Live data from Hacker News

Ask HN: Do we need to pay billions in fees to Stripe, Block, PayPal and Visa/MC?

news.ycombinator.com

111–120 of 377 posts

Re: Ask HN: Do we need to pay billions in fees to Stripe, Block, PayPal and Visa/MC?

#111
You're naming these companies that facilitate money moving in specific ways, but you could also zoom out and include a lot of banking which either serves to move money between parties or across space or time.

So I guess one question is: as credit unions are to banks, what missing organization type needs to exist as a counterpoint to payment services, which could return excess to owner-users?

Re: Ask HN: Do we need to pay billions in fees to Stripe, Block, PayPal and Visa/MC?

#112

Earlier quoted context omitted.

Yea I’m not proposing to replace low security credit cards with low security debit card this is a silly strawman. EDIT: I see the general problem of origination fraud. But that can be mitigated by imposing limits and requiring extra levels of authentication for bigger payments.

You said you don't want the ability to do chargebacks, but chargebacks solve two different problems: 1) origination fraud (i.e. someone not you originates a transaction from your account) and 2) merchant fraud (i.e. goods not as described/unsatisfactory/undelivered). It's fine if you say, yeah I can do without #2, but realistically you cannot do without #1 in any digital payment scheme that will have wide acceptance…

1) can also be solved with limits and increasing levels of authentication.

Re: Ask HN: Do we need to pay billions in fees to Stripe, Block, PayPal and Visa/MC?

#113

Earlier quoted context omitted.

> As long as debit cards have a magnetic stripe and have their full number printed on them, and that information is useful, this problem remains. Which the EEA/UK has also (partially) solved by enforcing Strong Customer Authentication (SCA) that mandates that (most) transactions require MFA.

Yeah, Europe is ahead on this; I hedged my earlier statements heavily. It's not a difficult technological problem to solve. A card's chip should be able to guarantee that the card is physically present for any transaction. Obviously online payments would pose a problem, people would need to either own USB card chip readers or banks would need to do something new and special.

In Germany (/ the EU?) we have electronic ID cards that can be used for a few online services.

The physical card can communicate via NFC, and there's a smartphone app you can use with it. For PCs, you can buy some fancy NFC interface if you want, but you can also have your phone act as a reader, the PC connects to it over the local network.

Maybe something similiar could work for banking cards. They all have NFC anyways.

On the other hand, you might as well just have an app that is registered with the bank on your computer/phone (like how it works for smartphone NFC payments) and skip the card.

Re: Ask HN: Do we need to pay billions in fees to Stripe, Block, PayPal and Visa/MC?

#114

Earlier quoted context omitted.

> As long as debit cards have a magnetic stripe and have their full number printed on them, and that information is useful, this problem remains. Which the EEA/UK has also (partially) solved by enforcing Strong Customer Authentication (SCA) that mandates that (most) transactions require MFA.

Yeah, Europe is ahead on this; I hedged my earlier statements heavily. It's not a difficult technological problem to solve. A card's chip should be able to guarantee that the card is physically present for any transaction. Obviously online payments would pose a problem, people would need to either own USB card chip readers or banks would need to do something new and special.

Online payments are done using pretty much the same system. Instead of the chip, you get either a 2nd authentication mechanism, or start out with a strong token (be it the strength of the token itself, or the stability of it).

An older example was getting transaction authorisation numbers. You would either get a long indexed list on paper, or you could receive then over the phone (voice or text). This was then mostly replaced (about 10 years ago) with hardware (H/T)OTP type tokens that required your card to be inserted in the token and PIN authenticated. Later on that too was replaced by a cardless version, and that one then was replaced (for consumers) with mobile apps.

The combination of minimum software versions, online authentication, transaction limits, daily limits, and time-locked temporary limit increases (so you can buy a car with your phone, but you have to up the limit a couple of hours ahead of time for it to take effect) make it pretty safe with acceptable risk for the bank. And then there's of course the standard fraud detection and prevention departments, so if you do something unusual that also involves a lot of money, you're likely going to get a call.

For business use, there are other systems, generally two types like EU-wide smartcards or bank-specific smartcards that can be used to authenticate and authorise. You'd use an USB or NFC connected method for that. Sometimes that involves entering a PIN on the device itself before the computer can talk to it, but that does make the OTP exchange very fast. You'd still have limits or multiparty authorisation setup in your organisation so you don't end up with one person just moving a couple of 100K around on their own.

And then there's some overlapping systems, apparently this one is going EU-wide: hhttps://en.wikipedia.org/wiki/EIDAS and apparently some implementations include useful things: https://www.idin.nl/en/businesses/ like age confirmation where the business doesn't need to know who, what or where you are just if you're of age (and not even a specific age). Granted, nothing is perfect, but it's a whole lot better than finding some S3 bucket somewhere with JPEGs of ID cards. As long as they don't do dumb stuff like trying to MITM TLS, it's progress. The overlap is in the concept where you can use some electronic means to prove who you are to get something done.

Re: Ask HN: Do we need to pay billions in fees to Stripe, Block, PayPal and Visa/MC?

