Live data from Hacker News

Poynt – Smart payment terminal

getpoynt.com

51–60 of 81 posts

Re: Poynt – Smart payment terminal

#51
post #38

Earlier quoted context omitted.

A very valid concern. To begin with, while our terminal is Android based we have taken numerous steps to lock this device down. Side loading apks is not possible nor is arbitrary access via adb. On top of that, we take great lengths to protect consumer data. In addition to full PCI compliance data is fully encrypted on the device. And if that's not enough, there are several anti-tamper mechanisms that will trigger an…

You are not PA-DSS or PCI certified. Where are the links to your letters of approval?

We are in the process of both PA-DSS for our cloud services and PCI approval for the device. This is the primary reason we are not shipping to merchants until next year. We have line of site to certification and we would not (and can not) ship to merchants until this is complete.

Re: Poynt – Smart payment terminal

#52

This device is insecure. It is going to take a long time to get the PCI/EMV certifications. Besides that how do you handle the certification of new applications running side by side with your payment application? Everytime you deploy a new application you should re certificate the entire stack, by the PCI standards. Nice concept, but you have a long road ahead before competing with VeriFone, Ingenico, PAX, Miura shut…

[deleted]

Re: Poynt – Smart payment terminal

#53
post #38

Earlier quoted context omitted.

A very valid concern. To begin with, while our terminal is Android based we have taken numerous steps to lock this device down. Side loading apks is not possible nor is arbitrary access via adb. On top of that, we take great lengths to protect consumer data. In addition to full PCI compliance data is fully encrypted on the device. And if that's not enough, there are several anti-tamper mechanisms that will trigger an…

Assuming that someone managed to not only walk off with the device from a retailer but were also able to gain access to the device itself. What kind of data could be harvested from the device?

First things first; the card data is encrypted on read and the device will soon be PCI certified. So none of the card data will be accessible to anyone on the device.

The transaction data (amounts, items, transaction statuses, etc) is managed by the PoyntOS (owned by Poynt). That data has the necessary authentication and authorization around it to prevent just anyone with the device from having access to it. Only a merchant user logged into the app and with the appropriate level of privilege will be able to access the data.

Finally, 3rd party applications will go through a strict vetting process and will be signed. Therefore, it will not be possible for some fake app to work on the device. Also, PCI requires us to constantly monitor the installed application for any kind of tamper.

Re: Poynt – Smart payment terminal

#55
post #51

Earlier quoted context omitted.

You are not PA-DSS or PCI certified. Where are the links to your letters of approval?

We are in the process of both PA-DSS for our cloud services and PCI approval for the device. This is the primary reason we are not shipping to merchants until next year. We have line of site to certification and we would not (and can not) ship to merchants until this is complete.

Afaik you should have PA-DSS to your app running on top of the Android OS that btw is not PCI. Just PA-DSS to your cloud services considering the architecture you are proposing is not enough. PCI-PTS to your hardware is another problem you are going to face in your certification because you are using a touchscreen 'pinpad'.

Re: Poynt – Smart payment terminal

#56

This device is insecure. It is going to take a long time to get the PCI/EMV certifications. Besides that how do you handle the certification of new applications running side by side with your payment application? Everytime you deploy a new application you should re certificate the entire stack, by the PCI standards. Nice concept, but you have a long road ahead before competing with VeriFone, Ingenico, PAX, Miura shut…

Hi - I work for Poynt on the PoyntOS and Payment interfaces - so maybe I can provide some clarity without going into too much of our IP. As mentioned on our site (https://getpoynt.com/specs), we have two separate subsystems - one for Android and the other for secure payment processing.

All the payments (EMV/NFC/MSR), secure key (including acquirer keys) management, P2PE encryption, EMV/PCI, etc. are handled by the secure processor. There are no other applications that can run on this secure processor other than the signed and certified applications.

On the Android side, Poynt's Secure service is the only service that's capable of communicating with the Payment Processor to initiate card reading (EMV/NFC/MSR/others) and pass through the encrypted data it receives to the merchant's acquirer. All the 3rd party applications run independent of the Poynt's Secure Service and when they need to collect a payment, they do so through our Poynt Payment Fragments to facilitate the Payment flows. (See here for information on how it works: https://getpoynt.com/developers/terminal#2.3 Poynt Payment Fragments).

So as you can see, we are able to keep the security domains separate and thereby able to handle PCI certification in a much more graceful way. Obviously they are some complexities but choosing a certifiable payment processor board was one of many ways we are able to deliver a secure solution.

Cheers!

Re: Poynt – Smart payment terminal

#57
post #30
post #27

Interesting merchant terminal -- but it seems to be little more than a pretty rendering and physical mock-up right now. I like how the first guy puts his card in, takes it out AND THEN punches in his PIN, which is exactly how PIN & Chip doesn't work. I would have hoped they'd at least be familiar with the process. It looks to me like a mobile computer strapped to a terminal. I'm not sure why this is better than havin…

Okay, I'll bite. I'm an employee so you'll have to take what I say with a grain of salt. The video was produced with a cosmetic device and with actors. You're right that the card has to be in the device during PIN entry. The scene you're referring to, however, is depicting tip entry. The device does not have an ethernet port but we will be shipping with a separate charging dock that will provide wired connectivity. I…

I appreciate you posting!

I am not doubting that you are building the product.

You/The company should probably put more effort in correcting the datasheet and the information you put out there. We can only judge by what is being presented. Your datasheet says Ethernet. It doesn't say Ethernet would be on a separate dock. It probably should.

If you are placing the antennas behind plastic surfaces, that is great. You should correct the diagrams.

Further to your point about tip entry, tip should be entered before the transaction is authorized right? So one would assume you'd enter tip then put in the card, and optionally enter a PIN or sign the screen.

I can appreciate that it may be just a video demo, but when you post it to a place like YN people are going to point out errors. Funny enough, that error was pointed out by a friend who was watching over my shoulder. She is not a technical person in any way and it jumped out at her.

Re: Poynt – Smart payment terminal

#58
post #29
post #27

Interesting merchant terminal -- but it seems to be little more than a pretty rendering and physical mock-up right now. I like how the first guy puts his card in, takes it out AND THEN punches in his PIN, which is exactly how PIN & Chip doesn't work. I would have hoped they'd at least be familiar with the process. It looks to me like a mobile computer strapped to a terminal. I'm not sure why this is better than havin…

Some ATMs require you to take your card out before entering your PIN. Or are they using the magnetic strip?

If you are using magnetic strip you're correct. For PIN & chip the PIN is sent to the card and verified by the card and the resulting "signature" is sent to the bank. The card has to be in for PIN entry.

An employee, above, said that it is for entering tip. Which would make more sense, but then the card would have to be inserted after the total amount I imagine but I can see how they would have a slightly different flow. Personally, I would want any terminal that I use to show me the final amount that I am going to pay before I put in my card. Lest I pay, walk away and the cashier adds her own tip.

Re: Poynt – Smart payment terminal

#59
post #38

What's to stop somebody from stealing this right off the counter and gaining access to customers' data?

A very valid concern. To begin with, while our terminal is Android based we have taken numerous steps to lock this device down. Side loading apks is not possible nor is arbitrary access via adb. On top of that, we take great lengths to protect consumer data. In addition to full PCI compliance data is fully encrypted on the device. And if that's not enough, there are several anti-tamper mechanisms that will trigger an…

Well, here is my big question: WHY ARE YOU STORING CARD DATA AT ALL? (sorry for the caps). You are a pass-through entity, merchant terminals do not store card data. They keep the authorization number from upstream provider to allow void/refunds but there is no need for them to store the number.

With respect to anti-tamper mechanism, are you FIPS-140-2 certified or plan to be?

Re: Poynt – Smart payment terminal

#60
Interesting to see Osama Bedier listed as one of the people. He is the guy who ran PayPal's merchant terminal integration efforts, left for Google Wallet, and then left Wallet.

I think there was a lawsuit filed against him and Google by PayPal the day of Wallet's launch, claiming Google stole their secrets. No idea how that turned out; though I imagine it was a PR move on PayPal's part.

Post reply on HN