EBay to Ditch PayPal for Dutch Payment Processor Adyen
bloomberg.com
bloomberg.com
PayPal seems to be unique in being able to take payments from a passive web page, because the customer conducts their transaction at PP's website.
This is why I continue to use PP for my tiny little business (without eBay). Even though I consider myself reasonably tech savvy, I don't trust myself to maintain a website that is compatible with everybody's browser, phone, etc., and that guarantees the security of their personal data. Moving to another payment processor requires a quantum leap in technology that I'd rather not keep up with. I'd rather design another gizmo.
From time to time I look around for an alternative to PP, and haven't found one yet. I suspect that many small-time eBay sellers may be in the same boat.
Iirc, still need to use backend code to do the actual charge, but at least you never see any sensitive info.
Oh noes, I have to run php code stripe has done all the work on and provided to me! Scary!
If my inventory service breaks I might have some pissed-off customers or have to re-ship some items, the odds of getting in bigger trouble than that are low. If my payment infrastructure goes down or gets compromised, the odds of lawsuits or federal/financial-org penalties are way higher.
So sure, you still probably have to have a "server" somewhere (you could probably make a fully static site for a merchant using third-party payment links, javascript, and mailto links or something--think "email as database"--but I suspect this would be neither featureful, secure, nor reliable), but the difference in what you need to maintain/serve is huge.
That’s very different from PayPal’s offering.
You also mention a passive web page, if you're talking about a static site (as in a jekyll or hugo site hosted on S3), you may be right. I don't fully understand how that might work since if you're accepting payment for a service, presumably you also need to keep state somewhere to track the delivery of that service to users and such. But if you did want to accept Stripe on a static site, I would think you could use Lambda functions in AWS to handle the callbacks without worrying about the maintenance costs and security risks of running your own linux server.
No lambda, backend, or database necessary.
You're right, I mean a static site -- one that cannot run a server side script.
At its most basic level, you can pay me by going to PayPal and telling them to send money to my account. PP takes your credit card info. I get an e-mail, and my PP account shows a log of transactions. Then I click on "create shipping label," and it creates a shipping label (USPS or UPS) to the customer's address.
At a slightly higher level, PP will generate a "add to cart" button in the form of HTML that you paste into your web page. But it does the same thing as sending money to my account -- it just looks a bit more professional and maybe less confusing.
This is for a gadget, but for enthusiasts in an area where people are not typically tech savvy, and don't feel put off by a site that doesn't look professionally maintained.
Edit: I should note that despite seeming sketchy, a lot of trust is built into PP's buyer and seller protection policies. If I try to screw around with you in any way, PayPal will happily reverse the transaction.
And they will also happily reverse the transaction if you don't.
Made numerous payments to shoddy businesses in SE asia the last month, but since most offer PayPal as payment provider I feel confident entering my CC number.
Think about java updates and a certain antivirus product as a great example of insane greed :)
I used to work for a small ecommerce webdev shop. I’ve worked on sooo many shitty insecure shopping carts over the years I simply know not to trust basically any small website asking for my card. Completely unencrypted, storing CVVs, sending CC details as GET parameters, I’ve seen it all. It’s painfully common!
If a company is not a huge name, and is handling your credit card info themselves, they are mishandling your credit card information in one way or another. I guarantee it.
Having been through PCI compliance, it’s no joke. It’s really not worth doing yourself in my strong opinion.
Not to be snarky, but a huge name is no guarantee of safety. See: Target, Equifax.
If trusting one entity can already be insecure, having to trust dozens of them is nuts.
Handing a merchant credit card details "feels" like handing them a blank Check and trusting them to not take more than they should because of the risk of them losing the data.
Edit: The digital hash should say where money comes from, to who, for what purpose, time, auth code and so on.
I live in Denmark, and they have a system of phone banking here called "Mobile Pay" it works kind of like that. Where you transfer money to the merchant public phone number and show them proof of sending.. However it only works for in-person payments where you can swing your phone to show.
Seconded. At the risk of simply rephrasing everything you just said:
It's a pity the banks and credit card companies just refuse to innovate.
When I buy something from an online vendor, they should never get my full card details. PayPal ameliorates things (you can generally trust PayPal), but really there should be no need for PayPal. The banks/credit-card companies should provide a convenient way to authorise the payment, in a way that doesn't trust the vendor.
