Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • They should have to ask for the ccv every double in billing average.
  • Should the father have been more involved to prevent this kind of thing? Sure.

    Should tech companies make this kind of thing this easy? No.

    Everyone in here defending our corporate overlords has had the Overton window moved so far on them that they've lost perspective on how companies should be expected to be part of the social contract.

    We should be building a world that makes it easy for people to do the right thing. Not penalizing them for accidentally doing the wrong thing because nothing matters anymore but the shareholders.

    Youtube is a fact of life for modern parenting, and it has absolutely atrocious parental controls. As we all know, these companies are filled with people who are perfectly capable of building systems that function to make the world better and easier for everyday people like the father in this story.

    And yet somehow we're defending the fact that they're doing the exact opposite...

  • > Everyone in here defending our corporate overlords

    Google specifically. The amount of people that "participate" in any thread related to Google posting and upvoting narratives that are good for it is staggering. The ones holding Google accountable are always at the bottom of the threads, flagged.

  • Everyone that thinks its reasonable for someone to set up an ad campaign for their 9 year old son's YouTube channel also has a very warped perspective and is well aligned with the companies you want to blame.
  • When I was 9, long ago in the dial-up age, I dialed into a long distance number within our area code and we got a $100 charge for my using Active Worlds.

    Suddenly, I don't feel so bad about that anymore.

  • My internet provider in the early 90s maintained a Unix system with pine and lynx; it only allowed access to WWW a few months after we subscribed to their dial-up. I didn't know what to do with that remote system, but I knew `cd` and `ls`, so I looked around. Somewhere on the filesystem, I found a Hexen (IIRC) demo, and decided to download it via Kermit (the only tool/protocol I knew how to use). It took almost a day to finish, but in the end it ran - I was overjoyed. I somehow even found a cheat code for all weapons, and spent a few weeks playing the first 2 levels, while occasionally poking around in the remote system. Then the phone bill came - for 7x more than normal, on top of the ISP subscription - and I lost access to both the Internet and the computer for more than a month. Needless to say, I learned to watch that connection timer like a hawk, and it served me well for the next 10 years before broadband connection was available.
  • Didn't the card have a limit?
  • Many corporate cards (or even personal cards for high-earners and impeccable credit) do not have "limits". At least not limits that will be reached with normal usage.

    There is undoubtedly still some balance threshold that will trigger an internal account review and probably a phone call, though.

  • Corporate cards often have huge limits. See also https://news.ycombinator.com/item?id=49725666
  • Literally the first sentence in the article

    "The button said approved every time as nobody had set a limit."

  • Do not let that kid (or his dad) anywhere near an OpenClaw instance.
  • "after the (9-year old) boy complained about views"...what a time to be alive.
  • I feel like there is a bizarro world I’m not privy to….

    I cannot relate to this story as a Dad of a 7 year old..

    1. Dad setting his son up on YouTube with his own channel at 9!

    2. Proceeding to tell him about the creepy world of ads and targeting.

    3. Creating an ad campaign for the kid!

    4. Putting that charge on a company card!

    5. Saving the card in an online account! Probably means the kid was using the Dad’s account?

    6. When things go south, even saying the words “matter has been escalated and he does not yet know whether he will get to keep his job or have to repay the costs.” as if it is all the universe’s or someone else’s fault… or such a common mishap that it is worthy of just waived away.

    As judgemental as it sounds… I feel sad for the outcome, but even more sad if this is the normal in our society of today :-(

  • i don't think it's that normal which is why it's newsworthy. I'm a father of a 16 and 14 year old. The 14 year old had a youtube channel when he was 9 or 10. I helped him set it up, he was making Minecraft tutorials which I thought was pretty cool.
  • This is one reason why I don't save my payment method for anything. No saved payment method means one less way for surprise charges.
  • I feel something is horribly wrong with these ad-companies if there is no contact and automatic approval for spending over 100k on ads... From seemingly small and unknown entity.

    I would expect some verification or contact, but maybe I just don't understand how world operates...

  • If I remember correctly I got a call from GMG, 15 years ago, to confirm a purchase of … $15 game key. Maybe Google Ads have such great deal with card acquirers they don't care about fraud/chargeback rate. Or it is the other way around, the amount of fraudulent spending is so high they don't even try fighting it.

    > maybe I just don't understand how world operates Amazon decided friction during purchase is more costly than asking for CVV/CVC. For better or worse (like in case of Ford Pinto) corporations can count their money.

  • Is there not something like fraud detection for an unusual amount of spending, like 40k per week?
  • There are so many things wrong with this story before you even get to the headline.

    From the information in the article, I can’t really blame Google for this one. This was a series of deliberate blunders on the part of the father. The first blunder was letting a 9 year old have a YouTube account.

    Putting aside whether a 9 year old should be making videos, the father should have been the one with the account and managing the channel.

  • Yes and showing the kid how to spam others when he's unhappy with not having as many viewers ad professional streamers is also questionable.
  • The article doesn't call it out very loudly, but...

    "to a company credit card the father had saved to his own Google account, which his son also used"

    It sounds like the son didn't have an account. It was just the father's account, with billing info attached with no limits.

  • The craziest part of this story, for me, is it was on the dad’s _company_ credit card. Which might not be as surprising except the reason it was already on file is because the dad used his company’s (not _his_ company, the company he works for as an employee) credit card to buy Roblox for his son previously.

    Is this common? I’ve had access to company credit cards before on a one-off basis (never in my name). Do people legitimately make this mistake? “oops, I put it on the company cards”?

  • I havent had a company card for a while, but when i had one the end of the month auditing was exhausting, I dreaded having to put together the report... Unfortunately for me, no one else wanted to take on the responsibility so I just had to do that for years...
  • He also says in the video that he spent 20$ with the company card on ads. (which probably made it much easier for the kid to spend much more on it)
  • I used to have a company credit card which I didn't use much--and avoided using whenever I could because I got more personal benefits on my own card (and that was a pretty universal attitude among most people to the annoyance of the powers that be). We were personally responsible for the monthly bills ourselves in any case. Never had a corporate card that the company just paid off no questions asked.
  • I have a company card on a permanent basis. I have not added it to Apple Pay exactly for this reason, I don’t want to risk accidentally selecting it for a private purchase.
    by msh
  • Small business, but basically everyone gets a card. We do not have a procurement department, so we are responsible for our spending. The card is in our name so we would be legally responsible for any purchases made using it.

    It helps reconcile purchases orders, and on the accounting side for purchases that aren’t directly attributable to something we track in the ERP.

    The dangerous part is effectively it’s tied to virtually unlimited credit without oversight, but it’s a serious criminal offence to miss use it so no one is going to purposely use it for personal expenses (embezzlement/fraud).

  • > Do people legitimately make this mistake? “oops, I put it on the company cards”?

    i've done this with like a cup of coffee but not something like a game for my kids! What happens in my case is the charge is not approved for reimbursement and it's up to me to pay the bill. I feel bad for that father.

    edit: it's a corporate card but it's in my name so I can actually charge whatever i want but the company only reimburses approved charges, whatever is left over is up to me to pay. As a sibling comment said, what everyone does is use their regular personal cards for the rewards/loyalty points and then submit receipts for reimbursement manually. In consulting where you travel a lot this can be thousands per month in rewards.

  • >Is this common? I’ve had access to company credit cards before on a one-off basis (never in my name). Do people legitimately make this mistake? “oops, I put it on the company cards”?

    It's worse than that, because he specifically entered the company card to pay for robux. It's not like he added the company card for an earlier (company) purchase and then it accidentally got used.

    >Dave said he entered the company card himself to buy Robux for his son, and it then sat saved on the Google account that also carries his work email, calendar, and files. Dave did not say why he used the company card for that purchase.

    Moreover I can't think of any reason why he would be using the company card in the first place. In any company with proper controls you'd have to justify every expense and/or reimburse. It's just simpler to use a personal card, unless he was trying to embezzle some money.

  • Robux has a lot of abuse, so is more likely to deny a legitimate transaction as a false positive. He probably used his own credit card first, it didn't work, and then used his backup card, the corporate card, instead. Then claimed it as a personal expense and paid it back.

    Corporate cards are generally set up to allow this. If you're traveling on company business, there's a relatively high chance your personal card gets denied. Especially when on corporate travel -- if you use the corporate card for airplane, hotel and car, the personal card use for souvenirs looks a lot more like stolen card use. Companies don't want employees inconvenienced while on company travel, so they allow use of the company card for personal expenses as long as the expenses get properly claimed and paid back.