Hacker News new | ask | show | jobs
by szc 4371 days ago
It sounds like a great idea, but thieves might want to own the servers that store this data. On these servers will be a list of products and because of the receipts, very likely the physical address of where they were shipped to and how new they are.

Also, although https://www.ssllabs.com/ssltest/ does say the site supports 256bit AES, the unioncy server does not prefer it and under "handshake simulation" every current device will only negotiate a 128bit AES key.

Arguing about 256bit v.s 128bit AES on for TLS isn't really important though; the risks are all with the data-at-rest and stored on the unioncy servers.

In reading the privacy policy it appears that the product information will be used to provide selected and targeted advertising.

1 comments

Thanks for sharing your thoughts. I take it that you have two main concerns in security and use of your data. Regarding security, I can't argue with the overall nature of the problem that you are pointing out. What I can say is that we take security very seriously and are being proactive about it by implementing measures such as SSL. To give some perspective, I think the service is very safe compared to many other online services that store personal data. We realise this is not enough for some and respect that, but we will keep improving.

Regarding your second concern about privacy. For the avoidance of doubt, the privacy policy says "We use your personal data, in anonymous form or by link to pseudonyms, when required, for the following purposes. In order to provide information and services required by you, such as customer service for example. To provide for an customised presentation of content, advertising and user experience. To provide news regarding the services of Unioncy and other administrative issues. In order to provide you with targeted marketing activities and advertising offers on The Unioncy website..."

This policy is vey much in line with Evernote and other leading personal data services. Similar to them we never want to compromise the user experience. Hope this helps!