What happens when you swipe a credit card
tech.affirm.com
tech.affirm.com
People look at you funny for not knowing how a credit card has worked for the last 30+ years. Here chips got introduced mid-80's and all cards had chips circa early-90's.
Why did it take so long for credit card to feature chips in the US ? Because it took a while for CIA's in-q-tel to take over control of gemplus, the company who owned the smart card technology, which happened early 2000's. This is known as "l'affaire gemplus". Once they got control, the company HQ got moved to luxembourg tax haven and the R&D and tech moved to the US. A few years later in 2006 it merged with competitor axalto to form gemalto famous for making SIM cards and recently for their SIM crypto getting in NSA hands[1]. In 2009 french government tried to counter the takeover by becoming gemalto's major shareholder, but it was too late, CIA got what they were after as shown by in-q-tel selling its shares in 2010 which coincidentally was the years EMV credit card got introduced to the US.
really exceptional reading material.
[0]: https://www.franceinter.fr/emissions/rendez-vous-avec-x/rend...
Another thing I find interesting is the anti-tamper features that are present in a standard credit card terminal. There's a great CC terminal teardown video by EEVblog that walks you through them: https://www.youtube.com/watch?v=tCgtTPwlDSo.
An interesting tidbit: An extra reason US fees are so high are premium credit cards choke full of rewards: Not every card has the same fees, and the highest fees come from cards that are handing you extra rewards, that are paid pretty much directly by the merchant. It's just that banks know that the better the rewards the more people will use the credit card, and the easier it is to take the business away from cheaper cards, as nobody charges you more at the register for using a Chase Sapphire Preferred instead of a debit card.
Security features also make US cards extra expensive, as the best you have is Chip and signature, and that doesn't cover online. If we demanded 2FA in every transaction, including online, fraud would go very close to zero, and with it, fees.
With more modest rewards and better security, interchange fees could shrink by over a percentage point: Banks just don't do this because there's little to no competitive pressure.
What we really have is mercantilism, where the issuer by contract disallows full information to be conveyed to the consumer without the consumer's consent, and this is in effect protected by law by the fact it isn't illegal. You could also call it an example of chrony capitalism.
So "if we really believed in the free market", we should regulate the details of how a private transaction can take place?
Leaving aside any other aspects of that proposal, whether positive or negative, it doesn't seem reasonable to describe it as "free market".
The information that has to be expressly stated as part of a contract is not some minor detail. It is at the very core of enabling free markets in the first place.
Some seem to think of free markets as a sort of natural phenomenon and of regulations as a distortion. But that isn't true at all.
Contracts, property rights and the responsibilities of all participants in a trade are concepts of law. Without them you would have to rely on implicit cultural conventions and resolve disputes by means of duels and vendettas.
Making it explicit to customers with debit cards that they're subsidising the rewards of other customers will [edit: "could"!] incentivise them to demand lower fees, for example. This is a free market at its best.
Yes. I don't think "free market" is incredibly well defined but the concept it evokes to me (as someone with a degree in economics), is a market approaching perfect competition[0], which is well defined.
A perfectly competitive market has a number of requirements, things like low barriers to entry, lots of buyers and sellers, no externalities, and so on.
A government policy that intervenes to try to aid perfect competition (e.g. some anti-trust legislation) could still be called a "free market", I think.
That said, I realize some people seem to define it to mean "free" from all government interventions, but they don't have a monopoly (heh) on the use of the word.
Either Chase has lower fees than most banks or it doesnt. The mony all comes from the same place.
[Edit] And if you are wondering how companies can store the creditcard data for automated payments like Uber, they cant .Uber have tied up with payment wallets to make payments seamless or you have option to pay by cash. For business there is an option for interbank automated transfer but that require you explicitly singing agreements.
Also there might certain us customs that might make certain things hard, like tips. I am not entirely sure if this is true though.
The actual implementation (for e.g. between the hardware terminal and their gateway) is usually using some custom API/protocol - for e.g. Stripe/Braintree have their own APIs as do other older players like like PTI (https://www.chasepaymentech.com/developercenter/index.html?W...).
The big 4 banks in Australia have historically offered an Amex card and a Visa/MasterCard linked to the same account (because Amex isn't accepted everywhere and often attracts surcharges). If ANZ's recent move is anything to go by, it looks like the banks won't be able to afford offering a linked Amex with their accounts.
Researching around the net, it seems for traditional brick and mortar, some issuers don't allow you to charge a percentage based card processing fee. Any idea is this is allowed on Stripe?
Sections 1.5.4.2 & 5.6
https://usa.visa.com/dam/VCOM/download/about-visa/15-April-2...
Section 5.11.2
https://www.mastercard.us/content/dam/mccom/en-us/documents/...
IANAL, etc.
I did run across this link, which might explain why when you asked your initial question I was thinking "no way", but after reading the recent agreements was like "maybe so" (I worked in payments for a number of years, and always heard that cash discounts/surcharges for credit card use were disallowed).
http://www.nytimes.com/2012/07/14/business/mastercard-and-vi...
So apparently there was a suit about that very problem which was settled in 2012. It looks like you would be able to, but if you're charging multiple thousands on the regular, it would probably be worth it for you to pay a lawyer to make sure you're in the clear. HTH.
Source: I used to run a payment gateway & ISO.
Note - none of them I work with have used Stripe. They are normally using a gateway provider (like NMI) and a payment processor (like PayPro, Auth.net, Vantiv, etc). Stripe combines the merchant, gateway and payment processor into one bundle.
Incidentally it also regulates debit interchange down to practically nothing. Processors like Stripe are making a killing on debit. Try to find one that does "interchange plus" pricing, and then you can accept debit at no additional cost to your customers.
[1] see p7 http://blog.legalsolutions.thomsonreuters.com/wp-content/upl...
I can't really think of a specific, non-political reason to show the fee to the customer specifically on the payment terminal. If it's important to call it out, just put it on he invoice/receipt.
this means if you choose to decline transactions for cvv or avs reasons in your gateway settings, those funds are still actually held by the customer's bank as pending for ~24h, preventing them from trying the auth again if it puts them over their credit limit.
the only way to release them is for the merchant to call the customer's bank and provide the, cc number and auth code.
we've had to leave these "security" settings off in our payment gateway and just assess the processor codes ourselves. then manually call the bank if there are mismatches. it's a massive pain in the ass and pretty much a neccessity if your avg order is hundreds of dollars. >:(
That's because the alternative is the acquiring/issuing bank doesn't immediately reflect the authorisation in the shadow balance and only deducts it once either a confirmation has been received or a certain amount of time has elapsed, and of course that leads to a very chatty protocol and race conditions. Not to mention that the systems on the backend side at the acquiring/issuing bank would have to put the parts together.
My experience with writing integrations with acquiring banks was that you needed to issue a reversal to have the held funds actually removed from the shadow balance. But it didn't always work, something about the reversals having to be the next request immediately after the corresponding auth. Obviously this was a system not built to scale and the whole AVS/CVV was a bolt on.
AVS is most interesting because (at least using APACS 70, not so much ISO 8583 depending on the acquirer/issuer) it only works on the address numerics and not the other chars. So when you input your street number and postcode (at least outside the US) you can put whatever you want in the form as long as numbers match, anything else is thrown away.
Who is your payment processor? They should be voiding the auth after the AVS or CVV mismatch.
Where can I read specifics for each network?
Also, the post doesn't do a good job of explaining what affirm is. All I know is it's some kind of alternative.
i've seen few "caveats". paypal has some tighter constrains on their fund availability guarantees. they make you run a re-auth after 48 or 72 hours - i forget the specifics, but it's in their api docs.
Sadly swiping is being replaced by chipcard.
EDIT: add reference
[1] https://www.quora.com/Why-are-chip-payments-so-slow-in-the-U...
As a consumer, chipcard provides no benefit. Yes fraud is theoretically lower, yet the banks aren't passing any of these savings to me (I'm still waiting for lower rates or higher paybacks).
He's not wrong although this is pretty far down my list of life's annoyances :-)
http://www.ncrcounterpoint.com/media/catalog/product/cache/1...
It has a slot for a chip card at the bottom, a slot to swipe a card on the right, a PIN pad for debit transactions, and may be tap-enabled. The screen portion displays the order total and other instructions, and is also touch-sensitive for providing a signature using the attached stylus.
You can swivel it, tilt it, and even pick it up off of its mount if it's in an awkward position.
IMHO , consumers find it reassuring that they are asked for a pin AFTER the amount is entered into a swipe machine in a bar (where you are much more likely to be drunk). This kind of a mechanism is very nice when amount is entered by someone else (the retailer/cashier).
At the ATM, you are the only one that enters the amount.
So the pin entry at the end of the workflow is not a bug..It's a feature.
That's not possible with the model used around here. The card's key never leaves the card, all the crypto is performed inside the card's chip itself.
The banks have not increased rewards, or lowered interchange fees (thereby lowering retail prices).
Federal law protects me from fraud no matter the card input method.
Due to the risk of online fraud, I still have to check my statement for fraudulent charges.
There are, however, noticeable downsides. Including everything coin mentioned, here are a few more downsides to chip cards, at least in the US:
* Chip cards are slow in the US. This has gotten better lately, but its still bad. Before the downvotes start, look at the references [1] [2]. This leads noticeably longer lines at stores.
* Not every merchant accepts chip cards. Sometimes its hard to tell which version the merchant accepts.
* There are a lot more annoying noises (the buzz when you leave your card in too long). Its a small nuisance, but it adds up. Previously the transactions were silent.
[1] https://www.quora.com/Why-are-chip-payments-so-slow-in-the-U...
[2] https://www.wsj.com/articles/chip-card-nightmares-help-is-on...
Even just the convenience of a more reliable read is worth it.
Visa announced Quick Chip EMV that enable you to dip your card at any time of the transaction for it to generate and capture a cryptogram before the end of the transaction. This will allow Visa EMV to be almost as fast as swiping.
https://www.visa.com/chip/merchants/grow-your-business/payme...
http://www.pymnts.com/news/emv/2016/visa-puts-the-quick-into...
Does anyone literally swipe a credit card any more? I can't remember seeing it done in years except in some parts of Europe.
They have had that for over a year in the States. Weakest point in the chain takes liability.
And don't forget paper checks are still circulating. I didn't try last time I was there but I imagine that when you go to cash a paper check you go to a guy sitting by an abacus.
No so for the US, they're still relatively new having been introduced in the last 5 years
China has a mishmash of system from in-app payments (a la WeChat) to QR-code based systems.
And the requirement for a PIN (or signature, depending on region) has more to do with amount than with method.
I see this being downvoted, and I'm wondering if it's not simply just misinterpreted.
Most places in the US I've used chip&pin, the process goes like this:
- arrive at merchant, select goods, get total.
- look for a sign that says chip is not enabled.
- failing that, move assuredly towards the chip reader and keep an eye on the cashier to ensure he or she doesn't move to stop you.
- put card in reader (if enabled you can do this at any time - but doing it earlier won't save you time)
- wait 2-10s while the reader figures out what to do
- approve whatever you need to when it pops up.
- wait 30-60 seconds for the transaction to go through, then find out you miskeyed your pin.
- Repeat previous steps and associated waiting. Ignore eye-rolling of others in line.
- walk out a satisfied customer.
Obviously I drew it out as long as possible there for effect, but I've only ever seen very slow C&P implementations here. I am usually spending up to a minute waiting for the transaction to clear.
By way of comparison, swipe cards take about 3-4 seconds to process. Debit cards with pins take 3-4 seconds + however long it takes you to type in the pin.
So I full understand the "sadly" prepended to the statement.
Every time I go to the local mom-and-pop butcher shop I commend them on their chip reader's super fast processing speed -- and each time they comment that "Thanks, everyone says that!".
I find it incredibly funny and frustrating that their card reader is so fast, enough so that others have noticed & commented on it too, while everywhere else -- the local chain grocery stores for instance -- consistently have roughly >=1 minute processing times.
Also frustrating? The cashier has finished ringing my items up. I put my card in, select "No cash back", type in my PIN number, it thinks for a bit ... and then, it asks me if I want to confirm the charges?! No, I don't, I just typed in my PIN for kicks! I get it, it's to verify the amount, but I'd love to know what percent of the time a user [intentionally] selects "No" at that screen -- I probably _accidentally_ select "No" about 5% of the time, and roughly 0% of the time have I ever intended to select "No". Small things, but annoying UX overall.
I'd think that many larger chain retailers are working on this. Some may have it solved w/ more "proprietary" systems; I don't shop at Target much lately, but I recall their payment UX being superior to most, unsure if their chip system is too though.
I'd love to get the speed of swiping back! :-)
I'm in Europe and never used swipe cards (haven't seen a cheque since I was a kid, not sure they're even used anymore, but I digress) but the experience is really simple and the times you mentioned are always shorter.
Select goods, put the card in, enter PIN, 10 seconds later I'm walking out of the store. With contactless cards it's getting even simpler and faster and I insist buying at shops that use them. In that case the whole transaction is just one short beep and I'm out. If the total is over ~$20 then I also need to enter the PIN.
With chip, I have to wait after the clerk has scanned all the products and after he pressed the "pay with card" button on his terminal. During the authorization, I have to keep the card plugged into the POS. I do this while I bag my own goods, because in Europe the clerks do not fill up your bags like in the US. At some point during the packaging process, I have to stop to take my card back because I don't like to leave it there while the clerk has started processing the next customer.
The experience sucks profoundly. The convenience at swiping at any time during idle time cannot be understated.
So you don't have any control over the amount he can enter/withdraw?
This isn't entirely correct. The interchange is the part of the transaction fee that goes to the issuer. The card network gets a scheme fee, and the acquirer/processor charge a fee on top of that. If a merchant pays the same rate, regardless of what type of card is used, (credit/debit, consumer/business) then the processor or acquiring is basically rounding up.
