The referenced write-up based on the Persona front end code is here:
https://vmfunc.re/blog/persona
I definitely recommend reading this primary source before drawing conclusions about the code as most of the secondary reporting is quite low quality.
Submitted 6 days ago but flagged https://news.ycombinator.com/item?id=47059129
@dang can this get a second chance?
I read it and, maybe it’s because I’ve spent too much time in fintech, I don’t share most of the concerns.
The differences in proclaimed data retention periods is concerning though. The rest is par for the course for KYC/AML.
Good article but the web site gave me eye and ear cancer.
Please make it actually readable and don't steal my audio!
Seems to be down for me. https://web.archive.org/web/20260220192124/https://vmfunc.re...
Note also there's a direct response from Persona's security team here[1], and a lot of back and forth from Rick on Twitter[2].
[1]: https://withpersona.com/blog/post-incident-review-source-map...
[2]: https://x.com/Persona_IDV/status/2025048195773198385?s=20