A simple solution to credit card fraud, part 3: the startup that never was
blog.rongarret.info
blog.rongarret.info
Money transfer is essentially subtracting from a number on one bank's hard disk and adding it to another on a second bank's hard disk. OK, it has to be done transactionally, and you need those numbers to be secure, but really... how hard is that?
I read today that share traders are excited that they can now do trades between Chicago and NY in 8ms instead of 12ms. So why does it take me days to make a simple payment? And why does it cost more than a few micro-cents to do it?
Revolutionising value transfer has the potential to be biggest benefit the internet gives us - but seems destined to be the last one realised.
I make six figures providing online services for schools, and spend roughly half of my effort on payments. Partly resolving problems where the payment processor refuses to accept credit cards (from schools - hardly a high fraud demographic, and we've never had a customer charge-back), partly handling paper checks, partly trying to match ACH payments with customers.
Bitcoin can't happen soon enough.
So sad and so true.
I wish more people could bear down, learn and realize how the money system works; how the Government controls it and what the banks involvement is.
The work that Stephanie Kelton and crew are doing over at http://neweconomicperspectives.org/ is really great if you're interested.
I'm sorry you don't like my narrative style. I'm trying very hard to stick to the facts and not over-dramatize. There's a reason I'm an engineer by trade and not a journalist.
And I'm sure your narrative style is much better than if I tried to tell it.
Just describe the user experience. There are plenty of people here who know plenty about cryptography, payments and getting service usage.
Note: here's all you have to tell us related to cryptography: the service is as secure as a mag-stripe.
http://en.wikipedia.org/wiki/Chip_and_PIN
> There are plenty of people here who know plenty about cryptography, payments and getting service usage
I've explained this to you before: not all of the people who read my blog are engineers.
> Note: here's all you have to tell us related to cryptography: the service is as secure as a mag-stripe.
Apparently I have to explain more than that because that makes no sense whatsoever.
Hm, if it quacks like a troll...
Hardly a troll.
You're moving the goal posts. You asked me to describe the user experience. It would be like chip-and-pin.
> Fraud is essentially a non-issue in card-present situations.
That is not true. If it were, they would not ask you to enter your billing zip at gas pumps. (Yes, I know they don't do this everywhere, but it is a very common practice precisely because card-present fraud is a significant problem in some areas.)
> Hardly a troll.
We'll see.
The user experience would be similar, yes.
> doesn't require new pos hardware
There are lots of ways it could be deployed. Some would require new POS hardware, others don't. But unlike chip-and-pin it wouldn't have to be custom hardware. It could be a smart phone or a tablet.
Compare: Electronic interference is essentially a non issue on aircraft... That is not true. If it were, they would not ask you to turn off your Kindle at takeoff.
Just because an industry does something doesn't mean it isn't cargo culting.
For that, you'd need to interchange payments with your system and bank accounts.
1) Gov't regulates financial institutions, and there are good reasons for it - otherwise Ponzi schemes and 'bankers' stealing deposits are a real pain and causes the public to ask for regulation. So they will want (force) you to submit to regulation if you want to do anything serious; or you may try to do "only information" and have another, licenced institution (a large bank) hold the actual money - this is what many finance startups do, but then they depend fully on the bank(s).
2) Gov't and banks don't like anonymous transactions, and there are good reasons for it - money laundering, tax evasion, organized crime and stolen money are very real issues. A basic principle is 'know your customer', i.e., don't do any [above $X] business with anyone you can't identify; and don't allow your customers to front payments on behalf of others, unless they identify all those others to you in each transaction. And it's often simpler/cheaper to disallow 'on behalf' deals at all than to integrate your customer/transaction data with the bank's systems. For example, see MtGox AML limits for money withdrawal - if you want to handle "real money", then that would apply for all transactions, not just withdrawals.
3) There are a bunch of consumer protection laws that may hurt you. For example, if a customer's account is hacked and money transferred, above a certain limit you (not the customer) will be liable for the loss. And there are other cases as well. So you (as the organizer) really, really want a money system where payments are (a) traceable, (b) revocable if legally required and (c) can't easily go to any other untraceable, irrevocable systems. Banks do so. The alternative is to charge huge fees to cover the risks to you.
4) Payment systems (ACH/etc) require huge collaterals or guarantees from participants - and there are good reasons for it, as you don't want to receive a gazillion payments, give the money to your customers, and then have the payer institution say that they're insolvent and won't cover the bill for the payment-messages that they sent. Technical and legal barriers to joining are also quite high.
And point 2... as a society, we have a very important decision to make. Do we trust our governments to control our money - and that of the terrorists, child pornographers and media prirates? The right to control our own money is disappearing as cash is slowly supplanted by cards, and I expect swift action against bitcoin if it gains traction.
I guess I'll keep reading because the inanity of it all has me hooked but pray tell part 4 gives some sort of short description of the user experience for this supposedly simple solution (that sounds anything but simple so far).
Sure, why not? Had to start somewhere.
> The insinuation that bank higher-ups were actually evaluating your idea and killing it is presumptuous.
I don't know what happened at Wells, but I do know for a fact that senior management (and in two cases the CEO) was not only evaluating the idea, but actually signed off on it later. Just because I started naive doesn't mean I stayed that way.
> Do you realize that Dwolla is trying to do similar things
Of course. So? Lots of companies are trying to do similar things. None of them (except Paypal) existed when I started.
> but it takes dozens of employees, millions of dollars and an indirect route to get there
Yes, of course I realize this. And your point would be...?
It seems that WF is now open to working with startups and opening accounts in other people's names (without notifying them).
http://blog.rongarret.info/2010/11/personal-banking-nightmar...
You've written five thousand words thus far...
FWIW, to move $100,000 USD through Bitcoin right now would cost you about 6%,
100000 USD * (1 BTC / 33.6 USD) = 2976 BTC
2976 BTC * (31.8 USD / 1 BTC) = 94636 USD
Or simply, (33.6 - 31.8) / 33.6 = 5.3%But I'm sure you know this already!
Those numbers from http://mtgoxlive.com/orders