Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Privacy.com is not about hiding your identity from authorities.

It's mostly about hiding the fact that the same person, you, are paying to merchant A and merchant B. It allows you to easily have a card per merchant, and lock it to the merchant so that when its number is stolen, it can't be used anywhere else.

The domain name is a bit lofty, yes.



>It allows you to easily have a card per merchant, and lock it to the merchant so that when its number is stolen, it can't be used anywhere else.

In my experience even that can fail. I had a card number stolen from them, charged to the tune of $200+, and their support refused to even entertain the idea of it being fraud, and when I mentioned a chargeback they basically said "we don't do those, because we have contracts with vendors."

A payment stop at the bank sure worked though.


>I had a card number stolen from them, charged to the tune of $200+

I'm curious, how did this happen specifically? In my experience, all privacy.com virtual cards default to being merchant-locked to the first place you use them. Did the merchant run an unauthorized transaction on the card?

I've had online payment info compromised once, and privacy.com caught it cold (and also clearly demonstrated that the vendor had mishandled the payment info, despite claiming otherwise).


Honestly no clue, different vendor than the card was setup for.

This was during a big wave of unauthorized activity being attempted on their cards as well, a lot of friends reported blocked charges for random amounts at like a retirement/hospice home(?) at the time.

This was like 3+ years ago, and my only guess now (read: can't remember if this is true) is that the card had never been charged to the merchant, only pre-authed. But even then I'd expect the pre-auth to lock it to a merchant.


Interesting, looks like there was some kind of attack on privacy.com in 2020[0] that caused transactions to be run from vendors without them.

0. https://blog.privacy.com/a-different-type-of-card-fraud-anat...


Thanks for digging that up! I knew they made a post about it. Didn't notice before that they tried to say they "made (everyone) whole".

Maybe they think that not sending me to collections after I stopped the payment at the bank and closed my account is "being made whole."


Woah, that is concerning. Making it harder, rather than easier, to chargeback fraudulent uses is not what I'm looking for.


> Making it harder, rather than easier, to chargeback fraudulent uses is not what I'm looking for.

Honestly I'm still confused by the whole thing.

I told them that it was a fraudulent transaction that I didn't approve, they then kept asking me for tracking numbers and finally closed the support ticket, and would close any further ones instantly on me with this reply.

https://i.imgur.com/EyjCGiU.png

Never mind the fact that it was a completely separate issue than what they would keep replying to me about, the fact that they included the line of

> At this point, the only possibility is that the shipment was stolen after the delivery. This is no longer a case where the merchant is at fault. Hence, the case would be concluded in the merchant's favor.

is a complete disregard for visa's rules. The fact that they wouldn't even let me open a dispute is the biggest factor of "wtf" here to me.


>is a complete disregard for visa's rules

Visa is probably easier to deal with in the case of fraud than what it sounds like privacy.com is like.

I use a single CC for everything (that I'm willing to pay with a CC for.) It's been compromised to the point that charges went through 2-3 times over the past decade and a half. CC company caught the fraud each time, automatically charged-back each of the fraudulent transactions, and overnighted me a new card. They also moved all of my recurring charges to my new card (somehow.) From what I understand, all of the big 4 CC companies operate more or less the same in this regard.

This thread has eliminated the chance of me using Privacy.com in the future. If they can't make dealing with fraud at least as easy as a regular CC (which is quite painless, there's no reason to use them.


I have never had to actually pay for any fraud, the bank's fraud detection alwasy catches it, it's never even showed up on my bill.

But I end up having to cancel and get a new credit or debit card about once a year. And this actually is really inconvenient, when you think of all the places you have stored a CC that have to be updated.

I guess my bank doesn't do automatic updates of any recurring subscriptions, I've always had to deal with it manually. (And in charitable contributions, amazon, paypal, stripe, grubhub, etc etc etc).

That was making me consider privacy.com instead... but if I'm doing it cause of that fraud inconvenience, which right now is just an inconvenience which I have no worry whatsoever would result in actual $$ (cause it's happened so many times now and it's never even been a threat), and switching to privacy.com may eliminate having to update card numbers everywhere when fraud happens but actually increases my risk of actually being out the $$ (or increases the amount of time I have to spend dealing or fighting with customer service or fraud recovery support anywhere) -- forget it.


> They also moved all of my recurring charges to my new card (somehow.)

