Square responds to Verifone's allegations
squareup.com
squareup.com
-Didn't mention the competitor by name, and stuck to addressing the arguments, without any messy ad hominem stuff.
-Set up a separate page to address this issue. They could have easily lost by simply shifting the focus of the discussion to questioning Square's security. Posting a message on their home page or their blog, for example, makes it an issue to people who had no previous exposure to the issue.
-Stuck to a basic analogy that everyone has experience with, and everyone can understand.
-Used the opportunity to discuss other aspects of Square without throwing it in the reader's face. I had no idea they had a partner bank.
Good on them. I feel Dorsey has a mind for this, but I also find myself wondering if they had any PR consultation.
Chase is probably their processor.
The device was something like this: http://www.google.com/products/catalog?q=usb+card+swipe+read...
Anyway, seems to me there's nothing new here... just the fact that people can now get a device capable of decoding the tracks on a magnetic strip for $0 instead of $30.
But then I started thinking, "That's it? A magstripe reader! You can get those anywhere and it will do the exact same thing. Unencrypted."
We had to pick one up for a customer so the can use magstripe time cards. To test it out, we plugged it into a computer, opened Notepad and started scanning anything with a magstripe.
---
I think I'm missing something.
People seem to think that the problem is that Square can be used as a skimmer - which I agree is stupid. That's like saying a pen & paper is a skimmer.
However, it seems like the real issue is that Square stores the data on the device in the clear. What happens if the device gets stolen?
Imagine if a web app stored CC information in the clear and it got hacked, people would rightfully hold the vendor/processor responsible. If devices get stolen and data is stored in the clear, Square is totally wrong and they are totally deflecting/mis-representing the issue.
Can anyone with actual knowledge about this, rather than two business pointing fingers, clear this up for us?
>Let me explain how easy it is to exploit the vulnerability.
A criminal signs up with Square, obtains the dongle for free and creates a fake Square app on his smartphone. Insert the dongle into the audio jack of a smartphone or iPad, and you've got a mobile skimming device that fits in your pocket and that can be used to illegally collect personal and financial data from the magnetic stripe of a payment card. It's shockingly simple.
The issue is that Square's hardware is poorly constructed and lacks all ability to encrypt consumers' data, creating a window for criminals to turn the device into a skimming machine in a matter of minutes.
The "problem" is that the Square reader thing doesn't encrypt its communication to the iDevice.
And it shouldn't. As Square said in the letter, by merely seeing your card someone has enough information to steal from you. At best they could public-key encrypt the data in the reader itself and pipe the encrypted data to their servers... until someone cracks the key. Or makes a fake Square reader that's identical to the ones out now. At which point we're back at square one. As it stands, Square just made a simpler version of a standard credit card reader, and for some reason they're claiming it's a security hole.
FWIW: Verifone just guaranteed I'll go out of my way to avoid ever being a customer of theirs. This is FUD, plain and simple; they're probably doing it because they see a threat and are trying to squash it, rather than out-perform it.
Lets follow the waiter example. In order to skim the card number they'd have to put the card down, pull out a pen, and copy it. Likely within plain sight of their employees. With a skimmer they just discretely 'double swipe' the card and they got what they need. It certainly makes it a simpler attack vector.
Now you don't really need square to do this. There are plenty of magnetic card readers out there (I seem to recall someone got caught doing precisely this with a PDA of some kind). That doesn't mean that Square should make it simple. Why not provide some sort of encryption to the communications layer?
What sort of encryption would you think they could do? And how much larger and more expensive would it make the reader? And where would it get enough power to perform the encryption (which MUST be asymmetric to be secure, or the key can be extracted from the device)? They'd lose all semblance of interoperability between devices, add a battery, add significant cost, and all to fight a bogus claim and do nothing to prevent someone from buying a standard, unencrypted card reader that isn't under fire.
Skimming equipment, both software and hardware, has been freely available for ages now. And it's quite simple. Anybody who knows how to use ebay and write a small application can create quite sophisticated skimming equipment themselves.
The problem is not the availability of the equipment or the know-how. The problem is what "average Joe" is used to. If "average Joe" would balk when presented an off the shelf mobile phone to swipe their card through, well, then skimming using a mobile phone would be hard. But if the banks and payment processors have trained "average Joe" to know that a mobile phone is a completely legit way of reading credit cards, well then this type of skimming is easy.
If no ATMs existed, well, then it would be really hard to skim cards using an ATM-like device, because people would balk.
It's all about keeping the different legit ways of accepting credit card payment to a minimum. The fewer legit ways, the fewer possibilities of skimming.
On the other hand, there is no doubt in my mind that mobile payment will be the future. Replacing the standard plastic will a chip in your mobile phone will become commonplace soon, and we will also probably see applications where you can transfer money to others simply by having both mobile phones interact.
So the question is if the big fuss really helps anyone, or if it's only delaying the inevitable.
Making it difficult to process credit cards doesn't solve the problem of credit card security.
Security wise an inexpensive portable standardised terminal would make much more sense. In the end it would cost a bit more, but this would not necessarilly translate to increased cost for the POS. Less skimming equals less cost to the service providers _and_ the POS.
(if there's a permanent URL for that, I can't find it).
[1] http://blogs.msdn.com/b/oldnewthing/archive/2010/05/11/10009...
I guess the question is this: why not use smartcards or RFID? Other countries have for years. Why not in the US?
I have a card with information stored on a magnetic strip, a smart card, RFID and text. It doesn't matter which of these you use to steal the information, the result is the same.
You know why Paypal lost a hundred million in fraud? One way was because they were the weakest link at the time: Paypal got used for cashing. (The hardest, riskiest part of stealing credit cards: transforming a credit card number into hard currency, without getting arrested. There are any number of ways to do this: buy items with a high resale value on eBay, pay with Psypal backed by stolen cards, sell items for cash. Set up affiliate account with merchant of high margin item, put sham transactions through using Paypal account backed by stolen cards, withdrawal clean money from affiliate account to which no accessible link to Paypal accounts exist. etc, etc)
Smart cards/RFID are basically worthless for preventing card not present fraud, which is the lion's share of it.
When I hand over my card to a merchant in a store, how do I know what they are swiping it in is a dedicated and secure card reader? I don't.
Now each credit card in the UK is has a chip (which uses end-to-end crypto), they're looking to phase out magstripes completely.
Currently if the merchant has to fallback to using the magstripe then he'll have considerably less protection against customer fraud, and he'll pay a much higher transaction fee.
Square would not be permitted to operate in the UK.
However neither would would the other 99% of the credit card in the US. The US infrastructure is insecure, and Square is no worse than the rest of it.
If someone is using a fake app, they wouldn't be able to incorporate your secret image, and you'd be tipped off. They'd still get your credit card, but you'd know it right away, and could cancel your card/call the police right there.
Same thing banks do on web sites to prevent this same kind of attack.
What about the value of also capturing the CVV1 code, which, as I understand it, is the only piece of info not already printed on the card?
I'm not sure what the security rationale is for 2 distinct codes. Maybe the CVV1 value is designed to prevent thieves from making swipable cards when they only have the credit card number and didn't clone a card (e.g. they obtained the card number from a rogue or compromised online store).
I disagree with tldr on this entirely, however; it's short, to the point, and an astoundingly good way of responding to the allegations (ie, FUD).