Square Debuts New Email Payment System
cagraham writes "Mobile payment company Square — best known for their smartphone credit-card swipers — has launched a new payment service called Square Cash. The service doesn't require users to sign up or make an account. Instead, they just email the person they'd like to transfer money to (with the amount as the subject), and CC 'cash@square.com.' Square asks the sender for their debit card info, and then sends a link to the recipient, who can transfer the money into any account they want within 1-2 business days."
This has got to be the most insecure payment system ever.
Account details over email and 1-2 business days?
Why not just put cash in an envelope and send USPS? At least that way you can't lost more than the cash you send.
Isn't this exactly the same thing as an Interac e-Transfer?
I've been sending money via email for many years this way.
MABASPLOOM!
Obviously this is a front for the NSA so they can get rid of the traditional means of tracking bank transactions and just lump it all into the haystacks of email data the already collect! Government efficiency at it's finest! Brilliant!!
So the From:, Subject, To:, and Cc: headers are what makes this work?
Not a bad idea, really, except that it can all be trivially spoofed, and the resulting set up/confirmation emails can be trivially intercepted and abused at will. Plus, of course, no easy drop-in encryption, and in the end it piggybacks on existing systems, so all the risks associated with them (like credit cards) will be neatly folded into the deal too.
I still prefer the Bitcoin schemes. Now, if I only had some bitcoin to toss around :(
Time Bomber the Book coming soon.
Why does the US have such an antiquated banking system? Hell, a lot of places still need checks because they won't take plastic!
I've had bank accounts in the UK, Australia, Germany, Canada and the US.
Canada is basically the US in this context..banks are no better. They do have email money transfers though.
Which is something every other damn country has. A way to transfer money between bank accounts of individuals securely and free. The only option in the US has been paypal or chase quickpay.
Not to mention the reliance on checks (ridiculous!) and the problems with ACH fraud. Again, in no other country has my account number been secret information which I have to protect. The worst thing people could do is put money into my account.
So many issues....
If you ignore ACs because they are anonymous - you're an idiot.
Drug Deal!
Except Drug Dealers don't keep Bank Accounts. Its a cash and you are carrying business.
This requires you to give Square Your debit card info, and makes your recipient give you THEIR bank details.
Seriously, the NSA couldn't have dreamed up a move invasive scheme. What could possibly go wrong with that?
Left unsaid in the linked article, (and also the Square website) is how square is going to monetize this, other than by
*cough* losing one out of a hundred payments. They claim the service is free. FAQ Here to both parties. So, how do they finance that, other than getting a piece of the debit card fee? (Senders have to use a Debit card).
One wonders just how much the debit card fee is jacked up to allow Square to assume the risk for this type of service, and handle the deluge of complaints and lost payments claims. And how many will be suckered into handing over their bank info to a 419 email purportedly from Square.
World Plus Dog is rushing to mobile payments, but I'm not so sure this is well thought out.
Sig Battery depleted. Reverting to safe mode.
From what I understand Square is a credit card processing service, which means they fall under certain other regulations. Not quite the same as banks, but certainly not out in the wild west as far as regulations go. I've known several small business owners who used them for credit card payments for a while now and both owners and customers seemed happy enough with the results.
How many times must people be hit in the head with a clue bat before they understand that this is a Bad Idea[tm]
Time flies when you don't know what you're doing
telnet random.openmailrelay.com 25 HELO victim.domain.com MAIL FROM: victim.email@victim.domain.com RCPT TO: dummy.prepaid.card.email@badguy.com DATA CC: cash@square.com SUBJECT: $1,000,000 Here is the payment I promised. . QUIT Profit!