PayPal has restricted our account after we invoiced a key containing “ALEP”
twitter.com
twitter.com
I called their support (finding a human to talk to was difficult) to ask for the reason why I would need to give out my mother's birth date. I was asking for other ways I could verify and that I shouldn't be asked to give out someone else's PII. The support person started to become defensive, sarcastically asking "you don't even know your mom's own birthday!?".
I could tell this person saw nothing wrong with the ask and thought I was being intentionally combative. I ended up conceding and giving the information. Since then, I've stopped using PayPal as a payment method.
I always thought this incident strange and have wondered about how their verification method works.
Also, if you bought something at a webshop, why does PayPal know who it's being sent to? They just need to know you and the webshop, don't they? Who the webshop sends it to is between you and the webshop.
Creating fake orders to enable fake reviews for a product to be posted, boosting the product listing.
Buy item from using junk email address and shipping address of person B.
On delivery day, wait near person B's home, and grab the package when UPS delivers it. If person B manages to get to the package first, scammer is only out some time.
Junk email and 3rd party mailing address - harder to track scammer. Of course, this ignores IP address and similar - smart scammer would also use Tor and other tools to obfuscate the online transactions.
Huh?
They (or probably just the form) don't like dots and/or too few characters in the field.
As sibling says you can actually enter anything you want in the "CARDHOLDER NAME" field 99% of times. For years I type "$BANK NAME" or "$BANKNAME CARD" (note the space) there and I never been denied.
With the move to teh chip cards and later to PayPass (which doesn't even transmit your card number in any meaningful way) rendered inclusion of anything viable there meaningless.
> There's something about payments that apparently I consider more "holy" than other things.
WEll there is always some idiot what would make it hard for everyone else. Like web designers who do ahve a very... interesting understanding of the outside world (people with Verylonglastnames-SometimesDoubledUp? living on Cultist Monks Revolution of May 1111 year Street? Don't kid me, they don't exist!). Or admins who made you think twice to enter bullshit in the form because the scary red letters says you would need a national ID to receive the package (and names there and in the receipt should be the same!) only for the courier just give the package and be on his merry way not even bothering to check anything (and sometimes forgetting to take money for the package paid in cash, lol).
For now I only know where you need to give your real (ie printed on the card, not your real one, lolagain) name is when the card data is processed manually. The only country where I know it still exists is US of A, last year friend of mine needed to fill out a PDF form (thankfully electronic without the need to print and send it physically!) to pay for Untappd Business.
I believe in this checkout flow, it kicked me over to PayPal where I could specify the shipping address there. PayPal probably relays the address back to the merchant, akin to checking out with Apple Pay where you specify a shipping address via the Wallet app.
I think instead they were just checking if I looked like I was answering the question confidently or if I looked like I was trying to make things up.
No, it's not, because the buyer has chosen to use PayPal's services for protection, and in order for the merchant to fulfill their end of the deal and also receive PayPal's protection (against chargebacks, disputes, etc) the merchant is required to ship to the address on the order (which PayPal has a record of for verification).
If you offer PayPal as a checkout option, you are required to follow their rules for fulfillment, otherwise you risk losing a PayPal dispute if filed later on.
They play all the games people here report - support reps who are nearly unreachable and who all refuse to read previous communication so everything starts from scratch, randomly just closing the case, etc.
It'd be hilarious if you could torture a paypal exec with their own company's treatment. Put a wheel lock on their car because you claim a similar looking car was stolen on the other side of the country. Refuse to take the lock off their car until they can explain the origin of the car's brandname. Relock the car immediately after unlocking it because they attempted to drive away too soon. Relock it the next time because they didn't drive away soon enough. Lock all of their cars because there's been "too much activity" on their vehicles.
> You’ll need to answer some questions to verify your identity. These questions come from a public database dating back as far as 20 years. They may be about property, places, or people you know. We don’t save or store the questions or answers in our system.
https://www.paypal.com/us/cshelp/article/why-do-i-have-to-co...
Interesting. This would mean that they actually have the data to confirm whether it is correct.
Wait, I need to verify my identity by regurgitating public information about me? However PayPal scraped up that information, an attacker could as well. This is absolutely security theater.
It's not great.
So not my address, but real ones that extended family members lived at. Just not me.
In one case, while, I think, signing up for something that should not have required strong security, I think an online account for a shipper, I was asked for the birth date of a 'relative who lived with me'. Only, she didn't live with me: she was my ex-aunt, who had not spoken to any of us since her divorce when I was around 8, and who had moved out of the house, and out of the state, around two decades before we moved into it. The matching appears to have been entirely based on two people with the same last name having been recorded at the same address at some points over the course of 20 years, with no cross-referencing of other data or whether the dates were at all near each other. And given how common my last name is, it would not have been too surprising to have simply been asked the birth date of a complete stranger.
I actually called the company to find out how to get an account without answering this rather infeasible question, and they pointed out that if I just tried creating an account again, it would ask me a different set of ridiculous questions. I did, and while I don't recall what the questions were, I do recall they were such that a basic search for my name online would have immediately answered them, providing no identity verification whatsoever.
I don’t find that surprising. I’ve hired a private investigator in the past. The amount of data US consumer reporting agencies have goes back decades. They will happily sell it to you as long as you agree not to use data older than regulatory thresholds. Credit reporting tends to have 5-7 year thresholds, so many people think that’s all they have. They keep it for much longer, and just make you agree you won’t use data older than the applicable threshold.
The reports I gotten from my PI have had biographical data going back to the late eighties. They’ve even provided SSNs and DOBs with nothing more than a name and general address match.
You can look up an individual’s salary in Finland online whether they work public sector or not.
It’s all creepy, but like my name on the deed of my house not being a secret is a good thing.
And she definitely has a birthday on her driver’s license now, but I think she might have to look at it to make sure she got it right.
This is what likely triggered it. People that steal PayPal credentials change the shipping address to something other than the address on the PayPal account.
I'm surprised if PayPal expected you to know your recipient's birthday, but "What's your mother's birthday?" would be a common question to verify your identity. They should have moved on to another question if you had a moral objection.
On the other hand, scammers will often ship goods to a nearby address and pick them up off the porch, so verifying that you know your recipient might actually be a fraud countermeasure.
They ask about information related to your identity.
In this case "someone else's" PII is on your birth certificate.
Did they call and ask to verify his listed employment? Naw. They sent me an email with a scan of his whole-ass rental application, complete with SSN and everything, unredacted.
I called them out on it and they completely brushed off my complaints.
A week later I tried logging in again just to see what would happen, and everything was back to normal. I could once again send and receive money as if nothing had ever happened. Needless to say, I took the opportunity to transfer every last dime out of the account.
In the EU, if you revoke their SEPA direct debit permission, they are committing a fraud if they try to pull money, and 99.9999% of companies will not even try. If someone still does it, you can revoke the transaction in your online banking interface, and the company will then have to pay an additional fee to the bank.
Netflix' fraud detection is garbage and someone created an account with random letters, some throwaway email and my bank account. I didn't notice until it was like three months in. For the two later transactions, I could reverse them immediately and the money was back in my account on the next business day.
The other one was outside of that window, but my bank filed a request with their bank and it took forever, but eventually they paid it back. I believe this works for something like 13 months. Beyond that, you could still sue the person (and their bank) who fraudulently debited money out of your account, but you don't get a default win.
So at least in Germany you have about a year to notice.
Experian routinely generates unauthorized credit card charges. The banks know, but they rely too heavily on the credit rating industry to stand up to them.
It was weird. They seemed very confused by the request.
If it's a Core SEPA Direct Debit, there is not the concept of a "signed mandate" but according to the rulebook [1] you have up to 13 months [2] to ask for a Return.
[_sigh_] I've spend so much team reading those rulebooks
[1] https://www.europeanpaymentscouncil.eu/what-we-do/sepa-payme...
[2] "If the request for a Refund concerns an Unauthorised Transaction, a Debtor must present its claim to the Debtor PSP within 13 months of the debit date. [...]"
Just forward them to phishing@paypal.com
> After a review, we decided to permanently limit your account as we found potential risk associated with it.
> You'll not be able to conduct any further business using PayPal.
> Based on this decision, if applicable, you are no longer eligible for PayPal Seller Protection as per our User Agreement. You'll also be charged a High Volume Dispute fee based on your activity for all existing and future cases you receive.
> Any bank or credit card information that's linked to your PayPal account cannot be removed nor can it be added to another account. You can still log in and see your account information but you can't send or receive money.
> If you have funds in your PayPal balance, we'll hold it for up to 180 days. After that period, we'll email you with information on how to access your funds.
> We regret any inconvenience this may cause.
No contact address, no escalation path, only vague rumors on internet forums of voodoo to get the ban lifted by the Paypal gods.
They continue to send me daily emails telling me to link my bank account. Okay!
And then a day or two later I get another email
> My name is YYYY and I work on the PayPal Business team. I am more than happy to assist you with your PayPal onboarding journey.
> So I understand the nature of your request. Could you please provide me with some additional insight to your business by answering the below questions.
And a bunch of generic business area questions (what do you sell, what's your volume, etc). Are you kidding? You open by telling a fellow to get stuffed, then talk about journeys and assisting them?
I don't get how people use this thing.
...so, is there a list of forbidden character combinations one should scan for somewhere? That sounds like a super useful thing to have.
In europe, the UX flow for someone ordering with a credit card goes: Enter cc info -> wait for 3d-secure notification -> click it -> enter passcode and possibly fingerprint as well -> click approve -> wait for the site to send you back from 3d-secure page -> order confirmed
With paypal, this flow, that happens everytime someone buys from your site, even repeat costumers, is reduced to: Click buy with paypal -> possibly login to paypal again -> click "yes i want to pay this" -> order confirmed.
