The Register Home Page

back to article Payment biz pulls plug on open source charity after KYC spat

The Free Software Foundation Europe says its electronic-payments provider Nexi Group unexpectedly "cancelled" its account – cutting the charity off from around 450 donors. The latest blog post from the charity, which helps to support free software, claims that over the past few months, Nexi requested "access to private data, …

  1. b0llchit Silver badge
    Facepalm

    Never attribute to malice what can be explained by incompetence. But it surely looks like incompetence at a malicious scale.

    1. Anonymous Coward
      Anonymous Coward

      Just because I'm incompetent, please don't try to impune or minimise my malice.

      1. b0llchit Silver badge
        Meh

        I'll leave that incompetence thingy you seem to suffer from to be handled by Dunning and Kruger. Then you may shine in maximised malice.

      2. Paul Herber Silver badge

        Well, I'm incompetent but I identify as malicious. Or is it the other way round?

    2. Len

      While I agree that far too often malice is assumed when incompetence is more likely, you should also be wary of malice disguised as incompetence.

    3. elsergiovolador Silver badge

      Never attribute to malice what can be explained by incompetence

      This is such a stupid quote. It exists to kill the follow-up question. And the follow-up question is always: why are you incompetent? Because usually the answer involves someone who deliberately underfunded, understaffed, or hired mates - and that's not incompetence. That's malice with plausible deniability.

      1. Anonymous Coward
        Anonymous Coward

        This is such a stupid quote.

        No it is not! It explains Donald Trump!

        1. Anonymous Coward
          Anonymous Coward

          Not really, he's malicious _and_ incompetent. If he was competent we'd be well and truly hosed (as opposed to just hosed)

  2. Doctor Syntax Silver badge

    Somebody's email got summarised by an LLM?

  3. LessWileyCoyote

    LLM talking to LLM?

  4. An_Old_Dog Silver badge

    Wait, What?

    ... access to private data, which we understood to be specifically the usernames and passwords of our supporters.

    "Understood to be"? There is no "understood" here! Either the processor did ask/demand the username/password info, exclusive-or, they did not. It's a binary condition, and FSFE having received the emails from their payment processor, must absolutely know the facts.

    The "we understood" phrasing smacks of weasel-wording and hand-waving/lying, though it may be due to the quotee's knowing English as a secondary language.

    Why did the quotee not themselves quote, or forward to The Reg, the relevant email(s) FSFE received from their payment processor?

    1. Alan Mackenzie

      Re: Wait, What?

      It is quite likely the request from the payment processor was couched in vague language, and attempts to clarify it failed. As though the PP wanted to demand the usernames/passwords, but in a plausibly deniable fashion. "We understood" might be an accurate statement of the FSFE's situation.

      1. doublelayer Silver badge

        Re: Wait, What?

        It is possible, but in that case, there'd be attempts to clarify what the data needed to be, subsets which the bank rejected, and plenty to back up that understanding. That is evidence that could have been provided. We're faced with two claims at most one of which can be true. Neither of the statements makes much sense to me so far, and the theory that the company intentionally wrote a vague thing which the FSFE nonetheless correctly and completely understood to mean something specific which the company explicitly denied here requires too many implausible assumptions for me to accept it without that evidence.

    2. EricM Silver badge

      Re: Wait, What?

      You might want to compare your simple 0/1 logic above to the extensive and mind-numbing legalese in letters from banks you probably received yourself.

  5. JLV Silver badge
    Black Helicopters

    KYC Know your customers laws make sense, but not in this context.

    They’re mostly in the banking and money-in,valuables/ money-out businesses, like casinos. You know, the mom and pop jewelry store that suddenly 3x their weekly intake and the extra is mostly badly used low denomination bills. Watching for money laundering, though they may look for spying and terrorism as well.

    It’s unclear what that type of overwatch would be looking for wrt donations to charities. And asking for passwords is not KYC stuff, IF that happens legally that will be law enforcement.

    Now FSF itself could be being checked out, but, errr, that’s just kinda bizarre due to it being so well known.

    1. Doctor Syntax Silver badge

      As per TFA, it's not FSF, it's FSFE, rather less well known.

      1. JLV Silver badge

        It doesn't have to be all that well known to the general public to fall well with the "known" parameters of KYC laws. A bank isn't expected to have deep expertise of its customers with them, merely report strange happenings and sudden unexplained increases of cash flow that could relate to money laundering to the appropriate authorities.

        The only thing that would make sense in a KYC context is if FSFE spent a good deal of its money financing dud consultancies that do little actual work, i.e. money in, money out. But that, again, isn't really something the bank / payment providers, at the entry end, would be looking into, that's more something law enforcement would have flagged, possibly through FSFE's accountants raising KYC concerns from exit side of things. And even then, a non-crypto donation coming in through credit cards and regular financial instruments looks like pretty clean money already, so not typically what KYC is concerned with.

        1. Doctor Syntax Silver badge

          "The only thing that would make sense in a KYC context is if FSFE spent a good deal of its money financing dud consultancies that do little actual work, i.e. money in, money out."

          Apart from being the province of lawenforcement, it's not something that would require user credentials.

    2. midgepad Bronze badge

      percentages and counts, and counters

      The bank etc wont be using it's brightest stars on this and they'll perhaps want some proportion of customers checked and cleared rather than of funds.

      1. JLV Silver badge

        Re: percentages and counts, and counters

        At least in Canada, where I had to take the test 3 years running due to working in a bank's IT, that is really not how KYC works. It's not a percentage of customers, it's 100% of transactions and situations that meet some very specific concern patterns. If you are in a regulated industry for it and you test 90% of your customers, but are found willfully ignoring a small number of recurring events they stated should be a red flag, you could be in trouble.

        1. OhForF'

          Re: percentages and counts, and counters

          Are banks although expected to ask their customer receiving the funds to identify the source if the bank can not?

          Is the bank expected to cut off the well known customer when they receive money from a number of sources the bank can't properly identify?

          I think the logical thing to do is to block the credit cards/accounts providing the money if those can't be properly identified, not the account the try to send money to.

          1. Anonymous Coward
            Anonymous Coward

            Re: percentages and counts, and counters

            > Are banks although expected to ask their customer receiving the funds to identify the source if the bank can not?

            Expected? Yes.

            The powers that be very much want citizens snooping around in each others' lives and reporting even the most mildest of suspicions (or perceived suspicions) to the "proper authorities." That becomes exponentially easier when money is involved somehow.

            Even those who don't directly feel the suspicion still experience the environment and worry about permission.

          2. JLV Silver badge

            Re: percentages and counts, and counters

            Typical things KYC Canada:

            - government IDs/biz registrations to be presented

            - EFTs > $10cad have special reporting reqs

            - multiple EFTs < $10k looking to fall under above limits: suspicious

            - large unusual cash deposits: suspicious

            - asking too much about KYC limits…

            Everyone - not “auditors” - customer facing is supposed to be watchful. Then there are compliance people who will look more closely and reporting mechanisms to liaise with authorities. Not cutting off customers, no. That would be counterproductive to catching actual criminals.

            I understand cynicism, to an extent, but we have so much damage here from hard drugs (no, weed doesn’t count) that a bit of inconvenience can be put up with. And, honestly, the patterns looked for are NOT typical money flows: that is the point. If you have a pizza stand you’re still expected to bring in tons of low denomination cash. Not regularly so if you sell new cars.

            The emphasis is on cash or foreign EFTs getting in, not tracking regular cheques or deposits emanating from actors already in the banking system. Scale matters: if you had $1M in $20 bills, how can you put them into sellable goods or “clean” bank accounts?

            As a normal individual, you can reasonably be expected to hit nominal flags from time to time, without tripping alarms. The teller will ask you some questions, at most. As a professional “mule”, you’re only worthwhile if you do this a lot more frequently.

            In any case internationally Chinese triads are undercutting laundering these days, charging 2-3%, instead of the usual 8-10%.

            1. Anonymous Coward
              Anonymous Coward

              Re: percentages and counts, and counters

              > I understand cynicism, to an extent, but we have so much damage here from hard drugs (no, weed doesn’t count) that a bit of inconvenience can be put up with.

              Equating invasive KYC with minor inconveniences normalizes a culture of pervasive, baseless suspicion, in which people who have done nothing wrong do have to worry about proving their innocence after tripping secret "flags" and inviting some degree of interrogation or account restriction. That's not minorly inconvenient, like waiting in a long bank line on a busy day.

              It's also corrosive to privacy when finances -- one of a person's most private spheres -- are treated as an open book for others to rifle through, interrogate, and demand justifications.

              > The teller will ask you some questions, at most.

              At most they don't like the answers, and freeze/take your money. Or nosy people get their jollies invading someone else's privacy.

              When it comes to finances, there really are a lot of things which are legitimately none of anyone's business. KYC snitch culture upends that.

    3. Mishak Silver badge

      Know-Your-Customer

      Is _not_ the same as Know-Your-Customer's-Customer

  6. Doctor Syntax Silver badge

    "Nexi insists it only wanted test credentials to check cancellation flows"

    In order to do that - in fact the best way to do that - would be to simply set up accounts and cancel them using the exact UI that real contributors would follow. No need to ask fro anything.

    1. ecofeco Silver badge

      I had to scroll this far down.

      1. Doctor Syntax Silver badge

        Yes, sorry. I should have spotted it earlier. I think we were ll too busy looking at how the spat developed rather than why.

    2. O'Reg Inalsin Silver badge

      Exactly why I think Nexi are lying.

    3. JacobZ

      ...or worse

      Im fact, if they wanted to do that check, the LAST thing they should do is to ask FSFE for test credentials.

      If FSFE were up to any funny business, they could rig their portal so that the test credentials would be recognized and take the user through acceptable cancellation flows, while continuing to do whatever shenanigans Nexi is worried about for everybody else.

      Far better to, as you suggest, to anonymously set up an account like a real contributor without announcing their intentions to FSFE.

      Everything about this smells.

      1. Claptrap314 Silver badge
        Black Helicopters

        Re: ...or worse

        There might actually be regulatory or compliance reasons that they could not do this. It might be considered "fraudulent" without the appropriate legalese.

        Might. Might.

    4. Liam Proven (Written by Reg staff) Silver badge

      > In order to do that - in fact the best way to do that - would be to simply set up accounts and cancel them using the exact UI that real contributors would follow. No need to ask fro anything.

      You think they have anyone smart enough to work that out?

      1. Anonymous Coward
        Anonymous Coward

        Nor any lawyers smart enough to insist on it.

      2. Doctor Syntax Silver badge

        "You think they have anyone smart enough to work that out?"

        In view of some of the other comments below maybe this is one where we don't attribute it to incompetence.

    5. FeRDNYC Bronze badge

      Even PayPal verifies bank-account access by posting, and then reversing, two small (sub-$1) deposit transactions via the provided routing and account numbers; you then submit the randomized dollar (or, really, cents) amounts of the two transactions to verify that you've provided the correct bank account details. Because, you're right: as with email-address verification, also, any type of transactional validation is best performed by making use of the actual system under examination.

      I suppose Nexi could claim that's what they were trying to do, but they wanted FSFE to go through the work of creating the accounts for them because they're too busy to bother with that half of the process when they only want to test the other half. They can say that, and I can say it sounds like they're full of shit.

    6. Anonymous Coward
      Anonymous Coward

      Out-of-Bounds

      It's not in a payment processor's bailiwick to do that sort of "testing".

      That's for governmental consumer protection agencies to do.

  7. xyz123 Silver badge

    Nexi has been doing this a LOT lately.

    Literally asking for usernames, passwords, dates of birth, home addresses, full financial records and emails received by donors from a LOT of charities and organizations etc etc

    Check https://en.wikipedia.org/wiki/Nexi for info on this company as it now has some VERY suspect Iranian, Russian and Chinese ownership........

