenAI preserving all logs in the same week?
- mycall 1y agoI think KYC has been beaten by AI agents according to RepliBench [0] as obtaining compute requires KYC which has a high success rate in the graphic. [0] https://www.aisi.gov.uk/work/replibench-measuring-autonomous-replication-capabilities-in-ai-systems https://www.aisi.gov.uk/work/replibench-measuring-autonomous...
- infecto 1y agoKYC has been around for a few months I believe. Whenever they released some of the additional thought logs you had to be verified.
- jjani 1y agoOpenAI introduced this with the public availability of o3, so no. It's also the only LLM provider which has this. What OpenAI has that the others don't is SamA's insatiable thirst for everyone's biometric data.
- leetrout 1y agoI actually contacted the California AG to get a refund from another AI company after they failed to refund me. The AG office followed up and I got my refund. Worth my time to file because we should stop letting companies get away with this stuff where they show up with more requirements after paying. Separately they also do not need my phone number after having my name, address and credit card. Has anyone got info on why they are taking everyone’s phone number?
- jazzyjackson 1y ago(having no insider info:) Because it can be used as a primary key ID across aggregated marketing databases including your voting history / party affiliation, income levels, personality and risk profiles etc etc etc. If a company wants to, and your data hygiene hasn't been tip top, your phone number is a pointer to a ton of intimate if not confidential data. Twitter was fined $150 million for asking for phone numbers under pretense of "protecting your account" or whatever but they actually used it for ad targeting. >> Wednesday's 9th Circuit decision grew out of revelations that between 2013 and 2019, X mistakenly incorporated users' email addresses and phone numbers into an ad platform that allows companies to use their own marketing lists to target ads on the social platform. >> In 2022, the Federal Trade Commission fined X $150 million over the privacy gaffe. >> That same year, Washington resident Glen Morgan brought a class-action complaint against the company. He alleged that the ad-targeting glitch violated a Washington law prohibiting anyone from using “fraudulent, deceptive, or false means” to obtain telephone records of state residents. >> X urged Dimke to dismiss Morgan's complaint for several reasons. Among other arguments, the company argued merely obtaining a user's phone number from him or her doesn't violate the state pretexting law, which refers to telephone “records.” >> “If the legislature meant for 'telephone record' to include something as basic as the user’s own number, it surely would have said as much,” X argued in a written motion. https://www.mediapost.com/publications/article/405501/None https://www.mediapost.com/publications/article/405501/None
- azinman2 1y agoOpenAI doesn’t (currently) sell ads. I really cannot see a world where they’re wanting to sell ads to their API users only? It’s not like you need a phone number to use ChatGPT. To me the obvious example is fraud/abuse protection.
- jiggawatts 1y agoThis is in part "abuse prevention"[1] and in part marketing. Making customers feel like they're signing up to access state secrets makes the models seem more "special". Sama is well known to use these SV marketing tricks, like invite-only access, waiting lists, etc to psychologically manipulate users into thinking they're begging for entry to an exclusive club instead of just swiping a credit card to access an API. Google tried this with Google Plus and Google Wave, failed spectacularly, and have ironically stopped with this idiotic "marketing by blocking potential users". I can access Gemini Pro 2.5 without providing a blood sample or signing parchment in triplicate. [1] Not really though, because a significant percentage of OpenAI's revenue is from spammers and bulk-generation of SOE-optimised garbage. Those are valued customers!
- paulcole 1y agoHN Don’t Hate Marketing Challenge Difficulty: Impossible
- miki123211 1y agoGemini doesn't give you reasoning via API though, at least as far as I'm aware.
- jiggawatts 1y agoWorks for me? Maybe you’re thinking of deep research mode which is web UI only for now.
- jjani 1y agoIf by reasoning you mean showing CoT, Gemini and OA are the same in this regard - neither provides it, not through the UI nor through the API. The "summaries" both provide have zero value and should be treated as non-existent. Anthropic exposes reasoning, which has become a big reason to use them for reasoning tasks over the other two despite their pricing. Rather ironic when the other two have been pushing reasoning much harder.
- finebalance 1y ago
- charliebwrites 1y agoDoesn’t Sam Altman own a crypto currency company [1] that specifically collects biometric data to identify people? Seems familiar… [1] https://www.forbes.com/advisor/investing/cryptocurrency/what-is-worldcoin/ https://www.forbes.com/advisor/investing/cryptocurrency/what...
- jjani 1y agoGP did mention this :) > I've never heard of that's a 'partner' of the largest AI company and Worldcoin founder
- 93po 1y agothe core tech and premise doesnt collect biometric data, but biometric data is collected for training purposes with consent and compensation. There is endless misinformation (willfully and ignorantly) around worldcoin but it is not, at its core, a biometric collection company
- malfist 1y agoCollecting biometrics for training purposes is still collecting biometrics.
- 93po 1y agothe original claim was "it collects biometrics to identify people" and that's just factually wrong. worldcoin in general is not about identification, in fact it's specifically designed to not identify people. its only purpose is to verify "does this private key have an association to any hash that was created after we scanned a unique set of human retinas". it cant even tell you which retinas it's associated with - the data simply doesn't exist
- coderatlarge 1y agothis reminds me of how broadcom maintains the “free” tier of vmware.
- teruakohatu 1y agoCan you explain? Is it not actually free?
- coderatlarge 1y agothere are so many non-functional websites and signups required to get to the end of the rainbow that any sane person quits well before getting to any freely distributed software, if, in fact, there still is some.
- lesostep 1y agoI actually can confirm that there is a bit of a software at the end of the tunnel! Got my free VMware that way. Then again, I also beat QT out of The Qt Company, so I'm pretty determent in that regard.
- coderatlarge 1y agothat’s amazing and deserves at least a blog post documenting that it is possible and how long it takes e2e…
- 5Qn8mNbc2FNCiVV 1y agoThis feels eerily similar to a post I've read a within the last month. Either I'm having a deja vu, it's a coincidence that the same exact story is mentioned or theres something else going on
- bgwalter 1y agoWhat should be going on? A regular Google search for "openai persona verify organization" shows withpersona.com in the second search result.
- 5Qn8mNbc2FNCiVV 1y agoYeah ok guess I misremembered it a bit but I was curious too and found the previous one I've thought of: https://news.ycombinator.com/item?id=43795406 https://news.ycombinator.com/item?id=43795406
- Barbing 1y agoGood eye! In this case, complaints are numerous. See a web search for: openai persona verification site:community[.]openai[.]com e.g. a thread with 36 posts beginning Apr 13: "OpenAI Non-Announcement: Requiring identity card verification for access to new API models and capabilities" But always good to be on look out for shenanigans :)
- Retric 1y agoThis is OpenAI’s fairly dystopian process, so the exact same thing happens to lots of people.
- verisimi 1y agoIt's a concerted attempt to de-anonymise the internet. Corporate entities are jostling for position as id authorities.
- xboxnolifes 1y agoThis is just the process for OpenAI. It's the same process I went through as well.
- bratao 1y agoYou are even luck to be able to verify. Mine give me an error about "Session expired" for months!! Support do not reply.
- Marsymars 1y agoOh I also recently got locked out of my linkedin account until I supply data to Persona. (So I’m remaining locked out of my linkedin account.)
- fakedang 1y agoAs someone not in the US, I do a straight nope out whenever I see a Persona request. I advise everyone else to do the same. Afaik, it's used by LinkedIn and Doordash too.
- ddtaylor 1y agoI also am using OpenRouter because OpenAI isn't a great fit for me. I also stopped using OpenAI because they expire your API credits even if you don't use them. Yeah, it's only $10, but I'm not spending another dime with them.
- cedws 1y agoAfter how long do they expire?
- zeograd 1y agoIIRC, 1 year
- 0xdeafbeef 1y agoSame for anthropic
- bonki 1y agoI wonder if they do this everywhere, in certain jurisdictions this is illegal.
- cactusplant7374 1y agoThat is so sleezy.
- johnnyyyy 1y agothen you shouldn’t use OpenRouter. ToS: 4.2 Credit Expiration; Auto Recharge OpenRouter reserves the right to expire unused credits three hundred sixty-five (365) days after purchase
- numlocked 1y agoHi - I'm the COO of OpenRouter. In practice we don't expire the credits, but have to reserve the right to, or else we have a uncapped liability literally forever. Can't operate that way :) Everyone who issues credits on a platform has to have some way of expiring them. It's not a profit center for us, or part of our P&L; just a protection we have to have.
- csomar 1y ago> How do I get my $20 back? Contact support and ask for a refund. Then a charge back.
- lakomen 1y ago[dead]
- cess11 1y agoI suspect their data collection might not be legal in the EU. https://withpersona.com/legal/privacy-policy https://withpersona.com/legal/privacy-policy To me it looks like an extremely aggressive data pump.
- wqaatwt 1y agoThere are stories about e.g. Hetzner requiring all sorts of data from people who want to open/verify accounts so perhaps not. Might just be an anti “money laundering” thing. Especially if the credit card company ends up refunding everything..
- 7bit 1y agoWhat stories? Can you back up that claim with some sources please?
- TiredOfLife 1y agohttps://www.reddit.com/r/hetzner/search?q=id https://www.reddit.com/r/hetzner/search?q=id
- 7bit 1y agoThat's not a source and it is not my responsibility to backup the claims you made. That is yours. If you don't have any sources, and admit to just saying things that are not probable, I can also live with that.
- wqaatwt 1y agoWhat’s the source on OpenAI doing the same? How is it anymore legitimate in anyway? Which kind of would make the entire “discussion” moot and pointless
- wut42 1y agoHetzner is famously notorious for this, but not enough for publications to pick up this. So by your definitions, YEARS of people talking about their experiences with this is nothing?
- askl 1y agoCrazy, I already gave up registering for chatgpt because they asked for my phone number. I'm not giving that to any random startup.
- gloosx 1y ago>ID Check Just send them a random passport photo from the Internet, what's the deal? Probably they are just vibe-verifying the photo with "Is it legit passport?" prompt anyways.
- sneak 1y agoIt requires video and an app. They are collecting facial biometrics.
- gloosx 1y agoApp? So you cannot verify without a mobile phone?
- _joel 1y agoI think modern face verification has moved on, it's been video in all my encounters.
- gloosx 1y agostill no real human is involved, as they mention their verification is automated and prohabilistic — which is especially funny to hear in context of verification. Im pretty sure even a kid can go around it, e.g. on the video showing a photo of a person holding his passport which you can find online.
- sneak 1y agoYeah, same. I am a paying API customer but I am not doing biometric KYC to talk to a bot.
- baq 1y agoMeanwhile the FSB and Mossad happily generate fake identities on demand.
- romanovcode 1y agoThe whole point of identity verification is for the same Mossad to gather your complete profile and everything else they can from OpenAI. Since Mossad and CIA is essentially one organization they already do it, 100%.
- belter 1y agoWith all this plus the saving of all chats they can't operate on the EU. But they do ....
- verisimi 1y ago> OK, so now, we've gone from "I guess I'll give OpenAI a few bucks for API access" to "I need to verify my organization" to "There's no way in hell I'm agreeing to provide biometric data to a 3rd party I've never heard of that's a 'partner' of the largest AI company and Worldcoin founder. How do I get my $20 back?" This should be illegal. How many are going to do the same as you, but then think that the effort/time/hassle they would waste to try to get their money back would not be worth it? At which point you've effectively donated money to a corp that implements anti-consumer anti-patterns.
- shmoogy 1y agoI was excited about trying o3 for my apps but I'm not doing this validation.. thanks for the heads up.
- righthand 1y agoThank you for reminding me why I’ll never touch these LLM services.
- predkambrij 1y agoInteresting, it works for me through openrouter, without configured openai integration. Although, I have openai account and did verification with openai before. Conspiricy theory would say that they are exchanging PII so openrouter knows who am I :)
- exceptione 1y agoWelcome to tech dystopia. Hello Human Resource, we have all your data, please upload your bio-metric identity, as well as your personal thoughts. Building the next phase of a corporate totalitarian state, thank you for your cooperation.
- _345 1y agoo3 is really powerful. I understand it tbh. They don't want scammers and abusers easily accessing it