If you're curious about how this works, read up on "Visa Account Updater".


Any way to deactivate that feature?


Hey @flutas, I'm sorry to hear about your experience. Send me a note at rachel@lithic.com and I'll look into this further for you.


As somebody who doesn't use any of these services, your request for somebody to contact you at a lithic.com address in response to concerns about privacy.com issues is uh.... well, it reads like the 3rd slide in a corporate SCORM annual "phishing awareness" training.


hey jimmy grapes, sorry to hear you had a bad experience with a Lithic employee. Please email us at lithic@gmail.com with your SSN and mothers maiden name and we'll have this dealt with shortly


Lithic is our parent company - you can also drop me a line at rachel@privacy.com. Both end up in the same space. If you interested in reading more about the rebrand and difference in the two business feel free to check out this blog post: https://blog.privacy.com/our-journey-from-privacy-com-to-lit...


They rebranded to lithic from privacy last year.


Author here.

My concern wasn't that Privacy.com knows who is using their service, but with rather how they choose to know that information through a third party (Onfido) and how terrible Onfido's privacy policy is.


Recently I've signed up with Paddle, and they have opted to verify user identities with Onfido, so they have asked for a government ID and a selfie. I have contacted Paddle and refused to provide a selfie, so they eventually asked me to upload my ID too in place of a selfie and manually approved the submission.

Paddle has no excuse for collecting selfies, they are providing services to businesses that can be verified in more humane and secure ways, such as an electronic signature.

Verifying people with selfies is a degrading and insecure practice, especially when you encounter Onfido during the installation process of a bank's app that you already have an account with, opened in person at a local branch in the EU. This bank also asks you to create a video of yourself and submit your speech to configure their mobile banking app. I'm sure the data will be useful for someone when Onfido eventually gets hacked, or just sells your biometric data.

My hope is that biometric data collection for online account verification will become illegal once all EU member states have intoduced electronic IDs which have an NFC chip. The verification should consist of a person holding their ID next to their phone, and the online service would only receive the minimum amount of personal data to complete the verification.


This is not how it works. Your NFC ID card establishes that a person that looks like X is named Y. That’s fine, that’s what we get, just less reliably, from a photo of your passport. You will still need to smile for the camera to establish that a) you look sufficiently close to X and b) you appear to be a live human being (as opposed to a photo being held to the camera)

The image of your face and the image (NFC capture) of your ID are stored to prove to auditors that you were indeed verified to required standards.

No one wants your mugshot, it’s a legal requirement they are having to satisfy.


Selfies are collected by a limited number of companies because it is a convenient way to satisfy KYC, but it is by no means legally required to collect this biometric data, nor is it secure to verify customers this way thanks to the proliferation of AI.

KYC checks are already being tested with electronic IDs, and the identity of the customer is verified by the presence of a government ID, and the input of a PIN. No selfies or similar farces are involved.


Maybe you should quote the whole thing instead of making it sound like they sell the data?

"As part of a business transfer. Onfido may disclose your personal information to an actual or potential buyer, investor or partner (and its agents and advisers) in relation to any actual or proposed divestiture, merger, acquisition, joint venture, bankruptcy, dissolution, reorganization, or any other similar transaction or proceeding"


I agree with you but the thing is I don't remember doing any of that stuff to use privacy.com. I hope they just changed their policy and that I haven't forgotten about uploading identification and photos of myself. I normally would not tolerate that.

All I remember is using the plaid bank API which is itself probably very dangerous and a poor decision to allow.


Then why drop a steaming pile of shit on the company who's not directly at fault via the title? For clickbait?

I've used privacy.com for years. Never had an issue. Never had to validate my identity. Never had any issues with support. If used as prescribed (setting limits on cards etc) it fits in directly to where it belongs in my threat model.

What a strangely charged article.


Not directly at fault? Privacy.com chose to use Onfido. I don't think the author's complaint is misplaced.


Using a company and having proper contracts and agreements with them to be properly protected is not malice, especially since the company is well known and assumedly adheres to regulation.

I'm not sure what you want privacy.com to do differently.


I think the ask was pretty clear: not to share confidential identification information with sketchy companies that are clearly sharing that information with everyone.


So you're saying Privacy should reinvent the wheel with an incredibly difficult, terrible-to-manage process, itself requiring an entire company worth of people and a huge support staff, laden with insane amounts of red tape, just to perform a small function of their business, instead of contracting out another company that specializes in doing this exact thing?

