Live data from Hacker News

What happens when you swipe a credit card

tech.affirm.com

91–100 of 178 posts

Re: What happens when you swipe a credit card

#91
post #4

> swipe your card Sadly swiping is being replaced by chipcard.

> Sadly swiping is being replaced by chipcard. I see this being downvoted, and I'm wondering if it's not simply just misinterpreted. Most places in the US I've used chip&pin, the process goes like this: - arrive at merchant, select goods, get total. - look for a sign that says chip is not enabled. - failing that, move assuredly towards the chip reader and keep an eye on the cashier to ensure he or she doesn't move to…

Any idea why is the experience this bad?

I'm in Europe and never used swipe cards (haven't seen a cheque since I was a kid, not sure they're even used anymore, but I digress) but the experience is really simple and the times you mentioned are always shorter.

Select goods, put the card in, enter PIN, 10 seconds later I'm walking out of the store. With contactless cards it's getting even simpler and faster and I insist buying at shops that use them. In that case the whole transaction is just one short beep and I'm out. If the total is over ~$20 then I also need to enter the PIN.

Re: What happens when you swipe a credit card

#92

What annoys me is the expiry date and CVV. It seems like their solution to "more secure" is just to add more numbers. How about put the last 3 digits on the back, and call it the cvv ? How about use alphanumeric card numbers so we dont have to use as many digits ? Get rid of the expiry date used as validation. It's just more entropy, if you need more entropy then add another digit. It's just annoying having to type t…

I think we can all agree the correct model is a card that generates a globally unique card number for each and every transaction (e.g. coin failed , final). It should also have a 2nd factor authorization like CVV which is not embedded in the magnetic strip (can't be read by swipers).

Recurring billing is a major feature of credit cards that some merchants find very important.

Re: What happens when you swipe a credit card

#93
post #77
post #11

I'm kind of disappointed that you didn't go into the security features present in a typical credit card transaction. For example, you could describe the crypto protocols used to communicate with the gateway and/or card processor, what kind of data the stripe and chip contain and how it is used for authentication, etc. Another thing I find interesting is the anti-tamper features that are present in a standard credit c…

The way I see it, this is describing the system exactly as much as it needs to make its case that 'banking system is bad and expensive, use our stuff'. Covering security, or the lower fees in Europe (thanks mostly to the security features), goes against the narrative. An interesting tidbit: An extra reason US fees are so high are premium credit cards choke full of rewards: Not every card has the same fees, and the hi…

Well if we really believed in the free market and consumer protection, there'd be a law requiring the total transaction cost be printed on the sales slip. Whether the merchant pays it or passes it onto the consumer would be up to the merchant, but the amount would appear on the slip so the consumer sees these costs and who is paying for it.

What we really have is mercantilism, where the issuer by contract disallows full information to be conveyed to the consumer without the consumer's consent, and this is in effect protected by law by the fact it isn't illegal. You could also call it an example of chrony capitalism.

Re: What happens when you swipe a credit card

#94

Does anybody know if using Stripe if we can pass the 2.9% fee onto our customers? We offer customized consulting plans that vary and typically in the thousands, so thinking of just adding a 3% credit card processing fee to the invoice for clients that use card. Researching around the net, it seems for traditional brick and mortar, some issuers don't allow you to charge a percentage based card processing fee. Any idea…

It's complicated and depends on things like where you're charging and whether or not it's a "fee" for using the card vs. offering a cash discount (how these are not essentially equivalent is beyond me):

Sections 1.5.4.2 & 5.6

https://usa.visa.com/dam/VCOM/download/about-visa/15-April-2...

Section 5.11.2

https://www.mastercard.us/content/dam/mccom/en-us/documents/...

IANAL, etc.

Re: What happens when you swipe a credit card

#95
post #94

Does anybody know if using Stripe if we can pass the 2.9% fee onto our customers? We offer customized consulting plans that vary and typically in the thousands, so thinking of just adding a 3% credit card processing fee to the invoice for clients that use card. Researching around the net, it seems for traditional brick and mortar, some issuers don't allow you to charge a percentage based card processing fee. Any idea…

It's complicated and depends on things like where you're charging and whether or not it's a "fee" for using the card vs. offering a cash discount (how these are not essentially equivalent is beyond me): Sections 1.5.4.2 & 5.6 https://usa.visa.com/dam/VCOM/download/about-visa/15-April-2... Section 5.11.2 https://www.mastercard.us/content/dam/mccom/en-us/documents/... IANAL, etc.

