Live data from Hacker News

Jonathan's Card shut down

jonathanstark.com

91–100 of 106 posts

Re: Jonathan's Card shut down

#91
post #57
post #8

So, this isn't necessarily because of Sam Odio, but everyone's thinking it. And... duh. The take-a-penny, leave-a-penny trays only work when more pennies follow the rules than don't. If somebody comes along every day to empty out the tray — even if they're bringing it right across the street to the Salvation Army — they're going to take the trays away. That's just not what they're for , and if they're not working the…

> So, this isn't necessarily because of Sam Odio, but everyone's thinking it. Are you kidding me? Starbucks doesn't give a shit that someone was syphoning off money. A few hundred dollars is chump change to them. What they care about is the thousands of people "defrauding" their rewards program designed for use with a single customer. I'm sure their TOS restricts use to a single person as well.

Interesting. Where are you getting that opinion from? Mine comes from the article Jonathan himself tweeted:

"At 7 p.m. PT Friday, Starbucks reluctantly pulled the plug on Stark’s pay-it-forward social experiment following allegations of fraud or misuse. ...

Adam Brotman, vice president of digital ventures at Starbucks, phoned Stark earlier Friday evening to inform him that the card would be deactivated. Starbucks, he says, was rooting for the experiment from the sidelines, even though the company’s terms do not permit the use of shared registered cards. 'I’m sad about it, first and foremost, because we were legitimately cheering on this experiment,' Brotman says. ...

Once the exploit was public, however, Starbucks felt compelled to deactivate the card."

http://mashable.com/2011/08/13/jonathans-card-shut-down/

Re: Jonathan's Card shut down

#92
post #63

No one has mentioned the obvious legal snags for Starbucks in this whole "experiment." Starbucks is not a money transfer service and therefore is not registered with the US government as such. If Sam could siphon off that much money so easily, how long before the Bad Guys learn that Starbucks can be used to move money? Or maybe they suddenly realized themselves that criminals could have been moving money through them…

I'm probably missing something, but the exploit was all about filling up a Starbucks gift card. It was touted as "Enough to buy an iPad", but at no point was one actually bought. The $500 card is now being eBayed for charity, which (for profit), would be one way to close the loop and get cash out, but surely that applies to any business operating a gift-card scheme.

Are you normally able to redeem these cards for cash? My (limited) experience is not only no, but sometimes the amount is rounded up to the nearest $currency_denomination as well.

Re: Jonathan's Card shut down

#93

The thing about computer security flaws is that unless someone makes a point of publicly exploiting them, others will go around quietly exploiting them. It is almost certain that someone was quietly siphoning Jonathan's card. Would all the donors really prefer to have their donations be embezzled like they are at a skeezy charity front like Palotta or Komen? Why, just for smug satisfaction of feeling good about givin…

Being able to mark a card as "only purchases @foodstuff products", or being able to blacklist it from refilling gift cards would be the easiest way to close this particular hole.

If you could only purchase actual physical objects (ideally, only fresh food, rather than, say, a coffee-maker), that would go a long way toward preventing misuse.

Re: Jonathan's Card shut down

#94

Social gifting is cool. The only problem with it is that the people who REALLY need the gift are the ones who can't afford smartphones, tablet devices, or computers. So i'd rather give my gifts the old fashioned way. But i still like the idea in a symbolic sense.

Print a bunch of tear-off QR codes and tape it to your nearest lamp-post? Or have a bunch at the desk of a homeless shelter maybe?

Re: Jonathan's Card shut down

#95
post #28

I am surprised at the hate against Sam Odio. Sam had the option of taking the gift card and selling the card and keeping the iPad. He exposed the vulnerability. If he hadnt you would have paid in for the card, but someone would have abused the system, and not disclosed it. Here is a though experiment. There is a widely used piece of software which has a vulnerability. There are bad guys who are going to abuse it. A g…

I think we were all aware that the system could be abused. It was based entirely on the honor system since we don't know who was using the card, only that it was being used. The original thread was full of people talking about how it could be abused. As far as what Sam did in particular, it'd be entirely different if Sam came out and said, "Hey, look! I was able to write a script that has syphoned off $625 from the c…

> "we were all aware that the system could be abused"

I think we were all aware that the system could be abused to buy yourself an extra coffee every once in a while, if you happened to be in Starbucks when the card had money on it. We were all aware that you could overspend, either on yourself or "for charity" (witness Sam's comment about buying food for homeless guys.) If that was the only vulnerability, most of us would think it acceptable -- most of the time money you put on the card goes to brighten an honest person's day, but occasionally someone games the system.

