I have background here and can take a pretty good guess at what happened. You used a Brex card, which Google sees as a “privacy card.” These are often used by scammers trying to circumvent Google blocking their credit card account numbers.
The solution here is to never use a hidden or “privacy” card number with Google, although of course Google will never tell you that or confirm or deny this. I only know this due to working with clients in this area.
You can try removing that card and adding a regular hard card number and asking for a reinstatement again, but it may be too late for this account.
Hopefully this helps folks reading this to not make the same mistake (although it’s incredibly frustrating that stuff like this has to be learned by trial and error or knowledge from those of us who have dealt with this previously.)
> of course Google will never tell you that or confirm or deny this
This is my problem with de facto utilities that are not regulated like utilities. Google can have enormous impact on your business and personal life but you cannot get proper communications with them. If something goes wrong you can't fix it, even if it's your fault because often you don't know what you did wrong. If it's their mistake, you might get a chance if your issue gets attention by a large audience.
It feels like there should be a legal recourse where you get compensated for damages due to service design choices of the utility. I'm sure in many places you can get compensated if the energy company cuts your electricity and doesn't clearly say the reason and what you can do about it.
You can lose your business, you can loose access to your digital assets that you built all your life and for what? So that some employees at Google can have easier time managing an issue(not disclosing the reason for account restrictions probably makes the scammers life harder too and you are just a collateral damage that doesn't even show up in the analytics).
Can you imagine E.ON cutting off the energy of the English futbol fans because it's easier for them to internally manage the surges during the games due to the tea kettles and not give them any explanation whatsoever?
Edit: Interestingly, UK GDPR seems to have some protections agains automated decision making[0].
So that some employees at Google can have easier time managing an issue(not disclosing the reason for account restrictions probably makes the scammers life harder too
Yet, while this is often the cited reason, it is simply not true.
There is no way on Earth, that scammers don't find out about such restrictions trivially, easily. So all this really does, is inconvenience the honest, and do zip, zero, nada to hassle the miscreants.
edit: more thought here, likely this is just an excuse, to not properly train reps, or to not deal with the issue at all.
It is the equiv of "think of the children!", but corp speak instead of politi speak. "Sorry for the bad service, security issue!"
The hilarious thing is that that excuse is essentially just security through obscurity. Which is especially rich coming from the company whose vulnerability research team famously set a hard disclosure deadline that was shorter than many others at the time.
The engineering reality is that, much of the time, information asymmetry is a big help when you’re an anti-abuse engineer trying to build systems that distinguish good traffic from bad. It’s not an “undisclosed vulnerability” to build a very effective heuristic that wouldn’t be effective if it were public knowledge.
you would be shocked at how effective simple things like this are at stopping 90%+ of the bad actors, leaving significantly less manual work to identify the remaining 10%
And Google aren't the only offenders here. On Tumblr (now owned by Automattic) the only support case type where you're guaranteed to NOT receive answers is for the reason "account termination".
Any company with revenue greater than a certain amount, like a billion a year, or even way less, should fall into some category of public regulation that sets certain standards for consumer support.
I see no problem at all on measuring it by market share, as a proxy of consumer choice. One just have to keep in mind that the market has to be localized, not aggregated at some huge population.
Market share isn't a good measure unless you can clearly define the market. Make it too narrow and they are at 100%< make it too broad they are near 0% ... especially complicated with products you don't (directly) pay for ...
That could inadvertently sweep up popular labor of love projects with almost no revenue, like hobbyist communities or fan sites and so on.
A billion in topline revenue should do the trick. Once you hit that level you have to provide individualized human support. You're allowed to charge money for the support but it has to be available to anyone willing to pay at least a modest fee to communicate with a real person.
If you don't like it fuck you, you have a billion dollars get the fuck over it.
If a lonesome Pizza Hut franchise can afford to give me customer support, then so can Google, no questions asked. Yet you'll still find people white-knighting for them.
If you serve a lot of customers but have lousy revenue you should have extra regulations which would probably drive you out of business because of the extra cost? Revenue seems a lot more reasonable metric.
Maybe if your business sucks that much that you don't have enough margin to treat your customers well when they have issues... well, maybe your business just shouldn't exist.
Supermarkets crucially already have a customer support infrastructure and you can physically go to them to work out issues. If the burden is simply to have human customer support you can speak to then the burden is already fulfilled.
It is absurd that it is impossible to speak to a human at Google unless you have a loud enough platform. Amazon is similar too in many cases. As an Amazon seller the robot once decided that the price for an item on sale wasn’t correct. I told the robot it was in fact correct. The customer support person who I was able to reach after an incredible runaround told me through text only communication that the solution was to change the price either higher or lower. There was no way they could manually verify it. The robot had decided. In the end it took multiple guesses of adjusting the price to figure out what the Amazon robot would accept. This is beyond stupid.
It is pretty stupid that the people who work at Amazon can’t even override the faceless algorithm that makes arbitrary decisions. I don’t care about the metrics. I care about common sense.
And yet, supermarkets close down quite often to make a political statement or when margins aren't sufficiently high enough. Kroger is fond of closing stores in areas threatening to raise wages.
If we have governments specifying what a company does in those circumstances, wouldn't you expect that they would mandate that Google not accept these credit cards? Accepting them sort of flies in the face of the whole "Know your customer" approach that it seems like every government is promoting.
Antitrust enforcement is so scattershot, varying over time and depending on current us administration. It's like an entire higher level of abstraction over the problem. And in practice we have extremely little antitrust enforcement in the us over the last 20 years. We'd have to theoretically fix antitrust enforcement, then eventually "market forces" would force google say, to improve customer service.
Google is not going to change, they are one of the trillion dollar babies and they can just ignore us. Just like apple. What anti-trust enforcement could cause them to change? I'm skeptical the new EU rules about how "open install of apps to breakup app-store monopolies" will work to effect change.
Google ads are a natural monopoly, like power lines. What are you going to do, go to 1/3 of its ad customers and tell them they're switching to Southwestern Google while another 1/3 have to switch to Pacific Google?
And then one of them becomes dominate after 5 years, and the other(s) fold. It's an inevitable problem. The only way to "break them apart" that would make any sense at all would be to break off distinct divisions, like Search, YouTube, Gmail, Google Cloud, etc. Into separate companies. Then forbidding them to acquire each other, and generally be extremely pessimistic/restrictive if any of them attempt to acquire any company at all.
Nope, Google is utility. It is embedded on how the web works, it's not a matter of not having an alternative but it is a matter on Google defining how everything works. Whatever Google chooses to do, it becomes a standart. People design their products to fit Google's infrastructure.
When that infrastructure rejects you or your product, you are in trouble because everything is build around the assumption that you will be reachable over Google.
This is a horrible argument. If Google disappeared tomorrow the web wouldn’t lose anything but ads that I block anyway and you would go to another search engine.
I think this is about as silly as claiming that Microsoft controls how all computers work, or that Apple has the final say over every smartphone. Chrome has the advantage here, but that doesn't make them a defacto monopoly. If your definition was right, every other member of FAANG would probably have worse crimes to answer to wrt "defining how everything works". Even the people standing behind Apple have lost this fight, since even Safari has admitted it was wrong about PWAs. Plus, it's not like Google is all-powerful here. Negative public response got FLOC shelved before it hit Chrome betas, and they still don't have the gall to bring it up again.
Google is not a utility any more than Apple or Spotify is a utility. And if we're going to break up both of those companies, we may as well just dissolve every other Fortune 500 company while we're at it.
Except I don't agree with their definition. Google's ability to "choose how things work" comes from their investment in the web as a platform for things like GSuite, Google Meet and more. Plenty of other companies have the ability to speak up, but none of the big players (Apple, Microsoft) do because it would sabotage their market position. So, Google is the only one left making significant changes, aside from open source contributors/committees.
> Sounds great.
Now you're grossly missing the point. The problem isn't the status quo, it's the system. Tearing down Standard Oil will leave a power vacuum, and adequate incentive from suppliers and processors will just make another monopoly. If your goal is to get rid of those companies, that's a pretty counterintuitive way to do it.
Personally, I think our world needs to start taking digital standards more seriously, like ISO but taken to the next level. We let ourselves get in these positions because we don't force these companies to provide interoperability or data ownership. Capitalism can work in the tech sector at this scale, but we need better regulation and more strict rules around proprietary interfaces. At least, that's the accelerationist mindset; we can languish in technological fiefdom for as long as we'd like, I'm sure FAANG doesn't mind.
> Now you're grossly missing the point. The problem isn't the status quo, it's the system.
That is my point. A system in which any of the fortune 500 companies can come into existence is grossly broken on multiple levels. Companies should be afraid of getting more than 10% of a worldwide market for fear of real anti-competition laws coming into effect rather than the farce we have now, or of vertically integrating too much, and should only make proprietary interfaces as a last resort.
A company being in a position to unilaterally change web standards, and force a monopoly on their web browser to further monopolise their advertising business should be grounds for splitting it into pieces at the very least, and seizing it in its entirety as the expected oitcome if they exercise that power.
> Capitalism can work in the tech sector at this scale,
The surveillance state and pending apocalypse we live in where you get jailed for successfully fighting in court says that it really can't. Any regulation or democratic control is ephemeral when you are systematically assigning more power to megacorps on a daily basis.
I think between the democracy we have in practice and the megacorps, most would choose the megacorps.
Partially /s. But in general, democracy isn’t doing too well, and a lot of it is due to a massive segment of bored, decadent, and petty populace that would rather watch the world burn if it owns their political enemies. At least with megacorps there is room for competence and science.
> But in general, democracy isn’t doing too well, and a lot of it is due to a massive segment of bored, decadent, and petty populace that would rather watch the world burn if it owns their political enemies.
This is what the megacorps being in control looks like because they're the ones that led us here through ownership of media and thus any political candidate with a chance. Facebook, microsoft and google are only just getting started in the same space, and it is already many times worse than fox ever was.
I agree, We need legal measures. Imagine OP getting the Google Account itself banned then the only hope is to write a blog and pray that it makes to the front page of HN. It's ludicrous that we've accepted that if the Internet service is operating at scale, There would be no mechanism in place to address the customer's grievances even if that customer is an advertiser.
The first time I tried using Microsoft Ads, I used a debit card in which foreign payments wasn't enabled and as soon as I clicked make payment my account was banned, No recourse through support just like how OP faced with Google. But that was in my past life, I don't want to see Ads, So I don't show Ads now.
I've been unable to close my Facebook Account, Because I couldn't take backup of my business page and there's no way to reach to them.
Okay, and in the three years since then, have they made any progress? If not, why am I wrong if I think they may have just been using that as an excuse?
I do want to clarify that the phone companies making money from robocalls are not YOUR phone company. Phone companies that provide services to consumers lose money from robocalls, have to deal with unsatisfied customers, and really want both a technological and legal solution. The problem is a vast array of VoIP providers that let anyone with a valid credit card sign up and start pumping calls in real time. To them the revenue loss from people sometimes signing up with a stolen card and sending a bunch of scam calls is much smaller than that gained from having a low barrier for signup.
Unfortunately, at this point the solution is to play hardball and say "start either vetting your customers better or providing us with accurate uuids so we can block/report them for you, otherwise we will no longer route calls originating from your voip service".
Perhaps even connect the call to a automated message that says, "we're sorry, <voip telco> has had its services disconnected for fraud. Goodbye"
But US phone companies don't want to do that because of the potential revenue loss.
That's the path the FCC is going down, with starting to implement "Know Your Customer" rules similar to banks that require them to gather enough information to prevent easily setting up fake accounts.
Starting to implement? They promised a fix like 2 years ago. I have about as much faith in the FCC accomplishing anything significant as I do in buying an extended auto warranty from a random caller.
I mean we were starting from a system that was basically e-mail, except where providers were required to deliver all messages without any discrimination or filtering. They had to create a new framework that allowed for carriers to choose not to deliver calls, interoperable technology to authenticate calls, and now close loopholes that are still allowing bad actors access to the phone network. It's a fundamental rearchitecting of how the phone network works that requires every single operator to make upgrades, so yeah it's going to take some time. And you're not really going to see much progress until it's nearly finished because if 90% of the network is secure you'll just see the same volume of crap through the remaining 10%.
That date has already passed and it is still a serious issue. Not to mention the billions we handed out to telecom companies to assist with upgrades that they just pocketed.
You don't need to go all orwellian though. Just charge a security fee that makes spamming or scamming unprofitable for every call and add a simple way for the recipient to mark calls as wanted or unwanted.
> Unfortunately, at this point the solution is to play hardball and say "start either vetting your customers better or providing us with accurate uuids so we can block/report them for you, otherwise we will no longer route calls originating from your voip service".
Then this becomes a backdoor way for the bigger players to discriminate against new, smaller players that are otherwise legit and doing their best to keep spammers/scammers off of their network.
The absence of these problems in a big part of the world will tell you the problem is not, and never has been, technical. It's a political problem, or rather the problem with the leadership of US telcos.
That's fine, then the offenders would be the robocallers and the issue can be solved by targeting the robocallers. If it isn't being solved it's probably because they don't want to solve it.
E-mail spammers went to jail, I don't see why robocallers don't go to jail. It's way easier to locate them anyway. If we can fight spam mail, spam calls can be dealt with too.
Unless you mean 'so we should jail more of them', GP's making the same point. (Not 'I didn't get where I am today by' tone as I initially read it and suspect you may have.)
No, not suggesting jail, just lamenting I get daily spam through my gmail and other email accounts. Not to mention the recruiter spam that would be basically impossible to stop.
Robocalling seems like a much more tractable problem to solve though.
If you murder someone, you go away. If you rob 100 million people of 0.00001% of their life, you just did the equivalent of 100 murders. Seems no less criminal to me - in fact more so.
Seems pretty solved to me, at least for hard spam. The soft spam of useless marketing messages from companies that do have a legitimate reason to have my contact info is a harder problem.
Sure, yet I'm quite happy to see some jailed spammers :)
The point is, we are not hopeless. Actually, the e-mail thing was and is quite more problematic with accusations of gatekeepers(domain blacklists) asking for money but at least you know what's happening an how to solve it.
You're happy to see people go to jail for sending spam? This seems crazy from my perspective. It seems to me like a minor offense that wouldn't require jail time (and where jail would be counterproductive).
Of course if you are actually talking about scammers then I can understand your perspective, even if I'm not sure I would agree either.
I don't see it as a minor offence at all, spam distracts me and breaks my flow and spends my cognitive energy and as a result makes me underperform. I like putting all my attention to the stuff I'm engaged with and it makes me very angry when interrupted with something irrelevant. I do often try to track back spam calls or spam mails to make sure that I'm an expensive target.
Some people can be better at dealing with that kind of annoyances, good for them.
You want to send to jail everyone who distracts you and breaks your flow ?
This seems extreme to me. Maybe you can take less extreme actions to avoid this, like putting your devices in "do not disturb" mode while you need to work.
No, I don't want to send everyone who distracts me to jail. When someone distracts me in person I tell them to come back later, no jail time imposed. Someone sends me an e-mail about something but I'm not interested? No problem, I'll tell them thanks but no thanks. Call me for feedback on your product I purchased last month? No problem, if I'm available I will talk to you and if I'm not I will ask you to call later - no jail time required. You want to sell me an upgrade to my plan? OK, let me hear it now if I'm available or call me back in few hours of this is not a good time - jail free.
On the other hand, I would like strong punishment for people who make inconsiderate noise(bikes, prayers, street vendors) or directly reach me without addressing me directly(spam mails, robocalls). The problem with those is that they saturate my attention without having anything for me in it. It is very cheap for them and very expensive for me. That's why I try to make it expensive for them too, usually by engaging with them and making it unpleasant and unprofitable conversation and even making them spend money on stuff like shipping only to have it returned.