    The company has collapsed from over $20 billion valuation to just over $5 billion. This looks like a last-ditch attempt to grab some data to sell to foreign governments.

    Probably doesn't help it was created by/for the Fascist Mussolini government in 1939......

    1. Claptrap314 Silver badge

      Wow. And actual, appropriate use of "fascist" in 2026. Will wonders never cease?

  8. FeRDNYC Bronze badge

    FSFE are the proponents of the REUSE standard for open-source license verification, and the developers of the software repository license management and validation tool of the same name. They're good folks.

  9. MachDiamond Silver badge

    Why not other ways to donate

    There's loads of payment services that support automatic monthly payments. YouTubers often use Patreon. Churches use plenty of others as a way to "prevent people from forgetting" to bring some money to put in the collection box/plate. If one payment service is getting a bit weedy, use another or several others. I know that one problem can be getting people to switch over since they might just decide to continue support, but that loss is better than losing the whole stream all at once. If there are several ways to donate, it spreads the risk of this sort of thing happening again in a large way. For the YouTube channels I like, I try to support them directly rather than through a service. More of my donation gets to them rather than being nibbled or nommed by a payment service. I don't do auto-pay.

    1. FeRDNYC Bronze badge

      Re: Why not other ways to donate

      Well, FSFE have already contracted with a new payments processing service and migrated their donations form to use that service instead, so there is indeed now another way to donate. As for why not offer multiple ways to donate, well...

      • Patreon, specifically, is not generally considered a good fit for charities or non-creative endeavors. There are a (very limited) few software developers who use it as a donations platform, but for the most part the typical Patreon page is a showcase for the work of a creative artist and that's where the expectations of its community of donors tend to fall. Plus, like Kickstarter (which is a very different platform in many ways, and slightly more popular for engineering/software projects) the expectation with Patreon is that you'll regularly provide your donors with updates on the work they're supporting — it's basically a blogging platform with a paywall component. The amount of effort required to maintain that line of communication with the donors is a potentially significant drain on a charity's already limited resources.
      • Offering multiple options can actually discourage donors, who (having chosen to part with some of their hard-earned cash to support an organization) don't want to then be asked to put in the extra effort of deciding how to donate.
      • Splitting the funding streams among multiple services also makes it harder for the organization receiving the funds, which then has to contend with managing relationships with multiple providers, each of which may have different percentages, timeframes, policies, and requirements.

      1. Anonymous Coward
        Anonymous Coward

        Re: Why not other ways to donate

        > As for why not offer multiple ways to donate, well...

        FSFE also must consider:

        *Donor with too many accounts skips $PLATFORM they're not on to avoid registering another.

        *Annoying registration process.

        *Left $PLATFORM for bad service or spam.

        *Donor has an issue with $PLATFORM's privacy practices.

        *$PLATFORM is in the wrong country.

        *$PLATFORM's politics.

        *$PLATFORM has obnoxious or intrusive verification/anti-fraud policies.

        *$PLATFORM asks to confirm identity.

        *$PLATFORM's past controversies.

        *Who $PLATFORM does or doesn't do business with.

        *Etc.

        Donors can be a picky bunch in general. Free software donors probably even more so.

      2. MachDiamond Silver badge

        Re: Why not other ways to donate

        "Patreon, specifically, is not generally considered a good fit for charities or non-creative endeavors. "

        I don't use them so you could be right. I know they do have automatic ongoing donations so it could be made to work in a pinch.

        I wouldn't suggest a dozen avenues for donations, but 3-4 might cover some bases including a way to mail in a donation for those that don't wish to use an online service. I know I skip loads of things through sign-up/app fatigue and I am not going to give my financial/payment information out willy nilly.

        The issue is solving a downside of having a single donation mechanism that is operated by an an outside entity. If that means some a bit of management, that's a cost of having some redundancy. To have donations suddenly stop is more worrisome than spending a wee bit of time setting up another account. There isn't "managing relationships with providers" as an ongoing and time consuming process. You sign up if you agree with their terms and monitor any changes to their policies and that's it.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon