Live data from Hacker News

Squareup

squareup.com

91–100 of 158 posts

Re: Squareup

#91

This may come as a shock to some, but: Magnetic cards (and all existing RFID equivalents) are bad. Instead of encouraging their use, we should be creating the mostly fraud-proof obvious alternative: one in which a single transaction does not give the other party permanent access to your wallet. Picture a card with a key pad on it, for entering a dollar amount. The transaction (through RFID?) would be valid for only t…

Entering an amount per transaction might be burdensome to the average consumer, which has a great time with just swiping cards and having all their transactions insured by the credit card company. Having a bulky keypad and a higher barrier of entry to buying that soft drink will have the majority complaining and opting out.

If your goal is verification, an alternate system might have a display on the card that simply verifies the amount charged on most recent transaction, signed by the card processor. Crypto on cards is cheap and tested. This will add no new tasks to those that don't care and provide for a peace of mind to those who do.

Re: Squareup

#92
post #17

Earlier quoted context omitted.

...and obviously paypal was ahead of it's time, and I doubt the execution was as clean or user-friendly as square.

I don't really understand the niche it's aiming to fill. Most stores/restaurants have portable card readers these days, so is it a poor-mans one of those? I guess I'm wondering what use-case it's aiming at. Also I absolutely would not trust someone swiping my card through one of these. I like a closed box that is obviously provided by a bank, which cannot be tampered with. Not an iphone that could be doing anything w…

Why exactly do you assume that a credit card reader is a "closed box that is obviously provided by a bank"?

I've implemented point-of-sale systems before, and lemme tell you, there's nothing magical about a magstripe reader, a microcontroller, and a bit of firmware.

Think for a second about recent credit-card purchases you've made. If your habits are anything like mine, aside from gas stations (where the reader is usually integrated into the pump), most card "swipes" happen through either a peripheral device connected to a generic PC, or a compact card reader with little more than a keypad and phone jack, with no visible branding, certification, or tamper-resistant seals in sight.

Re: Squareup

#93
post #91

This may come as a shock to some, but: Magnetic cards (and all existing RFID equivalents) are bad. Instead of encouraging their use, we should be creating the mostly fraud-proof obvious alternative: one in which a single transaction does not give the other party permanent access to your wallet. Picture a card with a key pad on it, for entering a dollar amount. The transaction (through RFID?) would be valid for only t…

Entering an amount per transaction might be burdensome to the average consumer, which has a great time with just swiping cards and having all their transactions insured by the credit card company. Having a bulky keypad and a higher barrier of entry to buying that soft drink will have the majority complaining and opting out. If your goal is verification, an alternate system might have a display on the card that simply…

> Entering an amount per transaction might be burdensome to the average consumer

Shoppers have dealt with counting out money for millenia. The time spent is a small price to pay for total security against remote theft. At the very least, those of us who are not terminally lazy ought to have the option of paying it.

> a display on the card that simply verifies the amount charged on most recent transaction

Ever have your credit or bank card stolen? Thieves typically split their theft into numerous small transactions.

Keypad or not, information sent to conduct a physical, face-to-face payment should not be re-usable in any way.

Re: Squareup

#95
post #87

Earlier quoted context omitted.

If you haven't read the PayPal story, you probably should. A good version of it is to be found in Founders at Work , as told by Max Levchin (the nerd who mostly solved fraud for PayPal). Turns out the early story of PayPal is the story of solving the fraud problem...so it is extremely relevant to this discussion. PayPal also started as a company doing security and payments on portable devices, so it's doubly relevant…

"think it's pretty safe to assume" Hope doesn't scale.

You're probably right.

http://paulbuchheit.blogspot.com/2007/03/how-to-be-right-90-...

Re: Squareup

#97
So our family business has been taking credit cards for 9 or 10 years - it's a mobile business, so we have always had to use a cell signal. The earlier machines were bulky and monstrously expensive, and so were the analog service plans for them. But now, data transfer is cheap, and card readers are as low as $400.

I think it's also worth noting that, in that time, we've never had a problem with our card reader (the latest, we've had for about 4 years) but my ipod touch, which is a year old and sees far less punishment, has a broken home button.

Re: Squareup

#98
Neat idea with the reader but I guess it'll be limited to the US market since it can't support chip & pin transactions.

Re: Squareup

#99
post #91

Earlier quoted context omitted.

Entering an amount per transaction might be burdensome to the average consumer, which has a great time with just swiping cards and having all their transactions insured by the credit card company. Having a bulky keypad and a higher barrier of entry to buying that soft drink will have the majority complaining and opting out. If your goal is verification, an alternate system might have a display on the card that simply…

> Entering an amount per transaction might be burdensome to the average consumer Shoppers have dealt with counting out money for millenia. The time spent is a small price to pay for total security against remote theft. At the very least, those of us who are not terminally lazy ought to have the option of paying it. > a display on the card that simply verifies the amount charged on most recent transaction Ever have yo…

> Shoppers have dealt with counting out money for millenia.

People have also worked 16 hour days to feed their families for millenia; no one's going to do that now. The amount of effort something takes almost always decreases.

> The time spent is a small price to pay for total security against remote theft. At the very least, those of us who are not terminally lazy ought to have the option of paying it.

How does this system provide 'total security' and guard against remote theft? There is no such thing as 'total security,' you're just mitigating risk. From the way it sounded, you punch in the amount at the time of physical swipe. Once you try to buy something online, you're outside the scope of your physical card.

I do agree however that you should be able to opt in for services that require more verification for transferring money. If you want to spend $25 to get an RSA token to provide a code every time you purchase something, I don't see anything wrong with that service being offered to you.

> Ever have your credit or bank card stolen? Thieves typically split their theft into numerous small transactions.

No, I guess I personally did not. As far as the information I read about and had limited contact when I was associated with a security lab, carders distribute cc numbers in the thousands and resell them, and eventually do get charged in small amounts. Again, I don't see how a two-factor system would prevent this. But also admittedly, I've never spent any amount of time thinking about it nor did I personally research into this.

Re: Squareup

#100
post #29
post #20

Interesting idea, I really like the hardware piece. Not sure how large of a market there is for this. Mom + Pop stores use CC terminals (cheaper than an iPhone), so that leaves this open to mostly people who accept payment outdoors at farmers markets, sports events, etc.. For that to work you'd have to be comfortable giving a merchant your credit card, which isn't a sure thing considering they can disappear without a…

it's unclear to me whether you need a merchant account to use square; i'm assuming from "0-$60 in under 10 seconds" that you don't. if you don't need a merchant account, the market for this is massive. there are millions of people who provide services and sell products who take cash, check, or paypal only. many of these people are dying to take credit cards with zero hassle, which square lets them do.

from http://www.techcrunch.com/2009/12/01/square-worth-40-million...:

"like PayPal, Square allows anyone to have a virtual merchant account and take payments directly."

yep, the market is huuuuge.

Post reply on HN