Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I cannot agree more, I do the same, and invite everyone else to do so.

- Useful as a canary of which website has been breached

- Useful as a canary of which website sold your details

- and if your details are in the wild, you can stop the spam by deleting the address

Credit cards should work the same way: a unique authorization code specific to this vendor or this transaction and useless to any other actor.



Re: credit cards, unless you insist on using debit cards for some reason, who cares if they are compromised.

If someone steals my credit card, AMEX has a problem. I'll take reasonable care, but I'm not going to generate transaction specific numbers or whatever unless there is a strong incentive to do so.


Because it's annoying to constantly get new credit card numbers. You have to update all your autopays. You can't get a new credit card instantly. Being denied due to fraud is embarrassing. You may be out of the country and stuck with a non working credit card. It's another thing to deal with.


I wish that it was much easier to generate temporary credit card numbers for all transactions. Like upon entering real number it would generate one and swap it for you.


I believe that's pretty much what Apple Pay and the like do.


Correct. My android pay says "a virtual number ending in xxxx was used to make this purchase." It would be nice if it was a token instead of an actual credit card number. I have no idea how is implemented.


Many had this feature (and Paypal for a while) but dropped it for some reason. My guess is they want to encourage subscription/repeat billing or some kind of fraud was rampant generating temporary numbers.


and AMEX passes the cost of that problem to all AMEX customers. You are still paying for it in the end.


how so? when a card is fraudulently used to make purchases, AmEx is not refunding you from their own pockets. they take back the money from the merchant it was fraudulently spent with (a chargeback). no loss at all on their side.


Which is then passed on to customers through slightly higher prices for goods.


But there is usually no way to opt out of this. Paying for it and not benefitting from it is lighting money on fire.


not really, prices are based on market demand. the market does not care about fraud issues and such.

whatever the theoretical rise in price would be (due to the fraud), don't you think the merchant would price things at that level in the first place to make extra profit, if they could?


For credit cards, check out privacy.com

I recently started using it, works great.


The fact that they publicize their 32-bit PGP fingerprint on their "security" page does not lend confidence in their security practices. Granted, there's also a link to the full PGP key, but the use of short fingerprints for any purpose should be verboten.

http://www.theregister.co.uk/2016/08/17/pgp_admins_kill_shor...


This looks pretty cool, but seems like they are invite-only for now... Any chance you can drop an invite for a fellow HNer? :)


I've got an invite, contact me via the email in my HN profile and I'll send it over.


I just checked their sign up page, turns out they are only available in the US for now :(

But thanks anyway!


I found an early access code on their twitter: "NETTED". They posted that 1st August, so I'm not sure if it still works, but give it a shot!


Wondering how this works. If one is using different number per transaction where they are getting so many free numbers?


Reading their footer, it says: "The Privacy Visa Card is issued by Customers Bank pursuant to a license from Visa U.S.A. Inc."

So, it seems they have some kind of partnership with a bank, which is able to generate unlimited card numbers for them.


geez, privacy.com, I wonder how much that domain cost.

I'm using a card from getfinal.com, which appears to be the same idea. So far so good, though it's not 100% disposable, I still have a plastic card who's number is no easier to change than a chase card.


Hey! I work at privacy.com - would love to get your thoughts on our product. Hit me up at bo@privacy.com for an invite if you're up for it. I'll tell you how we got the domain :).


Nifty. Discover Card offers this--or at least did when I was using it.


They got rid of it.


Is there a service (email host) that can give you "infinite email aliases"?

(Yes, I know about the '+' in gmail, but I suspect the word is out on it)


You can setup wildcard alias in fastmail (https://fastmail.com) and literally create addresses on the fly when signing up/sharing your email.


Fastmail has a really nice subdomains feature - I have an alias in fastmail of 'shop@mydomain.com'. Any email for XXX@shop.mydomain.com gets delivered to shop+XXX@mydomain.com. Better than catchall, because all the spam gets sent to JohnSmith@mydomain.com, which is dropped.


But you can't delete that alias if you start receiving spam on it, can you?

Also like realemail+alias@gmail.com, this is really transparent to a spammer and gives away the real email.


The benefit it has is that the 'shop.' subdomain can't be guessed from the DNS records. I get a lot of spam to <randomname>@mydomain.com.

Of course, if someone sees my email address, they could certainly infer a new one. But I'll deal with that if and when I get singled out. I don't think the spammers often actually look at the millions of addresses they use.

If I start getting spam on a particular alias, I can set up filtering rules to delete them.


Wow, this is great feature, thanks for the tip! :)


I use Google Apps for Work on my domain, which lets me forward all email to any address on that domain to my inbox. That way I can use adobe@ryanplant.net, github@ryanplant.net, fitbit@ryanplant.net, etc.


