Square Cash
square.com
square.com
- Take an existing known medium (in this case email) and makes it way more useful.
- They didn't try to build a bunch of new UI for connecting your Facebook so you can find and invite and pay your friends, paying out to your card, etc.
- It magically hides the messiness of an enormously complex problem (fraud, different types of debit cards & banks all over the world) behind a very simple interface.
- Unlike every other P2P payment system, I can actually sign up and receive money (or convince my friend to) using only what's in my pocket (debit card)... not hunting down ACH/wire details.
[0] http://valanx.org/index.php?option=com_content&view=article&...
>The recipient will be emailed a link to easily deposit their cash to their bank.
You have to wonder about the wisdom of training people to view such emails as legitimate.
Since we're in the realm of phishing already, let's not forget that people still commonly enter their email address and email password into sites claiming to "Find your friends who are using this service".
The problem with social attacks is that they spread socially, and it's not enough for just "some", or even "most" people to be educated for it to be stopped.
I don't think Square are ignorant about this, but I'd like to see some confirmation that some measures are in place to counter threats like these.
So, Square trains people that these e-mails are OK. In the happy case, you get the email from a friend, followed by a link/invitation from Square. Everything is fine.
After doing this several times, one day you just get the email that appears to be from Square, informing you that you have money. This is a phishing email and there is no email from a friend, which should raise a red flag, but for many it won't. Or they may just think Square changed the process. Putting the onus on the user to discern this is not a good plan.
Training users to click a link from an email that resulted from a process they didn't initiate, then enter personal/financial information or credentials is not a good idea.
There are also wrappers around this here like Chase's Quickpay or Ally's Popmoney but most require that both people use the same bank, or that you give your ACH details to a bank that isn't your own.
Paper cheques just have the routing/account numbers along the bottom, and AFAIK essentially work via ACH anyway, so they have all of the same downsides, plus taking longer to complete.
Also, the window for fraud with ACH is so great that when you tell one bank about another account's ACH details so that you can transfer money, they "authenticate" this by making small, sub-$1 deposit amounts, and asking you what the amounts were, to prove that you can see the target account. So this "linking" process takes the entire ACH transaction time as well the first time you do it. Some banks have taken to using a service called Yodlee which asks you for the target accounts' username and password. That's right, Wells Fargo asks for your username and password on Scottrade to authenticate the transfer because they don't trust the way ACH's liability lies. So this won't work to send $8 to your buddy anyway.
Moving money without a service like paypal/venmo/square/google wallet is really quite difficult, especially if you don't want to trust an organisation with a history of taking people's money (Paypal) or if you don't want to pay a transaction fee.
[1] http://www.npr.org/blogs/money/2013/10/04/229224964/episode-...
Interesting. I had come to a similar conclusion myself. I noticed that in paying my school fees all I needed was those two numbers (banking routing #, bank acct #) for payment with no further verification. As you have observed all of these details are readily available on paper checks.
One way to mitigate the issue of someone potentially wiping your account is to have two accounts. One public and one private. The private one would contain (most of) your actual funds whilst the public account, which you would share freely as needed would contain just enough funds to complete whatever transactions that you need to do. Sure, it is not as convenient because you have to manage two accounts but at least that way you reduce your exposure to your funds being completely depleted.
Anyway, good description of ACH above. Very few people understand how it works.
In Australia, the equivalent is EFT (Electronic Funds Transfer). You can deposit money to anyone's account by telling the bank their BSB (Bank/State/Branch number) and their account number; however this is not sufficient information to withdraw money.
To withdraw money: 1. at a physical bank branch: a. you put your credit/debit card in a POS terminal and enter your pin/sign to authenticate. b. provide yous credit/debit card and photo ID to the teller. 2. at an ATM: credit/debit card + pin number. 3. online banking: either the credit/debit card number and a password and often a pin as well, or a separate number and password.
All of these use an independent authentication source to the bank account number.
Also the delays quotes here are insane: In Australia, there are essentially 2 ways to pay for something (excluding cash): 1. EFT (Electronic Funds Transfer) 2. Credit card (possibly using a debit card) transaction.
On POS terminals, you can choose either; the differentiator being whether you want to use a savings account (EFT) which goes via your bank, or a credit (or savings account accessed via debit card) account, which goes via MasterCard/Visa.
All forms of EFT take 1-2 business days between banks, pretty much all the time; and they're universally free for the payer.
Credit/debit transactions seem to take 1 day universally.
We have a fairly stagnant banking system, with 4 major banks having basically the entire consumer market (and the vast majority of the nonconsumer market as well). Why, in a small, stagnant market like ours, do we fare much better than the US system?
[edit: I forgot to mention, checks are dead here, they're now almost only used for large transfers of money where: 1. you don't want to use EFT; 2. they're over the daily online maximum for EFT transfers, and you can't be bothered to go to a bank branch (although you can only get bank checks at a branch AFAIK); 3. You want an immediate guarantee that the ammount was paid and the date/time/payer/payee (as opposed to waiting 1 day for the payment to come through).]
Because it's descended from writing simple letters of credit (and by this I literally mean a letter that says "Hey bank, pay John here $15 out of my account kthx"), and giant ancient heavily regulated institutions are terrified of change.
The system wasn't designed exactly, it just sort of evolved
Not quite. Vendors can now legally add a surcharge to cover the cost for payments from a credit card. Some vendors traditionally refused Amex when they had to eat the charge, since Amex was something like a 4-5% cost to the vendor as opposed to the 1-2% costs of the other cards.
Why, in a small, stagnant market like ours, do we fare much better than the US system?
We have strong banking regulations, apparently. I heard somewhere that during the GFC, there were only ten banks of that kind globally that hung on to their AAA credit rating, and all four of the Australian big banks were in that ten.
Yeah, the real question I was getting at was, given the Australian market is even more insular and stagnant than the US, why do we have much better systems?
What you're saying sounds plausible; a comparison of the US and Australian regulations on deposit banks would be interesting.
No processing times too :)
They are minimal, but they are there.
Plus the fee for the terminal of course. Which varies significantly between banks in AU.
Specifically, you can do an EFT transfer from a bank account to any other bank account in Australia via online banking, and it's free (at least in all the times I've used it).
In the case of ETFPOS terminals, EFT is always free for the payer (the customer), and credit cards are usually free for the payer, but do sometimes have a fee for the payer (certainly AMEX and Diners).
As I've now been corrected on, both types of transaction have a fee for the payee (the merchant).
The fee for the terminal itself is definitely true - I was mainly thinking of fees in terms of payers, i.e. the customer, not the merchant.
Though given there are alternative methods for credit/debit payments (i.e. alternative terminal types, like the swipe thingy that plugs into iPhones) it'll be interesting to see if people keep the combined EFTPOS + credit/debit card terminals, or abandon the EFT side, as the number of non-debit bank/keycards dwindles.
Our bank regulations are a joke (in the last few years, we just nationalized a fraudulent bank for €2.7 billion and re-sold it for €30 million), and yet we have a similar system, plus free virtual CCs, plus an award-winning ATM network that doesn't charge any fees for usage/withdraws.
Other people have already weighed in on the fact that actually not all of the payment systems are free for the payer (even EFT via a terminal costs).
But ask yourself, why does it take 1-2 business day for this to happen? In the UK, the worst case scenario is 2 hours between different banks. And if the account transfer is within the same bank, it is instant.
In AU, even between St. George accounts you can see delays of up to 1 day. Insane! Especially since the money isn't changing banks but accounts within the bank.
The AU transfer delay is bizarre.
Seems to me like square cash is comparable to the extremely low friction nature of XBT to XBT transactions, but with fiat currency.
I'm not saying square did this in response to bitcoin, just that it's scratching the same (or a similar) itch.
Once the accounts are linked, either party can pull/push money without the other's approval.
There's no such thing as "free banking" in the UK
I tried to deposit a cheque into my landlords account and the bank teller would not accept it, had to be cash or bankers draft - I presume because they may have a limit on the number of transactions per month and anything over wold cost them additional money. I found it very bizarre.
The Barclay's "pingIt" system is a step in the right direction, I think all banks should adopt a similar system. Paypal "gifting" is a good alternative to this but not everyone has a paypal account
That said, NatWest's mobile app also allows this behaviour: I can send a contact a text with a link allowing them to deposit the amount specified: up to £250.
The Durbin amendment regulates the cost of debit transactions over the Visa/Mastercard network. It's $0.22 + 0.05%.
Mossberg reports that Square is planning to monetize via "premium options" like international transfers. But still, $0.22+ is a lot to lose every time someone uses your mass-market service.
Good thing they raised $341M of VC money.
Who said the dot com days aren't back??
Source: http://allthingsd.com/20131015/the-money-is-in-the-email/
The dotcom did get some things right. The internet is a big deal. There are land grab markets. They got timing and lots of other details wrong. Maybe they will need to have a freemium offering long term to avoid too balance this if they start hitting millions of active users. It should be easy enough to get $5 pm from big users.
They are playing for a big market(s) here. Very big. If bthey are paying to build their name and userbase, it could make good business sense.
We know a lot more hese days. Our instincts are better. We are not cming up with a valuation based on a multiplier of hits. A user of a financial service has a realistically high value.
Remember when PayPal paid out a $20 referral bonus for each new customer? Yeah, those days.
It's worth looking at how PayPal tried to steer towards profitability in later days, though. They basically became more evil. When paying merchants, they try to trick you into preferring ACH transfers direct from your checking account over using your credit/debit card. The former has weaker consumer protections, no rewards and risks overdraft fees, but lets PayPal keep almost all of their 2.9% + $0.30 fee, since ACH costs just pennies.
Not saying Square is going to become evil. Just saying they'll have to figure out how to break even with it eventually, because right now there's a built-in operational loss that scales with usage.
Edit: to elaborate on how I calculated that:
1. We don't know transaction size so I just focused on the 0.05% transaction fee. Obviously if transaction sizes are small, the fixed element of fee is higher as a proportion of the amount held for 1-2 days so the required return to break even is much higher.
2. If the transaction fee is 0.05%, $1 transferred turns into $0.9995
3. Square is sending $1 to the recipient. Therefore to break even, it must turn 0.9995 into $1.00 in the 1-2 days it holds the cash for.
4. To do that in 1 day, it must earn a return that is roughly equal to 20% annualized. So the annual return is (0.9995 x 20) = 0.1995. The daily return is 0.1995/365 = roughly 0.0005.
5. Adding the return of 0.0005 to the $1 brings you back to the $1 that Square sends on to the recipient. So they break even if they are earning 20% a year on the cash they hold before it gets sent on to the recipient.
Note the required return to break even is lower if they hold the cash for 2 days. However I'd guess they don't because one of the banks along the way probably hold it for at least half that time. Also, even if they do hold it for 2 days, you still have to overcome the fixed cost, so that moves the required return back towards my 'north of 20%' figure.
PS - since the Square guys are obviously smart, I'm sure they've done the above math so I'd question whether they really are paying these kinds of fees on each transaction. However if they are, Abalone's dotcom days comment is entirely correct.
After spending the last week trying to find a cellphone plan for my mother, seeing a Canadian institution that mostly works and is mostly good for the consumer is a welcome breath of fresh air.
But you're right, I'm sure that for every person like me there are many who just pay the $1.50 for the convenience.
Email money transfers? I've been doing them through my bank for years. It's incredibly simple.
I guess this says something about the state of innovation and technology; there are gaps, even in the mainstream between neighboring countries whose cultures are nearly identical. By finding those technological gaps, you can impress a lot of people.
In Canada, the email/Interac bank transfers that are so prevalent here still cost $1.50 charge per transaction.
Planet Money recently did a great episode all about the US's ACH system and why it works the way it does.
http://www.npr.org/blogs/money/2013/10/04/229224964/episode-...
Are you afraid of entering your debit card number? How do you make purchases online?
Credit card numbers are much safer to use online than debit cards, mostly because credit card dispute mechanisms give consumers a lot more power. If a merchant behaves in an unsavory way, with a credit card you can usually just call your bank, issue a chargeback and that's the end of it. You can't do that with a debit card.
You absolutely CAN dispute charges with debit cards. The problem OP might have with debit cards could be that a fraudulent charge temporarily locks cash funds (with debit card) instead of credit availability (with credit card).
There are wide differences in consumer protections between credit and debit cards.
The list of reasons for a valid chargeback on a debit card is much more narrow than a credit card. For example, suppose you purchase a tablet online and when you get the package, you sign for it, open it, and it's a paperweight. If you charged that on your debit card you're out of luck and will have to go to small claims court. On a credit card -- especially a good credit card -- the charge would be reversed. The issue there is that you signed for the package. If you don't believe that, give your bank's fraud dept a call, and then your credit card companies.
American Express obviously is great for consumer protections but truthfully any Visa Signature card offers a competent level of service.
Personally, I would never use a debit card online (or anywhere else for that matter) and would advise anybody against it. Not to mention, you can earn some fantastic cashback/mileage benefits. My wife and I are flying next spring to Europe, first class from San Francisco, over $20k in airfare, for only $2500 out of pocket for taxes and surcharges. To earn this we've spent $40k between 2 British Air cards in 15 months.
You can dispute most debit card transactions now.
Besides the "one is availability of credit, the other, real money", there is a liability difference.
It used to be, at one point, that debit card liability was essentially unlimited but a consumer's liability for fraud on their credit card was limited to $50 by federal law (see 15 USC § 1643). Debit card liability now has a maximum as well, but your maximum liability actually depends on how quickly you notify.
If it's within two days, it's $50 liability on a debit card, but if you notify past that, they could legally make you liable for up to $500.
(There are other liability generating situations that exist for debit cards but not credit cards)
Really, it's because I use my credit card as a firewall account. If my credit card gets compromised (which has happened twice before), I have to change maybe a dozen things that link to it. It's an inconvenience, but my bank can get me a new card the next day. Worst case scenario I lose my credit card for a week or so.
If my checking account is compromised, things are worse. If my checking account gets locked, not only can I not use it, I also can't pay my credit card. I'd have to setup my paycheck (pain), rent (pain), and some other things. Then I'd have to re-link a couple of other bank accounts. While I like my current bank, I don't want to take the risk of that account being locked for a week.
The idea of giving a random website (in that I don't have an account/relationship with them) a number that provides direct access to my paycheck gives me the shivers.
You could do basically the same thing with ACH. If a payment service asked you to enter your routing and account numbers, would you be OK with that? I see it as the same thing.
In most countries, bank account numbers are effectively public knowledge, and appear at the bottom of invoices and such. The trick is that with this knowledge you can pay money in to an account, but you can't get it out - for that you need authorisation. This makes paying via echeck or direct credit very easy.
Am I right that in the US you can get money out of an account if you know the account number? If not, why the secrecy about your bank account numbers?
- these are electronic requests, so there's nothing to distinguish "genuine" from "fraudulent" ones
- you really do have all of the information that goes into an ACH payment
Really, it's much more similar to forging a check than to counterfeiting one.
1) ACH. Everyone has mentioned that already. I'd need routing and account number, and likely need to know if it's checking/savings or business/personal. Like they've said, everything that I can find on a check. You could contest it for ~ 60 days, but you'd have to sign something at the bank, and you're out the money till you do.
2) Drafts. They're like checks, but not. Some health clubs (Curves, iirc) do this as well as some other less reputable businesses. Basically, once you sign an authorization (that they keep on file, not like it gets passed to the bank or anything), they can print a check like thing and put some specific language in the signature block area, and deposit it. Typically, this is done in bulk. Often times, it's then immediately converted into an electronic equivalent check (Check21 law) and then deposited in one big file. Return rates on these are astronomical. Most banks won't touch them. They should die.
To remove money from a US account, you also need authorization. The trick thieves use is to lie about having authorization. In that case, it's fraud.
I don't know of many fraudulent transactions that can't be reversed. Even fraudulent/unauthorized wire transfers can be reversed. The bigger problem is the hassle that comes with losing access to cash while the situation is resolved.
Can someone with actual banking knowledge correct me where I'm wrong and clear up this confusion?
Here's another comment that describes someone's actual experience with the product: https://news.ycombinator.com/item?id=6557516
I believe it's done by opening bank accounts at major banks, and then using the interbank transfer system which is instantaneous and only requires an account number and a name. Other services offer pushes to credit cards or debit cards using bill pay systems or blind credits.
It isn't actually that hard to move money from person to person. The real issues with this sort of stuff are: a) payments fraud b) money transmission law and regulatory compliance
The Planet Money podcast noted that some banks (Capital One, BoA) offer a similar service if both ends have accounts.
That they are not allowing this for credit cards indicates that they are using the pin debit networks.
not necessarily. you can't think of any other reasons why they'd do this?
I believe the transaction fee is higher and there's a percentage rate taken for non-pin debit card transactions.
That "something" is most likely just "replacing cash and cards", but will be interesting to see how it plays out. It's a bold move regardless.
EDIT: I meant debit card transaction fees, not credit card fees.
This used to be the case, but in recent discussions with retail owners I've been told that the fees are now comparable.
Otherwise I could deposit $10,000 from my credit card into my on-line gambling wallet, then withdraw it, repeat...
But yes, you also will not earn points on balance transfer transactions. But they typically are processed via ach.
Perhaps this is just an attempt to backdoor people into becoming users of Square Wallet. Give away person-to-person transactions for free, get a massive user base for business-to-consumer transactions and charge the businesses for the use of your network.
(Would have been nice to see this on the actual page rather than hidden in "Troubleshooting")
But really I don't need to be talked out of using Google's like it's the default, and I'm not clear on why you do. I don't really get the "why do you use your own favourite toy instead of my own favourite toy?" crowd
On the other hand, Square is positioning Cash as a dead-simple way to send money to friends, whether or not they've download the Latest Social Micro-payments App™. Its plumbing. Long run, they are obviously gunning for cards-on-file to support their merchant tools, where they make money hand-over-fist.
Who knows...Square Cash might expand into something that resembles what Google Wallet is today. They seem to be starting with the basics.
Besides that, Google Wallet is available in all 50 states, while Square does not allows residents of Hawaii and Tennessee to send money (only receive it).
What stops someone from spoofing my email address, CC'ing it to cash@square.com, and clearing me out? And if someone does get in to my email account I'm toast?
Wait, what? I don't think that is a thing.
So you need to confirm it (and provide a debit account) I guess - but not sure how subsequent transactions are handled.
> Square verifies each Square Cash email to authenticate that it comes from a legitimate sender. For added security, we send you a text confirmation each time you send Cash if you have linked your mobile phone number.
Now, how can they make sure that the email is genuine and wasn't spoofed? Sure, they can check for white-listed domains and SPF records, but still seems fairly weak process. The FAQ [1] doesn't say much either. Human validation is even worse.
It helps that the send receives an email confirmation with the transfer, but you may not check the email before the money is posted. I guess they're pushing the onus of the proof to the receiver -- after all to receive the money you have to have a bank account and a visa/mc debit card.
Whatever the security mechanism, it's a brilliantly simple solution. If it takes off, it'll quickly replace Dwalla and other micropayments.
[1] https://squareup.com/help/en-us/article/5144-square-cash-sec...
Moreover, why hasn't a bank or credit card company done something like this yet? Amazing how the solution disappears into a cc: address line and unique link in your email.
That being said, I have a question: Here in Canada, I can send an email transfer of funds from my bank account to my contacts by simply logging into my bank online and specifying the email address of the recipient. Does this type of system exist in the US?
Residents of 48 US states have the ability to send and receive Square Cash. Currently, you'll be limited to receiving Square Cash if you live in the following two states..
Amazing what you can do with a card number and expiration date. Don't loose your debit cards!
http://online.wsj.com/news/articles/SB1000142405270230337690...
That got me thinking though. It's 2013. The ideal solution is not to be beholden to any centralized authority or group of 'clearing' accounts for routing. The ideal solution is security but flexibility and distributiveness. The ideal solution is a network of trust with similar 'hubs' / 'clearing firms' that one can choose to route through automatically, have all the routing be automated for you via solid protocols.
There is the chance to create clusters of payment routing networks that are more elegant. It would make money movement so much more liquid in our world. And would be a really great thing.
Maybe Square is the beginning of that solution. I hope it gets even more distributed though. It's mostly companies leading the way for this. And good for them. But there's another possibility: something very open, but given the right protocols and architecture, very secure.
There is no incentive to create such an architecture other than the amazing world that it would mean where you could travel to different countries and authenticate seemless money transactions to whoever had a phone or email endpoint (again there would have to be name servers + some sort of money equivalent of SMTP + TLS / chains of trust + distributed clusters of shared 'clearing' bank accounts + routing algorithms to these accounts, etc.).
But that didn't stop Tim Berners-Lee or the early internet folks....
What banks does this work with?
Looks like the help in only available in US English. If that is the case, and it looks like they are using some sort of CMS, then it should be fixed up and and content fallback to something useful rather than a 404. This is a link off the landing page on a site with very little content, pretty unacceptable in this day and age (but for now there is the benefit of doubt to assume you are doing a beta run for feedback).
The only thing that was concerning was when I sent a spoofed email, the receiver was able to know the sender name (cash account name) – "ABC is about to send you cash". Very minor but it allows anyone to find out your name provided they know your email address.
Edit:
Looks like it's not even available in all states in the US [1]
[1] https://squareup.com/help/en-us/article/5136-troubleshoot-sq...
Most obvious long-run plan would be for user/debit card acquisition (which has lower interchange rates) to support their bread and butter business (merchant tools) as this would increase their profit margins by reducing processing expenses, especially since Square simply charges a single rate to merchants...
Ok now I'm confused. I realize it's probably a marketing ploy, but how could the fees on this not eat them alive?
Square Cash seems nice, but I prefer the approach of Swish.
Seriously, I am all for the simplicity of the system and the flow of the narration, but where the heck is the explanation of how this is not trivially exploitable?
"You’re sending $1 to xxx@yyy.com Just link your Visa or MasterCard debit card to send this cash."
If I did sign up and not receive a confirmation email for any following transfers I send, then I agree, I'd be worried as well.
With this I can tie my debit card (which I guess is the same thing). So, I don't seen any real positive benefit over Venmo IMO. Can anyone else point anything out?
Read this: http://www.quora.com/Square-Inc-1/What-are-the-details-behin...
E.g. if I have an debit card with my account at a Jamaican bank, can someone from the US email me cash and it arrives instantly or is this just a US service? Can't find any details about this on the site.
1. The "float". The interest that they make from the period that people have cash in their accounts. If an ACH takes 4 days to complete, they may take 5 days to complete it, and collect a day's worth of interest
2. The halo effect. Now you're a Paypal/venmo/square user, and therefore more accessible to vendors using them as a payment processor. Those vendors pay the service transaction fees.
But didn't we agree that email wasn't a safe protocol?... How long do I have to cancel a transaction? Are they going to honor the fake ones like Visa does?...
They solve this problem with the least amount of friction.
"Checking Card Adjustment POS Pin (Credit) $1.00"
So I sent him $1 back (to: my friend, cc: cash@square.com, subject: $1). And it instantly sent it to him. I didn't have to verify my details or anything.
I'd feel a lot more comfortable if there was a security blog explaining how they are validating that I indeed sent the email and it wasn't simply spoofed.
Edit - I did this from Gmail which I presume authenticates all of the emails via dkim? I'm guessing this won't work as automatic for other providers?
Edit2 - Just attempted with another friend and had to verify manually. The automatic-authorization appears to only apply when it's between two previously validated parties.
Another issue: if you make a mistake on the initial email, and want to send a different amount, you're out of luck. When you send a corrected email from the same address and go to the payment page, it adds any previously unfinished transactions from your email to the amount being sent, with no way to cancel the mistaken one. So just never make a mistake, and never do a test transaction you don't intend to finish, or you'll be required to finish and pay for all of it when you finally do have the correct amount and want to send a transaction (which you can only send with a small subset of the debit cards in existence).
These payment companies are always introducing interesting new things and then they hobble them with basic oversights and fundamentally flawed policies. In the last hour I've gone from excitement to disappointment with this service. It had promise based on the description, but this particular service (probably not Square itself) will fail very quickly.
Are you a parent? I do not have want to my kid buying products unfettered.
And if you legitimately have a $20 bill, I can walk into a store, represent that it's mine, and buy things with it, never encountering an obstacle along the way. That's the same fraud you're worried about in prepaid cards.
1) Government wants to ensure it can track all digital transfers (many pre-paid cards require activating with SSN)
2) Failing to approve certain transactions is the equivalent of a financial firewall because banks and payment processors know they haven't hardened their servers enough to prevent another one of these: http://www.nytimes.com/2013/05/10/nyregion/eight-charged-in-...
Now, if policy-makers were convinced the online-children-purchases market were bigger than the drive-by-ATM fraud, we would see the rules changed tomorrow.
The general categories of things that children are commonly restricted from buying:
- Drugs. These are all black market, so availability of prepaid cards is unlikely to change how they're bought.
- Alcohol. I've never tried to buy this online; I know eBay Now wanted to sell it and concluded that the cost of legal compliance was too high. Even assuming they could find mail-order booze, it would arrive in the mail, easily detectible.
- Pornography. This can be consumed directly on the computer, raising possible detection issues. However, if you're afraid of children buying it over the internet, I've got some very bad news for you...
- Birth control pills? I'm running out of ideas.
Are you afraid they'll buy digital goods? Why?
Says who? Who says they couldn't send a package to a friends house, or a workplace?
How would you react to receiving a package in the mail for your son's friend?
Exactly the kind of thing teenagers should be able to buy without their parents' consent.
Of course if you're with one of the four majors, well... they're owned by Australians, what did you expect?
I see a "cancel" link in the email Square Cash sends me.
Why are you starting transactions you don't intend on completing anyway? I haven't tried it, but from what I've read so far the workflow seems perfectly reasonable for the vast majority of transactions. It's not like when I pay a friend the 10$ back he fronted me last week in the bar when I forgot my wallet, that I give it to another friend first and say 'hold on to this for a bit while I ponder whether to actually go through with this 'transaction''.
Here in NL, its so much each to use send someone money: They tell you their IBAN, you grab your Random Reader and enter you pin and get a secure code to authorize the payment, and it's done. There's not even a market for companies like Square, since the banking system is designed to handle these typical situations. People here look at me like I'm crazy when I say that if I want to give someone money I either have to use PayPal/Square or just cash.
.. Aaand it's not an accident either.
This is to prevent money laundering and tax fraud.
In the US at least, these are not covered by the $50 limitation on losses on unauthorized transactions. In practice the banks often honor that anyway, but AFAIK they don't have to.
In this case however, it appears the bank could argue that when you got phished, you gave access to a third party.
Wow. I would never do this. It's a good practice never to use a debit card online, and it's unclear to me whether the service here offers any enforeceable assurances to participants.
This doesn't feel quite right, as you describe it you'd validated that it's ok to receive money from them, not send it. I'd be more comfortable if it was validated in some way when you first send something to a person. Receiving money doesn't mean I trust a person.
I could send you a dollar, and when you accept it I could fake an email back giving me 100. I hope this only happens with signed emails.
About DKIM, does it stop someone from repeating an email? Could I fake an identical email that has been sent before? If so, that's something that normally wouldn't be an issue (duplicate emails aren't really a problem, you can't inject any information, change links to dodgy sites) but would be huge for sending money.
EDIT - from the DKIM site
> DKIM does not protect against re-sending (replay of) a message that already has a valid signature; therefore a transit intermediary or a recipient can re-post the message in such a way that the signature would remain valid, although the new recipient(s) would not have been specified by the originator.
EDIT2 - Squares security page is brief and, well, sounds odd
> detects suspicious behavior in real-time, and in many instances, even before it happens.
How do you detect behaviour before it happens? Isn't that inherently impossible?
And yes, the exchange was B -> A which gave automatic authorization for an A -> B transmission, which I do agree is a bit presumptuous on their part.
Didn't Minority Report answer that question?
Not sure how that translates to this service, but if something is compromised, you might just end up with an empty bank account.
http://blog.charleyma.com/square-cash-initial-thoughts-scree...
Overall though, extremely impressed with Square's offering and it was also instantly debited to my account. Curious to see if the value increases to a somewhat significant amount if this "instant transfer" translates into 1-2 business days.
There are monetization strategies which don't involve charging the end user anything for the service provided.
email guarantees none of those traits 1. Encryption from server to server is optional, 2. Who knows how many MXs are hit until it finally makes it to my mailserver 3. Mailservers have know authentication mechanisms that ensure someone cannot send mail on my behalf.
Yes, well configured mail servers will make attempts at these things through SSL/TLS connections, doing direct connections only (no proxies/relays) and by only accepting mail from servers listed as MX servers or with SPF records etc.
Thanks for the -4pts.