#115

Stripe, Block, and PayPal each solved a massive pain point. PayPal provided a way to pay people and vendors without giving away your credit card number. Square made it easy to accept payment in person on a phone, without an extensive upfront underwriting experience and without expensive fixed monthly fees. Stripe did the same as Square, but for accepting online payments. Fraud and Risk come in many forms, and these p…

PayPal: In Netherlands there is system called iDeal which provide online payments via tokens, without giving any of your data to seller (recipient). It is supported by all banks. It is super-convinient, you scan QR code by bank app on your smartphone if you pay on other device (laptop, computer) or link is opened by your bank app on mobile and you approve payment. You don't need to enter anything, only select your bank from the list. You don't need to pass your payment data to 3rd party like PayPal, there is no place to steal or phish your card or account data in this scheme.

Visa or MC could do the same, without additional parties. But no.

Re: Ask HN: Do we need to pay billions in fees to Stripe, Block, PayPal and Visa/MC?

#116
post #37

Earlier quoted context omitted.

I thought chargebacks were generally considered a pain: for merchants because it's used by abusive customers, and by customers because it means the merchant (or rather, their payment provider) needs to play a guessing game about whether you're going to do a chargeback and may baselessly deny you the purchase, as well as increasing the cost for everyone due to this increased risk the merchant has Or maybe it's just me…

It's probably just a cultural difference between (broadly) the US, Europe, and Asia. In the US it's increasingly uncommon to buy things with cash or cash-equivalents (Venmo, Zelle, etc.), especially high-value items. Basically we have very few consumer protection laws compared to the EU, and it's very much a "buyer beware" culture here. If you get screwed by a merchant, most of the time it's just too bad for you, unl…

Thanks for providing the context

> paying with cash (which leaves you almost always without recourse if anything happens)

One remark about this though: you always have recourse in court. We often hear the USA is incredibly litigious, but it's not like we'd not (threaten to) bring action against a merchant not acting honestly

The main situation where I see chargebacks being useful is when you fell for a scam and the perpetrator cannot be located for enforcement. Which is a legitimate concern for sure, but there's more ways of dealing with that than giving everyone the option to chargeback anything on a whim with no repercussions for them

Re: Ask HN: Do we need to pay billions in fees to Stripe, Block, PayPal and Visa/MC?

#117

Earlier quoted context omitted.

This is not right at all (it's mandatory fo all banks and merchants in the EEA), although you're correct that SCA still has loopholes (like a US merchant... just trying, although a bank could just mandate 3DS to solve that).

How do you explain the example I gave where the taxi app only has to SCA me once and not upon every transaction? This is in the EU. What I suspect is that the "mandatory" bit is by law (and the law has flexibility, which covers this taxi app scenario) but there is no technical solution to make it mandatory, thus a non-compliant merchant can still drain your account until your chargeback claim goes through.

You're right that it's not fully enforced technically. It's complicated, and I don't think that's really solvable by technology (being that this scenario is roughly equivalent to direct debiting). Banks can validate if a particular merchant has already been used by a customer and blocking them from debiting your account, but since that SCA has exceptions for recurring debiting, this is not really enforcable once the customer has authorized the merchant for any debiting.

Re: Ask HN: Do we need to pay billions in fees to Stripe, Block, PayPal and Visa/MC?

#119
No we don’t need to pay billions. There are moves afoot in the UK to do direct bank to bank payments with Open Banking. HMRC (the UK tax authority) has been doing this for years. When I pay my tax bill, I select my bank, scan a QR code with my phone, that launches my banking app, I authorise the payment and off it goes in just a few seconds. Instant and a few pence, even for thousands of pounds. This particular implementation is provided by Ecospend but there are a few other companies offering this same service now in the UK.

I agree with the OP, Visa and MC charging so much is just insane when you think about it. It’s more expensive AND settlement times are days, not seconds. The only barrier is consumer awareness and detrimental UK legislation forbidding card fees to be added to bills which while well intentioned completely ruins any competition on payment methods.

Re: Ask HN: Do we need to pay billions in fees to Stripe, Block, PayPal and Visa/MC?

#120

Stripe, Block, and PayPal each solved a massive pain point. PayPal provided a way to pay people and vendors without giving away your credit card number. Square made it easy to accept payment in person on a phone, without an extensive upfront underwriting experience and without expensive fixed monthly fees. Stripe did the same as Square, but for accepting online payments. Fraud and Risk come in many forms, and these p…

A lot of the fraud hinges on the fact that all you need to drain an account is a static card number. A lot of hacks are subsequently piled on top of that to try and make it harder (SCA/3D Secure, captchas, etc), and a lot of busywork is spent tidying up the consequences of that (chargeback handling, etc).

You could eliminate a lot of the fraud by moving off a mostly-static identifier to merchant, amount and time-limited tokens the user generates with their bank (or the merchant redirects them there). This would address a lot of the issues - the tokens are useless when leaked (as they only work against the merchant's own account) and can't be misused even by the merchant to go beyond the agreed amount or time limit.

This means with such a system you’d immediately eliminate a whole category of fraud, with the only thing remaining being merchant-level disputes like goods not as described/etc, which can easily be made optional and the user can choose to opt-in for the extra fee. Then you would actually have a good case for lower/no mandatory fees at all.

One problem you need to keep in mind is that fraud mitigation is a big industry in an of itself (some of it is real, some complete snake oil but relies on the underlying problem being real to sell itself) and wouldn't be in favor of a system that is inherently immune to (at least some types of) fraud.

Post reply on HN