I do this exact same trick and have been using it for years. It led to a couple of brief and somewhat awkward phone calls with local business owners when I asked them rather pointedly about them sharing my information with third parties.

I also take this one step further and have inbox rules to automatically send all promotional email (from sites I'm interested in) to the trash folder. If I want a coupon for a website I frequent, I'll just search my trash for the latest offers from that company. Google conveniently purges messages from the trash folder every 30 days or so, and I don't have to worry about a massive backlog of promos.


A Small Orange does this cheerfully, even for the smallest shared hosting plan. You can then go into cPanel to configure a catch-all account for the domain you're using.

Biggest downside to ASO: you have to pay $7/yr extra on domain registrations to make them private. So I register with Hover and host with ASO.




mailhero.io lets you set a username, then anything sent to *.username@mailhero.io is forwarded to an e-mail you choose. It's only somewhat an e-mail host at the moment (added a few weeks ago), and it has stated that the hosting is only temporarily free, but if you already have a host this can give the feature without requiring any form of migration.

There was an HN discussion about it fairly recently, https://news.ycombinator.com/item?id=11781361


The problem is, I have yet to someone who accepts '+' in email address.


"a unique authorization code specific to this vendor or this transaction and useless to any other actor"

Sounds a lot like a bitcoin address.


...except not traceable, works with people's payment systems, sends actual US dollars, and doesn't have a 5% chance of getting stolen.


That's an amazing system you just invented, I wish it existed :-)


Fine, "not traceable by arbitrary people on the Internet".

I know the credit card company and everyone they share your data with can see your transactions, and that's a problem some may wish to avoid, but that is still a much smaller number of people who can see your transactions than Bitcoin. Bitcoin does not inherently include privacy.


I wish phone numbers could work this way. When my personal data gets leaked or sold, just revoke access to that particular token.


> Credit cards should work the same way: a unique authorization code specific to this vendor or this transaction and useless to any other actor.

Isn't that how chip-and-pin works?


Except that the merchant still gets to see my credit card numbers (both sides). But it's how paypal works. The merchant only get an authorization code from paypal, and this code is useless to a hacker.


I also use a Unique-per-service email address with Paypal, and I noticed that Paypal actually passes on that email address to the retailer when I pay with Paypal. I receive order confirmation emails (from those retailers) and quite a few unwanted newsletters to my unique paypal address now.

I have no idea what Paypal is trying to achieve by passing on this fairly personal piece of data. I always have to enter a separate email address with the retailer anyway, and because of this scheme, those two of course never match.


Paypal is great at that kind of unintentional disclosure. Six or eight years back, because I liked what she had to say, I used it to donate to someone who was then speaking under a pseudonym as a result of some fairly credible threats. Imagine my surprise when, in the process of transferring funds, Paypal showed me her full legal name and domicile address in the UI!

Of course I let her know about it, and I seem to recall her saying she'd addressed it successfully, but if she described how, I no longer remember. It quite astonished me that this was even a thing that could happen, though. One hopes it no longer does.


This sounds like she just set up her full name and address with paypal.

It's like her giving out her email address and it being firstname.lastname@gmail.com

I'm not sure the fault lies with the service.


It's been a while, so that might be true and I just don't remember, but it would be a surprising mistake to make for someone with a great deal of professional experience in operational security.


>>>I have no idea what Paypal is trying to achieve by passing on this fairly personal piece of data.

For years the Paypal API sucked, and even today their are many companies that do not have full integration with paypal, so this is a way to match payment records as for 99% of shoppers the email address for the order/account will match the paypal email address.


> the merchant still gets to see my credit card numbers (both sides)

With chip and pin? I don't think they do.


Chip and PIN cards can support tokenization, which prevents the merchant (or anyone who has hacked the merchant) from seeing the card number, but they are not required to do so. I haven't seen any numbers on what fraction of cards use tokenization.

Something to keep in mind is that when chip and PIN was developed to combat credit card fraud it was card present fraud that was the big problem, either by someone using the stolen card itself at a brick and mortar merchant or making a counterfeit cart by writing the stolen number onto a blank card and using that at a brick and mortar merchant. Card not present fraud, where the number is used but not a card such as at an online merchant or a mail order merchant or telephone order merchant, was much less common.

Chip and pin made card present fraud much harder because it was much harder to obtain blank chip cards and the equipment to write a stolen number to them, and it made using an actual stolen card harder because of the PIN.


In the UK the numbers are printed on the receipt - part obfuscated on the customers copy, fully shown on retailer copy. So whilst the retailer may not touch the card they still get everything except the magic 3 digits.

Where I work you need the 3 digit security code and some address numbers (which you can make up) to properly process a transaction without the card.


Yes that's what I said - they don't see both sets of numbers.


Chip and pin is not for online transactions, but in-store transactions. The merchant can see your credit card and would often manipulate it themselves.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: