Live data from Hacker News

Coin

onlycoin.com

61–70 of 720 posts

Re: Coin

#61
post #28
post #25

How would you prevent mass credit card theft in this case? Couldn't an unscrupulous person, say a waiter at a restaurant, take your card, use his/her own Coin to make a copy of your card, add it to their own Coin, and then use that card at their leisure at a future date? I know, the same question was asked re: Square and the like, but the difference is that you need a Square account to steal other people's cards, and…

Credit card theft like you describe is already possible and already happens

Yes, card cloning devices have existed for decades, but this automates the process, allows you to carry a single (disguised) device that can store multiple cards. If one doesn't work, try another card, without eliciting suspicion, and simply replace / swap cards that are cancelled.

The old method requires use of credit card blanks, a duplicating device, and the card itself doesn't look like the card when presented in person. In this case, as someone mentioned, Coin doesn't display the card #s on the front, so it's like a Card Not Present (CNP) transaction, but needs to be treated as if it was.

This doesn't bring anything new to the card skimming operation, but it simplifies, optimizes, and can in some ways facilitate it. They need some sort of ideally biometric authentication and/or a server that identifies when two Coin devices carry the same cards on it to avoid this sort of fraudulent use.

Re: Coin

#62
post #25

How would you prevent mass credit card theft in this case? Couldn't an unscrupulous person, say a waiter at a restaurant, take your card, use his/her own Coin to make a copy of your card, add it to their own Coin, and then use that card at their leisure at a future date? I know, the same question was asked re: Square and the like, but the difference is that you need a Square account to steal other people's cards, and…

From the FAQ: "As an additional safeguard, the Coin app will only allow you to add cards you own." So it sounds like if the name doesn't match, it won't work (you have to take a picture of the front).

Except that names aren't required to match on credit cards. For instance, my wife is an authorized user on my card. Her signature is on the back, my name is on the front. Similar situations abound for business use cards.

Re: Coin

#63
post #38
post #28

Earlier quoted context omitted.

Credit card theft like you describe is already possible and already happens

But with Coin, they can potentially copy all your cards, instead of just one, by pressing the button multiple times. It's not obvious how to prevent that without affecting the UX.

It affects the UX somewhat, but since it has to be in proximity (implying data contact) to your phone to operate, you could just move the "switch active card" feature to the mobile app, not the Coin itself, then you wouldn't have to worry about people in posession of the Coin (e.g., when you put use it to pay the bill in a restaurant) toggling through the other cards stored on it for nefarious purposes. Or, for less impact on UX, put a "lock active card" option on the mobile app, and still leave the actual card switching on the Coin.

Re: Coin

#64
post #59

I'm slapping my head and thinking "this is such a great idea, why didn't I think of that?". I'm sure lots of other people are doing the same, and it's a sign of a truly great idea. Congrats on launching!

Yes. This happens all the time to me. I'll sit and burn out my brain trying to think of problems to solve... and I can never think of any then I see this and I want to just bang my head on the keyboard because it's just.. so.. simple.

Re: Coin

#65
post #52

Earlier quoted context omitted.

From the FAQ: "As an additional safeguard, the Coin app will only allow you to add cards you own." So it sounds like if the name doesn't match, it won't work (you have to take a picture of the front).

And how exactly is this verified? I don't think there's OCR there to verify that it's your card you just snapped a photo of.

Card.io will scan cards and OCR them. Maybe they do something like this to ensure the name matches the registered name on the account? https://www.card.io

Edit: And it's on the magnetic data, too.

Re: Coin

#66
post #25

How would you prevent mass credit card theft in this case? Couldn't an unscrupulous person, say a waiter at a restaurant, take your card, use his/her own Coin to make a copy of your card, add it to their own Coin, and then use that card at their leisure at a future date? I know, the same question was asked re: Square and the like, but the difference is that you need a Square account to steal other people's cards, and…

I see it as possibly the reverse opportunity. I typically hand out a Google Voice # as a sort of DNS for phone calls so that I can change my device number at will. Wouldn't this allow me to swap out credit cards in a pinch without having to carry new plastic? Or, as you suggest, if I lose my Coin do I have to get all new cards?

If you lose your coin, and someone else picks it up, then you've compromised not just one card, but multiple. Unless I'm missing some sort of authentication when using Coin? And if that authentication exists, how would the non-Coin holder use that card? Is there a timeout that requires the user to authenticate, select a card for presentment, and holds that card in the stripe until a timeout? if not, then there's problems here.

Re: Coin

#67
post #52

Earlier quoted context omitted.

And how exactly is this verified? I don't think there's OCR there to verify that it's your card you just snapped a photo of.

Swiping a card passes along the name on the card.

But a waiter doesn't ask for ID when taking your card... so even if the Coin identifies you as John Smith when you pay your check, the fact that you are Steve Jackson who presented the card doesn't mean anything. And you can have multiple cards with multiple names in your Coin.

Re: Coin

#68
I wonder how this would fare in an ATM. What happens if the ATM accidentally presses the card selection button? If the ATM gobbles the card, now you've effectively lost your entire wallet. What happens if the cashier presses the card selection button while running your card too? Oops, now your boss wants to know why you've just paid for your groceries on the business credit card and why you've cloned your business credit card!! The first can be an innocent mistake, but the second can be grounds for disciplinary action.

I can't see the banks being happy about customers cloning their own cards. In fact, it will probably be a convenient excuse for them to absolve themselves of all liability in the case of loss, theft, or misuse. Some, if they found out, might pitch a fit and close the account.

This also is going to pose a lot of problems when used with non-domestic cards, as they point out in their FAQ. It's possible to use an EMV-based card with just the magstripe, but it's a pain in the butt and the bank may well be aware that all your meatspace transactions are not using the EMV-chip. They may assume that your card is broken or (quite correctly) cloned and block it. A call from the fraud department may well lead to a fit being pitched.

From wikipedia: "Magnetic stripe cloning can be detected by the implementation of magnetic card reader heads and firmware that can read a signature of magnetic noise permanently embedded in all magnetic stripes during the card production process." [0] Oops, now your card is blocked.

Retailers might also get skittish if they figure out this isn't actual bank-issued plastic. They may well refuse it because of the risk of fraud. I would. I really wouldn't want to be running someone's cloned card, even if the cardholder was the one that did the cloning. In fact, it might jeopardize a retailer's merchant account if the acquiring bank found out the merchant were running cloned cards!

The best way to counter a bulky wallet is to not add bulk in the first place. How many credit cards and debit cards does one need to carry on a daily basis? I carry maybe two or three cards, some ID, my Oyster card, and a Costa rewards card that I use daily. I also have a backup wallet that contains a second set of cards in case I lose the first. The bulk of my wallet is receipts that accumulate, but even when I carried way more my life wasn't burdened by a whalelike wallet.

It'd also be a pain in the butt to use this with some rewards cards. For example, my Costa rewards card is swiped at the same time as I'm paying. Would I really want to fumble through pressing a button to find the right rewards card, give that to the cashier, have it handed back so I can fumble through pressing buttons again so I can pay? Certainly not, and even less so the impatient people in line behind me.

Sorry to promulgate the Hater News stereotype, but it's just too easy to poke holes in this idea. It has superficial appeal but I really wouldn't pay $100 for so many potential problems, especially as it would only make my wallet a few mm thinner.

[0] http://en.wikipedia.org/wiki/Magnetic_stripe_card

Re: Coin

#69
This would be an excellent opportunity to add some encryption to credit card numbers. Imagine taking this, except for it has a pin-pad where you enter in your password/passkey. All credit card numbers stored on the device are encrypted with this key, so it's impossible for a thief to swipe your card. However, it doesn't solve the malicious waiter problem.. but of course, you could still keep it locked down so that the most the waiter could get is one card, rather than all of them.

Ideally, it'd be something like:

* Entering your key keeps exactly one card decrypted for up to 2 minutes * Changing cards requires a reentry of the key

You could even go crazy and do things like allow different cards to have different passkeys. Not sure how useful that would be though

Re: Coin

#70
post #35

I'm not sure of the prevalence in the US, but does this support chip + pin transactions? They're the standard in the UK now, and I suspect it's a little harder to mess around with than the magnetic strip.

I understand chip+pin is still a novelty in the US. Back in 2009, I was (apparently) the first person to use the chip+pin machine in one of the biggest bookstores in Toronto - the cashiers got excited and all gathered round to watch. It was a little bit bizarre.

I was in the UK with my non-chip and pin card and there was a similar response. It took like 5 people at Tesco to figure it out.
Post reply on HN