5 ms·
I feel frequent data leaks, credit card number leaks, difficulty in un-subscribing or stopping payments after subscribing, etc... makes me appreciate and want t
by manzanarama 3y ago
I feel frequent data leaks, credit card number leaks, difficulty in un-subscribing or stopping payments after subscribing, etc... makes me appreciate and want to use consolidated sign in / subscription management / payment management options almost exclusively.
- bryanlarsen 3y agoUntil there's a breach of the SSO providers, like the Okta incident.
- gunapologist99 3y agoOkta, Lastpass, Jumpcloud, Authy, Auth0.. the list of hacked SSO providers gets longer by the day.
- anononaut 3y agoDIY or die
- toyg 3y agoIt's a bit like keeping money... You can stash it under your mattress, hoping you'll never suffer a burglary; or you can give it to a bank, and let them spend money on security and insurance. This said, banks have specific fiduciary responsibilities and the above-mentioned insurance, which compensate for the big target they're painting on their own backs; whereas most tech services, even massive ones, tend to hide behind service agreements boiling down to "eh, if it happens it happens, nothing we can do, sucks to be you". Unless they're in healthcare, they're barely required to disclose whether they've been breached, let alone compensate us for the loss of privacy and increased risk of identity fraud that we endure. Maybe it's time for the legislator to define "personal data providers" a bit more rigorously.
- thfuran 3y ago>and increased risk of identity fraud that we endure. The problem is even worse than that. The whole framing of the issue of identity theft as a thing that happens to a person rather than a bank is problematic. That the bank issued credit in my name to someone other than me really should be entirely their problem, not one that probably messes up my life for years.
- _heimdall 3y agoThe bigger difference between a mattress and a bank is that a mattress can't create new money or operate on a fractional reserve system.
- toyg 3y agoSure, but that's not why banks were originally invented.
- systems_glitch 3y agoYeah those services offering one-time or service/vendor specific CC #s for total management are probably going to have a bright and profitable future.
- phpisthebest 3y agoUntil the banks, and credit card companies just offer the services themselves for cheaper... Like Capital One and I think Discover are already doing
- systems_glitch 3y agoYeah but the banks will screw it up somehow :P
- staplers 3y agoCapital One had per-transaction CC#'s for a bit but eventually just went to a single "virtual card" number.
- phpisthebest 3y agoI have taken to using a single card in person, and a single card online. The Card on use online is also a Capital One account so I make use of their Eno service to make virtual cards for every vendor If some company does not want to unsub me, I just turn off that virtual card.
- Modified3019 3y agoI do the same with privacy.com, along with a unique email via fastmail’s masked email feature.
- 2OEH8eoCRo0 3y agoApple can be hacked like anyone else.
- Retric 3y agoShared passwords place you at risk if any of serval services are hacked. Password managers provide similar convenience with a smaller attack surface. I’ve defaulted to picking random passwords for most services which I don’t bother to remember instead using password resets. But it’s inconvenient.
- shiandow 3y agoThat doesn't do much to protect you against a website storing government mandated passport information. The only protection there would be if authorities stop demanding that everyone takes copies of personal IDs.
- staplers 3y agoif authorities stop demanding that everyone takes copies of personal IDs They're actually considering the opposite for social media.
- hhh 3y agoNo it's not. Some of the stuff https://decodeproject.eu/ https://decodeproject.eu/ has been working on seems apt for this, specifically the attribute based credentials stuff.
- systems_glitch 3y agoYeah, when did that become acceptable?! I've had a bunch of sites request a photo or scan of my state-issued driver's license, like that's just OK to ask people to send to them.
- hhh 3y agoWhen courts started requiring it.
- hosteur 3y agoBanks KYC practices normalized this.
- systems_glitch 3y agoI have no problem showing ID to my local bank though. They at most photocopy it and put it in a paper file, which maybe goes into Docstar or something. I don't trust $big_tech_site to actually a) do a good job securing it and b) not just sell the information to someone anyway. It's silly. AT&T wanted it from me to add a phone on a business account that was shipping to our physical address, which has not ever changed since the account was opened. eBay wanted it (and my SSN! and my wife's!) despite our account being a business account registered with an EIN and connected to a business bank account. Instagram/Facebook/Meta/whatever wanted it to reactivate a dormant account that talked to a still-valid email address to which I had access.
- hiccuphippo 3y agoYes. Why wait to get p0wn3d one account at a time when they can p0wn all your accounts at once.