Live data from Hacker News

Coin

onlycoin.com

601–610 of 720 posts

Re: Coin

#601

It's a neat concept, but I just don't think this gets anywhere. Dead in the water - as much as I would personally like to see them succeed. The biggest problems here are security. () Merchants will hate it since there is no physical imprint / swipe of the bank-issued card. This will lead to chargebacks in favor of the customer. So this alone kills this company/product. () Banks might change their terms forbidding cus…

> () Merchants will hate it since there is no physical imprint / swipe of the bank-issued card. This will lead to chargebacks in favor of the customer. So this alone kills this company/product.

Yeah I know right, this is why I can never buy anything online, oh wait.

> () Banks might change their terms forbidding customers to create digital copies / clones of their card. As per card holder agreements, if you (or Coin) has ever read one, you don't own your card. You're fully bound by the terms of the agreement.

The bank that does not enforce these agreements will have my business. Bring it on.

> () There is the issue of PCI-DSS compliance. They mention they're "in the process of earning" it but this is a lengthy, difficult and _costly_ process ($100 k). They're using a loophole to ensure consumer peace of mind but this won't last at all.

Every startup has to start somewhere.

> () Adding a card seems flawed. You're asked to take a picture of the physical card after swiping to "prevent fraud" ok but unless Coin uses some advanced image processing/OCR to validate the card with the swiped data, you can take a picture of any card. So big fail here.

I've used the camera to accurately scan my card data into 3 different apps in the past week.

> () Coin seems to access a cloud service. Another major reason that this simply isn't going to work. If you've paid any attention to the NSA situation within the past 6-months, ordinary/average consumers (not the HN crowd) are becoming weary of cloud/hosted service. Not to mention, Coin will never ever work outside of the US (or San Francisco for that matter).

Just... stop.

> () Most users are totally fine with credit cards and big wallets. It's actually empowering to them. I spoke to a guy who loves the fact that he has every color Amex card! So in essence, this is geared towards a micro-niche of tech savvy SF/NY/LA crowd.

You talked to one guy who loves that he has every color Amex card, and then came to this conclusion?

> () Selecting a card by tapping the button - great. What if the waiter taps the same button? Or someone you're paying does? So many issues with this button here.

I've had my card charged twice before, so what you are telling me is that the same thing that happened to me before might happen to me again? Thanks.

> () The obvious issue of losing Coin and losing everything. People like backups. It's a mindset.

You mean like how people lose their wallets?

> () Battery issues with digitizing a non-battery product (credit card). Be in no doubt that more than half of users will forget to charge their credit card (as if we don't have enough things to charge). So you'll see people having lunches and presenting a dead Coin. And since you don't have any plastic, well, now you're screwed.

So once every 2 years, I might have to ask my wife or a friend to pay for my meal at a restaurant, and I trade that for the convenience of not having to carry a wallet? Where do I sign up?

> Products are supposed to make life better, easier, more intuitive.

If everyone was using Coin, and then you introduced me to the concept of a wallet, it would be downright laughable.

Re: Coin

#603
post #167

SUPER clever idea -- kudos for that. In theory, this is awesome. As a consumer, I love it. As a merchant, however (which I am), there is no chance I would accept this. None. Unless the issuers (that is, Visa, MC, Amex) drastically change their policies, which I don't see happening anytime soon. Why? Because the issuers are very clear about a few things: When push comes to shove and it REALLY gets down to it, unless t…

I don't understand America's love for credit cards. They're unsafe, both for users and for merchants. PIN cards are safer, and they're much clearer about where the risks and responsibilities lie. Of course modern credit cards also support PIN, but I never see them used that way.

A more convenient way of handling credit cards is a useless idea to me. What we need is a safer and more reliable way to handle transactions. Preferably one that doesn't rely on politically motivated monopolists.

Re: Coin

#605
post #595
post #545

Earlier quoted context omitted.

I'll let you in on a little secret - paywave/paypass etc are EMV cards. The interface is wireless and they have a shorter transaction flow. There are less (zero) customer validation techniques, final evaluation (pass/fail) takes place at the stage a 'normal' EMV transaction would decide on pass/online/fail. As usual there are variations between implementations, but underneath it's all good-ol' EMV :) So I doubt that…

Why have the coin with "contactless" payment (as paywave etc is known in the uk at least) when the phone itself should be capable of that itself.

I wonder why the big US banks aren't on board with driving contacless NFC payments?