This seems like a larger security/privacy surface area than the latter approach.


OP's original point is that a company marketing themselves as a privacy tool are forcing customers to use a 3rd party for processing very personal identification data. That 3rd parties TOS, which binds customers of privacy.com, says they can and will share data with anyone they want for any reason. That's nearly the antithesis of the privacy the company is marketing itself on.

Privacy.com don't have to use Onfido, there are other options out there. There could be a myriad of reasons why they chose Onfido over the competition but the TOS bind the privacy.com users and they don't offer any alternative.

For a company leaning on "privacy" as their primary marketing tool, this is a double standard. It doesn't mean Privacy.com is a bad company with horrible people building a terrible product. They're just calling out a company for doing something seemingly opposite to their marketing, and saying that's why they personally aren't using the product.

You can disagree with OP but doesn't make their point wrong, invalid, or stupid.


No, i didn't say that, nor did the post. You keep making these absurd leaps. Privacy.com advertises themselves as being private. I expect them to be private. They're the ones who chose to hinge 100% of their marketing strategy, all the way down to their name and domain, on how very private they were.


They should just verify identities without selfies, like most payment providers. This trend of using selfies comes from shady crypto companies that were eager to pretend that their users have been verified, while also benefiting from the collected biometric data.


So it wasn't privacy.com who chose Onfido?

If your contractor chooses a bad subcontractor, who do you blame?


Privacy.com is not a contractor, firstly. IMO that's a weak analogy at best. I've asked elsewhere - what do you want privacy.com to do differently?


To use another service to do the user identification or at least to offfer an alternative.


The name is doublespeak and not concerned with privacy as an ideal, it's really just to manage CCs in a sane way, like using a CC once and then disposing of it so you don't get unexpected charges. Also it limits the blast radius if a vendor gets breached and your legal name is not exposed. (So you need to sacrifice your privacy to privacy.com to get privacy on other vendors). They need to rebrand as 'SaneCard' or something similar.


No, they don't. One of the main features is being able to put in any billing information you want and they'll accept it. Typically a bank will validate the name and sometimes the address against your account on file. Privacy ignores it.

This IS a privacy enhancement in many cases.


Nope. You have to go through KYC with them, give them your address, last 4 of social, dob, and yes, I got stuck on identity check too. Just because it didn't happen to you, doesn't mean it doesn't exist.


You misread my comment. When I check out on a website using a card generated by Privacy.com, I can put any billing information into the checkout form on the site.


Huh, I've been using privacy.com and had no idea about this. Thanks! Keeping the blast radius of leaked billing info to privacy.com instead of a myriad of merchants sounds like a good deal.


This. You have to waive your privacy to privacy.com to get privacy on vendors/merchants. If I lived in the US I would happily waive it to privacy.com, since I buy stuff on e-commerce sites a lot. Enough times that I would be pissed if my personal info got leaked. Also being able to manage my card and lock it to specific vendors is sorely needed and should be a feature on all CC providers.


Privacy is not binary though. It's not "either you have complete privacy, or none".


Yeah, my main use of Privacy.com has been with web payment portals that look old/unmaintained or otherwise untrustworthy (surprisingly common with state government sites).

If there’s a better option for this use case I’m all ears, though. Reading sibling comments that Privacy won’t actually stop charges past set limits is disconcerting.


>It's mostly about hiding the fact that the same person, you, are paying to merchant A and merchant B.

What merchants out there are cross-correlating credit card numbers to deanonymize people? Can you even do it in a way that's PCI compliant? If you're actually interested in preventing random merchants from tracking you, I think credit card numbers are the least of your worries. Your billing/shipping information, which is almost always collected is much more revealing about you and can't be anonymized. Given this I do think the name of "privacy".com is misleading. At best it's stopunauthorizedcharges.com.


That's not what it's about. It's the same reason why you use many passwords across all your sites. If one is breached, using privacy.com means your card information is not globally vulnerable to the point you have to get a new card, invalidate all your old ones, worry about personal information being correlated etc.


Back in the GPU scalping-craziness days of covid many online vendors limited purchases to 1 per household and that limit was enforced by full name, zip and billing address. With privacy you could generate one time use cards and use random names and fake apartment numbers in the billing address getting past the limit.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: