Let people pay you. Make it easy
github.com
github.com
Yes, in its normal (unattacked) operation, the connection to Stripe will be safe HTTPS. But if someone does a man-in-the-middle attack, then there will be no connection to Stripe, just a connection to an evil website that steals the card (or both to be sneakier; it doesn't matter).
If you're not serving your site over HTTPS, then an attacker can arbitrarily rewrite the content of your site, so no one can trust it.
I'm not disagreeing with you, but the site running on https only is important in the context of the user not being thrown away by the lack of https, sensitive information is only transmitted through https.
Of course, the obvious answer is to run everything over HTTPS, but I'm not sure I understand the difference in what Amazon do and this demo page.
I would like to believe that everyone follows that methodology, but I have more experience that that. So for now, I like to believe that at least people who visit hn follow that methodology.
Almost best to roll with a cheap $5 plan from Digital Ocean - except then you lose all of the ease of use this project is meant to solve.
At the very least he should probably highlight the possibility of MITM attacks when not serving the original page over HTTPS, but I'm not sure how to solve the SSL issue in a way that's as simple as what Heroku offers without dropping a lot of money in monthly fees.
That is, the page has mostly loaded. You scroll down, and start to read. The rest of the page loads, and it scrolls back up to the top. (I'm assuming the page codes this, and it isn't a behaviour of FF 20.)
So many sites do this, and it is so annoying. Probably, on github's own servers, loading is so fast that they never experience this problem themselves.
http://thenextweb.com/uk/2013/03/01/stripe-uk-europe-launch/
Couldn't be easier to work with. Major, major props to the Stripe team.
That said, there's not much to my app. Just some rails routes, a form, and Stripe Checkout on the client side. But it gets the job done.
Connect is for marketplaces and does some amazing things to make 3 party payments substantially less painful.
Checkout is for 2 party payments and does some amazing things to make getting credit cards and storing them in a secure vault substantially less painful.
However, neither solution is drop-in zero-code.
Stripe focuses on removing friction at the hard parts of the problem so you can build machines that do payments, Paypal focuses on payments that require no effort on the backend.
But when you do something wrong they generally want to make it clear.
That is what is happening with PayPal here. No one feels the need to write something good about them when everything is going right(Even if that is happening all the time). One genuinely dissatisfied customer can bring you a lot of bad name(Even if sometimes that is purely an exception).
In fact the problems with PayPal are much more wide spread. I'd say that PayPal got lazy because no one has challenged them. As a result they still have an underinvested product that is painful to use.
I've used paypal as a merchant/developer on many products and on my latest project I actually decided not to bother charging customers until Stripe arrived in the UK (which it now has).
It's not that people don't feel the need to write something good about PayPal, it's that there's very little good to write about PayPal.
(not to detract from what PayPal originally did, which was monumental at the time, but they rested on their laurels)
As a developer outside US, Paypal is pretty much the only option available to my startup (selling paid subscriptions to a blogging platform). But it would be good to hear about some issues developers have had with Paypal so that i could try to avoid them.
http://conferencesburnedbypaypal.tumblr.com/
http://elliotjaystocks.com/blog/good-riddance-paypal/
http://open-source-scotland.com/2012/news/oss2012-is-hereby-...
http://www.xbmc4xbox.org.uk/2013/01/paypal-guilty-until-prov...
http://www.escapistmagazine.com/news/view/103385-PayPal-Free...
I like it BUT it is SO simple and ad-hoc that I wonder if people would be put off by it.
Like the story about users who disbelieve a big system has done something unless it takes a few seconds to process etc.
I wonder if people will think "This is too easy; it must be a scam"
PayPal is pretty much the only payment gateway supported.
Is there something like this, but for PayPal?
Also, see these entries in Stripe's FAQ - you're not required to be a business to use stripe: https://support.stripe.com/questions/sole-proprietor-without... https://support.stripe.com/questions/do-crowdfunding-sites-n...
AIUI, incorporation is mostly about limiting liability, and making it easier to sell off the business (or shares thereof) later. There are probably other advantages as well, but making it legal to accept payments at all isn't one of them.
They should just put that center at the top of the site so I can bounce faster.
Thanks!
the check's in the mail. ;+)
-bowerbird