4 ms·
The referenced write-up based on the Persona front end code is here: https://vmfunc.re/blog/persona https://vmfunc.re/blog/persona I definitely recommend read
by bri3d 8mo ago
The referenced write-up based on the Persona front end code is here:
https://vmfunc.re/blog/persona https://vmfunc.re/blog/persona
I definitely recommend reading this primary source before drawing conclusions about the code as most of the secondary reporting is quite low quality.
- dunder_cat 8mo agoSeems to be down for me. https://web.archive.org/web/20260220192124/https://vmfunc.re/blog/persona/ https://web.archive.org/web/20260220192124/https://vmfunc.re...
- beacon294 8mo agoIt's up.
- bondarchuk 8mo agoSubmitted 6 days ago but flagged https://news.ycombinator.com/item?id=47059129 https://news.ycombinator.com/item?id=47059129 @dang can this get a second chance?
- vincnetas 8mo agodamn. why did the website stole my audio?
- pavel_lishin 8mo agoSome of the most interesting authors in tech on the internet have just absolute awful websites. Blinking animations everywhere, weird sounds, "cute" little javascript animations like it's 1999 again.
- john_strinlai 8mo agothe last time the website was submitted, over half the comments talked about website design instead of the actual content. we can probably skip doing it again. different people have different tastes. people complain about boring websites, people complain about websites with animations or colors. the only guarantee is that the conversation isnt interesting. if you are on the side that doesnt like music, animations, whatever, i recommend a combination of noscript and using reader mode.
- Larrikin 8mo agoThe layout and design is a matter of taste. I actually find websites like OP refreshing to see. Blasting music or sound on auto play when you aren't directly navigating to audio or video content is just rude. It's the same as playing your speaker on the subway.
- rezonant 8mo agoThis is my problem with it. Put in a mute button if you're going to do this, otherwise it's just user hostile. No problem with stylized websites and fun animations.
- rezonant 8mo agoWhy not use your main account to post this, unless you mean it was submitted less than 4 days ago when your account was created? Genuinely curious what benefit a fresh account gives you here?
- john_strinlai 8mo ago>unless you mean it was submitted less than 4 days ago maybe you are unaware, but you can browse HN without an account, and you can browse previous submissions (years back, even!). its not like i can only see posts made in the last 4 days. second, i saw the original post because it was posted in this very comment chain we are on, 5 hours ago, by bondarchuk (https://news.ycombinator.com/item?id=47137961 https://news.ycombinator.com/item?id=47137961). my turn! what is your comment trying to accomplish by cross-examining me about something completely unrelated? what point are you trying to make? if you think my comment is wrong, you should talk about the contents of the comment, not the age of my account.
- fuddle 8mo agoYeah, come on! I'm trying to watch a video and read the article!
- vincnetas 8mo agoyeah no. i was listening to background music of my choice while browsing the internet.
- dgxyz 8mo agoGood article but the web site gave me eye and ear cancer. Please make it actually readable and don't steal my audio!
- BoredPositron 8mo ago[flagged]
- dgxyz 8mo agoReading mode doesn't work on Safari for me... I get a paragraph and sod all else. So respectfully, do not make assumptions. And if you want someone to read the content, don't surround it with shite.
- BoredPositron 8mo ago[flagged]
- dgxyz 8mo agoI didn't flag it. I wouldn't unless the content was problematic, which it is not!
- righthand 8mo agoThere is more than “unique web design” that cause reading issues with that article. For one the lowercase and as well as arcane keywords and organization. Not mention the autoplay music. I have communicated this to the author and they shrugged it off.
- BoredPositron 8mo ago>> Please don't complain about tangential annoyances—e.g. article or website formats, name collisions, or back-button breakage. They're too common to be interesting.
- nebezb 8mo agoI read it and, maybe it’s because I’ve spent too much time in fintech, I don’t share most of the concerns. The differences in proclaimed data retention periods is concerning though. The rest is par for the course for KYC/AML.
- boppo1 8mo agoTell me more before I doom about this too much.
- nebezb 8mo agoAny time you interact with the financial services industry in a meaningful way, they are doing almost exactly all of these checks on you. It is mandated by law, and they're overseen by FINTRAC in Canada and FinCEN in US. When you applied for a bank account for your freelancing business (or startup idea), some people googled you, looked for PEPs (politically exposed persons) in your family, stored photos of your IDs and probably even printed them off, and sent everything in a nice package to some "risk" department. Who knows how that department is handling your data. The only difference is that Persona is trying to put a front-end on it and selling the process as a SaaS. Look up "KYC/KYB saas" and you'll find hundreds of businesses doing this (including, of course, Persona). edit: I want to emphasize that this isn't restricted to just business banking. Poor wording on my part. Lots of industries are legally mandated to conduct KYC/IDV. Notaries do it in home sales, your stock brokerage is doing it, employers in regulated industries do it to everyone on payroll. The list is very long. Unfortunately... The government should take on responsibility for KYC imo, instead of letting 100 vendors come up with their own solutions. But that would probably have some nasty externalities.
- bri3d 8mo agoI agree; I didn't want to editorialize too much as I think the writeup stands on its own. My takeaway was that in this case, even an author with a clear and extreme bias against this sort of thing could find only unfortunately-common bad practices rather than deeply nefarious intent. Of course, this is just the front-end code, but this just looks like a KYC platform to me. Most of the secondary reports on this write-up seem to completely ignore section 0x13 and jump to the specific conclusions the author does not draw. The fact that we've created a system where Discord need and want a KYC platform is a different and quite strange thing, but the KYC platform itself just looks like what it says on the tin.
- tofuahdude 8mo agoThat was a great read, very interesting!
- deleted 8mo ago[deleted]
- cloverich 8mo agoNote also there's a direct response from Persona's security team here[1], and a lot of back and forth from Rick on Twitter[2]. [1]: https://withpersona.com/blog/post-incident-review-source-map-exposure-non-production-subdomain https://withpersona.com/blog/post-incident-review-source-map... [2]: https://x.com/Persona_IDV/status/2025048195773198385?s=20 https://x.com/Persona_IDV/status/2025048195773198385?s=20
- nailer 8mo ago> About the name: The subdomain was called onyx, a reference to the Pokémon Onix (a Pokémon made of multiple boulders, fitting for a multi-node architecture). It was an informal codename chosen by the engineer. It had no connection whatsoever to Fivecast ONYX, an unrelated 3rd party commercial product previously used by ICE. We understand this coincidence caused confusion, and we address it further below.
- UqWBcuFx6NV4r 8mo agoThe fact that this is even being discussed is truly a bad smell of bad-faith “dig up anything that sounds bad” “reporting”
- tharkun__ 8mo agoYeah I'd sorta second that actually. I can't "judge" on everything they say in the blog post. But some things I definitely recognize as "bad-faith". Datadog RUM (browser-intake-datadoghq.com) - real-time user monitoring. every click, every page load - on a FedRAMP platform processing PII and biometrics. Well duh, yes, DataDog does have those capabilities. Doesn't mean you use all of it, just coz you use RUM in general. We also use DataDog and RUM. But we also use filtering, including filtering out the known PII sources we have in our specific case (non-FedRAMP) and we don't have entire session recording enabled for example and we only sample. Yet no mention of that in the post. They just assume that they must be sending PII from a FedRAMP site to DataDog. No proof of what data actually does get sent.
- sghitbyabazooka 8mo ago
- cloverich 8mo agoAnd his follow up here: https://vmfunc.re/blog/persona-2 https://vmfunc.re/blog/persona-2