For those, jail is the civil alternative. I would be completely fine with anything more brutal, I have no sympathy. How can I have sympathy when their engagement is not a human one, its automated impersonal engagement designed to drain my time and resources for their gain.
Excessive punishment for minor infractions is a hallmark of an authoritarian police state, where the government selectively enforces laws in order to jail people it doesn't like.
I don't want to live in that society. I, too, get very annoyed when there's an unreasonable amount of outside noise encroaching into my private space, but the right way to fix that is to address the societal ills that cause people to engage in antisocial behavior. Yes, that's a lot harder than just throwing everyone in jail, but that is the only way you're going to create a healthy society.
It's alright, I don't have any juridicial power. I simply desire their demise(slow and painful one). In case I acquire some, we can discuss what's the proper punishment for spammers.
I'm assuming they are thinking more about fraudulent spam, Nigerian prince's and fake goods and the like, rather than just advertisements for real products spam
Spam is literally attacking communication infrastructure and stealing money. It is a form of cyberterrorism. Not to mention the sexual spam that is sent to minors non-stop. The fact that you think that is like speeding is messed up.
Isn't sending porn to minors already illegal? That should definitely be illegal, but I don't see why all spam needs to be criminalized to the level of cyberterrorism.
Scams are already illegal under anti-fraud laws.
Why should spam that isn't already criminalized (fraud/illegal porn distribution) be treated as a significant crime?
Because the only way to stop it would be at a federal level. If it originates on domestic soil and is traceable, then it could be a states issue with civil punishment, but most spam comes from overseas and the most effective solution would be to treat it as a serious foreign affairs issues and start heavily sanctioning countries that can't get it under control.
They could have used any spam filters they might have written to simply flat numbers so their customers could decide what to do for themselves. Instead we have to rely on third party services (and thus share private information with those parties).
Sure, I have no objection on that. The problem is that they don't communicate it and you need to guess. With Google, you don't have someone explaining you what's the problem and what you can do to fix it.
Right, and even if it's true that disclosing the detailed reason for a ban would hurt their security posture (I doubt it), I think in most cases it should be pretty obvious when the person disputing a suspension is just someone who got caught in the algorithmic crossfire.
But expending even the smallest amount of effort to determine that isn't something Google feels like spending time or money on.
The GDPR is useless though because they don't tell you why.
You're just left guessing as to what the problem may have been, not that you can do anything even if you did know. I've had the same problem with eBay.
Problem is it encourages the very behaviour they want to stop. If you're going to have an account thats central to your business, but can get shut down at any time, it just encourages burner accounts so you aren't left high and dry when the inevitable happens.
This is a recipe for a dystopian bureaucratic nightmare .
As soon as it's illegal to make design mistakes, there will be no more innovation or updates, everything stays exactly as it is. The Department of Design Friendliness will audit you quarterly. Improvements get designed and approved by government committees. It's like a scene out of the movie Brazil.
There seems to be this mindset of a certain class of folks that feel these companies [Google, Apple, Microsoft, Amazon, Twitter, Facebook, Netflix, etc.] are somehow entrenched for centuries and the only option . They're not. They're barely 20 years old in most cases. That's nothing historically speaking. A third of them will be failing into niches over the next decade. Capitalism sucks in many ways, but it is really good at "creative destruction". True monopoly power is rare.
Many are extremely vulnerable to disruptive competition as most of their revenue is from a single source: ads. Take that away, and they crumble. As Facebook and Twitter are discovering now that Apple/iOS default to blocked app tracking. Google search quality has plummeted and people are turning to alternatives like Reddit.
Microsoft, Apple, Amazon are less vulnerable to ads, but they too have vulnerabilities.
Google isn't a utility: you don't need to use it, nor do most people. Google search is dying in favour of alternatives like Reddit. Google mail is only one of many options. Android phones are only one of many options.
The solution for a better service is to build (if you're an entrepreneur) and use (if you're a consumer) better services!
This is such a naive take on this issue. Just because it is possible to live without Google doesn’t make it easy. Even if you try to actively avoid all of these companies you’re still going to most likely end up with your data harvested via third parties fed back into their machine meaning you’re still padding their bottom line. People are not going to suddenly switch to Linux on the desktop or Google-services free android forks en masse because they’re demanding better services.
Maybe they die and get replaced but in between that happening you are still having to deal with the realities of the situation you are currently. People just want shit that works and for most of them it does most of the time. But some people get absolutely fucked and there is no good excuse for it.
Who is talking about Linux on the desktop? It’s dead easy to avoid Google completely for average people. The Microsoft ecosystem is one way, at least on PCs and tablets. There is also the Apple ecosystem, which can easily avoid Google entirely down to the phone level, and not get anything harvested due to copious privacy features.
People get fucked with Google accounts all the time, yes. The excuse is that Google is made of humans. As is the government. Or Apple and Microsoft for that matter. Some of these humans are better at software than others. If you think this is an easily solvable problem through laws and regulations, that regulators are going to get software design and support processes right… I think you might not have studied the history of of such laws and regulations. The good ones take decades to get right.
The benefit of not enshrining these companies as a public utility, and thus guaranteeing a mandatory mediocre experience for decades, is that it encourages the use and creation of alternatives. That dies when you legislate features.
You mentioned those other companies as well though. So if you’re trying to avoid all of them then you are backed in to a corner and no average person is ever going to do so. It really isn’t that complicated. I’m not asking for the government to audit the software. However I don’t think it is too much to ask for an actual support channel. It is insane for a company that touches almost ever person on earth in some way to be impossible to reach for support.
I don’t even think the problem is that the company is made of humans. The problem is that when the black box algorithm makes a decision that locks someone out of their account or some service/feature there is no recourse. The humans are the solution to the problem, but you can’t get them to look at it unless you have a platform to stand on. It’s disgusting.
But some human made that algorithm. ML models are alchemy, no one understands how they work fundamentally, so they're very susceptible to human bias. James Mickens USENIX '18 keynote is a great laugh/cry view of this.
Regulations mandating a support channel of some sort is reasonable.
Also, I don't think it's reasonable to say a person needs to be free of ALL those companies. Decentralized for-profit organizations are how we get things done as a society, mostly. Pick the companies you trust/value. My point was mostly about avoiding ad-revenue-driven companies.
I think then we are actually a lot more on the same page. Not the read I got initially but this is my general feeling on the issue. Appreciate the discourse.
Experience has taught me they have no such qualms when keeping advertiser money whether or not they revoke publisher earnings.
As a teen (back in '09), I ran a domain parking network that was used by a modest number of users (about 50 users with ~300 domains total). At the time the Google AdSense TOS allowed any site that had "content" (there was no stipulation about it being original), so my network worked by displaying random wikipedia articles that are relevant (using a very simple algorithm) to the domain in question, along with several adsense blocks and a few other features. Each domain was also a fully functional wikipedia mirror, and content was properly attributed etc.. Anyway, most months I would get a payout of around $800 that I would then distribute to my users (I took a 20% cut). At 11:30 PM the night of payouts one month, they decided to change the TOS, revoke all of my earnings, and suspend my AdSense account. I sent an email to my users explaining the situation and I actually paid them all out-of-pocket for the missed earnings because I had the money to do so from doing random web design for local businesses and I felt quite bad -- some of my users were in dire rent situations, etc., and I was in regular contact with them so I wanted to make them whole even if it meant I would lose a good bit of money since I was a teenager without these sorts of problems.
Anyway, one of my friends ran his own online service (a network of web proxies) and he actually specifically advertised on my network because for some reason the traffic converted well for his particular service. I had him check his AdWords spend several weeks later and we discovered that he was never refunded for the ads that ran on my network, even though those earnings were taken away from me. In other words, at least back then Google probably didn't refund advertisers in cases of clickfraud, etc., unless the advertister specifically knew they were being defrauded. At least that's what appeared to happen based on the info I had access to haha. They are super shady.
The issues exist with normal non-anonymous cards also.
I'm currently having an issue because I used the same amex card on multiple Google accounts (within a corp gsuite instance), and I must have triggered something because now that card won't work anywhere with Google. And it fails with a useless "try again later error".
Same then happened with a standard visa card. These corporate cards haven't worked for over a year.
I wish they would just do some extra bit of verification rather than blacklist the cards without explanation.
Corporate cards have some of extra handling to deal with them. I know I tried to buy a WASD keyboard using a corp card, and their payment processor didn't let me use it either.
Looking around, it looks like when a Corp Card is issues (Capital one example[0]), they can lock the card to only be allowed with certain MCC (merchant category code). These are the codes that say what kind of product is being purchased. So it's possible the issuer of your corp card locked your card to certain MCCs. If your card in MCC locked, the merchant and processor likely won't know this until the payment has been tried, and there is a good chance the network/bank didn't send back a useful error code.
I'm sorry, but if this is the cause, it's complete and utter bullshit on Google's part. B2B is their bread and butter. They should have this (paying via a corporate card) shit figured out (or at least not give opaque reasons to the failures).
You should be able to handle for this by card type? When I wrote merchant software way back, we could separate restricted corporate cards from standard cards prior to processing, because we had to send itemized purchase records for corporate cards in a special format as part of the approval request. I believe corporate cards had their own card ranges and it was trivial to determine if you have the card number.
A funny story. Because they shoehorned this functionality into a fixed length messaging spec instead of repeating segments, we could only send like 12 items. Anything after that was just approved. If I remember correctly the same spec applied to EBT purchases as well. I'm sure they use a different message format now and you totally can't get away with buying 12 things and then beer with an EBT card.
I believe AMEX tries to mix all of their card types together (prepaid, corp, etc..), so you can't do that. But I do agree for MC and Visa, I think you can figure out many of these with BIN information.
Keeping in mind my perspective is as someone who helps clients with these—and I also have a tech company background, so I understand how anti-spam systems are built. I don’t have any inside knowledge.
Google likely uses privacy cards as one signal of whether an account is spammy. If you’re a customer who spends $1M a month with Google and you add a Brex card, it’s going to be far less likely to trigger an account suspension.
If, on the other hand, you’re this guy, with a brand new account and you start off with a privacy card, that puts their internal systems over the threshold for what they consider “spam” - bam, instant suspension.
I don’t think this is personally fair to new customers. Unfortunately, Google is always going to be geared to large customers and not to smaller ones. Most smaller companies will never encounter this situation anyway since they will use hard cards.
It doesn't sound like they are new though. They use other Google services and have a history with Google, it's just the Ads service relationship that is new.
If 50 ad impressions in half a day on an account they helped somenoe create a moment before ban is considered SPAM, then their SPAM detection systems are a bit lol, I guess.
Google has an internal policy of not talking about anything related to enforcement. They've banned and ghosted their own business partners, not to mention their own employees' husbands, with zero explanation. This isn't anything new either; you can find examples of it going all the way back to the company's founding.
The underlying logic seems to be to lay traps and pitfalls for bad actors to fall into rather than having a transparent and evenly-enforced set of rules. i.e. if we tell scammers they can't use privacy cards, instead of just silently banning anyone who uses them, then how can we tell scams apart from real users?
The goal is to capture as much revenue as possible. A company would never intentionally limit their revenue intake unless it was absolutely detrimental to the business. Inconveniencing the few customers who use these cards most likely doesn't show up on their radar.
> The goal is to capture as much revenue as possible. A company would never intentionally limit their revenue intake unless it was absolutely detrimental to the business.
Yes they would. Their goal is POWER and NOT dollars, which are worth less and less every day.
Just like corporate controlled mass media, the goal is POWER and NOT dollars. Dollars are the plausible deniability -- "it's just for the money!" is a mis-direction.
Using a privacy card is not an acceptable indicator of fraud or anything in a country with due process and a supposed presumption of innocence.
This is about enforcing approved behaviors in the Corporate Nanny state.
Google is constantly politically defeated by random old people in Mountain View with lots of free time. There is no amount of money you can spent to build an apartment building that might cast a shadow on their house one day a year.
Whether or not they lose revenue by doing this is hard to measure though. They're not just losing the business of the people they ban. They also lose the business of people who consider Google to be unreliable and risky.
In areas where they benefit from their monopoly, such as search advertising, it may not matter much in the short term, because people don't have a choice. But in areas where people do have a choice, such as cloud services or Workspace, it does matter.
It seems like a risky strategy to keep damaging your own brand while relying on monopoly rent to cover up any short term financial impact.
> The solution here is to never use a hidden or “privacy” card number with Google
The author regularly uses the same CC with many other google services
> The same credit card on the account, a corporate Mastercard from Brex, is attached to Google Cloud, Google Workspace, and Google Domains. Collectively, Google services have successfully charged that same card over $2,000 since that email.
Google Ads is a separate division with separate policies, separate payment infrastructure, and separate fraud detection systems. Don't try and make sense of it; it's inscrutable on purpose.
If Google Ads was a separate company, then the rest of Google wouldn't have an income source. Google is one breadwinner (Ads) + N loss leaders for it.
(They're trying to grow a second revenue generator — GCP — but it's not been the success they've hoped; especially compared to Azure. Microsoft had the B2B relationships already in place, while Google has mostly been a B2C company, so they've been struggling to win clients.)
Of course they would have an income source. They would sell space on their pages to Google Ads or any competitors, like most websites or media companies (newspaper, tv).
Ok I see what you're saying. You're right that we cannot really separate google from googe ads for their own products.
But Google Ads also sells ads on websites outside google (via Google Adsense). So it might make sense to separate AdSense from Google.
Aren't bans from Google services always eternal in the sense that trying to circumvent them by e.g. creating different accounts just gets you in even hotter water? Plus, it is very easy to detect when someone reinstates an ad (or Play Store app / YouTube channel) for something that was already banned under a different account.
If you make a new account just make sure the recovery phone number and email address aren't ones which have a bad history.
If you want to make a new ads account make sure in addition the postal address doesn't match a bad one.
If you want to make a new payments account, make sure none of the credit card numbers in the account match a bad one.
Note that because different teams within Google don't talk to one another, you don't for example need a new postal address if the issue is on the payments side.
Then the rules are quite different for AdWords. For Google Play Store accounts, "termination" means that your primary account, as well as any "related" account (what Google's algorithms determine to be operated by the same person/company), are all eternally banned from the Play Store. Attempts to open any new account will be subjected to the same algorithm and get automatically rejected if determined to be "related" to the previously banned account.
I am not making this up. Some indie Android developers have ended up in pretty Kafkaesque situations with their livelihoods (Play Store accounts) terminated without any explanation or human recourse, and with any attempts to circumvent the ban only leading to more trouble.
> any attempts to circumvent the ban only leading to more trouble
Is this a figure of speech, and not a literal situation? If you’ve already been banned, failing to circumvent that ban ultimately only leads to the same outcome: still being banned?
These bans seem to be completely automated. But if the developer did manage to get a human being to take a look at their case, any attempts to circumvent the ban would surely not look favorable.
> because different teams within Google don't talk to one another
Let's say they fix that at some point in future. Suddenly you will find yourself banned.
I get why this is hard for Google - there are probably thousands of scam accounts who've been banned making scam appeals all the time. They don't want to give those people a script to follow to get all their accounts unbanned, but if you are giving them money, they should generally be able to afford to have a real human look at your case.
I use a normal credit card that I use everyday and they canceled my account for no reason that I can see at all. No reason. No appeal. And they keep sending me email to create ads! This is despite paying for google domain, apps, and google drive space forever.
Can you imagine a company treating you like this in person?
Like say you walked into Wal*Mart and selected some merchandise from the shelf, then walked to the register and paid using a Vanilla Visa card, as you noted there was a Visa sticker on the door when you entered. While you are picking up your bag from the bagging area a security guard roughly picks you up and throws you out the door and tells you to never come back. You ask why but their only response is "You were being suspicious."
I have actually seen this multiple times - a very common thing, at least in the US, is using gift card magstripes for cloning stolen card track data onto.
This is mostly irrelevant in countries that use chip and pin.
You probably have enough history with Google to get away with it.
What they likely do is have several flags that push an account closer to being autobanned, so it's not just one thing, but a combination that gets you knocked out. I'd imagine a list like:
Using scammer friendly credit card: -10 points
Used a TOR exit node: -20 points
Account age < 2 years: -15 points
Account spend < $1000US: -10 points
Service being advertised is not well known to Google's data mining: -10 points
etc...
Get enough demerits and your account is toast, and since people are expensive once a bot flags the account you don't really have a recourse. Ironically if you want your ad to continue to run the best people to talk to probably isn't Google's tech support but black market scammers who have built and industry around understanding and circumventing these protections.
This is your best bet, because you used a some kind of burner/debit card.
Google does indeed discriminate on your payment method.
Most likely due to them having too much data to process they analyze the data from abusers and these kind of cards seem to stick out like a sore thumb.
That's not true, it's their choice not to process the data manually.
Google loves to leverage developers and code to fix every problem, including (especially?) customer service. In particular, they hate manual labor and seek to automate everything -- which is a horrible approach when it's applied unilaterally to all aspects of business relationships and customer service.
At some point, Google needs to grow up and learn that being clever only takes you so far. As it is, Google leaders seem to love computers and money, not people. I'd wager 20:1 that anyone at Google reading this thread takes action by tweaking algorithms, not by restructuring the company to help customers in person.
Google gained a tremendous amount of goodwill early on because they provided incredibly powerful free tools - search, web mail with 1GB of space, etc. -- which was so much better than what stingy incumbents offered (Yahoo Mail's free tier offered 10 MB of email storage at the time). But the rest of the industry has (mostly) caught up technically with them.
But cleverness and free tools will no longer be enough, since they're invading people's privacy (as ad revenue motivates them) and failing in customer service.
I'd say Google has fallen behind. Gmail is a good example. I switched to Fastmail, which loads on my PC in less than a second after I click the bookmark. Gmail takes nearly 10 seconds. And Fastmail provides a configuration profile to provide push notifications to the native iOS email client, something Google stopped offering 6-7 years ago.
The Gmail web interface has been crud for 10+ years now, but...it's free. Not too surprising that paid services are better. It's really hard to beat 'free' as long as it's barely good enough.
Too much data to process than they are willing to put time in to
When handling with huge streams of data, like in for example a SOC it's the 'big' streams and patterns of data on which is zoomed in.
For this reason the system is made (and learns to) discriminate against payment methods that are known to be abused.
Is this bad? Well.. do you want these scam ads to be around to hurt for example, your grandma?
Perhaps it's a necessary evil to make it all work.
Yeah the automation is a big problem but this seems to be essential for their scalability to work and be able to provide us all with the services they offer.
Burner/single use. Maybe it is different in different countries but Google do allow debit cards. Company credit cards are not standard in large parts of EU for instance.
Anyone know of a way to know if one's credit card is classified this way? The author was using the corporate card they were issued... and presumably hadn't sought out a "privacy card", a term I never heard before today.
Brex has a feature where you can create vendor-specific cards, which I think is what's being referred to as the “privacy” feature. It makes it less disruptive to disable a card if a vendor leaks it, because it only interrupts payments to that vendor instead of having to update your card with every vendor.
I wasn't using that feature here, but it might be the case that the information that arrives at Google is just the issuer so they classify all Brex cards as “privacy” cards?
Well that will just cement my lack of relationship with Google and ensure that my business goes to AWS.
Considering that many banks are doing this sort of service to protect you against data breaches, I can't see how this is actually an appropriate policy.
AWS does the same thing. My account was randomly blocked until they went through the documents I had to submit. IIRC, I had to use a different payment method too just like the OP.
The solution is to use multiple clouds. Switching from one SPOF to another doesn’t help.
With AWS I know I can always get someone on the phone who can, or if they can't they will find someone who can, explain any billing or technical question.
I don't know your situation but unlike any of the Google stories, you found out that you needed to submit a document and then you gained access? Google refuse to tell people what the problem even is.
The article implies that the card issuer (Brex) triggered the fraud suspension and the comments above agree. It was the same issue I had with AWS (but with a different issuer) and they never told me that was the problem. The paperwork I had to submit was in addition to fixing the payment method.
Some comments in here imply that, but there is no evidence anywhere other than randoms on the internet. There isn't even any implication from those people that changing card providers at this point would resolve this.
> The paperwork I had to submit
Who told you to submit paperwork? It already sounds like you had a terrible but better experience.
> Well that will just cement my lack of relationship with Google and ensure that my business goes to AWS.
How can you run your ads through AWS? Or a better question, what other ad networks that are comparable to what Google offers are there? Because to me it seems almost like a monopoly in regards to how impactful Google's services are - sadly they aren't regulated as such.
I'm assuming OP here was referencing Google's cloud services vs AWS. As in Google's abysmal behavior in regards to AdWords has spoiled them against using any other Google services.
This is true, although I don't manage our ads. But the amount of articles from folks on a weekly basis where they broke some unspoken rule that got them banned with no recourse and any relationship point of contact ghosting them is unsettling.