Some sites even make use of paypal's delivery address API and don't even require you to enter it.
It's really a no-contest that costumers using paypal will drop out of the flow at a significantly lower rate than costumers using a card. In some markets, your busines is dead in the water if you decide to not accept paypal.
I'd love to be wrong though, since after reading all this I kind of feel bad for the merchants, but otherwise I'll continue to prefer using paypal.
The issue is that the credit card system is broken. PayPal is a bit less broken from the customer POV. (At least in my country, where if they just removed money from my bank account, I'd go to the police and somebody would likely be arrested - or rather, I'd report to my bank, confident they would go to the police.)
I have no good solution to this either. Fixing the credit card system requires replacing credit cards, and the US will be an enemy of anybody that tries that.
> The issue is that the credit card system is broken
in what way, is it the fees?Trustworthy to whom? The customer doesn't even know who your card processor is.
As a customer, I don't see the fees. But yes, by an eagle-eyes view the amount of inefficiency on the system is a problem too, as is the oligopolization. But those don't get in my mind when I make that kind of choice.
Not that I’m claiming that credit cards are a bastion of security, but could you be more specific?
What rights are you giving up? What inefficiencies do you see?
Too many people generalize specific stories or their own PP experience to all of PP.
This makes me wonder: what's the best way to generate "safe" license keys? Binary feels like an obvious solution (binary keys surely get through virtually all blacklists?) but at the same time: binary license keys would be very long and very atypical, so maybe fraud detection systems mark them as suspicious anyway.
Maybe just generate random alphanum license keys and run them through some open source blacklists yourself? I doubt "ALEP" is in those lists though.
I know you should never underestimate human stupidity but even taking that into account this still feels like security theatre on the part of PayPal.
If someone X is comfortable doing business with/as entity Y but a bank Z is not, it's totally sensible that X would say Y to the bank Z and bank Z would block them.
More importantly, "terrorists" is often used by some governments in reference to protesters or any group that they see as unfriendly to them.
Bottom line is: it happens, but I agree with you that people that know what they are doing are not putting "Pay for assasination by Osama Bin Laden on 03/28/23" in reference field.
Those of us “of a certain age,” will remember the old adage ”To err is human, but it takes a computer to really f*** things up.”
In the library (like the kind with books) field where I work, one identifier standard was devised that intentionally has alternating letters and digits, with never more than two letters in a row. Explicitly for the intention of avoiding the possibility of any meaningful words (that might end up being offensive or just off-putting in an undesirable way.)
It does make the identifiers longer for the same entropy/byte width, compared to a more normal BASE-X with an alphabet. Which mattered to me when they were going to be used in a URL, although probably doesn't for a license key. I personally in my projects stopped using this system for a more straightforward "Ascii-85" like encoding (which can contain coincidental meaningful words), because it was more convenient.
The particular system the library community was using [https://n2t.net/e/noid.html] was, I still think, over-complicated for at least my needs, but the alternating letter/number schema seems attractive to me now and perhaps worth slightly more characters in identifiers and slightly more complex algorithm for creation than a simple base-x encoding.
Some security scanners do check for this kind of thing.
But, sure, it's just one idea. You can add more layers to make it even less likely something will seem problematic to someone somewhere; a 100% guarantee seems impossible, especially if you are going to allow things like above "What if we brainstorm for a way this could be a puzzle where the answer is a problematic word to someone". No "scanner" will even possibly catch every possible thing in that domain, no matter how unlikely.
That's a special kind of evil...
**
Eh. Coming from that environment, it would not be that easy for a reason that has nothing to do with technology. The lists that financial companies use are largely known ( some published by US Treasury for everyone to use ) and you can reasonably estimate a threshold most institutions will find acceptable.
However, the issue is political and not technical. OFAC itself has grown its SDN list[1] to 6300 names and that is just one list and the tool has been already severely overutilized ( in my opinion anyway, so take that with a grain of salt ), but if the trend and current geopolitical situation is any guide, this number will only increase.
What I am saying is that you have a big and very variable base to build a key from ( edit: come to think of it - not from:P ) and there is no guarantee and old key won't suddenly become 'hot'.
Here, the answer is to the problem is actually political. Affected businesses have to start really complaining, if they are affected by the requirements. I have no evidence suggesting that is the case ( based on what I saw maybe 20% of transactions face that kind of scrutiny and even smaller percentage is questioned the way the OP is ). Naturally, it does not help that this process is not standardized so every single financial institution does their own thing..
[1]https://home.treasury.gov/policy-issues/financial-sanctions/...
Regular KYC procedure usually involves using a blacklist of disallowed words, and then if anyone triggers the filter, you block them, and ask them to submit any and all documentation they have for all recent transactions (but importantly, you dont tell them the transaction or word that triggered the check). Someone then reviews the documentation, and unless it explains the blacklisted word, the account ban stands.
>Proven to be scalable to visor applications, the laser protective filter in the Gentex spectacles utilize the latest, most advanced laser eye protection materials developed for and tested by both the NAVAIR and USAF/AFRL advanced technology development and demonstrator programs.
If the Government is creating a list of no-no words (which in itself is violative of the constitution) it should be required to publish them as "Secret Laws" are defacto unconstitutional,
Further the government having a list of words I am not allowed to use, AND not allowed to know I am not allowed to use should be abhorrent to anyone the values freedom
If it were just paypal they absolutely wouldn't care about the subject so much as to match random characters in descriptions, wouldn't give people zero recourse, etc.
If the government or some agency published all the indicators of fraud that it used to check that people were filing their taxes legitimately (and catch crooks), how would you ever conduct anti-fraud operations? Every criminal would have the manual on how to circumvent the detection mechanisms and move to techniques that the IRS doesn't know how to detect.
Should the government equally publish its root passwords because that's within your right to be able to know how the government operates also? That would be ridiculous.
When my wife sent me a message saying, "pick up some sea weed," T-Mobile was blocking it. Fortunately, we transitioned to using iMessages, which resolved that problem.
However, I continue to receive various spam and scam messages - but T-Mobile is not blocking them.
the drugs are what is illegal, not the messages.
"No, they clearly acknowledge their service is used for crime - they block these other messages."
For bonus points, find a case where blocking the 'weed' message got someone killed. (You order drugs, the guy says 'weed on the way' but you don't get the message so you don't meet him, he thinks it's a setup and gets mad ...)
[0] https://www.reddit.com/r/tmobile/comments/h8cotr/tmobile_sil...
[1] https://www.reddit.com/r/tmobile/comments/i1fk1z/tmobile_are...
It's quite fascinating, because I come from a country with an actual official government censor's office. But I've never been blocked from accessing a smutty joke comic here. Yet in the US a major mobile provider takes it upon themselves to do so!
Good that no one uses those crappy SMS services and feed those crap carriers more data.
More info from Twilio: https://support.twilio.com/hc/en-us/articles/360045004974-Fo...
> It can't be 'because it's federally regulated' because that would literally make it a 1st amendment issue.
thats what i was thinking as well... it seems for the us, its mostly about spam prevention and marketing messages (referred to as SHAFT in the link below)...seems not intended for individuals but those messages intended for commerce?
For example, it would violate their industry standards to send messages like 'Cool your thirst! No-ID beer sales in your area, reply now for $5 off your first 12-pack', sent out as a bulk message. But if I just message you saying 'wanna go for a beer later', it's not a commercial message. These guidelines are to prevent spam that might fall in one of the SHAFT categories, not to police communications between private individuals.
How is that even legal...
Thank god I never left any money in there or it would have been stolen. And to this day I still get emails from them as if my account isn't banned, but logging in just takes me straight to the ban notice and I can't actually close it or opt-out of emails.
That's not true. They banned my account when I was below 18 because it's forbidden to have an account for minors, but there was absolutely no problem retrieving the $1000+ that I had.
Even if the account is banned they let you link a bank account and withdraw.
Considering that Zelle is focused on traditional bank-to-bank transfers, probably something pretty sketchy to be banned.
Either you're at a small ISP and paypal doesn't care about a handful of customers that need to dig an email out of the spam folder, or you're at a large one and it won't have an effect because nobody else is reporting it
This doesn't hurt paypal but might annoy a small email hoster that might have to clean up your mess.
People use Paypal because they can't get around it. If you want to hurt them, help reduce their market share. Complain to the support of the service where you needed paypal, asking for better payment options (cite articles like this or whatever). That's what I do anyway, and doubly so when I know the owner. That they need to also offer paypal to get more customers, sure that's their risk (I make sure they're aware of it), but at least offer legit payment options as well
Spam is by definition email users don't want in their inbox.
If you've used a service, even briefly, and willingly given them your email address, and then later get emails from them, that's not spam. Yes, it is super annoying that they automatically sign up your address for marketing, but there is a way to unsubscribe.
There's a second category of unwanted email where unsubscribing has as only effect that you'll get more spam because now they know that your email address is actively being read. The sender is a hacked server or a botnet, and no business is identifiable as sender. This type of illegal activity is what spam filters are designed to combat. You're not helping the designers by marking other email as spam: it muddles the data, causes legit senders trouble (like me, I don't have a newsletter but spam filters are so aggressive that personal messages sent from my server still regularly ends up in spam), and makes everyone's life harder.
Or you culd report it as spam in your email client. Because legal or not, it's still spam.
Can you provide a reference to that definition?
I have checked on merriam-webster, oxfordreference.com, oxfordlearnersdictionaries.com, and wikipedia. None of them include the "from someone you never have had any sort of (business) relationship with" clause. Or even anything which could be read that way.