Until the exploit was posted, I was not aware that it could be abused by skimming $50 at a time onto your own card within moments of it being deposited on the main card. This is an unacceptable level of exploitability -- if you put money on the card, it's very likely that it will go to a scammer of some sort.

I'm glad Sam exposed this far-more-serious-than-most-of-us-realized vulnerability. I'm not pleased with how he went about it (particularly the game he and his brother seem to be playing; Daniel's startup deposited exactly $625, the same amount Sam took.) I'm not pleased with the "yuppies buying coffee" vs "starving kids in Africa" comparison. But I'm glad this particular exploit has been exposed, which means we now have the opportunity to set up a better-and-safer version of Jonathan's Card.

Re: Jonathan's Card shut down

#97

Earlier quoted context omitted.

My point is that if he intends to give the money to starving children in Africa (or, really, to people who say that some percentage will end up being given to starving children...), the fact that money is money means that there's no reason not to do that at once. I'm not one of those willing to call what Odio did theft; it's merely rude and underhanded. But I do wonder if people who do business with him in the future…

From a business persepctive, Sam Odio's action was fantastic. He made one of the best answers ever seen for the YC application question "when have you hacked a system?" He walked up to a pile of money just sitting their being used for a suboptimal purpose, and he took it and put it to good use.

I know I'll never buy anything from a business run by Sam Odio, unless he somehow were to redact all this douchery. I suspect I'm not the only one who feels this way. There are too many decent people out there to waste time and money with someone like this.

Re: Jonathan's Card shut down

#98

Earlier quoted context omitted.

He's like the kid who destroys other kids' sandcastles to show that they were not so awesome after all. What's not to hate?

At worst he's being snarky. But I don't think he'd destroy sandcastles. He's not that kid. He's the kid adding concrete and rebar so that when a storm comes, his castle is still standing.

Don't rape my analogy. He's not building (in the relevant sense).

Re: Jonathan's Card shut down

#99
post #92
post #63

No one has mentioned the obvious legal snags for Starbucks in this whole "experiment." Starbucks is not a money transfer service and therefore is not registered with the US government as such. If Sam could siphon off that much money so easily, how long before the Bad Guys learn that Starbucks can be used to move money? Or maybe they suddenly realized themselves that criminals could have been moving money through them…

I'm probably missing something, but the exploit was all about filling up a Starbucks gift card. It was touted as "Enough to buy an iPad", but at no point was one actually bought. The $500 card is now being eBayed for charity, which (for profit), would be one way to close the loop and get cash out, but surely that applies to any business operating a gift-card scheme. Are you normally able to redeem these cards for cas…

I don't believe most retailers will redeem cards for cash (if they can avoid it) but gift cards are use widely as a money laundering and value-exchange system amongst criminals: http://en.wikipedia.org/wiki/Stored-value_card#Money_launder...

Re: Jonathan's Card shut down

#100
post #36

Would be great if Starbucks took up on the theme and made a card designed for sharing but allowed the creator to define a single purchase limit. I don't think a system like this could ever be completely locked down to abuse but at least it could take away the gift card thing.

Now that's a great idea. Have a card that is limited in certain ways: max purchase of, say, $5 (I don't know if $5 will buy anything in $tarbuck$, since I haven't been there in many years). Limit purchases to coffee (or tea) only. No transfer allowed from one GC to another. No more than, say, 30 uses per location.

It would be an interesting series of social experiments to limit the card in these various ways, and see which limitation helps the uptake, and which hurts it. Fascinating!

Post reply on HN