Europe's Square
izettle.com
izettle.com
For private individuals a facebook account is needed to accept payments.
The legal agreement is a mess, they even warn that your data can be transferred to countries where privacy laws are not in par with european standards and data is stored for 7 years
Location of the transaction is stored and cannot be turned off, it's unclear why this is needed.
They seem to comply with PCI data security standards but are not audited (yet?)
The customer must sign the transaction on the ipad screen with finger (even harder with iphone). it's very hard to check that to the signature on the back of the card. also the customer must type his/her email on the screen if they want a receipt (there is no receipt printer). So each transaction takes a long time.
So it's good for selling at fleamarkets and such but for serious business it's no match for a payment terminal. Also if you don't already own iphone/ipad then it's also more expensive.
In my experience, signing works really well. Also, in Sweden nobody checks the signature. I don't even bother signing my card, and I can't understand how anybody can read the signature on the card. I think it's happened once that someone's wanted to check my signature against the card.
Checking the signature was the norm in the UK before chip-and-PIN.
Yeah, I think it was in the UK they wanted me to sign the card, since I hadn't done it already. This was before chip-and-PIN. Oh well...
Tesco don't have the swipe slot, and they now train till staff to say they can't swipe cards. But it does work on the till itself (I know this because when a friend visited we made the poor till attendant try it :)).
EDIT: also, interestingly, it looks like this service only uses the chip feature, not the pin :)
Generally I've found that swipe almost always works, it's just that most people don't know that it does. (And you have to be willing to help show them how.)
The skimming just got out of hand.
(And yes, this totally defeats the security aspect of C&P)
As I understand it, C&P isn't meant to be more secure for users - it's meant to be more "secure" for banks, since if someone fakes your signature it's not your fault (and the bank has to swallow the loss), but if someone gets hold of your PIN it IS your fault.
Many automated machines (e.g. gas stations) don't support swipe at all, only chip & pin.
And in Belgium, most of the terminals in smaller shop seem to be swipe-less, they're pretty big square things and only have a slot for chip-based (above the screen rather than below), no swipe slot.
In our defense: we had to, because the skimming by eastern european criminal organisations was getting out of hand. There were incidents were they completely replaced cash machienes with identically looking clones.
So, in holland, get money at a tourist bank, the airport or your hotel. Beyond those places, you cant swipe anywhere.
So, although most hardware is still technically capable to swipe, no bank is supporting it any more.
It was in response to eastern europe based organized crime, that was modifying cash machienes.
Likewise, all online bank transactions use a secondary device for authentification.
If you visit holland, and only bring a credit card, make sure you get cash at your hotel, the airport or a bank, because you cant use it anywhere else.
In Belgium and the Netherlands, it's not usual to see supermarkets even taking credit cards, and some restaurants (!) don't either. This is changing, but slowly.
Usually I remember to get enough money from ATM's. The worst day to forget to withdraw some cash is the first of May, when it's a bit different because all the ATM's are closed to prevent the protesters from breaking them.
Also, signing with anything other than a pen and paper is still a disastrous user experience (see every courier's PDA system ever built)
Where are the finger print scanners or iris scanners when we need them?
For them to include a PIN entry system, they would need to do so on the chip reader device itself (non-iPhone).
The keypads for PIN entry systems always hash the PIN before it leaves the keypad... no other software gets the PIN.
If you cannot offer secure PIN entry, then you cannot offer PIN entry.
You can still take a signature, but now the burden of responsibility changes. Fraud is covered by the merchants if you use signatures.
They can still screw around with that one single transaction, but they cant duplicate the card.
Its like an ssl tunnel straight from your card to your bank. The other party is just passing the encrypted one time permission slip to charge money.
It completely ended skimming here. As for unsecured devices like an iPad, the goverment mandates two way authentification. This is done by sending an authorisation code per text message, or an auxiliery device, not connected to anything, that uses the signing chip on the card, to provide the user with a one time authentification code.
Edit: they definitely support VISA.
I was previously under the assumption that you can't authorise a payment via a signature nowadays in the UK?
What if the retailer does not accept chip and PIN?
Where the retailer has not upgraded to chip and PIN technology, you will be asked to
follow the current card payment process using your signature to confirm the
transaction.But if the retailer lets the user sign instead the liability is with them: this is an incentive for retailers to accept and promote Chip/PIN over a signature.
iZettle read the chip (good), but then you sign for the goods (bad). It's not at all clear if that means liability for fraud now rests with the seller rather than the issuer. Their help page is very vague on the subject, and alludes to the fact card issuers won't allow PINs to be captured on mobile devices (this makes some sense, from a phishing perspective).
In fact, iZettle's help page has zero results when you search for 'fraud'. I think this is something they should address.
Coincidentally (shameless plug here), I blogged about this exact problem a month or so ago, bemoaning the lack of a good Chip & PIN solution. I'm not convinced iZettle is it...I've now written up some more concerns about fraud in a new post, here: http://cleveryou.net/post/23162180527/izettle-square-killer
So, if you're going to use this system, you will have to take the liability issues into account.
(The cynic within me suggests that even in the case where a fraudulent chip & pin transaction has occurred, merchant agreements probably do their utmost to shift liability to the vendor regardless though.)
For example Visa offer contact less payments for merchants via pay wave.
Barclays have payments from your smart phone via ping it.
Then there is nfc technology.
Just trying to test the longevity of this product. Does it alleviate the pain of using a card and remembering a pin.
Edit: also worth mentioning Paypal, Barclays Paytag.
On the other hand, what the fuck is with that name? iZettle? What's a zettle when it's at home?
I hope they change it.
You triggered my curiousity, though: what's your (mis)interpretation? I don't understand the reference to "at home" at all, and basic Googling failed to resolve it.
Another point about their communications is that their main (English) front page copy says "[...] is as easy as pie", an idiomatic expression that to me screams of the US, which was funny because of the European angle.
It seems they're actually fellow Swedes (yay); I've seen some ads for their card reader in local press, too. The reader was then coupled with (if I recall correctly) a phone with a business-type subscription, the ad was by one of the local/Nordic cell phone operators. Interesting.
We use "easy as pie" in the UK too, although it's probably an American import. (EDIT: almost certainly 19th century American. Mark Twain used similar phrases http://www.phrases.org.uk/meanings/as-easy-as-pie.html)
I think maybe my accent has a much harder Z than they were anticipating.
On the other hand, "Kindle" is something like an angel in German (or a beer), and I think it is a great name anyway!
On the other hand, iZettle is neither memorable, nor makes any sense.
YMMV - I thinks it's both memorable and makes sense (sounds like "I settle"). Also, I've never seen a Square device so their domain isn't memorable to me!
"Social" in this context just sounds like "here is another way we think we can make more money off of you". Bah. I've no love for my credit card company but at least it's not trying to be a social network. (Yet. (That I know of.))
Perhaps that's a little unfair. I guess as more and more apps and devices become avaliable for reading you card inforamtion more and more opportunities exist for stealing your info.
I guess with Android there is more change of the device owner not knownig it's there, it's much easier to say phish someone into installing malware onto an Android device than it is to jailbrake their iOS phone.
I wouldn't like to be in the shoes of fraud departments right now...
However, what I really dislike is when people also start copy the look and feel of the innovator´s website. I think we should apply the same moral values to startup ideas as we do in science: That implies to create your own work, not to rephrase and to mention the original source. This piece might be missing in the system.
without a card reader its 1.5 SEK + 3.5%