> Yes, it is super annoying that they automatically sign up your address for marketing
Yes, super annoying. And also spam. If I didn't ask for it it is spam. If they trick you to "agree" to it (for example by having a checkbox where checking the box means you don't want to receive emails) without you realising, that is still spam.
> there is a way to unsubscribe
Sometimes. Doesn't make it any less spammy.
Spam is illegal, but I'm pretty sure none of the mentioned sources make the law about what is and isn't allowed to be sent. Maybe you can find the actual definition in the laws that apply in your jurisdiction.
The law follows the existing understanding of what constitutes spam, just as it does for "murder", "theft", and a myriad of other cases. The law does not define these terms, only how they will be applied within the context of the legal system.
That's, like, the definition of "unsolicited". In the dictionary and everything.
Doesn't matter if there's an unsubscribe link either. It's still fucking spam.
Do they now mark your address as "still active and being read" and send it more messages because it's now more valuable?
Or will you stop getting email from them?
That's the difference between things you should be marking as spam and things that annoy you but are legal and you'll just need to press unsubscribe on (and be careful with whom you give your data to). Write to your representative if you want the law changed on what's legal.
You can also complain to the market authority if an identifiable party sends you unsolicited commercial email outside of the law. If they're not identifiable then it's never legal, and that's what you should classify as spam because spam filters are meant to catch this. A legit business can be held accountable and has an interest in remaining in business, but real spammers aren't so simple to trace down and stop so that's what these filters are meant to do.
Ditto spam. Yes, some of the spam I receive might be within the law. That doesn't stop it being spam though. I could also take the time to write to a politician to try and change the law on what spam is legal and what isn't... or I could just mark it as the spam it is and get on with my day.
> Yes, I could take the time to write to a politician to complain about junk mail, or I could just chuck it in the trash and get on with my day.
What you're suggesting is messing with a spam filter designed to handle illegitimate email to get confused enough to also filter out legitimate emails based on a guess as to whether or not you might want it. You're not "just chunking it in the trash and getting on with your day" but actively harming the system instead.
No, I'm teaching my spam filter about which emails I consider spam, so it knows to automatically filter them out in future. Which is exactly what I want my spam filter to do. That's its job. That's why I installed it.
> You're [...] actively harming the system instead.
Lol.
Same with physical mail, which also explicitly just has an option for "bulk mail", which is even worse. If I could opt out of receiving mail from the USPS entirely, I would. (Although I consider them to be the most reliable service for sending and receiving packages.)
For example, I went to a mechanic, and provided my email address as a way to contact me. I started getting marketing emails from Sirius XM, despite never having interacted with them. Therefore, marked as spam. If Sirius doesn’t want their emails to be marked as spam, they shouldn’t be sending out spam.
Edit: Or, in the case of Walgreens, their "Unsubscribe" link reported that there was no subscription at the email address to which they had just sent an email. For that one, I did give a reply to let them know of the issue, and got no response. When the next one arrived from Walgreens a week later, that was reported as spam.
I might however have misremembered something so please if someone knows, feel free to fill in.
I think in the Netherlands (or EU?) it has to also be one-click. It can't first give you a survey or ask you to enter your data again or other hurdles. It's quite strict in that way, but then quite loose in the way that businesses are allowed to send you unsolicited commercial (e)mail if you previously purchased something and they want to market a related product to you. Win some, lose some. I can see the point, though, that you might be genuinely interested in their new fancy better improved heat camera if you previously bought a heat camera of theirs, and the message still has to have that one-click unsubscribe link. I'm willing to accept this compromise even if I am usually not interested in those offers.
What has to die is the type of spam where you have no idea who the sender is or how they got your data. That's what spam filters are designed to filter out, since you cannot filter that by normal/legal means. It's much harder to try and make a spam filter read your mind on whether email from a legitimate business is something you're interested in reading (you may or may not care for that order confirmation, newsletter that you may or may not have signed up for, etc.).
But I've learned today (from the subthread above) that having the general public make this distinction and correctly train spam filters (such as email, but presumably also on reddit and such) together is a lost cause. We'll have spam forever, yay.
Hence, the "Report Spam" button.
You’re just supposed to sit there and take the unsolicited non-spam from everyone around you and never touch that button ever, or dare call something that doesn’t fit one person’s ridiculously narrow definition of “spam” that.
And if you don’t like it, your inly course of action is obviously talking to your representatives to change the legal definition of spam. Anything else is breaking the system.
/s, for those wondering.
The name "spam" comes from an old Monty Python skit about hearing the same thing over and over and getting sick of it, so this definition doesn't really respect the history of the term. The name spam started as a Usenet moniker some time after some lawyers started trying to get people to pay to enter the free green card lottery run by the US government.
This definition almost sounds like you're gesturing at "UCE" (unsolicited commercial email) which some people started trying to push as a definition for spam back in the day.
> Yes, it is super annoying that they automatically sign up your address for marketing, but there is a way to unsubscribe.
I mean, you're responding in a thread where they mentioned that's impossible to reach that page because they're banned and ignoring that people long ago found that unsubscribe was being abused to confirm (and then sell) verified emails to other spammers.
Some of us do crazy things to let us use unique emails per service, so we can find out who is selling our info.
We've got problems with messages sent to literally millions of people: viagra spam, phishing scams, banking malware, you name it.
There isn't a problem with messages that you don't want to see in your inbox anymore but that are from a legit business where you can unsubscribe. Trying to unsubscribe from real spam just confirms that the email address is active and the message has been read, and now you'll just get more spam and your email address is more valuable. That's very distinct from a legitimate sender.
There's a clear distinction and I'm wondering if we'd have an easier time filtering out the actually bad stuff if people that think like you didn't muddle the data by marking normal email traffic as spam
I see your overall argument, however this dilemma is ultimately caused by PayPal's ruthless/unpredictable ban policy
Or use GDPR or some other legal option if you have time to spare and want to cost them some time=money in dealing with your request.
If it keeps the undesired email from landing in this person's inbox, it certainly sounds like it's helping to me.
Maybe some providers also denylist the sender-receiver pair when you click spam to combat this problem nowadays; back when I used public email services this was rarely the case. Nowadays I use a different system altogether so I don't know if this might now be common.
Either way, this is not what the spam button is for, but from this subthread I see that enough people on HN already don't understand how these systems work (and education is hard: people don't even read relevant oneliners pushed in their face at a relevant time, such as error messages), so I guess there's no hope for the general public altogether. I didn't know this is an entirely lost cause and is making me rethink about reporting spam on platforms like reddit. I guess they get so many false positives that I'm wasting my time reporting anything as spam ever.
> There's a clear distinction and I'm wondering if we'd have an easier time filtering out the actually bad stuff if people that think like you didn't muddle the data by marking normal email traffic as spam
Something tells me that you missed most of the history of dealing with spam, because people used to be naive about this back in the day and spammers exploited the hell out of them by using unsubscribe to confirm that the email was live and similar tricks.
Unwanted is unwanted. It really does vary by person, that much is true, but even your viagra spam is wanted by some people. But the people sending it are very often also doing a lot of shady stuff like running botnets, so the technical measures to stop that look very different from, say, looking up the SPF record for Paypal:
https://mxtoolbox.com/SuperTool.aspx?action=spf%3apaypal.com...
So the short answer is no, people not wanting to get spammed by Paypal isn't likely to get you more viagra ads from botnets. Maybe, just maybe, it could create some small headache for Sendgrid (who is in Paypal's SPF, but is no small player), but I doubt it.
That aside, I think a few of them frequent HN and they can answer that one for themselves if they want to.
> sometimes I wonder if spam is such a big issue in part because users report anything they don't want in their inbox, like a newsletter they previously signed up for, as spam or similar
It's been a problem ever since some green card lottery lawyers decided to spam Usenet and then moved on to using botnets and whatnot while people fought back with DKIM and SPF and such, so I doubt it.
> This doesn't hurt paypal but might annoy a small email hoster that might have to clean up your mess.
It's not clear to me why Paypal would be routing emails through a small email host and most people are using the few big webmail providers at this point.
> If you want to hurt them
I don't think people want to hurt Paypal, they just want to turn off the damn marketing campaign when they're literally banned from the service. Personally, I just set up filters to dump all the junk like the constant emails from Amazon so that I don't have to deal with it.
If they fail, you get paid the fine (not the state)
Source for this?
In my experience, there is actually quite a barrier to this, meaning most situations where you see a GDPR violation are not easy to escalate.
They nominally don't do just anything (like take your money), because they want people to use their service, and if they cheated everyone all the time, you'd hope that people would catch on and stop using their service.
Having said all that, dealing with illegal transactions, fraud and scammers is tough. The corporations will, honestly, make mistakes, and having enough customer service to deal with it all properly is expensive. Hence automated bans. Often there is no recourse except moving towards a lawsuit, which may be unreasonably expensive for most cases, as compared to the money that has been lost.
I'd guess that they'd just not show up, you'd get a judgement, and then just have to figure out how to get it paid. Or maybe they will show up, hire a local lawyer to represent them and point out the fine print in the ToS that forbids holding them accountable for any reason in any venue. And with any luck, the judge will laugh at them and give you treble damages.
Problem is, it's not worth whatever court costs I would probably incur. Granted, there isn't a lawyer involved in small claims, but could they judge order me pay their lawyer fees if I lose?
[0] https://www.federalreserve.gov/paymentsystems/fednow_about.h...
[0] https://www.ftc.gov/business-guidance/resources/can-spam-act...
https://www.law.cornell.edu/wex/inbox/can-spam_and_consumer_...
Seems as though CAN-SPAM has lost its teeth to protect the consumer through precedent if that's not a viable path.