Thanks, I may have to reach out to Stripe directly to get an answer. My fear is that Stripe will say it depends on Visa, Mastercard, AMEX and defer to them which is not very helpful.

Re: What happens when you swipe a credit card

#96

What annoys me is the expiry date and CVV. It seems like their solution to "more secure" is just to add more numbers. How about put the last 3 digits on the back, and call it the cvv ? How about use alphanumeric card numbers so we dont have to use as many digits ? Get rid of the expiry date used as validation. It's just more entropy, if you need more entropy then add another digit. It's just annoying having to type t…

I think we can all agree the correct model is a card that generates a globally unique card number for each and every transaction (e.g. coin failed , final). It should also have a 2nd factor authorization like CVV which is not embedded in the magnetic strip (can't be read by swipers).

The first part is basically what Final claims to be doing:

https://getfinal.com/

Re: What happens when you swipe a credit card

#97
post #64

What annoys me is the expiry date and CVV. It seems like their solution to "more secure" is just to add more numbers. How about put the last 3 digits on the back, and call it the cvv ? How about use alphanumeric card numbers so we dont have to use as many digits ? Get rid of the expiry date used as validation. It's just more entropy, if you need more entropy then add another digit. It's just annoying having to type t…

Expiry date: It checks that you're not using an old card that someone has just thrown away, often card numbers remain the same if you get a new one. This is effectively just specifying the version of the card, and is something that needs to be on cards anyway (so the user knows when they're no longer valid). Additional benefit is that it means your customer has just checked that their card is still valid. CVV: Not su…

Expiring cards has a few other benefits as well. It ensures that the card company has a reasonably-recent mailing address for each of their customers. And it makes it easier to roll out security features/improvements to the actual card since they can limit the maximum age of any valid card. Also, merchants can use the expiry date to alert customers to re-enter credit card details prior to expiry for recurring charges.

Re: What happens when you swipe a credit card

#98
post #94

Earlier quoted context omitted.

It's complicated and depends on things like where you're charging and whether or not it's a "fee" for using the card vs. offering a cash discount (how these are not essentially equivalent is beyond me): Sections 1.5.4.2 & 5.6 https://usa.visa.com/dam/VCOM/download/about-visa/15-April-2... Section 5.11.2 https://www.mastercard.us/content/dam/mccom/en-us/documents/... IANAL, etc.

Thanks, I may have to reach out to Stripe directly to get an answer. My fear is that Stripe will say it depends on Visa, Mastercard, AMEX and defer to them which is not very helpful.

That's very likely to happen, unfortunately...

I did run across this link, which might explain why when you asked your initial question I was thinking "no way", but after reading the recent agreements was like "maybe so" (I worked in payments for a number of years, and always heard that cash discounts/surcharges for credit card use were disallowed).

http://www.nytimes.com/2012/07/14/business/mastercard-and-vi...

So apparently there was a suit about that very problem which was settled in 2012. It looks like you would be able to, but if you're charging multiple thousands on the regular, it would probably be worth it for you to pay a lawyer to make sure you're in the clear. HTH.

Re: What happens when you swipe a credit card

#100
post #11

I'm kind of disappointed that you didn't go into the security features present in a typical credit card transaction. For example, you could describe the crypto protocols used to communicate with the gateway and/or card processor, what kind of data the stripe and chip contain and how it is used for authentication, etc. Another thing I find interesting is the anti-tamper features that are present in a standard credit c…

The transactions on the network (i.e. between the banks and the association) typically use the ISO 8583 protocol: https://en.wikipedia.org/wiki/ISO_8583 The actual implementation (for e.g. between the hardware terminal and their gateway) is usually using some custom API/protocol - for e.g. Stripe/Braintree have their own APIs as do other older players like like PTI ( https://www.chasepaymentech.com/developercenter/in…

FYI "e.g." means "for example", so "for e.g." means "for for example".
Post reply on HN