Live data from Hacker News

Squareup

squareup.com

81–90 of 158 posts

Re: Squareup

#81
post #68
post #66

Earlier quoted context omitted.

It seems like what you are suggesting is akin to credit card skimming: http://en.wikipedia.org/wiki/Credit_card_fraud#Skimming How is this any different?

barrier to entry is much smaller, you don't need to piggy back on a legit business or have to play a spy to install a skimmer at the bank. All you need is a taxi, and iPhone, and you can go around town collecting credit card numbers. And unlike websites, there is no paper trail to link you to the scam.

[deleted]

Re: Squareup

#82

Earlier quoted context omitted.

In order to make $90,000 begging, you would have to get $250 every day of the year. This seems highly unlikely. I'd say most beggars make more like $20 a day, but I'm just doing armchair science here.

While commuting back and forth to Seattle on the ferries, my dad said he heard a couple people comparing how much they'd made begging that day and it was in the $200-$300 range. They had been disappointed in the "slow" day.

The problem with this is that it's the same as asking a bunch of people how much they make - it's always overstated.

Re: Squareup

#83
post #71
post #37

This sounds like a money grab business to me. They'll launch, make a couple hundred mil, then they'll get hit with fraud, a ton of people will lose money, and they'll be forced to shut down, since noone will want to use the service, in fear of getting defrauded. Since there is no barrier to entry, it'll be like 2 weeks before someone comes out with a black market version, that will look exactly the same, but instead…

It looks to me like the iPhone is the user's own iPhone, in which case the user will have installed the software on the phone side themselves. So I guess the flow would be: user starts software; merchant takes phone and plugs in device; software checks device and makes sure it is authentic; then UI presents signature page to user. What is the hole in this? I'm not saying there is no hole, and I did like your question…

Only thing I can think of would require uploading malicious software with a modified version of the square device but that doesn't look possible, yet. Why not just use your phone to pay, for example the business owner gives you a qr code that you scan in then use an app that interfaces with your paypal account that pays the business they get confirmation you don't have to worry about using extra hardware, or why can't the business owner give you a number to text and then collect payment through that then you don't even need a smartphone any cellphone will do. Really things would be more secure if I could send money to an account rather than have them remove money from mine.

Re: Squareup

#85
I am excited about this ... at the same time, it would need some specific features for me to be a customer.

This would be ideal for us at tradeshows and seminars. We attend/sponsor about 5-10 per year and do quite a bit of business at a few of them. Instead of having a dedicated laptop in the back for sales, this would be much easier.

On the other hand, we already have a merchant account (with Brain Tree). Plus, we have older clients still paying us with PayPal subscriptions. The last thing we need is another gateway/merchant company.

I suspect there are many other businesses like us.

I hope they are either very flexible or license the technology to other companies.

Re: Squareup

#86
post #37

This sounds like a money grab business to me. They'll launch, make a couple hundred mil, then they'll get hit with fraud, a ton of people will lose money, and they'll be forced to shut down, since noone will want to use the service, in fear of getting defrauded. Since there is no barrier to entry, it'll be like 2 weeks before someone comes out with a black market version, that will look exactly the same, but instead…

Magstripe readers have been within the reach of any reasonably-clever fraudster for a long time. Attaching them to an iPhone and using audio modulation for the signal doesn't magically open the floodgates to card skimming and duplication.

This isn't even as big a threat as, say, making people acclimated to the idea of joining open wireless networks at coffee shops -- card skimming at least requires physical access to the card for a few seconds.

Re: Squareup

#87
post #37

This sounds like a money grab business to me. They'll launch, make a couple hundred mil, then they'll get hit with fraud, a ton of people will lose money, and they'll be forced to shut down, since noone will want to use the service, in fear of getting defrauded. Since there is no barrier to entry, it'll be like 2 weeks before someone comes out with a black market version, that will look exactly the same, but instead…

If you haven't read the PayPal story, you probably should. A good version of it is to be found in Founders at Work , as told by Max Levchin (the nerd who mostly solved fraud for PayPal). Turns out the early story of PayPal is the story of solving the fraud problem...so it is extremely relevant to this discussion. PayPal also started as a company doing security and payments on portable devices, so it's doubly relevant…

"think it's pretty safe to assume"

Hope doesn't scale.

Re: Squareup

#88
post #71
post #37

This sounds like a money grab business to me. They'll launch, make a couple hundred mil, then they'll get hit with fraud, a ton of people will lose money, and they'll be forced to shut down, since noone will want to use the service, in fear of getting defrauded. Since there is no barrier to entry, it'll be like 2 weeks before someone comes out with a black market version, that will look exactly the same, but instead…

It looks to me like the iPhone is the user's own iPhone, in which case the user will have installed the software on the phone side themselves. So I guess the flow would be: user starts software; merchant takes phone and plugs in device; software checks device and makes sure it is authentic; then UI presents signature page to user. What is the hole in this? I'm not saying there is no hole, and I did like your question…

that's not the flow. the reader is plugged into the merchant's iphone/ipod.

Re: Squareup

#89
This may come as a shock to some, but:

Magnetic cards (and all existing RFID equivalents) are bad.

Instead of encouraging their use, we should be creating the mostly fraud-proof obvious alternative: one in which a single transaction does not give the other party permanent access to your wallet.

Picture a card with a key pad on it, for entering a dollar amount. The transaction (through RFID?) would be valid for only that amount.

All of the required cryptographic math has existed for decades. All we need now is the hardware and some infrastructure.

Re: Squareup

#90
post #86
post #37

This sounds like a money grab business to me. They'll launch, make a couple hundred mil, then they'll get hit with fraud, a ton of people will lose money, and they'll be forced to shut down, since noone will want to use the service, in fear of getting defrauded. Since there is no barrier to entry, it'll be like 2 weeks before someone comes out with a black market version, that will look exactly the same, but instead…

Magstripe readers have been within the reach of any reasonably-clever fraudster for a long time . Attaching them to an iPhone and using audio modulation for the signal doesn't magically open the floodgates to card skimming and duplication. This isn't even as big a threat as, say, making people acclimated to the idea of joining open wireless networks at coffee shops -- card skimming at least requires physical access t…

> Magstripe readers have been within the reach of any reasonably-clever fraudster for a long time.

If today a beggar extended his card reader-equipped iPhone to you, would you swipe? If this company takes off, in a few years you very well might.

Payment methods which give third parties permanent access to your wallet are bad.

Post reply on HN