Slashdot Mirror


PayPal Unveils Mobile Payment System

angry tapir writes "PayPal is targeting small businesses, service providers, and casual sellers on the move with its new PayPal Here service, which allows vendors to process a variety of payments including checks and cards using their mobile phones. The new service includes a free app and encrypted thumb-sized card reader, which allows merchants with an iPhone, and later Android smartphones, to process payments."

6 of 99 comments (clear)

  1. Re:Why hasn't PayPal been innovated out of existen by CaptSlaq · · Score: 5, Informative

    Since you probably don't work in this space, I'll drop you a hint: https://squareup.com/

  2. Don't do business with merchants who use this by frovingslosh · · Score: 1, Informative

    It is nice to see what the thumb-size card reader looks like, and I assure you that if I ever see one I'll refuse to let that seller scan my card. Paypal is one of the most absurd abuses to ever come out of the Electronic Bay of thieves. and I'll never do business with them. This even concerns me that some retailer might trying processing your info through Paypal without your knowledge or consent.

    --
    I'm an American. I love this country and the freedoms that we used to have.
  3. Re:How do they expect.... by EvilIdler · · Score: 3, Informative

    It wouldn't be very usable in my country for long, because magnetic strip readers are being taken off the market (due to a large number of East-European criminals skimming cards). Smart cards have started to become a requirement, with legacy devices losing the functionality to read the strip. PayPal's solution is a bit too late to be that usable in Europe.

  4. It's actually quite safe.....as long as you don't by neokushan · · Score: 4, Informative

    Full Disclosure: I work in the credit/debit card industry. Specifically, I work in the part of that industry that involves testing the shizzle out of them.

    Your old magstripe only card isn't safe, the magstrip can be easily copied in a variety of ways. Readers are cheap and skimmers that are so small, they can fit inside ATM card slots, are easy to buy online (and don't cost much). Lesson? Don't use the magstrip for anything, ever.

    So what are you meant to do? Well, like a lot of the rest of the world, the US is switching over to EMV. In the UK, it's known as chip and PIN, but the basics are as follows:
    Instead of a magstrip, your card has a "chip" inside it. That chip is where the communications happen. Readers contact the chip and exchange a bunch of cryptographic data, but the key thing is that the chip isn't simply "read", but it performs calculations itself, using its own private keyset that cannot be read by the chip reader. I can't stress that point enough. There's no way to read the contents of the chips, all you can do is communicate with it.
    Each transaction is "Unique" and the card itself will sometimes request to speak directly to a Host (i.e. somewhere at your Bank's HQ), in what's called an "online" transaction. If the card chip isn't sure of a terminal, it will demand to go online before processing a transaction. Hell, sometimes it'll demand to go online just because it hasn't recently. The two then communicate in such a way that the terminal (the middle man) can't intercept in any meaningful fashion. Each message is cryptographically generated so that the host knows the card sent it and not some MITM.

    The bottom line? Come 2013, when the US is mandated to support EMV, card skimming will be a thing of the past. Stick your card wherever you like, nobody can do anything with your bank account*.

    *there is, of course, a small caveat to this. As I said, each transaction is unique, so theoretically someone could skim a single offline transaction from you, but if they try to replay that transaction, there's every chance the transaction will then go online (the terminal AND the chip can demand to go online at any point), in which case the host will void it immediately. There's also plenty of upper and lower transaction limits, so for example if a transaction amount is above say $50 or $100, it HAS to go online or will fail outright.

    --
    +1 IDisagreeSoHeMustBeATrollOrAnAstroturferOrAShill
  5. Re:WTH? by krinderlin · · Score: 3, Informative

    Universe, I'm wishing desperately for mod points for the parent. People are so blind to just how horribly insecure the system is already. A rooted phone is the least of your worries. They just busted a skimming ring here in Atlanta restaurants a few months ago. This is no less insecure than what's already in place but far more convenient.

    As for the GP: Also, realize that most of this is US based and we don't use "chip & pin". Period. Also, most people run debit cards as credit cards. Companies actively encourage you to sign for purchases and not key in your pin with various rewards. Some banks even charge the customer a fee per pin-based transaction. These are magnetic stripe machines that always run the card via the Credit Card processing company (MasterCard and Visa), not via the bank. The rules are different for those, and you most certainly won't be using your craptastic PIN.

    I won't go into the level of security a 4 digit PIN does not provide given enough money you can get via fraud for a particular card.

  6. Re:Why hasn't PayPal been innovated out of existen by MickLinux · · Score: 4, Informative

    Nonsense. Don't you remember the fiasco about them claiming to insure against fraud? Then it turned out that they were "self insuring", and never paid once.

    I was one of those who lost something like $350 on it [the normal used price for that particular Quark Xpress]. I proved fraud 5 different ways: two of them were that the seller claimed to be selling a licensed copy of Quark Xpress, and actually delivered a Windows 95 user manual; and the seller claimed to be from the Antilles [not a Russian mafia hotbed] and shipped from Tbilisi Georgia, which would have caused me not to buy, right there.

    Anyhow, Paypal said that since he shipped *something*, they considered that a 'quality dispute', which they didn't cover.

    I never got my money back, and Paypal has never paid on the claim, and as far as I am concerned, *Paypal's fraud* worked hand in hand with the sellers' fraud.

    No, it is NOT TRUE that Paypal doesn't abuse customers in general. There is a class actual lawsuit that demonstrated that. I just never signed on to it, because plaintiffs in class action lawsuits typically never collect. But if Paypal ever wants me to consider doing business with them in any way, shape, or form, they'll first pay me back the money I lost, plus interest.

    And yes, I am aware that Paypal is in the middle of a media blitz right now, which means that they probably are paying for "online reputation protection" as advertised on National Public Radio, and therefore I am probably going to be modded with a combination of "Troll" and "overrated" to make my post vanish. I've noticed that that has been the pattern these days.

    So be it. I'm still going to post the truth.

    Saying "they don't abuse customers" is false. I'll assume you said it in ignorance.

    --
    Correct Horse Battery Staple: 72 bits of entropy. Enter "Correct H" into google. When it generates the phrase, that's