Commonwealth Bank, the largest bank in Australia is very soon releasing native Android NFC support and NFC style "smart tags" that you stick to the back of your iPhone.

https://www.commbank.com.au/personal/online-banking/commbank...

This pretty much eliminates the need for any kind of "card aggregation". I wonder how quickly other countries will follow suite?

Re: Coin

#606
post #488

I remember the US refusing to rely on foreign technology, hence refusing to issue plastic money with chips. But this changed after the CIA got their hands on the technology through in-q-tel acquisition of the french company gemplus then world n°1 company in the business. Then cards with chips were coming the US and it was expected for the rest of the world to get backdoors with their US issued chip cards, years later…

>> (not that it is that much harder with chips, see yescards). Never heard of that before, interesting. I used programmable test cards when doing EMV and did wonder what would happen if I made such a card but (as the wikipedia page says) they're of very limited utility as they don't have the right keys to do anything but low-value offline transactions. Cloning chip cards is still pretty hard, IMHO, though that is int…

When Serge Humpich, a french engineer, found the vulnerability the yes card is based on at the end of the 1990's, he got in touch with the GIE in charge of european bank cards to warn them and propose a fix in hope of landing a job.

They asked him for proof, as an engineer he gave them proof by buying metro tickets and sending them the tickets, the receipt and the card used to exploit the vulnerability. The GIE CB then went on pressing charges and using those as evidence of the crime and Humpich was sentenced to prison, the flaw was not fixed and the whole story got in the media.

Then yes cards started to appear all over France and Europe and people would draw money directly from atms with yes cards, until all ATMs were replaced by fixed version gradually over a few years.

The amount of fraud related to yes cards and subsequent iterations was never disclosed, but it was estimated to be in the tens of billions euros per year.

In 2001 a network of gas stations got exposed for copying the magstripe of chip cards which were then sent to be cloned in other countries and the same CBCarbon surfaced, a software dedicated to cloning chip cards issued after 1999 (those including the crypto bump from 320bits to 768bits)

I suppose this is not the low hanging fruit of getting the money from ATMs as the current method is a physical attack based on making them explode using gas but I sincerely doubt chip cards are really secure nowadays, probably just not as easy as it used to be.

Re: Coin

#607
post #219

Earlier quoted context omitted.

I don't know why the US hasn't adopted EMV. It's not perfect, but it has cut down fraud massively here in Europe. They're very hard to clone (I won't say impossible, but attacks against EMV have not generally been of this nature) and the transaction records at both ends will tell you whether the actual, real card was there. The liability is more clear-cut as a result. If the customer claims the charge was unauthorise…

In Australia, we've even moved beyond EMV; the majority of merchants now accept Visa PayWave and MasterCard PayPass for tap-and-go. [edit: Oh, and all my debit/credit cards are now paywave/paypass enabled, and they are all from the big 4/5 banks] The Coin page doesn't mention this at all; does it have this? If not, it sounds like a step backwards.

I don't know much about PayWave and PayPass, but this actually sounds even less secure than credit cards. And it still relies on the big two. Sounds like a step in the wrong direction.

It's not about convenience, it's about security and reliability. That's the direction we need to take.

Re: Coin

#608

Earlier quoted context omitted.

I'm european, and hold my wallet in the back pocket or in my jacket. I just take it out and put it on the table when sitting.

I simply do not buy pants which don't come with extra pockets over the thighs. They are really hard to find, but they Solve The Problem. (I'm Brazilian, but atypical in this habit)

Wait, there are trousers which don't come with pockets in the front/over the thighs?!

Re: Coin

#609
post #285

Earlier quoted context omitted.

Americans going to Europe: Remember that your credit card might not work as often in Europe. Be prepared for hearing "We only take chip & pin cards here" in shops etc.

Imagine my dismay when a coffeeshop in Amsterdam would not take my magstrip only American Express.

For those who don't know, the term "coffeeshop" in the Netherlands refers to places that sell cannabis. "café" is a regular café.

Re: Coin

#610

Can anyone elaborate how the magstripe trick works? That's the only thing that I can't find, and it's kind of the crucial point of the whole project.

Some time back I described a project to do this with a single data track (http://www.flashingleds.net/swipecards/swipecards.html)

This was a crude first pass, which is evident from the fact that the shim is a sawed off kitchen knife. In principle if you make the electromagnets smaller you could fit three. Make them adequately decoupled and you're away.

If these guys have an alternative approach I would be interested to read about it, but as far as I can tell they don't describe the method anywhere.

Post reply on HN