Explore Problems
Showing 307 of 8,810 problems · matching your filters
Reissued Fraud-Protection Cards Retain Compromised Card Information
After reporting fraud, a customer can be issued a replacement card described as needing no activation because the account information hasn't changed, meaning it may retain the exposure that caused the fraud in the first place. The subsequent fraud claim is denied and closed against the customer despite a clear pattern of repeated unauthorized charges.
Loan servicers hold payments unapplied for months despite escalations and deadlines
A student loan servicer failed to apply a $1,200 payment for nearly 11 months, repeatedly missing its own self-imposed resolution deadlines even after regulatory complaints and confirmed payment trace numbers. Borrowers have no enforcement lever to force timely reconciliation beyond filing repeated complaints.
Wells Fargo Restricts Account for Fraud Alert Then Charges the Disputed Transaction Anyway
After a customer flagged an unrecognized transaction, Wells Fargo restricted their account and issued a new card — then processed the disputed charge anyway. The fraud prevention process caused double harm: account disruption plus no actual protection. Customers are left worse off for engaging with the bank's fraud reporting system.
Debt Collectors Report Accounts Without Providing Required Validation
Consumers dispute debt collection accounts that collectors furnish to credit bureaus without completing the legally required validation process. They receive no adequate documentation proving the debt is valid or that they agreed to it, leaving them unable to resolve or remove the entry.
The Web Is Built for Human Fingers, Not AI Agents
AI agents capable of autonomous work are blocked at every turn by human-centric web infrastructure: CAPTCHAs, browser-rendered UIs, 2FA flows, and modal-heavy signup gates that assume a human is present. This is a structural gap between agentic AI capability and the web stack it must operate on, creating a compounding bottleneck as agent usage scales.
AI Chatbots Hallucinate Bookings and Promises in Service Businesses
LLM-based customer service bots in high-ticket businesses (clinics, salons, restaurants) frequently hallucinate compromises, confirm impossible bookings, and promise nonexistent discounts because they are optimized for helpfulness rather than business rule enforcement. This creates liability, lost revenue, and damaged reputation.
Unbundled Admin Gaps in Professional Services Costing Revenue
Professional service firms in dental, legal, CPA, and property management lose significant revenue and time to repetitive admin tasks that off-the-shelf software handles poorly. Specific unmet gaps include missed-call text-back, prior authorization tracking, scope creep monitoring, and tenant communication logging. These businesses have budget and are willing to pay for focused, lightweight standalone tools.
Hardened self-hosted servers are compromised via unknown attack vectors with no forensic tooling
Self-hosters and small teams running hardened VPS configurations face server compromises from novel attack vectors — potentially kernel exploits or init system vulnerabilities — that bypass all standard defenses including disabled password auth, fail2ban, and locked root accounts. Post-incident forensics are extremely difficult without enterprise-grade SIEM tooling, leaving self-hosters unable to understand the attack vector or prevent recurrence. This gap between enterprise security tooling and self-hoster budgets is widening.
Unexpected $642 International Roaming Charge With No Dispute Resolution
An AT&T customer made a small number of short international calls and was retroactively billed $642 without warning; the carrier refused to apply a lower-cost plan retroactively or resolve the dispute, threatening service cancellation if unpaid. This illustrates a structural lack of upfront cost transparency in telecom international billing.
Homeowners Insurance Adjusters Systematically Underestimate Storm and Water Damage Claims
A homeowner with a $270,000 policy received a fraction of the payout needed after storm damage, because the insurance adjuster performed a cursory inspection, missed extensive water damage and mold later confirmed by a remediation company, and refused to revise the settlement. This points to a structural gap in how insurers assess and validate damage claims.
Hardcoded API keys and PII leaks in client-side code go undetected
Developers routinely accidentally embed API keys, tokens, and personally identifiable information directly in browser-accessible code repositories. Standard CI/CD pipelines and code review often miss these leaks before deployment. A local, privacy-first scanner that identifies credential and PII exposures without transmitting code to external services addresses a high-severity security gap.
Credit Bureaus Reject Disputes Without Real Investigation
Consumers who dispute inaccurate accounts on their credit report are frequently told the information is accurate with no visible evidence of a substantive investigation. Repeated disputes over the same error rarely trigger deeper review, leaving errors uncorrected indefinitely.
Teams Outgrowing Spreadsheets Need Database-Like Tools with Permissions
Large organizations with 200+ employees struggle to manage complex data in spreadsheets. They need structured database solutions with spreadsheet-like interfaces, granular permissions, and file management capabilities.
Incorrect Foreclosure Fees Applied After Mortgage Servicing Transfers
Borrowers with a spotless payment history report being charged foreclosure-related fees after their loan is transferred between servicers, based on inaccurate claims of a prior foreclosure status. The new servicer cannot clearly identify the borrower's original lender or justify the charges, and disputing the error is met with dismissive responses. This reflects a recurring breakdown in payment history and fee accuracy during mortgage servicing transfers.
No Unified SDK for Object Storage Across Cloud Providers
Developers must use separate, incompatible SDKs for each cloud storage provider (S3, GCS, Azure Blob, R2), creating vendor lock-in and requiring rewrites when switching or supporting multiple backends. A unified abstraction layer is missing in the JavaScript ecosystem. 229 HN upvotes validates strong developer demand.
AI Citation Traffic Is Invisible to Marketers
Marketers and SEO professionals have no reliable way to track when their content is cited by AI assistants like ChatGPT, Perplexity, or Gemini. This traffic gets misattributed to direct or dark social, leaving an entire growing channel unmanaged. As AI search becomes a dominant discovery method, the measurement gap creates compounding strategy errors.
Shopify gates basic ecommerce features behind mandatory paid app subscriptions
Shopify deliberately excludes standard ecommerce functionality from its core platform, requiring merchants to purchase third-party apps for features competitors bundle as standard. Monthly app costs compound into hundreds of dollars per month on top of Shopify's own fees. During outages or billing disputes, merchants face fragmented accountability with Shopify and each app vendor disclaiming responsibility for the combined failure.
Shopify removes native features in updates to force merchants into paid app subscriptions
Shopify platform updates routinely remove or degrade previously available native functionality, with the removal justified by directing merchants to third-party apps. Merchants accumulate a fragmented stack of app subscriptions for features that were previously built-in, with each app adding monthly costs and an independent support relationship. When the combined stack breaks, neither Shopify nor individual app vendors accept accountability for the interaction.
Business automation pipelines silently fail with no reliable observability
Companies running critical automations via tools like Zapier, Make, or internal scripts lack reliable monitoring — failures are silent or produce subtly wrong data that is hard to catch. Existing solutions focus on infrastructure monitoring, not business process health. The gap causes real financial and operational harm when automations break undetected.
Identity Theft Discovered Too Late During Mortgage Application
Multiple fraudulent accounts were opened using a consumer's identity and went undetected until a mortgage lender pulled their credit report. Existing credit monitoring failed to alert the consumer before significant damage was done.