Some detail about the pricing might help here. Most of the fee is actually going to customers, believe it or not, and sometimes processors. It is an interesting study in complex two-sided market dynamics. This is critical to understand when thinking about how to improve the system, and it's something many startups figure out the hard way.
Most of the processing fee goes back to the issuing banks, not Visa/MC. On a typical transaction:
1. Visa takes "only" 0.11% + 2 cents.
2. Depending on the card maybe 1.5-2% + 10 cents goes to the bank that issued the card (e.g. Chase, Citi, Bank of America). These are fixed and published rates called interchange.[1]
3. The remainder of the fee is processor markup (e.g. Stripe, First Data). They are responsible for merchant fraud so their markup can vary a lot depending on merchant risk profile and bargaining power. E.g. Starbucks pays virtually nothing in processor markup, while Stripe's markup on thinly vetted ecommerce sites is huge.
So while 0.11% of all card transactions is a lot of money for Visa/MC at scale, most of the "high" 2-3% card fee is actually going back to banks. Competition between Visa & MC keeps their cut to where it is. Even though they control "70% of the market", there is two-party competition there.
So what's the deal.. what are fees so high? Don't banks compete with one another? Well, yes, they do, but it's not by picking lower interchange rates. There's one more piece to the picture: card benefits like reward programs that refund 1-2% to the customer, thinning the bank's take considerably. Banks compete on how much reward to pay out to the customer.
Merchants dislike higher fees, obviously, but given the importance of card acceptance to completing a sale, they are more tolerant of fees than customers are tolerant of poor card benefits. The bottom line is banks need to compete for customers more than card networks need to compete for merchants.
The only way merchants have been able to reduce card fees is through regulation. Visa/MC have built systems that effectively leverage the power of customer choice. If you want to build something different you need to look at the customer benefit side of things, not just offering merchants a lower-cost method.
[1] https://usa.visa.com/dam/VCOM/download/merchants/visa-usa-in...
When Apple Pay launched, Clover had a detailed post on tokenization. http://clover-developers.blogspot.com/2014/09/apple-pay.html
That would break so much as most of the message formats and batch files use fixed width fields. It's probably the same for the databases underneath. Changing to alphanumerics sounds nice but the check digit algorithm would have to change from Luhn to Luhn mod n. More breaking changes.
Banking systems are one of the ultimate forms of legacy, which is why most of the security additions have been bolted on. Just look at 3D secure - they added an entire subsection to the message format and it was still just another single factor auth method that nobody wanted and everybody hated.
or just get rid of it. It was a relic from 20+ years ago when networks and computers were 1/100th the speed they are today. Let them enter invalid numbers. Let the server return an error (as it already does)
CVV: Not sure why it's on the back, but the point of this is that it's a number that's not raised, so it's not recorded when using a credit card imprinter (less common than is used now).
I assumed that it's a leftover from early days, before online card checks, so the merchant can check that the card is still valid (besides checking signature and ID or whatever). When introducing online checks of the magnetic swipe, expiry date was part of the data transmitted, and early phone/Internet payment systems relied on reconstructing the data present on the magnetic strip, to "fake" a swipe. Then it just stuck from there.
I believe it's a convenience thing for the end user, when issuing a new card - offer a couple of days "grace" - and arguably there isn't much risk associated with this practice: lost/stolen cards are always cancelled immediately.
1. Use your real card number. I never do this. 2. Use a merchant-locked card number. I use this commonly for online pizza and other online shops I don't trust much. Once a merchant uses it, only that merchant can use it. 3. Use a one-time card. The number is used once and disabled. Good for one-off orders or skeezy purchases.
Overall I've been pretty pleased. I think the idea that card numbers should be disposable is awesome.
edit, i checked it out. so 1) its no open to sign ups, and 2) you have to have pretty stellar credit to even be considered. so that leaves out most people.
An object which signs every transaction it's asked to sign is an improvement (can only be in one place at a time) but still broken (evil terminals).
What we can agree on is that there should be strong authentication. Apple Pay is the best system I've seen. It creates a unique but static account number that can only be used with Apple Pay, which has strong authentication which is also convenient (Touch ID), so it can be mandatory. Thus it doesn't matter if the number gets stolen as it's useless without Apple Pay.
But payments in general are just totally effed and can't seem to move forward without some sort of fix. as a consumer its both amazing and incredibly frustrating. as a merchant it's essential. Imagine how much money netflix would lose if you had to auth payments every 30 days.
The whole point is that you can't skim the CVV2 from the magnetic data and then use it to make purchase.
(Yes, there are probably a lot of retailers breaching their PCI-DSS compliance by storing the CVV, but the point is they're not supposed to. Until we can do chip-and-pin or similar for online purchases, e.g. Apple Pay, the problem remains)
http://www.creditcards.com/credit-card-news/ownership-statis...