Marketing people please take note of this. It is particularly galling to be continually pestered to buy things from a company that has refused to do business with you. An Intuit company tried to sell me a home mortgage, and I applied, only to be refused because my home was manufactured off-site. OK, I moved on. But they continued to plaster me with offers for that same product almost daily for years, and now my relationship with all Intuit products is as distant as I can manage.
Amazon: Sell your textbooks!
Me: Ok
Now: Amazon: Sell your stuff!
Amazon: You are banned from selling due to inactivity.
Amazon: Sell your stuff!A registered association:
" ALEP e. V. works in the field of youth welfare, especially with disadvantaged, at-risk children, young people and their families."
So maybe PayPal should adjust their block lists.
Do it for the children.
Can an accidental space get you banned for "pago por anal isis"?
WiseTransfer blocked my transfer because they didn't like my full name that they got from Monzo (Mozno has partnership with Wise). They blocked my transfer, hold it hostage until I contacted them, spent a few days hanging on phone, emailed them etc... they wanted to know what my surname means. I made an international transfer to buy a conference ticket. I don't remember the precise dates, but I spent full days on phone, emailing dozens of people and took me 3-4 weeks to revert the transfer. They. wanted. to know. what. my. surname. means.
Edit: I filed a complaint to Monzo and Wise, and stopped using both.
That depends on where you're from. Often in the English-speaking world, they do.
To take the another commenter's example, "Smith" comes from a word meaning, roughly, "craftsperson", as in "blacksmith". The ancestor that the surname comes from was likely either a blacksmith, or some other type of crafter whose profession can be described as "smithing".
https://en.wiktionary.org/wiki/smith
Likewise, the surname "Wright" comes from a word with a similar meaning, as in "playwright", "wheelwright" or "cartwright".
When I meet a "Johnson", my mind immediately goes to "John's son" even though "John" is probably a distant ancestor of the person, not their father. The name's meaning has not changed.
Adoption exists. I'm the first in my patriline to be born with my surname. So yes, technically I am descended from a person with that surname, but my father wasn't.
Also, changing a name on marriage happens.
Most first names mean something as well.
Sure, when the company says "We're banning you and not telling you why. Hahahaha!" it's infuriating, and probably worth even more than an angry Twitter rant. But "Can you explain what this specific thing means?" is not worth the rant IMO. Just explain and go on living your life.
It is unlikely an engineer decided to introduce a block list of names and this likely came from a product manager driven by compliance and risk mitigation. Problems are rarely the cause of the implementer and usually that is the side effect of layers of poor decision making in corporations. Poor because of the aggregation, not poor because of any one specific decision maker in the chain.
But yes anyone who has worked with the list of sanctioned persons circulated by the US government understands what a joke this is. Last time I looked Saddam Hussein was still on it, despite being dead for most of my life at this point. I've also been informed by at least one C-level exec that it was vitally important that we prohibit North Korean internet users from using our website.
Monzo couldn't reverse the transfer as the money wasn't in their hands. Wise Transfer customer support is just garbage. I spent 5 hours on a phone until > their side < ended my call during UK working hours. I called again and again, they never answered. I sent them emails, but each email I was getting was from another person who, like I said in another comment, didn't read previous email from Wise, so each time I had to explain the context and the whole situation. When I sent my response in a morning, they responded the next day afternoon.
> What was the amount of money here?
About £170 for the conference ticket.
>But yes anyone who has worked with the list of sanctioned persons circulated by the US government understands what a joke this is.
I already paid for hotel and plane tickets without issues. Best to my knowledge I'm not involved in any terrorist organisation, unless you account working for EU banking infrastructure company as such.
You don't stand up to a bully just for their initial transgression. You stand up to a bully because if you don't they'll come at you again, even harder, and the world will see that you're soft, that you're a mark.
Gimme your lunch money, kid.
Hey man there's no need to remind me that I'm old.
What's wrong with that?
There are many ways. The most common are: If the users tell you they're from North Korea, you can tell that they're from North Korea. Also, if they connect from a North Korean IP, you can tell that they're from North Korea.
> And what sensitive information could they access? It’s defacto public.
The request likely had nothing to do with "sensitive information", but instead, sanctions.
International sanctions laws are pure and utter madness, with extremely high stakes if the government changes its course on selective enforcement, so everyone is "playing it safe" rather than "doing what makes sense and question outright bullshit".
[1] https://www.trendmicro.com/en_us/research/17/j/a-closer-look...
Usually, that's court cases and resulting case law, as well as executive fines... which means there is an insane amount of risk attached to everything related to sanctions, and additionally enforcement may vary between different governments.
Either way, your company is required to follow the law regardless of your opinion on it.
that's an order I would break; to do that goes against the principles of the internet.
I suppose I'm not getting hired any time soon.
yea, I'm not 'obedient' enough... I have principles like open internet, shared culture, freedom, and so on.
what's worse, I feel for Korean culture, split in half by AmeriRussian "interactions".
(Of course, sometimes it takes breaking the law to change the law. Revolutions, for example, have never been lawful. Governments may even praise a revolution - especially the ones that brought them to power, - yet they would always make sure that any future revolution is illegal.)
Germany reunified. Korea might have as well had it not been for North Korea's invasion of South Korea, and China's support of North Korea as a buffer zone.
And why no blame for Japan?
And what "internet principles" are you writing about? Everyone can access everything? This hasn't ever been the case. There have always been access controls.
Is the implication here that the should walk away from being robbed of 170 quid? They're fighting for dignified treatment.
I know this is an example of another problem, but in the US it's easy to see someone actually being killed over attempting to rob someone of $200.
People have strong reactions to unjust treatment, especially when they believe they are dealing with a fair system. (I feel it's different when you know you just have to pay the bribe.)
I’ve been using crypto and stablecoins for this for nearly 7 years now. Basically it skips international transfer scrutiny and for both the sender and the recipient we are using local banking on each side.
The exposure time is like 5 minutes, which mitigates every theoretical issue with the confidence of a stablecoin, or even the volatility of any particular crypto.
So what would have been an international transfer is converted to a scrutiny-free domestic transfer, which goes way faster too.
never mention any = "there are no valid use cases for crypto"
And this is a fairly common one. For example it's how GrapheneOS pays their developers, because TradFi (especially cross-border) is too capricious.
Just speculating. I'll never downvote or argue against anyone pointing out that use case, personally.
Or if you are transacting with someone with a funny sounding name, or who lives in a developing country (especially in MENA).
You can conduct your business without worrying about intermediary risk.
Hell, I've had bizarre issues in the past trying to make transfers between some large American banks and a number of European banks, the transactions just get "stuck" for a couple weeks, then get refunded, because somewhere in the middle something goes tits up.
"HN is weirdly inconsistent about digital currencies. Generally pro encryption, net neutrality, open-source software, VPNs, etc. But mention "Bitcoin," and suddenly half the commenters lose their shit about the Four Horsemen of the Infocalypse. Then they go back to commiserating with another Ask HN startup founder whose PayPal account was frozen."
Simultaneously ignoring the benefits of cryptocurrencies and the problems they are trying to solve, while only looking at the negative edges that are covered by mainstream media, seems short-sighted at best. That's the inconsistency.
> Simultaneously ignoring the benefits of cryptocurrencies
I don't actually see a lot of that happening here, though.
Source? Seriously. I mean, we have CEX going down with SBF and Molly White posting anti-web3 stuff. I'm sorry, but that isn't the core fundamental technology that we're talking about here.
> I don't actually see a lot of that happening here, though.
Again... media focuses on the failures and not on the successes.
ETH moving to proof-of-stake was a massive technological advancement that only happened after many years of development, and has gone off without a hitch.
While, at the same time literally decimating all of the GPU based proof-of-work mining in a single day. Not only that, but they were able to MVP release the code without even implementing withdraw! People have trusted the developers with 0.40T dollars worth of value [0]. It is not insignificant.
Next up is some really interesting work being done with zero-knowledge proofs, which will enable the scaling phase of blockchain to happen.
Please try to get past the HN trope of 'crypto has zero purpose other than number goes up or down and bitcoin mining is destroying the planet' and look at what is actually happening in the industry.
And that's the thing that causes the most cognitive dissonance. If you're going to trust someone, why not trust entities that have had hundreds of years to work out the kinks?
The road is literally being paved and is being done so iteratively. I'm ok with that as that is a standard way to develop things over time.
> why not trust entities that have had hundreds of years to work out the kinks?
Simple. Because they are not acting in your best interest. We've been sold on the idea that money is scary and we shouldn't touch it ourselves. We should put it into 401k's and forget about it until we retire. We should 'trust' people who know these complicated finance things better than us. It is a self fulfilling prophecy.
For 95% of the population (including me) crypto is the same trust system. I can't audit a smart contract and the underlying virtual machine it runs on. I would have no clue whether my transactions can be front-ended by bots that take all of the gains I expected, and then some.
I do have a general idea what happens when I use a credit card to make a purchase, and what to expect. I also have a general idea that if I put money into an investment account what fees will be deducted, and what stocks and bonds are being bought and sold.
And if I make the horrible mistake of sending money or NFTs to the wrong account, I know it can at least theoretically be reversed in non-crypto systems (and that often the reversal costs will be eaten by the bank, not paid by me). Whereas with crypto I have no expectation that the validators care about me to do a MakerDAO reversal on my behalf.
https://www.smithsonianmag.com/smart-news/people-had-to-be-c...
You obviously have some understanding of the system if you can speak about bots and front running. Fact is that front running exists in all markets, not just crypto.
As for reversible transactions, that's something done with smart contracts and escrow services. We are not there yet in terms of development, but it will happen eventually. Today, people actually appreciate the immutability of transactions. It enables the effective store of infinite wealth as a basis.
Credit card companies are providing the reversal business, which is paid for by the people who are borrowing money at insane interest rates... no reason why it can't be replicated once there is enough demand for it, but honestly, I'd rather move to reverse the model.... over collateralized loans. This is what is done in countries without the whole bogus credit rating systems.
> You obviously have some understanding of the system if you can speak about bots and front running.
What I've read on crypto skeptic blogs. So basically my understanding is equivalent to the understanding that anyone gets from reading news articles written by content-expert journalists. From what I understand the front-running in crypto can have pretty egregious effects, and can occur with simple monetary transactions, not just the crypto equivalent of stock market transactions. (Yeah, sure, front running can occur in currency exchanges in non-crypto, too, but as an individual, when you go to a currency exchange, or make a purchase overseas, you know the exchange rate before you trigger the exchange.)
> Today, people actually appreciate the immutability of transactions.
I don't. And I don't see how this follows: "It enables the effective store of infinite wealth as a basis." Infinite wealth cannot exist. And how does immutability facilitate this? And how is a blockchain that can technically be rewritten at non-infinite cost immutable (i.e. the MakerDAO rewrite, or any Sybil/51% attack)?
> Credit card companies are providing the reversal business, which is paid for by the people who are borrowing money at insane interest rates... no reason why it can't be replicated once there is enough demand for it, but honestly, I'd rather move to reverse the model.... over collateralized loans.
From what I understand, the interest rates go to the issuing banks, and the credit card companies take their profit from fees. Credit cards (and payday loans) exist for people who lack the collateral for a non-signature loan (without having to collateralize their freedom, aka debtor's prisons or endenturing). The only way to do this in crypto is to trust a third party lender such as Voyager or Celsius.
> you know the exchange rate before you trigger the exchange
You know this in crypto too. The issue is that the market depth might not be large enough to support your transaction. That will change over time, or you just stick with the basics... BTC/ETH/Stables and ignore the rest of the stuff.
> how does immutability facilitate this?
If you know that it is impossible to double spend, you can trust the math.
> And how is a blockchain that can technically be rewritten at non-infinite cost immutable
This is well covered in Andreas Antonopoulos videos on YT.
> Credit cards (and payday loans) exist for people who lack the collateral for a non-signature loan.
In Vietnam, there is no credit reporting agency. You don't get a credit card from a bank, but you can get a MasterCard/Visa "credit card". The thing is, they are effectively debit cards because you have to time deposit collateral in order to use them. People still get to shop online, but they are limited. This is honestly a far better system because it encourages people to spend what they have, not what they don't have. I also prefer to cut out the middleman who's generating all those fees for both the merchants and the end users.
> The only way to do this in crypto is to trust a third party lender such as Voyager or Celsius.
Bad examples given that Celsius was a ponzi. There are decentralized lending protocols. AAVE is a good example.
We have? I guess I was passed over when that sales job happened.
> > We should 'trust' people who know these complicated finance things better than us.
That's not how I look at it. How I see it is that when I'm operating in the established monetary system, I have some amount of protection and recourse available to me if/when things go wrong. With cryptocurrency, I have none.
To me, that's a really significant difference, and is in the top 3 reasons why I avoid cryptocurrency.
It has nothing to do with "trusting" financial institutions, or feeling like money is too complicated to understand.
We just literally witnessed several banks fail in the last few weeks, along with a litany of startups freaking out about how they were going to pay their staff. The government had to step in to prevent things from going totally ape shit and we are still on the edge of things getting worse by the day. All because people had some sort of belief like you do.
> With cryptocurrency, I have none.
This is simply not true.
We did, and those startups got into the state they were in because they chose to avoid getting insurance on their deposits that exceeded the FDIC limits. That's not the fault of of the financial system. And the financial system protected them well over and above what it had committed to do.
> All because people had some sort of belief like you do.
Not at all. If I had a large deposit like them, I would have actually used the services that would have protected my deposits.
> This is simply not true.
It isn't? What protection is there?
Hilarious. On one hand, you're saying that cyrpto is this big mess full of bad actors and on the other hand, placing no blame on a financial system that can just blow up in a week because of poor design and oversight.
Just like it isn't the fault of cryptocurrencies that there are bad actors. It is just intrinsic that there will be issues in any functioning system.
> What protection is there?
You said none, but I can provide you with at least 3 different decentralized insurance protocols with proven track records. Here is one: https://nexusmutual.io/
More will come over time and demand. DeFi is still quite new.
You've taken my stance on both counts to an extreme that mischaracterizes them. I never said cryptocurrency was a "big mess", and I never said that the established financial system is some paragon of virtue and perfection.
What I said is that the financial system did what it promised to do for those people who were affected by the bank failures.
> You said none, but I can provide you with at least 3 different decentralized insurance protocols with proven track records.
And yet, until now, you didn't actually mention any of them. I can't read your mind.
The one you link to doesn't seem to cover the most important protection (to me), though. I could be wrong -- the website isn't exactly clear. Does it offer the same coverage as I can get through chargebacks on a credit card? Does it cover me if I accidentally send money to the wrong destination?
Wait, there is a law that says that when a bank fails, the government has to step in and bail them out? Wrong. Otherwise, all banks would get bailed out.
> Does it offer the same coverage as I can get through chargebacks on a credit card? Does it cover me if I accidentally send money to the wrong destination?
No. You're asking for a credit card product. I don't believe that crypto has to be a credit card to be effective and useful. A good analogy is Zelle, which allows you to transfer money, but they don't bail you out. I'll tell you... even with bank wires, you send money... it is gone. Our finance department got phished last year. They didn't get the money back.
I'm curious when the last time you accidentally sent money to the wrong destination though. Is that really a common use case?
With crypto it doesn't matter whether it's you sending the money to the wrong address, someone who has hacked your account sending the money to the wrong address (and if you have insurance to protect against this, you'll have to prove it wasn't you), or a smart contract that someone slipped you without your knowledge sending money to the wrong address. You're out the money regardless. The last case isn't possible in non-crypto, and in the middle case you're protected by depositor's insurance in the US.
And yeah, I'm not using Zelle or a wire transfer unless I know who it is and what it's for beforehand.
For this reason, the choice is to only use credit cards where merchants have to pay exorbitant fees and end users have to pay massive APYs for borrowing.
If only someone could at least try to come up with a better system.
Payday loans and cash purchases? We have a variety of "systems", each with pros and cons. And hopefully that kind of diversity will continue into the future. For daily consumer purchases most crypto systems seem to have more cons than pros. For investment purposes I really don't know. And as a store of large chunks of value, maybe crypto will have an important role at some point.
No specific source, just how it looks to me based on what I hear pro-cryptocurrency people say (mostly here).
> media focuses on the failures and not on the successes.
By "here", I meant HN, not the larger mediasphere.
> Please try to get past the HN trope of 'crypto has zero purpose other than number goes up or down and bitcoin mining is destroying the planet' and look at what is actually happening in the industry.
This comment is mis-aimed. I'm not on that trope (I see one legitimate use), and I do loosely follow the industry. I don't follow it deeply because it's not a field that is technically interesting to me, but I am interested in the ramifications to society at large.
All I'm saying is that a rather large percentage of people I see advocating cryptocurrency are not making cryptocurrency look good.
It was anecdata the first time. The second time, it became hand-waving.
> I do loosely follow the industry
You follow it closely and care enough to comment here. 'disturbingly large percentages' and 'rather large percentages'... all say it is the big bad cookie monster... but it is just that... all anecdata.
You're trying to spread a myth, without anything more than anecdata, which is the whole point of this thread. I'd love to see less myth and more research.
Yes, because I'm concerned about the societal effects of it. What I don't follow closely are the implementation details.
> You're trying to spread a myth
No, I'm simply reporting what I personally observe. I even stated where I've observed it (mostly here on HN). My observations can, of course, be incorrect -- but describing it as "trying to spread a myth" is misleading. I'm not trying to spread a myth at all. I'm explaining why it is that I view the cryptocurrency space as having a lot of sketchy things in it.
I asked you for a source of the 'why' and you couldn't give me anything concrete. Therefore, my only other recourse is to assume you're spreading a myth. Burden of proof.
In any case, since you brought up burden of proof, it's the cryptocurrency world that is presenting the new thing, so it's on them to prove that what they're offering is an adequate substitution for what we currently have. I am the potential customer that has to be assured about it. So, in the larger sense the burden of proof is on the cryptocurrency people.
What I'm reacting to is your inability to quantify your opinions. Specifically, 'disturbingly large percentages' and 'rather large percentages'.
> it's the cryptocurrency world that is presenting the new thing, so it's on them to prove that what they're offering is an adequate substitution for what we currently have.
"for what we currently have". See, that's the thing, we had newspapers and tv before we had the internet. The internet came along and gave us an entirely new medium. It took a while for people to get used to that. You're in that phase now.
While millions of other people are off experimenting with these new things (and effectively using as part of their daily lives). Nobody forced anyone to use the internet. People gravitated to it because they found value in it.
Just because you have come to the opinion that it has 'large percentages' of grift, doesn't make that opinion true.
That said, every advertisement I get for a bank or financial institution, doesn't seem much different. Instead of individuals, it is big organizations trying to shill us into letting them manage our money for us.
Instead of arbitrarily low amounts
It solves the friction for the person I replied to, and anyone that wants to avoid that particular kind of friction
In a case like that, threaten to contact a lawyer because they are engaging in discrimination against you on the basis of (I assume) national origin. Unless your name is something like 'John International-Jewel-Theft,' they have no case.
> slow, expensive payment system using its own wildly fluctuating currency that consumes the energy of a small country
You don't have to use Bitcoin, you can e.g. use a stablecoin on an Ethereum roll-up.
It's not slow; transactions finalize within 1 minute (and soon, less). It's not expensive; it costs less than 10 cents (and soon, less). It doesn't fluctuate wildly, because it value is stabilized using one of several mechanisms. It doesn't consume the energy of a small country, because it does not use proof of work.
I'm sorry but you have no idea what you're talking about. I bet you couldn't even name three stablecoins and describe how they maintain price stability.
Hint: There are three main backing types (tradfi-backed, overcollateralized, algorithmic), and two peg types (fixed, floating).
> planet destroying ponzi
I don't see how Bitcoin is a ponzi scheme.
Just no. PayPal has always acted like this and shut down people's accounts for vague reasons. Stop cheerleading for them.
Criminal activity on a public and traceable blockchain makes crypto worse for criminals to use. That is why scammers and criminals are using Zelle and the banks for their criminal enterprise. [0]
[0] https://www.nytimes.com/2022/03/06/business/payments-fraud-z...
IMHO most Eth L2s already show more promise than PayPal as a future payment rail tech, despite them all basically being in beta state. Much lower fees, faster transactions, permissionless withdrawals, fully programmable, negligible energy usage now thanks to PoS.
(IMHO it’s likely that other tech/protocols will emerge in 3-5 yrs that supersedes the protocols in development today.)
Lots of typical crypto caveats - eg: USDC on an L2 is centralized around Circle’s ability to redeem. Protocols can have bugs that make coins go poof. Non custodial ownership is harder for many users than asking PayPal or a bank not to lose their funds. L2s specifically are typically run by a single sequencer who could potentially disrupt your ability to use the network smoothly (but then you could use an escape hatch to permissionlessly get your funds out if that happens).
The UI is really up to the apps, the good thing is there are many teams working on payments so there will be plenty to choose from to find the UI you like, and people will be able to pay via the same wallet. Stripe already has USDC payments on crypto rails and Visa is working with Starknet to integrate with these L2s too.
All the L2s with their usage, security, speed and tradeoffs are at http://l2beat.com
All being said and done, all the L2 are just centralization projects. These chains and tokens will always be controlled by a small number of early movers. Eventually, it doesn't even fulfill the very purpose of all these tokens - being peer to peer money.
And we will be thankful for that when we are all classed as criminals.
Many years ago, I used bitcoin to pay for web and e-mail hosting. Heck, there were several pubs in town offering the option to pay with crypto. I was paid for remote freelance web development work using bitcoin several times, none of it criminal (one example: a car dealership sales portal customization). All of that was above board, reported to government, taxes paid, etc.
Providers moved away from it because of sentiments like this becoming prevailing (lots of people used it for illicit activities of course) which is a shame.
Public sentiment has nothing to do with what the tech can actually be used for.
That said, the environment impact caused is the larger concern to have IMO.
I would say people moved away from accepting bitcoin for beer because it's wildly fluctuating value made it unsuitable for use as a day to day currency, and because they realized it was a gimmick whose inconvenience (for the vendor) was not worth the limited interest in using it as such.
Coinbase has the option of immediately converting crypto payments into fiat, eliminating that problem.
> and because they realized it was a gimmick whose inconvenience (for the vendor) was not worth the limited interest in using it as such.
This is the bigger issue.
Even if it's an online vendor where having to wait an hour for the transaction to get 6 confirmations isn't a problem, they still have to either integrate with another payment processor like Coinbase to accept the payment, or spend money building their own. In any case, it's cost and infrastructure to setup and they're probably unlikely to see RoI.
Sure. You want to update your bitcoin prices what, hourly, to make sure you are charging what you meant to? I'm not sure that coinbase service exactly eliminates the problem. But I'm sure that is a useful service for some!
But yeah, we're on the same page. Overall... it is not a convenient thing for an ordinary business to take as payment for ordinary daily things.
That's one way to do it.
The other is to charge in USD just like you normally would. When the customer opts to pay in Bitcoin, they get sent to Coinbase which will convert the price into Bitcoin immediately and tell the customer what the balance is in Bitcoin. The exchange rate won't favor the customer, as it will include some amount extra to cover the possibility of the value dropping before the transaction is confirmed.
Sometimes, criminal activities are justified when all you do is to protect yourself. For example, when you live in a lawless area, and you need protection against bigger criminals. Peaceful countries with overall working systems are just one side of the world.
So calling it 'acting stupid' totally negates the stranglehold that Paypal and Stripe have on a majority of online commerce and payments and totally liberates people from their unregulated tyranny then...
...
Things dont change their nature by 'rephrasing them differently'. Unregulated private tyrannies that dominate people's lives are still unregulated private tyrannies.
There is a time and place for each argument and there is a time and place for conceding the argument. This is one of them:
No one can ban anyone from crypto. If your business wallet gets stolen, you suffer some losses, but you can create a new wallet, add it as your payment option in your business or personal account at your site or wherever, and just continue your life.
With these unregulated private tyrannies, you cant.
> planet destroying ponzi.
2010s called. They want their proof of work back. What decade are you living in. Dont keep repeating invalidated arguments. That looks like religious zealotry.
For a list of examples, see the categories used in Operation Choke Point:
Maybe cryptocurrency isn't the best answer in the end, but there needs to be some alternative even if only to pose a threat to the status quo.
People of Isis st., somewhere across UK, were also out of luck.
At least the word 'is' did not get corrupted.
Oh, and let's not forget the routing protocol - https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/iproute_is...
Probably a sanction scanning program.
Unfortunately, I do not know of a better solution than "match transaction data on this list of regexes" that would scale for the millions of daily payments that banks are processing.
Also…how would KYC stop a terrorist from abusing your mothers bank account to transfer money?
This is why you need KYC and also transaction screening (and also X, Y and Z).
For example:
Chase Bank blocks California man’s online payment over service dog’s ‘terrorist’ name
https://www.nydailynews.com/life-style/chase-bank-blocks-onl...
These stories are really common. Usually a phone call fixes it.
By analogy, would members of the KYC/AML cult have the opinion that terrorists should be free to use roads for their terrorists needs? The solution is police roadblocks and checks every kilometer or so?
Wouldn't it make more sense to allow these transactions to proceed but report them for investigation?
Aiding terrorist organizations is a crime. Wouldn't it be better to know who's doing it?
It feels like it would make more sense than automated block lists and account closures.
It's sort of similar to how bone-headed the shutdown of Backpage was. Backpage actively and willingly worked with the police to investigate human trafficking etc... It was basically a giant honeypot. From what I've read, when they were shut down the government lost a valuable tool and ally in the fight against sex slavery.
Of course all positives are going to be false positives, but what did you expect? Fighting international terrorism one regex at a time?
Also, curious about your source that all screening positives are false positives. Can you link to that?
I think it would be reasonable to ask you, and other supporters of this, to provide emperical data of the positive law-enforcement impact that grepping transactions for "ALEP" has had, so we can weight it against the human cost (capital and time spent across all sides, including legal departments in financial institutions, Google Docs written, impact on affected customers).
Because the default assumption of a normal person is, of course, that this is ridiculous.
https://www.reuters.com/article/us-ing-groep-settlement-mone...
(It's not at all clear that this fine is due to a lack of regexes.)
If the argument is "banks have to do this because of non-sensical and unjust regulations" - fine, that's one for the lawyers and maybe risk managers.
I understood your position as defending the regulations itself.
Paypal is a dumpster fire of scummy business tactics. Their emails don't even properly go through paypal.com and are filled with all kinds of phishy tactics.
It's not a dealbreaker for me, but if the PayPal integration exists, I'm using it 100% of the time. I'm already logged in, it has my payment instrument saved, and I don't have to worry about security as much.
It might be a deal-breaker for me, and if another option exists, I'm hsing it 100% of the time. I don't need to log in, password manager or browser has my payment instrument saved ready to auto-fill, and I don't have to worry about security or privacy as much.
Most people have a PayPal account. Your "emails me forever" is not a real concern for 99% of users.
And why is this a popularity contest or that the uniformed public’s (or your) opinion matters? People do dumb financial shit all the time. In the US at least, PayPal puts you at a disadvantage from a fraud protection standpoint since they are yet another unfriendly, large essentially unregulated middleman to deal with.
I extremely doubt that. Maybe in the US?
> Your "emails me forever" is not a real concern for 99% of users.
I'm not saying that is itself much of a problem, just that it isn't a guest checkout. It's not the accountless WorldPay/SagePay/Stripe/... alternative it presents itself as.
(As a result, more people have a PayPal account(s) than know it or want one. They refuse to delete mine without proof of identity, which I certainly didn't provide during checkout when it was created 'for me', so is not warranted and I'm not going to provide to allow my 'delete' request to result in net more of my data held...)
They're also excellent as a singular source for managing my subscriptions. If I ever forget what I'm subscribed to or want to cancel things, you can do it all in one place with PayPal just blocking further payments from processing from that business.
If people want PayPal to stop being used, then update your bank technology so the UX isn't so ass. Then perhaps we'll switch.
It's frankly ridiculous that these are the only two widely supported options for international payment. It's easy to make something better, but somehow much of the world seems stuck with the two worst options.
You got some interesting cognitive dissonance there...
It’s not like they do it for fun. The denominators are whether those companies implement decent recourse if you’re flagged. Stripe does; PayPal doesn’t.
I put “Cuban food” in the description field and it didn’t like that.
There should be laws and penalties for triggering any of those nonsense checks for such insignificant amounts.
Do you think Paypal enjoys spending effort to prevent itself from collecting fees?