Unless these are actually all astroturfing stories by Microsoft and Amazon, I will stick to the companies who will actually speak to me if I have problems. They have internal communications, so my support ticket will actually reach other teams, and even working in a start up I can get conversations with finance and technical employees to get problems solved.
Google can have the advertising dollars since they are the 80 ton gorilla, but I can't see how anyone can trust them with anything critical to the running of your business.
> Google can have the advertising dollars since they are the 80 ton gorilla, but I can't see how anyone can trust them with anything critical to the running of your business.
Well that's my point - you might end up in a situation where you cannot use them for advertising and where you won't have many viable alternatives.
And it seems like Google will just get away with automation like that, either due to manual support just not being possible at that scale, or for other reasoning of theirs, without mechanisms in place for you to bypass the automation and actually get a solution for your problem, unless you operate at a certain scale.
It can be a hard problem to solve, but it is frustrating. Google ads has a threshold billing system in place (based on their public docs). What this means is they probably track how much each payment method has spent, and charge that payment method when it reaches $X.
My theory is below, but I have not researched or looked into virtual cards.
The problem with virtual cards or privacy cards: What's stopping a single physical card from having multiple virtual cards generated for it? So if someone had a card they knew could only be charged $100 and googles threshold is at $200, they could make 10 virtual cards and add the physical card resulting in 11 payment methods. Now they can theoretically get $2200 worth of ads (if all ad campaigns reached the threshold at the same moment).
In other words, fraud risk can go up significantly.
For corporate cards (and I beleive gift cards and debit, no idea about privacy cards they didn't exist yet) when I wrote this sort of software way back you could identify by card ranges/format (that was the case in the past), just like how you identify if a card is Visa, Mastercard, Amex. A Visa subrange will be corporate, restricted purchase, etc. So for example, a trucker can have a corporate card that works to purchase gas outside but not the CStore inside.
If you know someone who write's merchant software they should be able to get you the ranges from their payment processor's specs.
One version of it that I have used is "virtual" prepaid cards. The way it works is that I can use my online banking account to create a new "virtual" card and load it with a fixed amount from my bank account. A new single-use credit / debit card number (by Visa or Mastercard) would be generated with CVV and expiry date that I can use online anywhere. It provides an easy and secure way of transacting online without providing the Primary Card / Account information to the merchant. Another version I wasn't aware, has been explained here in another comment - https://news.ycombinator.com/item?id=32238813 ...
I have unique cards generated for online transactions, and I see this feature with multiple banks here in the UK. It seems mad that this would be considered a bad thing.
It's due to fraud risk. If googles threshold billing is X, then their risk of revenue loss is X*(N+1) where N is the number of virtual card numbers that have been created for a single physical card. The +1 is for the physical card.
Visa/Mastercard likely don't supply a way to link a physical card to it's virtual card generations (that'd be a security risk), so Google doesn't know that virtual card A is associated with physical card B.
But if somebody steals your login, they can create multiple virtual numbers and spend a lot. And since these are virtual number, MC or Visa will not have tools to find problem or block it.
Can somebody which knowledge of this explain problems with "privacy" cards and why scammers love them?
Mastercard and Visa aren't the ones at risk by such activity, the issuing banks are, and as someone who works for a bank, yes, banks have tools to detect and stop account takeovers and assist card members in recovering from such incidents.
Scammers don't care about privacy cards. They'll use anything they can get their hands on, metaphorical or otherwise. If it doesn't have their details attached, it's fair game to them.
That is extremely frustrating. I use a "privacy" card (issued by privacy.com) to containerize my monthly subscription spend, as I don't feel comfortable with any company having the ability to charge my actual card (which is a legit card). I'm using one with YouTube TV. I'll be pissed if they suspend my account because of this. There has to be a better way.
Nobody cares. Google, a 1,3 trillion company, a gargantuan gatekeeper, the 3 letter acronym factory can't give you a proper error message :D. And they smear it right into your face. They don't care about you. Just give them your money and shut the F up. That's all.
And people try to sort it out. I mean what's wrong with people? :DDDD
I have had similar problems using many platforms. I use virtual cards whenever I can to achieve better security and control of expenses (compartmentalization). I have given some companies my real name and address but used a virtual card, and then they locked my account later. This situation seems to be ramping up due to the escalating financial war with Russia. It would certainly be helpful if companies would tell us up front that if we use a payment card that cannot be firmly tied to our identity, they will lock the account afterwards. This would allow us to go somewhere else without wasting all the time to setup the account.
So, I've started using LibreFox recently. Signed up for IBM Cloud after verifying my credit card and lo and behold, an account suspension letter was delivered after an hour. I guess it has something to do with their algorithm triggering accounts signed up using privacy focused browsers.
Curious how this works. Google surely verifies things like business addresses, DUNS numbers, company principals (CEO et al), etc, eh? So what if the card is "private" if the rest is legit?
The solution here is to never use a hidden or “privacy” card number with Google, although of course Google will never tell you that or confirm or deny this. I only know this due to working with clients in this area.
You can try removing that card and adding a regular hard card number and asking for a reinstatement again, but it may be too late for this account.
Hopefully this helps folks reading this to not make the same mistake (although it’s incredibly frustrating that stuff like this has to be learned by trial and error or knowledge from those of us who have dealt with this previously.)