Live data from Hacker News

Poynt – Smart payment terminal

getpoynt.com

71–80 of 81 posts

Re: Poynt – Smart payment terminal

#71

This device is insecure. It is going to take a long time to get the PCI/EMV certifications. Besides that how do you handle the certification of new applications running side by side with your payment application? Everytime you deploy a new application you should re certificate the entire stack, by the PCI standards. Nice concept, but you have a long road ahead before competing with VeriFone, Ingenico, PAX, Miura shut…

Hi - I work for Poynt on the PoyntOS and Payment interfaces - so maybe I can provide some clarity without going into too much of our IP. As mentioned on our site ( https://getpoynt.com/specs ), we have two separate subsystems - one for Android and the other for secure payment processing. All the payments (EMV/NFC/MSR), secure key (including acquirer keys) management, P2PE encryption, EMV/PCI, etc. are handled by the…

How are you securing the PIN entry? It looks like that happens on the same screen as the random 3rd-party apps get to run on, leaving open the potential for an app to intercept the PIN. As i understand the PCI stuff, anything that the PIN hits is fully in-scope.

Re: Poynt – Smart payment terminal

#72

Earlier quoted context omitted.

Hi - I work for Poynt on the PoyntOS and Payment interfaces - so maybe I can provide some clarity without going into too much of our IP. As mentioned on our site ( https://getpoynt.com/specs ), we have two separate subsystems - one for Android and the other for secure payment processing. All the payments (EMV/NFC/MSR), secure key (including acquirer keys) management, P2PE encryption, EMV/PCI, etc. are handled by the…

How are you securing the PIN entry? It looks like that happens on the same screen as the random 3rd-party apps get to run on, leaving open the potential for an app to intercept the PIN. As i understand the PCI stuff, anything that the PIN hits is fully in-scope.

The same question here. Anyone can develop and 3rd-party app to capture the PIN on the same screen from the payment app.

Re: Poynt – Smart payment terminal

#73

Earlier quoted context omitted.

Hi - I work for Poynt on the PoyntOS and Payment interfaces - so maybe I can provide some clarity without going into too much of our IP. As mentioned on our site ( https://getpoynt.com/specs ), we have two separate subsystems - one for Android and the other for secure payment processing. All the payments (EMV/NFC/MSR), secure key (including acquirer keys) management, P2PE encryption, EMV/PCI, etc. are handled by the…

How are you securing the PIN entry? It looks like that happens on the same screen as the random 3rd-party apps get to run on, leaving open the potential for an app to intercept the PIN. As i understand the PCI stuff, anything that the PIN hits is fully in-scope.

We designed a solution to keep the switching logic between standard touch and PIN entry within PCI scope such that PIN entry is not even visible at the lowest levels of Android (and thus 3rd-party apps). Also, 3rd parties do not get to run on or take control of that screen.

Re: Poynt – Smart payment terminal

#74

Earlier quoted context omitted.

How are you securing the PIN entry? It looks like that happens on the same screen as the random 3rd-party apps get to run on, leaving open the potential for an app to intercept the PIN. As i understand the PCI stuff, anything that the PIN hits is fully in-scope.

The same question here. Anyone can develop and 3rd-party app to capture the PIN on the same screen from the payment app.

A rogue app asking for PIN on the merchant facing screen ? not sure there's anything much we can do about that other than making sure we catch that during the review process. Whenever there is a need for the consumer PIN entry, it's driven by the second payment processor - not from the android side.

Re: Poynt – Smart payment terminal

#76
post #15

This is the first EMV payments terminal I've seen that allows PIN entry using a touch screen. Is that really allowed by EMV, as a tamper-evident PIN pad?

The requirements are that the consumer must have some way of concealing pin entry. That, and some stuff about how hitting different numbers can't make a different sound, or have easily picked-up electrical signatures, etc. I believe the EMV specs are publicly available, too.

Tamper-evident is likely baked into the device, instead. Make a circuit that trips when you open the thing up, wire that up to wipe the keys and brick the device until it goes back to factory.

Re: Poynt – Smart payment terminal

#77

Earlier quoted context omitted.

The same question here. Anyone can develop and 3rd-party app to capture the PIN on the same screen from the payment app.

A rogue app asking for PIN on the merchant facing screen ? not sure there's anything much we can do about that other than making sure we catch that during the review process. Whenever there is a need for the consumer PIN entry, it's driven by the second payment processor - not from the android side.

Should be able to prevent PIN information from getting accepted by any means other than your locked-down PIN entry screen. So, any app that wants to grab people's PIN entry would either require them to enter their PIN twice, or block the transaction from going through, which should be very visible.

Re: Poynt – Smart payment terminal

#78

This device is insecure. It is going to take a long time to get the PCI/EMV certifications. Besides that how do you handle the certification of new applications running side by side with your payment application? Everytime you deploy a new application you should re certificate the entire stack, by the PCI standards. Nice concept, but you have a long road ahead before competing with VeriFone, Ingenico, PAX, Miura shut…

Hi - I work for Poynt on the PoyntOS and Payment interfaces - so maybe I can provide some clarity without going into too much of our IP. As mentioned on our site ( https://getpoynt.com/specs ), we have two separate subsystems - one for Android and the other for secure payment processing. All the payments (EMV/NFC/MSR), secure key (including acquirer keys) management, P2PE encryption, EMV/PCI, etc. are handled by the…

Are any team members from automotive? This sounds similar to automotive head unit designs. Consumer-facing processor + OS and secure processor (or core) with separate OS.

I'm nervous about the Android part of this product. I've seen some poor implementations of devices that want to use Android because it's 'easy' to get a lot of features up and running but then struggle with the quality of the middleware layers or Android-specific UI patterns that they try to strip out.

Otherwise, I think the dual screen and industrial design looks good! I hope the LCD looks as good as the renderings.

Re: Poynt – Smart payment terminal

#79
post #57
post #30

Earlier quoted context omitted.

Okay, I'll bite. I'm an employee so you'll have to take what I say with a grain of salt. The video was produced with a cosmetic device and with actors. You're right that the card has to be in the device during PIN entry. The scene you're referring to, however, is depicting tip entry. The device does not have an ethernet port but we will be shipping with a separate charging dock that will provide wired connectivity. I…

I appreciate you posting! I am not doubting that you are building the product. You/The company should probably put more effort in correcting the datasheet and the information you put out there. We can only judge by what is being presented. Your datasheet says Ethernet. It doesn't say Ethernet would be on a separate dock. It probably should. If you are placing the antennas behind plastic surfaces, that is great. You s…

[deleted]
Post reply on HN