PayPal and the others like it are not banks, as such they play by different rules worse for consumers. What is kinda horrifying is that nothing has been done about this despite PayPal doing exactly these things for entire history seemingly it has existed.
Why?
The banking system in Europe relied for long time on federated and regulated wire-transfer/direct-debit. More than a decade ago SEPA made cross-country transfers easily. And the instant-transfers are great! Little to no fees for transfers itself. Downsides? Both should have been added much earlier! Especially instant-transfers. Most Europeans don’t value that.
I’m always baffled by differences, especially using checks. And yes, we rely on cash because…you’ve seen PayPal? And fragile infrastructure.
If something goes wrong during an order (too many items shipped by merchants mistake) you’ve an uncooperative party on the other side.
It's extra work and expences, but it's worth supporting at least two payment processors.
Keep in mind that some people can't pay with PayPal - e.g. register a credit/debit card with PayPal, PayPal account gets locked - you can't pay with that card any more through PP.
https://blog.patreon.com/the-first-ever-patreon-creator-cens...
Crypto is the only one creators voted *against*.
Yes, Patreon creators, where a lot NSFW content comes from, voted against cryptos.
I wonder how they'll think when Visa/Mastercard threat Patreon to ban them (which is just sooner or later).
Features are never purely additive, they can also be transformative or even detrimental. Adding crypto support to Patreon would have changed what Patreon is by attracting different people. Regardless of whether any of the people already using Patreon might have benefited from crypto, it would also have attracted people who would specifically be interested in Patreon because of the crypto support.
Like it or not "people whose adoption of Patreon hinges on it adding support for crypto" is a very specific demographic and mostly people they probably didn't want to be associated with. You can call it guilt by assocation or digital NIMBYism but it would have changed a lot more than just having another option for payouts and donations.
I pay for my food in dollars. For my rent in dollars. For my clothes in dollars. For my equipment and supplies in dollars.
What would I do with crypto?
Okay, let's say I get paid in crypto. I still need to convert that to dollars. Price fluctuation of bitcoin is such that if I was paid 1 dollar worth of bitcoin last year, it would be less than 50 cents by the end of the year.
Also, note that you'd probably receive more donations if accepting crypto currencies, so even if the values of these were to fluctuate (which they won't, cause you can sell) you'd still be making more money overall.
"just"
> It won't lose or gain 50% of its value in a matter of minutes.
If someone sets up a recurring payment of X bitcoin it means that on any given pay day your actual money is X*(absolutely random number). Minus the fees for converting to fiat.
> Also, note that you'd probably receive more donations if accepting crypto currencies
"Probably"
Relating to the varying amount monthly:
1 - It's a donation, not your source of income. If you really on that money that's your issue not of anyone else's.
2 - The platform such as Patreon could simply quote the value in dollars instead of BTC or whatever cryptocurrency. Recurring payments with crypto will have to be done manually anyways so this is a non-issue.
[0]: https://www.forbes.com/advisor/business/credit-card-processi...
[1]: https://help.coinbase.com/en/commerce/getting-started/fees
We're literally in a topic about creators and Patreon where Patreon is a substantial source of income to quite a few creators.
And the dismissive tone about donations in general... well, I won't comment on that
> The platform such as Patreon could simply quote the value in dollars instead of BTC or whatever cryptocurrency.
Or they could just not bother.
> Recurring payments with crypto will have to be done manually anyways
Ah yes. The great digital system of the future where even such a simple thing as recurring payments must be done manually
> And the dismissive tone about donations in general... well, I won't comment on that
Why not? > Or they could just not bother.
That's true. The creators have the option of creating their own cryptocurrency wallets and accepting the donations without any middleman. They could also choose a more libre alternative to Patreon such as OpenCollective [0][1] or Liberapay [2]. > Ah yes. The great digital system of the future where even such a simple thing as recurring payments must be done manually
I see that as a plus personally. Recurring payments are so hard to cancel at times with credit cards I'm at the point I create a new virtual credit card for every subscription I create. Theoretically you could also setup your wallet to automatically transact, it's just that's not a functionality of your cryptocurrency, just as recurring payments aren't a functionality of the dollar but rather of your bank/credit card provider.[0]: https://opencollective.com/
[1]: https://docs.opencollective.foundation/how-it-works/financia...
Because a lot of people live or earn a lot of their living through donations, and quite a lot of opensource you're using would actually be helped with more donations.
> The creators have the option of creating their own cryptocurrency wallets and accepting the donations without any middleman
Except, you know, all the actual things that those "middlemen" do like provide verification that it is the actual artist and not a rip-off, provide hosting for their content etc.
> Recurring payments are so hard to cancel at times with credit cards I'm at the point I create a new virtual credit card for every subscription I create.
Yes, dark patterns around subscriptions are a problem. However, subscriptions and notifications about whether a person has canceled their subscirption or became a subscriber is valuable information to, you know, actually be able to plan ahead, and not wonder whether that person who did something manually yesterday will be there tomorrow.
Edit
> They could also choose a more libre alternative to Patreon such as OpenCollective [0][1] or Liberapay [2].
The could skip all the middlemen, or could chose these middlemen that I personally like and call them "libre" just because they accept cryptocurrency. And LiberaPay is literally a middleman with exactly zero additional value
So, as always every discussion about "but crypto" almost immediately devolves to "not crypto, but a very specific coin that seems to be more-or-less okay at this particular point in time"
> or pay people directly with it
Which people? The dozen or so places in the entire world that accept crypto?
I don't understand why you want to be so hostile towards it, it's literally the solution to this problem.
1: https://usa.visa.com/solutions/crypto/auto-payments-for-self...
If Patreon doesn't do it, someone will. Probably a porn site somewhere underdeveloped accepting Monero or something. Cutting power away from financial intermediaries just has to be better for other market participants long term and that makes the shape of the future easier to guess at.
> Yes, Patreon creators, where a lot NSFW content comes from, voted against cryptos.
This is a gross misrepresentation.
Quoted from your link:
> In the Census, 68% of visual artists and 50% of writers were opposed to creators having the ability to accept payments in cryptocurrency on Patreon, while 39% of image, 34% of audio/music, and 31% of video creators indicated it would be a “crucial” or “nice to have” capability. Across creator types, about a third say they “don’t care.”
If you're opposing the "where a lot of NSFW content comes from" part, I apologize for the wording, but it's true. I just said a lot of NSFW content comes from Patreon. I didn't say they're the majority.
If you're opposing the "voted against cryptos" part, then:
https://live-patreon-blog.pantheonsite.io/wp-content/uploads...
I would assume that NSFW creators largely fall under the "Images" category where only 26% voted against the idea.
It wouldn't. At the end of the day you need to pay for stuff in your life: food, rent, clothes. None of those things are paid in crypto. All of them are paid in actual real money.
When the price of crypto can go up and down hundreds of percents per day this makes it a very bad substitute for money.
Last week alone bitcoin price fluctuation was ~8%. Last month? 146%
Any source on that? It would need to go from 20K to 50K.
But we could take past year as a whole. Fluctuations from 47k to 16.4k (3 times drop) then 27k (1.6 rise, still 1.7 below the high). There are drops that go to a price 1.5 lower in just a week. Imagine you need to pay rent on that week.
And yet, for some reason reality exists and intervenes every single time.
If you want you can also get paid in crypto, so it's not as hard as you might think.
Of course they can't
> Rent is probably harder, but I guess when you live in a place like Dubai that also won't be a problem
Ah yes. The solution to everyone's rent problems with crypto: just move to Dubai.
> If you want you can also get paid in crypto, so it's not as hard as you might think.
There are over 200 000 creators on Patreon. I'll let you guess how many of those live in Dubai
The world doesn't need crypto, it needs to turn Visa/MasterCard/Amex into utilities.
In the background, the payment rails are bitcoin and lightning, but all the user needs to see is US$.
Good to know :)
More regulation can only help in forcing PP to have a human that you can talk to after the algorithms have banned you.
The problem is regulation, or at least the interaction between strict KYC/AML regulations and a business model that allows basically anyone to accept electronic payments. Banks and money transmitters are substantially deputised to enforce a raft of laws regarding the conduct of their customers. Either you're choosy in who you accept as a customer, or you're liberal in who you accept as a customer but have a hair-trigger response to any transaction that looks even vaguely suspect. Any alternative strategy will eventually lead to jail time.
Except, then you have even bigger problems than just PayPal.
For example, it seems like most people don't hold their own keys. I know, "not your keys, not your coins," but it does mean that Bitcoin doesn't provide that kind of safety for most of its users. Even if you do hold your own keys, there's a decent potential that you'll lose your keys. I've known people who have lost Bitcoin that way. If you're holding your keys yourself, how are you keeping them safe? You certainly need off-site backup and probably a weak enough password protecting them to be sure that you won't forget the password. People have those key safes that only allow a certain number of tries: https://www.bbc.com/news/technology-55645408. That guy has $240M locked away. Sure, PayPal feels unaccountable when you're a tiny player who uses PayPal for thousands of dollars, but a lawyer would be able to get that $240M.
From that article, "Currently, about $140bn worth of Bitcoin is lost or left in wallets that cannot be accessed, according to cryptocurrency-data company Chainanalysis." Given that Bitcoin had around a $700B market cap back then, we're talking about 20% of the total Bitcoin out there simply being lost.
Yes, in theory, these are things that you as a user have control over. But human life is tough. If you get in an accident that impacts your memory, do you lose access? If there's a fire, do you lose access? If you die, have you prepared a way of transmitting those Bitcoin to your heirs - and a way that doesn't give them access currently? How would you do that? "Here's how you access the private keys, but pinky swear that you won't until I'm gone."
> no one can ban you from the blockchain
I'm not so sure about that. Bitcoin are traceable. The government could blacklist certain coins they determine are the proceeds of criminal activity. Sure, the person holding those coins could still transmit them to others and then those people could transmit them to more people, but if the US/EU blacklisted certain coins, people would refuse to take them as payment. For example, Mt. Gox froze accounts that deposited Bitcoins that were known to have been stolen.
Let's say that the US says, "no business under our jurisdiction can do business with any wallet that has held Coin-X after today." The value of that coin becomes much lower than any other coin. You can't accept that coin as payment if you're looking to change it (or any other Bitcoin you own) into dollars in the future. Coinbase and other companies couldn't do business with you. Let's say the US takes it one step farther and says "any coin held by Wallet-X today is tainted and any wallet that accepts any of the coins held by Wallet-X (no matter how many transactions removed from Wallet-X) is also tainted along with all their coins." That means that everyone in the Bitcoin network needs to treat the coins in Wallet-X as radioactive. If you accept payment from Wallet-X, you now can't convert your money to dollars at Coinbase or similar companies. Even if you accept payment from Wallet-Z who got the coin from Wallet-Y who got it from Wallet-X, you're still compromised. There'd need to be an updating blacklist of coins that couldn't be used by US companies - a list that would expand over time. If Wallet-X had Coin-X and sent it to Wallet-Y, it would taint Coin-A and Coin-B in Wallet-Y which means even more Bitcoin are now blacklisted by the US.
Even if you never want an off-ramp from Bitcoin, others do. Maybe you dream of making every transaction with Bitcoin for the rest of your life. Still, the value drops hard if others don't share that dream. Even if you never want US dollars, let's say you want to buy a house with Bitcoin. The US sees the purchase and seizes the home as the proceeds of illegal activity.
The Bitcoin network generally treats all coins as the same kinda like how we treat all dollar bills the same, but our dollar bills all have unique serial numbers and similarly different Bitcoins can be differentiated from each other. If the US government starts blacklisting coins, they aren't technically banning you from the blockchain, but they kinda are for all practical purposes. Sure, there are ways to get US dollars that don't involve Know-Your-Customer US-jurisdiction rules. However, the value of Bitcoins that are blacklisted like that, especially if they taint your other Bitcoin, goes way down.
Sure, you can't be banned from the blockchain. However, if the US government bans all coins in your wallet, you're going to effectively lose those coins since others aren't going to want to accept those coins.
So because a random identifier contained a four-letter-long substring of the name of a city in a sanctioned country the whole thing was flagged. Makes perfect sense.
Additionally, *a lot* of scams operate exclusively with PayPal, because PayPal doesn't care as long as it's profitable for them. There's no risk of a bad reputation because you can't have a reputation worse than PayPal anyway.
Oh, and PayPal has also many times banned activists because of simply disagreeing with their cause. Not because required by law or any similar obligation, simply their own will.
We really need decent payment providers; it's sad how many have to rely on this kind of business because they don't realistically have a choice.
PP asked for a Death Certificate, which I provided.
They then said that I needed to PROVE THAT SHE WAS DEAD.
I even went an spoke with a lawyer about it. He too was pissed off. Alas there was no money in the account so he said there was no point in dealing with these morons, just open a new account.
PayPal NEEDS TO DIE!
What are the viable alternatives for international transactions? Ones that don't want my Social Security Number as part of the sign up process (I've had issues with identity theft and give my SS# to no one)?
> They then said that I needed to PROVE THAT SHE WAS DEAD.
You'd think that a death certificate is literal proof that someone had, in fact, passed on from among the living. I'm sorry you had to deal with such algorithmic bullshit for such an emotional circumstance.
It seems like there should already be regulations in this area and (in the US) prosecutors willing to pursue companies for the fame or a portion of the payout.
Is this area of finance really totally unregulated?
I was never able to unlink my personal phone number from that account. Worst mistake was ever trusting PayPal with it.
“ALEPH YOU ARE GOING TO DIE.”
Then there was light.
https://unsongbook.com/chapter-34-why-wilt-thou-rend-thyself...
This is fine for many use cases, but totally different from the paypal experience.
Do they hold assets other than their customer’s deposits? Are they even a bank?
As far as I know, paypal doesn't do fractional reserve banking (because it's not a bank and that would be illegal), it just collects a fee on the seller's side for each transaction, so everyone pulling out all of their money at once would probably not be that disastrous, supposedly they do have that money just sitting in an account. It would be disastrous to paypal as a business, and they would probably use fine print to keep that money, but out of greed, not out of lack of liquidity.
I don't think they do any fractional reserve banking though (at least they didn't two decades ago), so there shouldn't be any liquidity risk. All dollars in deposits should be backed by real dollars.
A system where instead of trusting banks and governments and other entities, we could harness the decentralised nature of the internet.
A system based not on trust at all.
A system where the total number of units of currency was limited to a pre-determined amount.
* Association of Leasehold Enfranchisement Practitioners
* association of employment and learning providers
* Aboriginal Landcare Education Program
* Acute localised exanthematous pustulosis
Seems to be the Romanian name for Aleppo too.
And of course it's 4 random letters, which if random in say 32 character code would have 28 attempts to get. If those characters are letters without IOQZ it would show up once every 8000-9000 codes generated, 12k for a 24 character code.
Does anyone know what (presumably conspiracy theory) this refers to?
Also Catalan, Croatian, french, …
> Does anyone know what (presumably conspiracy theory) this refers to?
Like other commenters I’d assume it’s related to the syrian sanctions.
We're building Tools to get rid of paypal/visa/mastercard and other rent seekers.
Here's mine: https://peanut.to
There's lots of other people building useful stuff in the space.
My dms are open if anyone wants to chat
> It is the payments are in XMR.
If you mean Monero, isn't that just asking for trouble? As in, you'd be supporting a cryptocurrency that has a history of often being used for illicit purposes (as many unfortunately are), with no KYC processes in place, non-compliance for which has historically resulted in some pretty hefty fines by the powers that be as well: https://shuftipro.com/blog/record-breaking-fines-on-banks-fo...
Assuming that the protocol/platform works out and assuming that you don't attract the attention of neither nefarious individuals, nor regulatory bodies, nor media that would lead to one or both of the former, it would probably be fine, but that's a lot of "if"s.
It makes me feel dirty that nowadays the choice is between large orgs that can ban you and kill your business with a (possibly automated) wave of their finger, and between oftentimes shady platforms, using which is just asking for trouble.
That's absolutely untrue unless you think "crypto" is only bitcoin. Ethereum block time is 12 seconds, polygon is 2 seconds. And not random in both cases (because no mining).
People, just don't use PayPal, Stripe and other "inovative" payment providers. They are doing this since at least 10 years yet people never learn.
Seems like a racketeering operation but ianal.
Excepting truly major state-level interventions, almost nobody can stop you from collecting a payment from a third party or sending it to them, or keeping your payments collected secure from some bullshit arbitrary KYC corporate freeze. It works internationally, it works 24/7 and funds received are funds that are yours.
Sure, the space as a whole is loaded with scammers, collapsed exchanges and etc, and its more technically difficult than using things like Paypal, but the essence I describe above is wonderful and should exist on a much broader scale as a basic right for people wishing to move funds and hold them. How you later convert them to fiat cash for daily spending is a separate debate.
I can already image many people here in their bubbles of privilege decrying much of the above, or companies and governments not being able to randomly freeze funds and block their flow for individuals, but I invite you to deal with a corporate freeze of YOUR money, or simply live in a place where state-level corruption is endemic, frequent and hard to escape by any conventional means.
Finally, Paypal truly is a hideous dumpster fire and deserves a slow, strangling corporate death. I look forward to a day in which that happens.
Also well summarized by patio11 with [1]:
> The actual probative value of SARs varies wildly; at the top of the spectrum, they can include sufficient investigatory work and documentation, produced by the analyst at the financial institution, to lead to convictions for e.g. human trafficking.
> Across the financial industry, that SAR is wildly outnumbered by “Mohammed tried to do something, we didn’t let him, and when we told him that he became agitated.”
> An example from here in Japan: an immigrant attempted to wire the equivalent of $600 to his cousin in Africa. He was asked the purpose of the wire and said it was for a tuition payment. Bank staff asked for supporting documentation like e.g. a tuition statement or student ID card for the cousin. The customer refused to provide that documentation. The bank refused the wire. The customer accused the bank staff of racially profiling him and raised his voice.
> I was not a party to that transaction and, for clarity, it did not involve any employer or business partner of mine. I winced when reading a news report about it, because this is practically ripped from Compliance training. The customer is absolutely right and they are very likely getting a SAR filed on them.
[1] https://www.bitsaboutmoney.com/archive/money-laundering-and-...
That’s a very big “if”
Cryptocurrency trades one set of problems for another set of problems. If you’ve ever seen the analytics for password reset at a large website (general, non-tech audience) and looked at the support statistics for account lockout help requests, you’d see why self-managed crypto is infeasible for any general market operations
Tech people look at their own usage patterns and see that they can manage passwords and private keys just fine, but the same is not true for the general population. It’s not even close.
Crypto also lacks one of the big selling points of credit cards and PayPal: Disputed transactions. Disputes are terrible when misused by lying customers, but disputes have also saved me from some sellers who never shipped the items I bought. With crypto, my money would be gone forever. Other scammers would see that there was no recourse and would start running more scams. Buyers would notice that crypto transactions have higher risk and would lower their purchase price tolerance. Sellers would notice and would offer alternate services at higher prices. And we’d be back to everyone using PayPal and similar services.
I stopped using paypal long time ago. Phone number I used expired when I moved countries. Paypal somehow activated 2FA authentication and I can not login.
Perhaps I will try this