Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

All cloud providers I've tested will reject proxy cards, which are assigned from prepaid card pools. More businesses seem to be doing this as of late. It's rather unfortunate, since proxy cards are a fantastic fraud prevention device.


Considering how many people on the internet talk about using these cards for evading contractual obligations (e.g. cancelling the card instead of going through the contract cancellation process and paying the termination fee, if any), it's surprising their acceptance has lasted as long as it has.


> evading contractual obligations

If by contractual obligations you mean "clauses that are most probably illegal but the average person will usually just shut up and pay rather that lawyer-up against a multibillion corporation", then yes I can see how many, me included, just opt for one of those cards whenever possible.


It goes both ways. Im sure there are scummy customers out there using it as a tool to not pay businesses money that is legitimately owed.


Cancelling is oftentimes borderline impossible. Especially for people who can’t spend all day on a phone getting shifted around countless times or waiting forever for online support to respond (and sometimes never follow up).

Maybe if companies didn’t make cancellation processes so actively hostile to users or throw in mysterious charges that continue accruing for all eternity, people wouldn’t be so uncomfortable using their normal card?


Cancellation fees are ridiculous nonsense in 99% of cases anyway. I have no sympathy.


They are ridiculous. Nonetheless, they are legal obligations.


They are usually not, illegal clauses are still illegal even if you clicked an "accept" button.

Edit: one of many examples https://www.washingtonpost.com/business/2021/06/02/automatic...


I would be with you if so many corporations didn't already exploit customers with the whole "yeah, tough luck, whatcha gonna do about it? have fun suing us" attitude. You can't blame customers for taking the same approach when that's already corporate America's MO.

And don't forget that on top of exploitative practices, corporations frequently game the legal process too... like forcing customers to sign away their rights to sue in court, and all that.


It's almost tragic that how many times things that are "legal", are neither right nor good. In ideal world, atleast, those qualities should have been mandated to make something a law.

Either laws are way too old for the current times or were made worse by lobbying groups in favour those with might.

Things don't seem to be getting better (cookie annoyance being one example) unfortunately.


Immoral obligations aren't obligations.


Nonetheless, a prepaid card is legal tender.


> Nonetheless, a prepaid card is legal tender.

No, it's not, an even if it was, that would create no obligation of a vendor to let you use it to establish an account. The effect of legal tender comes when making an attempt to pay an existing debt, not when trying to establish a relationship in which charges might be incurred in the future.


Are you just saying that randomly or do you have any good reason to think it's true? :)


I use them all the time to ensure I don't get auto enrolled for garbage services. Like when you buy something from Nordic track and there's no way to opt out of auto enrolling for iFit. It's predatory and feel no shame in my tactics. I've also caught a number of breeches and just plain old scummy businesses (three times I got pings on one time use Amazon cards).


You can use proxy cards in your day to day life.

If you hand your classic card details to a company like Oracle or AWS, your card isn't exposed to the same threats as when you use it to buy something at the gas station.


AWS overcharging my card due to their unclear pricing structure seems like a much more realistic & costly threat than someone putting a skimmer in a gas station


Especially as one is a 'once off' use, the other is billing on demand.


That's a great world to live in but it's not true. I have caught three fraud attempts from cards only used on Amazon.


For what it's worth, I've been able to use a prepaid card with <WELL-KNOWN LARGE CLOUD PROVIDER> for a while now without any problems. Maybe they're not all created equal.


I’m willing to bet it’s AWS with 90% certainty - they seem to have very lenient card policies compared to other cloud platforms I’ve worked with. (GCP, on the other hand, won’t even accept debit card - only credit)


> GCP, on the other hand, won’t even accept debit card - only credit

That's not true in my experience: I've been paying my GCP bill with debit cards from three different banks for years. (They were branded as VISA or Mastercard, mind you, but still debit cards.)


GCP in the EU accept debit cards, same as AWS, Azure, Oracle, Scaleway, OVH. They'd be crazy not to ( credit cards are rare here), but still.


I second and confirm this. It is true, but my <CLOUD PROVIDER> has been cracking down on it more more recently.


Just curious: why are you and GP unwilling to mention the providers' names?


I figured it might be a little imprudent to explicitly mention what I'm getting away with, and with whom. Especially in a public forum where many of this company's employees may very well see it. I'd be shocked if they took action, admittedly. Still, I feel like it's good policy never to explicitly invite misfortune upon yourself.


Sounds more mysterious, gets people going.


I've not had a problem with this with <LEGACY DEDICATED SERVER PROVIDER>.


I had one that worked a couple years ago but it expired. I couldn't add a new one.


> All cloud providers I've tested will reject proxy cards, which are assigned from prepaid card pools. More businesses seem to be doing this as of late. It's rather unfortunate, since proxy cards are a fantastic fraud prevention device.

You do realize that letting people anonymously host whatever they want from reputable ASNs is a bad thing, right?


I would say that the invention of the concept of "reputable ASNs" is the root cause.


How dare you to send me a mail from an IP range which was used for port scanning three years ago?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: