Hacker news

  • Top
  • New
  • Past
  • Ask
  • Show
  • Jobs

FSFE supporters affected: Payment provider Nexi cancelled us (https://fsfe.org)

108 points by rasjani 2 days ago | 26 comments | View on ycombinator

sam_lowry_ 2 days ago |

Reminds me of the famous "Our security auditor is an idiot. How do I give him the information he wants? [1]

[1] https://serverfault.com/questions/293217/our-security-audito...

Freak_NL 2 days ago |

The FSFE justly drew the line at providing private information of supporters. How many other customers of Nexi simply handed over such data 'because audit'?

eequah9L 2 days ago |

> Over the past few months, our former payment provider Nexi S.p.A. (“Nexi”) requested access to private data, which we understood to be specifically the usernames and passwords of our supporters.

I must be missing something, but why is there an expectation that clear text passwords would even be known?

samsk 1 day ago |

We work with MLS provider(s) that requires us to keep plaintext password for our users and provide it on request in case of `breach in the security of MLS Listing Information or a violation of MLS Rules`.

The user is accessing only copy of their data in _our_ systems, the user has no contact with MLS itself directly or indirectly.

rswail 1 day ago |

Sounds like someone is being "overenthusiastic" about interpreting the KYC/ALM regulations.

Combined with the FSFE not being your "usual" charitable or business organization so setting off auditor red flags and perhaps raising the risk profile of Nexi as a payment processor.

butokai 2 days ago |

As an Italian living in another EU country, I always thought that the amount of (broken) bureaucracy of Italy was not particularly worse. However this story comes after a couple more I heard this week, in a line of absurd practice possibly due to absurd regulations.

janpio 2 days ago |

So what did Nexi really want, and how did it get mangled so badly that it came out as "specifically the usernames and passwords of our supporters"?

littlecranky67 2 days ago |

Everytime people say bitcoin has no use case, I'd like to point them to cases like this.

undefined 1 day ago |

undefined

lokimoon 1 day ago |

[dead]

grigio 2 days ago |

Maybe now more F/OSS supporters will understand the need of Bitcoin/Monero