Here in the UK, we already have chip-and-pin, and card readers (the kind that show unique numbers - they're used for online banking), but we're still stuck with the trust-the-vendor-or-use-PayPal model for online payments.
Using card-readers for online payments would also help with credit-card theft.
I agree, but I also have a counterexample:
"Oh, you bought SOFTWARE?? All those pretty marketing pages about our amazing safety and protection system do not apply to virtual products. We agree this vendor totally screwed you over, but it's not our problem."
(this was a few years ago, may have changed)
edit: It eroded my trust in the company completely. I don't really have an opinion of their technology.
At a glance it seems software products are now covered - https://www.paypal.com/il/webapps/mpp/ua/useragreement-full?...
If their online banking password policies are anything to go by — Halifax and especially Nationwide — then very definitely no thankyou.
Nationwide asks you to set three pieces of memorable information. You can then log in with any 1 of those 3, at your option. https://onlinebanking.nationwide.co.uk/AccessManagement/Logi...
This seems obviously stupid to me, but I'll accept that Nationwide knows better than me if HN says so.
Well of course I trust my bank. No escaping that. The point is not to have to trust the vendor.
> online banking
I wasn't suggesting a payment system based on signing-in to online banking.
Your complaints about online banking security may be valid, but aren't the same issue.
Google Pay follows this standard. Apple Pay has a similar, but Safari-specific, API.
The alternative, telling the user to manually go to their bank and generate a token for amount X, would lead to so many people not bothering, and to so many lost sales. Or copy-paste errors, because users are dumb.
Many just don't turn it on because it's another step and they don't have issues with fraud, as well.
Adyen works with your shop no matter how PCI compliant and well-built, so you can have it in the checkout or the separate payment page. Interestingly you can also pay by paypal via Adyen.
I have found the online login bit for merchants to be as flaky and naff on Adyen as other payment gateways of yesteryear - forever timing you out and not letting you in, just really bad UX as banks seem to prefer.
I don't see these blockchain based payment systems as fundamentally solving anything in online payments needed for ecommerce, the Adyen tool kit is pretty large and bits such as the 'token' are not needed in real life, or some of the stranger mobile payment solutions that also promise to change the world as much as the crypto-coin 'promises'.
Just because a vendor doesn’t NEED to store your CC doesn’t mean they’re not out of sheer ignorance or incompetence.
As a reply you'll get some kind of token that you can use to actually charge the credit card (or SEPA, or whatever else).
It's a secure way of handling payment without the "we're now redirecting you to some payment site" which BY THE WAY Paypal themselves offer in the form of their Braintree payment services.
"etc."? That leaves a lot of companies where you potentially do business. Note that the size of the company isn't necessarily an indicator that the company knows how to safely handle payment information.
I'd much rather trust Paypal than a company worried about losing track of me or that I might see a different branding.
That different branding is the very reason I'm doing the transaction in the first place: I trust Paypal way more than any company's self-hosted checkout.
They can't do this because then the untrusted merchant has access to everything again. It needs to be sandboxed in a separate page so that the customer is talking directly with the processor, with SOP, cors, https, and simply not being able to intercept PII and payment information.
They usually offer some kind of "pay links" or something similar.
There's a shared secret you can use to verify the payment when they callback to you after payment, and their HPP is skinnable.
[1] https://docs.adyen.com/developers/api-reference/hosted-payme...
For those of you contemplating Adyen vs. Stripe: Adyen is much more "bare metal." Think more like a modern Authorize.net. Nobody comes close to Stripe's turnkey developer-friendliness.
Glad to hear on the developer friendliness! If there are ways we can continue to improve on that front, please shoot me a note: lachy@stripe.com
I'm curious though what you mean when you say Adyen is much more "bare metal" than Stripe. We don't typically talk too much publicly about our underlying infrastructure (our goal is to abstract away that [hopefully] unnecessary complexity), but we do strive to be as close to the bare metal as possible. (We're directly connected to all of the major card brands, and have "acquiring licenses" in numerous markets.)
Basically, great work.
But for larger companies ready for deeper optimizations, especially on the pricing side, "bare metal" merchant services will always have their allure.
The link in the alert email cannot be “parameterized”... it will only go to "the_saas_company.com". But I need the link to go to a per customer url, eg. "customercode.the_saas_company.com/billing". Heck basically anything that would allow my server to redirect the request to the "right" billing page (eg. the_saas_company.com/failedpayment/stripecustomernumber).
I was just recently refunded over five hundred dollars for a purchase made on ebay because the seller never had the item to sell. Now I had to wait until the last day of delivery passed and wait the "resolve with seller first" delay which is only three days I think. In the end ebay refunded me.
This is not to say ebay is perfect, they don't require sellers to provide tracking through ebay and they should. they should require it within three business days or allow a refund. In my case the fraudulent seller never provided tracking information even though I made three requests
I use PayPal as a buyer, I would NEVER use them as a seller.
Although I get the logic behind it, not one other PSP requires such a huge reserve, therefore we decided not to work with them.
Todays payments world is v competitive and players like checkout.com and many others are v aggresive trying to disrupt stripe's dominance in this area
(I also noticed on the video that it is pronounced "Adi-an" where I first thought "Ad-yen" which makes them sound more like an ad wholesaler than a payment processor.)
I'm curious what the integration with Ebay will look like. Will users be redirected to their Ayden accounts ala Paypal or will it be branded via Ebay?
Major upside for Adyen is they price match(at least for my company, we process USD ~350mil/annum). This may sounds crazy but my company constantly negotiate the pricing with them. Almost on monthly basis.
I knew this because my team have to work with lots of local and China-based payment processor to create PoC. Just so that corporate team can show this to Adyen and renegotiate the fee.
To me it sounded very much like Limburgs dialect (specifically Kerkraads dialect) "adieë wa" (only first part, but sometimes the second part is omitted anyway) [1]
English Wikipedia also has an entry for the company Adyen, btw [2].
> On October 3, 2002, PayPal became a wholly owned subsidiary of eBay. On September 30, 2014, eBay Inc. announced the divestiture of PayPal as an independent company, which was completed on July 20, 2015.
Cocky maybe, certainly not stagnant.
Hmm. Maybe I'm misinformed? What kind of innovative things have they done recently? As a PayPal merchant, the UI is still a clunky mix of old and new, and weird session errors and logging in twice, etc. We just barely got past SHA1 certs.
It has reached the point that i think twice about doing business if the store only offer Paypal.
I wonder when eBay will change their rules that currently state that you must offer Paypal and cannot mention other payment options (including cash) in a listing.
One common use case we see is trust accounting for lawyers. The gist of it is that trust and operating funds are stored in separate bank accounts, depending on the context of the bill. It’s a legal requirement that can result in disbarment if not followed properly.
Another scenario we run into is with insurance billing where policy payments need to go to different bank accounts or even be handled by a different processor, depending on the policy.
I know of other software systems that can do payment routing as well.
Stripe is a flat-rate payment processor: 2.9% + $0.30 on everything.
Interchange fees range from 0.05% to 3.2%, more or less. Most consumer cards are going to be significantly cheaper than 2.9% to process. Many people use "check cards" from their bank which are in that 0.05% category, for example. American Express and the top tier Visa and MasterCard rewards/business cards are the ones where interchange can exceed 2.9%.
There are many "interchange-plus" merchant account providers now. I get better rates than Adyen is advertising on their website right now.
The more volume you process, the more a switch makes sense. and this difference of mentality is reflected by the fact Adyen has minimum monthly invoices when Stripe does not.
Adyen had a better story for omni-channel commerce with card present, but they made us integrate with COM. COM! Apparently they have card present readers coming out that allow you to send some JSON.
In the end after hundreds of hours invested in it, we ditched Adyen. We did have it running in production, BTW. Their pricing was not any cheaper than we got from stripe with interchange plus.
Today I feel like Paypal has a lot more traction than Ebay, and this is going to be a big flop for them. As a consumer I don't want to sign up for yet another payment service.
It'd be like claiming that SpaceX is South African.
https://www.startupgrind.com/blog/the-collison-brothers-and-...
As far as I can tell, the founders are Irish but the company has always been American.
Unlike CC you don't get a new number/have half a dozen of different ones of them. So it's a quite a bit more of a hassle should the payment service provider ever have a breach/leak.
Many people didn't like to sign up with PayPal to begin with but, due to its dominance with eBay it was a bitter pill most people just swallowed to do their eBay buying and selling.
They just can't be trusted not to fuck over your business. Not intentionally... but algorithmically. And once that happens their customer support rarely seems to be able to fix the issue.
They just don't seem to care about false positive vendor issues.