Hacker Newsnew | past | comments | ask | show | jobs | submit | throwaway2955's commentslogin

AFAIK the carriers require a double opt-in for this.

The first opt-in, which the Medium article describes, can be online with boilerplate language. But then you have to opt-in a second time by replying to an SMS sent directly to the device by the provider with language pre-determined by the carrier. The user has to reply YES to the text message, and you have to keep auditable records of these things.

If these 2 providers aren't requiring the second opt-in step, I expect they'll be kicked off the platform pretty quickly.


I just visited both sites and both showed my full name, e-mail address, physical address, and T-Mobile billing plan information. I never opted into anything on T-mobile's site (and I can't find any opt-outs that I don't already have), I never opted into a text message, and only one of the sites required any other info (my zipcode).


I'd assume that's because the site in the article is a demo; the requesting and user IPs are the same. If they're different, then verification comes in.


If these 2 sites aren't following the carriers' policies, others aren't either. If these two sites exist, it doesn't look like the carriers are actively auditing for policy violations.

If true, it appears that any applicable carrier policies are not being effectively enforced. This is dangerous as it leaves the door open for selective enforcement of such policies by the carriers.


If that's the case, why don't the carriers do the second step themselves?

That's the very least they could do to protect their customer's privacy.


They're not trying to protect your privacy, they're trying to leave no money on the table. Selling your data is obvious, it's all they have above the commodity of a properly working dumb pipe.


Why do they care? They are selling access to your information.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: