Coin
onlycoin.com
onlycoin.com
As a merchant, however (which I am), there is no chance I would accept this. None. Unless the issuers (that is, Visa, MC, Amex) drastically change their policies, which I don't see happening anytime soon.
Why? Because the issuers are very clear about a few things: When push comes to shove and it REALLY gets down to it, unless the merchant takes a physical swipe of the actual card AND has backup to prove it (i.e. an imprint of the physical plastic), the issuers will side with a consumer in the event of a fraud dispute.
So why, do you ask, do most merchants not bother taking imprints of the actual cards? Because a visual verification and physical swipe is usually enough (for 99% of cases). Instances of fraud via card duplication are rare, so it's usually not worth the hassle. But in some cases, it is.
My business runs large-ticket purchases though CCs (average is $2000), and we take super extra precautions when our customers buy from us. We take magnetic swipes, visually verify, AND take physical imprints.
We've lost several chargebacks because of lack of doing this. You'd be surprised how these little-known rules crop up when you least expect them. "Sorry, customer claims charge not authorized. Merchant doesn't have physical imprint. Chargeback approved." It's happened and we've been defrauded out of $thousands because of it.
The ONLY way we've been able to successful combat chargeback fraud is through the multi-layered approach.
Anyway, I know this is a fairly esoteric perspective and my business may be different from lots of others where this isn't an issue, but I have a feeling V/MC/Amex aren't going to get behind this.
I carry 19 cards, of which 16 are essential. Some of them are not for swiping so they wouldn't benefit from Coin. The solution for me is a wallet that can hold 20 to 30 cards, but as far as I can tell there's no such thing.
* Costco membership card
* three loyalty shopper cards for my common stores (I need the physical card because none of the apps I've tried using that scan the bar codes work with store scanners)
* a card to pay for my train rides,
* bank debit card for ATMS
* business credit card
* personal credit card
* medical insurance card (this one would be easy to just use a photo of)
* AAA card (would be easy to use photo of)
* Zip Car Card
* Bus pass card for corporate shuttle
* Airlines MVP card (likely easy to just use a photo of, I think....though I'm not sure about speedy checkin).
* Access card for corporate office.
* Drivers license
I have about 25 other cards that I keep at home, like Library, more shopper perks cards (usually because they can lookup by my email address in store), etc..
This doesn't really help my wallet situation that much.
I'm surprised your loyalty cards aren't the smaller key ring ones. I have half a dozen on my keys and barely notice them.
I leave my AAA and Airline cards at home and pull them out when I need them for trips. Could probably do the same for your Zip Car card (unless you use the service multiple times a week or something) and other rarely used cards.
Last year my medical insurance company switched to paper cards which are much thinner and easier to deal with even if they're less sturdy. Same as my car insurance.
All that being said I still walk around with about a dozen cards in my wallet, so I can definitely sympathize. But I could probably edit out 3 or 4 right now and not really miss them.
I do have a lot of the shopper cards available on key. But I run uber-light on my keys and shifting cards from one pocket to another doesn't really help me gain anything. Also, with the key-ring versions, I've shared them with my S.O. so we can keep all our groceries and loyalty points together so they add up faster for household items or discounted gas, etc...
The problem with leaving a card like Zip Card at home is I'm inevitably going to be somewhere that's not home and need a Zip Car.
The problem is that Coin doesn't really solve this. It only encodes credit cards; most of the other cards either don't have mag stripes or require other information on the cards than just what's on the mag stripe.
Soon to be one.
Also, I was a user of both Belly and Level Up for awhile. But the merchants around here have been finicky with the services and some of the shops I frequent stopped using them.
EDIT: I should add that the main grocery store I shop at, you scan your card when you enter and are given a wand to checkout your groceries as you add them to the bag.
Though because of the size I keep mine in my front pocket, also handy as I believe it lessens the chance of having it pick-pocketed.
Also, I could elaborate more on why certain cards need to be with me, but I thought things like Costo & Zip Car were pretty obvious.
So the list of home cards:
* MTA Metro Card for when I'm in NYC.
* USA Cycling license for racing (they have an app now that I can use when I show up at races)
* Best Buy Rewards card (I know, I know....but they can look up by my email)
* Several complimentary coffee cards for Peet's coffee (Yeup, they are useless to me at home, but I got tired of carrying them around)
* Borders Reward card (ooops, looks like I haven't cleaned out my home stack in awhile)
* Amtrak rewards card (just need the number and website has this remembered)
* Local Library card (they can use my driver's license, but I can't use the self checkout, which is OK becasue the line isn't ever long and I don't use often enough)
* Library Card for the bigger city by me
* NSSA Press Credentials (only needed when attending certain sporting events - I grab this one as necessary)
* APIS Press Credentials (same as above)
* Bike Club Membership card (provides discounts at local stores, but they know me and I don't need it anymore)
* Panera card (I think I needed this at one time to access Wi-Fi or something)
* Card for my season ski tune & discount (though customized, I think they just look me up in the computer or remember my face)
* Season pass card to get into a apre-ski venue for free
* AMC Entertainment gift card (I go to the movies once/year, and everytime I forget to bring this thing)
* Safeway Card (only useful when I'm on the West Coast grocery shopping. I've since learned to use my Brother's phone number)
* EFTA racing license for mountain bike race series around here in the summer time.
* NEMBA Membership card (mountain bike related)
* Gift Card to another coffee shop
* Home Depot Gift card (exact credit card shape and size)
So, as you can see, I've optimized a good chunk out of my wallet , but it's not all the way there. Though a couple of my cards "could go" there's still about 12 or 13 essential cards I must carry with me.
I do have all of those cards scanned and stored in dropbox with 1password, but I don't have good 3g coverage so I carry them just in case.
I carry my fat wallet in a fanny pack. Not very elegant, but incredibly practical.
I'd love to have one with a classy finish and that would block NFC signals from leaking.
I ended up ditching all but essential cards and got down to five. One debit, credit, health insurance, license, and AAA.
Eurpean here. I was shocked to learn many USAian men keep their wallet in the back pocket. How do you sit on that?
What happens is you grow a dent in your butt, and get a lopsided spine. Yay!
Thus my billfold must go in one of my rear pockets.
The keys and money clip are distinct enough that I have no problem pulling out the right thing. And the keys are not going to damage the money clip like they would damage the phone.
Also, with the fitted slacks it's harder reach past the keys to the money clip or vice versa.
Often you will spot them with a month's worth of paper receipts crammed inside so the poor wallet is about to burst.
It is just conventionally where a man's wallet goes in America--One of those things where you don't apply common sense because it's just "how it is" and you've never really thought about it.
Unlike the upper pockets, those extra two are in an area which you don't squeeze when sitting.
I remember before I even had a cell phone myself and people in general still put their wallets in the back right, and it was cool to have a chain attached to it and hooked to your front right belt loop. I'd use my front pockets for all sorts of random crap, but I think I always had my keys in my front right. I've been really good about virtually never having lost a key in my life. I used to carry a pocket watch in my left.
Now I am faced with a pocket dilemma. I carry one phone for data and a 5s that I am using with a SIM (connected via pdanet/foxfi hotspot). So the two phones are taking up both front pockets! I'm currently either putting my keys in my jacket or in my back left pocket, which can potentially be quite uncomfortable to sit on. Would be cool if there was an easy way to flatten keys like a wallet.
http://www.ridgewallet.com/ http://www.kickstarter.com/projects/124039987/the-bridge-fro...
I think I'll be able to get down to about 8 essentials, and hope I don't forget the others when needed.
http://www.kickstarter.com/projects/markabramson/thinfolio-t...
It's paper thin, but strong enough that it hasn't fallen apart after years of use. It only has 6 pockets though, so it's not going to separate all of your cards.
With credit cards, unless there was a unique image on it then you'd often be able to guess from the number what the other card details should look like.
that's not true at all; have you been outside of any major city in america?
I've stayed in hundrends of small cities, from Ogalala, NE to Ozona, TX and Oatman, AZ, and used my credit cards for all kinds of purchases, from Kroger and CVS, to outlet stores, gas, local shops, small eateries, fast food places, restaurants etc.
Never had a vendor inprint my card.
Agree, SUPER clever idea. I'm wondering how this would work to make purchases _online_. I know, I know. I'd use my real card. But it strikes me as ironic that the big idea for this digital card is that I don't have to carry my 'analog' cards around. Unless I want to make a digital purchase. Then I need my analog card.
Which is why the poster above is warning about this; if there will be merchants out there who won't accept it, it's pretty much DOA as you can't replace all the cards in your wallet with it.
With that said, they require verification of the signature on the back of the card with the one on the receipt / screen.
In the event that the card is not signed, you are then allowed to require identification and the card must be signed by the customer before it is used.
Most credit card companies prohibit the "See ID" that some people put on their cards in place a of a signature.
But writing "See ID" on the back of the card and then using a completely different signature on the receipt is not acceptable as far as I know.
It's all very silly anyway given that online credit card transactions almost never require a signature.
Quite honestly though, once a thief has access to your card, you have other problems. If they're close enough to see it, they're likely close enough to duplicate it and leave you the card with you ever knowing.
If the signature is that concerning, then use one signature consistently for your credit card transactions that's unlike the one you use for anything else.
If you don't like that option, then you probably shouldn't be using credit cards currently offered.
Now, this is all very hypothetical for many reasons, but generally it's my practice to follow cardmember agreements that I am, after all, agreeing to follow.
They're very hard to clone (I won't say impossible, but attacks against EMV have not generally been of this nature) and the transaction records at both ends will tell you whether the actual, real card was there.
The liability is more clear-cut as a result. If the customer claims the charge was unauthorised, that's between the bank and the customer.
--edit-- of course with EMV cards Coin would no longer be possible or relevant. Neat product, only useful in a magnetic-stripe world, which is at least a decade behind the curve now.
Theoretically with EMV you could put all your credit-cards on one chip and the terminal will either choose a supported default or present you a list, but that would require cross-bank cooperation, never going to happen.
--edit-- and did you think us Europeans just rolled it out for shits and giggles?
Meaning shifted entirely to the consumer?
Under law in much of Europe, the consumer is not under much risk. In the UK (for example) the credit card provider is legally a party to the debt and has a responsibility to refund the consumer on demand if the consumer is willing to state (in a legally binding way) that the transaction was not authorised by them. Debit cards are governed by different rules that amount to much the same, though the legal protections are weaker.
There's a cap of EUR 150 consumer liability for lost&stolen (physically) cards up until you notify the bank; zero liability for lost&stolen cards after the time of notification, and zero liability for any fraudulent transactions if your card isn't lost or stolen.
Only UK law (and MC/Visa rules for UK) is a bit different, but another poster describes them below.
In reality, much of your money is going to huge companies that supply their products, like Sysco.
And the EMV transition has been going on behind the scenes in the US for years too, so expect to start getting cards with a chip as your cards expire over the next couple of years.
It is extremely common.
Mainly because it would make my trips to Europe a lot easier, where many systems I've encountered won't work on some non-EMV cards.
[0] Technically: chip-and-signature rather then chip-and-pin. Also, you have to ask for the EMV but they're super friendly about it.
I had one chip & sig card that didn't work except in like one restaurant I went to. A couple of places I could use any regular credit card though. Ended up having to go to ATMs and carry cash, which is so uncommon that people think you're a drug dealer. :D
Flat 2% cashback cards are great. Rotating 5% category cards a great. Big signup bonuses are great.
I have a Chase British Air card I opened with a 100,000 mile bonus, plus a companion pass once a certain spending level was reached. Long story shorter, we opened two (one for me, one for my wife). Pooled the miles together. We have 220k miles and a companion pass. We're using this for 2 first class tickets from SFO to Europe in the spring. That is, literally, $25,000 in airfare.
Oh, and it's chip + sig :)
tl;dr Often annual fees are very worth it. And also often, an issuer will waive them in all or part.
If they get some sense and implement this on their lower-end charge cards, I'd be a pig in shit. I try to have this be the only card I use.
Chip-and-sig is almost useless.
Also, I'm a stingy bastard with the fabled Unicorn Card (Zync) that's no longer offered. I think any changes would mean a forced upgrade. I'm worried about a forced upgrade when the card expires too.
Surprised to hear it's next to useless, but not really surprising that it's less useful.
There are a handful of credit unions that issue dual C&S/C&P cards. It's a little harder to get one than an ordinary card, but probably worth it if you're traveling abroad. (I got one from Andrews.)
Shopping for a new bank, for many reasons.
Note that a lot of places wouldn't accept credit cards in the first place (swipe or not), only debit cards.
I actually called Visa about it and they told me that any vendor accepting Visa transactions is required by their contract with Visa to accept swipe transactions. She said it was there because the US was still rolling out chip and pin cards.
It can actually be a bit tricky to use my company card to buy lunch at restaurants sometimes because "there's no chip".
Their FAQ says future versions of Coin will support EMV, but I'm not familiar enough with the hardware to know how difficult that is.
Would be good for those stupid loyalty/membership cards I guess, if you are good with explaining what the hell this weird card looking thing is and why it will work like the normal cards every single damn time you use it.
In theory, you could slam mastercard, visa, amex, credit, debit, whatever else you want, all on the one chip. Depending on the exact card and terminal implementation a transaction would either use the default application or get an on-screen display asking you which you would like to use. But you'd have to get the banks to load the app on there as there are sensitive keys involved.
That's not exactly the same as Coin - you couldn't pre-select which card to use in which situation, and you couldn't load them yourself. I suppose in theory you could have multiple EMV chips on a card like Coin and have a circuit-switching arrangement of some sort. There would need to be a way to embed them there and that would put a limit on things...
--edit-- about the stupid loyalty card things - in Australia I noticed most of them had started working on barcodes, and people had smartphone apps that gave them a menu and displayed the right code, pretty cool.
One, you may not be able to download the card app from one card and upload it to another. My GlobalCard fu is not well honed enough to tell you what ADPU you'd need to invoke in order to try, but it goes against the goals of the product to allow this anyway.
Two, if a credit card company provides you with an EMV card, it's got a private key loaded into the card, and may have even originally been generated on the card. It is outright not allowed under any circumstance to download that private key and upload it to another chip; that would be a major hole in the scheme.
Three, not all banks use the same crypto. Even if they all agreed to a single kind of crypto operation, different EMV chips have different performance characteristics when carrying out crypto operations. If the bank can't control the actual EMV chip any more, then they cannot control elements of their payments processing (e.g. session closure within a certain time frame). This problem is the easiest to solve of these three problems.
So, unless the banks get on board with allowing their apps and their keys to be provisioned on an already existing card, or provide some kind of proxy mechanism whereby an EMV card can delegate another card to act on its behalf (and imagine the security concerns with that) then this isn't going to happen.
I don't see the benefit to the banks for doing this. You're far more likely to see paypal succeeding in turning your phone into your wallet (and they are doing it) then you are to see Visa or MC allowing you to link multiple EMV cards into one.
2) Yup, and combined with '1' this means that you'd have to get the banks to do it
3) You'd have to get some more cross-scheme standards about the crypto capabilities sorted out. I estimate we could have all the schemes in agreement by... 2025? Or is that optimistic?
The benefit would only be to the consumer, in the same way that Coin may benefit people, however any method of doing this with EMV would present some sort of extra attack surface and that's generally Bad(TM).
Want to add some loyalty cards on the same chip? Sure!
Want to combine two different MC products? Sure!
Want to have Mastercard together with Visa or some local card network that we dislike? Nope, we don't want that so we'll not allow you to issue such cards.
Share branding? Are you CRAZY???
1. Chip cards do make this almost completely irrelevant
2. Supporting EMV is going to be tricky, because cloning those cards is also tricky (skimmers have spent hundreds of thousands on it and haven't figured it out).
3. Most membership cards, even ones that have magnetic stripes on them, actually use the barcodes on the card. Safeway, CostCo, Shoppers, etc. all have mag stripes, but they all use the barcodes. The Coin won't help you with a single one of them.
4. If, as a cashier, someone handed me a Coin and said 'It's okay, it's a Visa', I would say 'no'. No signature, no card number, no anything. There's no difference from my perspective between a person putting their Visa onto the Coin and a person putting someone else's Visa onto the coin, and I'm not going to start accepting obviously cloned cards regardless of who's holding it.
"Swipe" cards have been phased out years ago - you'd have to try hard to find a bank which will still issue one.
Specifically because you can no longer find ATMs which rely solely on the magstripe. Some banks have biometric fingerprint readers (where you put in your hand and it reads multiple fingerprints at the same time) in addition to the PIN code of the debit/credit card, and sometimes additional passwords.
My bank does not rely on biometrics, but in order to do any transactions, I have to enter a code generated by the bank which consists of three strings, which are prompted one at a time, displayed on screen mixed with other random and unrelated strings, so that someone peeking over my shoulder would not be able to match the button with what's on screen and finally, before the transaction is complete, the account's password. And that's with a chip.
The portable readers you can find everywhere still have magstripe readers in addition to the chip reader and will refuse to read the magnetic strip if the card contains a chip.
Those portable readers use either a 3g connection or standard dialup.
As for the physical "imprints", this is something that 30-somethings like me can barely remember.
Also related: there are no bills which can't be paid online. All banks accept them, unless specified otherwise (usually there are restriction after the expiry date). If you get a bill by mail (instead of email), you can just type the barcode. Or scan it, if you have a reader or a mobile phone with the bank's app.
The concept of getting bills by mail, and then mailing back cheques, as found in the US, is completely alien.
You hit on something though; in the U.S. there are tens of thousands of ATM machines all over. They all accept PIN numbers, and I "believe" magnetic-strip as well (not sure if they're doing fancy stuff too with built-in chips or not). It's the standard that everyone uses; debit card and credit cards alike.
To change that to support different tech, you'd have to upgrade all of the ATM machines, all of the credit cards, and all of the backend tech. That's a lot of coordination between banks/credit-card companies. On top of that you have POS systems in stores which are all magnetic-strip based as well, accepting PINs and/or signatures.
Any sort of switch would have to be phased-in over years and require a lot of buy-in. Unless retailers, banks, ATM providers, and credit card companies have a good business case to do so, they probably won't.
I'd imagine it would be easier for some other type of technology which displaces cards entirely, like phone-based payments, would eventually replace all of this. An idea like Coin augments the current "archaic" system and has the potential to take off. But outside of the U.S. it sounds like it won't work without modification.
I think it took at least 5 years.
So yeah, non-trivial. And if (as it sounds like) the banks in the US have managed to offload most of their fraud problems to everyone else involved in the transaction, then there's probably little incentive.
"Chip and PIN was trialled in Northampton, England from May 2003, and as a result was rolled out nationwide in the United Kingdom in 2004 with advertisements in the press and national television touting the "Safety in Numbers" slogan. During the first stages of deployment, if a fraudulent magnetic swipe card transaction was deemed to have occurred, the retailer was refunded by the issuing bank, as was the case prior to the introduction of Chip and PIN. On January 1, 2005, the liability for such transactions was shifted to the retailer;"
Also note this bbc article[1] suggesting a Feb 2006 deadline for not accepting signatures from cards that were chip and pin enabled.
I would guess the banks had been rolling out EMV capable ATMs well before 2003. Retail level EMV may have taken two years from trial to liability swith. Infrastructure changes would have pre-dated that by years.
I know EMV cards had been distributed to customers since the late 90s because I used to use mine for testing while I developed the software I wrote that ran several of the retailer systems in that Northampton trial :)
From a consumer perspective, it was virtually painless. The biggest change is that credit card transactions now require a PIN (assuming a chip card and chip-enabled POS).
The lack of chip card support in Coin effectively makes it a US only product at this point as most of the card-heavy countries have moved past mag swipe (or, are in the process).
Also, as other people have pointed out, the US is moving to chip cards in a couple of years (2015). So this product already has a very short shelf-life.
Once a quarter of cards sport chips and a quarter of machines support chips, it's just a question of issuing new chip cards when old cards come due (or get lost/stolen).
The Chip and Pin machines have a channel to swipe. There are very few places where you hand over a card. For example, in the train stations, the machine to swipe a card is on the same side of the glass as the customer. The agent never handles your card.
So they might be more accepting of Coin (given that they don't see that it is different) than American businesses.
It's entirely possible that Coin may still be useless outside the US if most machines will reject your card's strip.
And it is coming to the US too, in some form or other: Pretty much all the major banks have committed to introduce it (though in some cases chip + signature) by mid 2015.
I'm not saying the US isn't behind the times, but where else has a singular rollout of tech like this been done on a US scale?
Of course you can. Countries outside the US did it city by city, bank by bank.
In fact, the US is in the process of a gradual rollout of EMV cards now - a mix of chip+pin and chip+signature cards. The aim for when to complete the transition varies by state, bank, and type of merchants, but most aim to be complete by mid 2015.
There was no big bang switchover anywhere that has already made the transition to my knowledge.
The banks did rolling releases of chip and pin cards as people were issued new cards over a period of years before the switch was complete. When the first people got chip and pin cards there were no locations where they could use the pin.
And in the UK at least, it took a couple of years before you had to use the pin even when faced with a chip+pin terminal - you could keep opting to sign for a long time.
Doing a singular rollout of tech like this is stupid and unnecessary.
It seemed like a completely unusable system for it's complete lack of any security.
(Particularly if you consider there are now live payment systems that use pretty much the same audio jack serial port hack as this one does to clone cards)
The fraud you're speaking of is not limited to this technology; anyone could find and use a credit card they found on the ground if the merchant did not verify it.
1) They require you to register this "coin" device 2) They require you to add some banking account details
Now, if you were to "clone" someone else's card without their permission, the trail would lead directly to you...
I don't think so, there's also no way for anyone to trace the transaction back to them
Thankfully, in Canada, everything is done via chips, so even with Visa purchases my card never leaves my hand (or at least, my sight). Restaurants bring the terminal to your table, they process everyone there, and then you're done. Sending your card away feels almost archaic now (and a bit patrician, which has its appeal).
See some of the following case studies by the FOS that support the fact that the customer is not always liable even if the PIN is used:
http://www.financial-ombudsman.org.uk/publications/ombudsman...
Other than that, here in Europe, customers are protected by law from having to take on the liability. Varies by country, but basically it's a case of "you're responsible to see that nobody else gets to take my money, that's why you're a bank numbnuts"
[edit: Oh, and all my debit/credit cards are now paywave/paypass enabled, and they are all from the big 4/5 banks]
The Coin page doesn't mention this at all; does it have this? If not, it sounds like a step backwards.
"Australia leads the world in contactless payments, which have grown from almost zero three years ago to more than 35 million transactions a month and now account for 60 per cent of all MasterCard and Visa credit card transactions, according to Westpac."
http://www.theland.com.au/news/agriculture/agribusiness/gene...
The whole time I was watching the video, I was thinking "Huh - who swipes their card any more?!"
As usual there are variations between implementations, but underneath it's all good-ol' EMV :)
So I doubt that these could be supported easily by Coin, it requires various keys that the banks do not allow to escape.
If Coin do manage to get talking to banks about allowing wired or wireless EMV apps to be loaded onto a customer Coin card then that would be awesome. I predict that layers of bureaucracy and brand-management will prevent this.
But good luck to 'em if they try!
Commonwealth Bank, the largest bank in Australia is very soon releasing native Android NFC support and NFC style "smart tags" that you stick to the back of your iPhone.
https://www.commbank.com.au/personal/online-banking/commbank...
This pretty much eliminates the need for any kind of "card aggregation". I wonder how quickly other countries will follow suite?
It's not about convenience, it's about security and reliability. That's the direction we need to take.
And it is about convenience - people are willing to accept the risk for the added convenience.
In Netherland, there's also one electronic payment system that does not require a PIN: the "chip knip" (chip wallet). You explicitly transfer an amount of money from your account to the chip (often about $20), and you can use that to pay. You still need to approve the payment by pressing a button on the machine, but if you lose it, you don't lose a lot.
And it probably works without a phone/internet connection, because the money is right there on the card and nothing needs to be verified on any server.
The cost of rolling out EMV was determined to be greater than the cost credit card companies paying for the increase in fraud and chargebacks out of pocket.
The first large chip and pin deployment was in France, in 1992. At the time, Eastern Europe was in economic chaos, and not really on the radar.
Credit cards are divided by payment scheme's. Banks just issue cards for 1 of the scheme's eg. Mastercard or VISA, ... don't think Mastercard. In this field I don't think Mastercard will want their competitor on the same card. Even technically it's not so easy to implement for a payment processor (I work for a payment processor).
btw, it sounds like you should have had a lawyer handling some of those chargebacks, particularly if you had captured the driver's license info. We started using a (cost conscious) lawyer to deal with every chargeback and our win rate went way up. And by "dealing with a chargeback" I mean forwarding along our response on his letterhead.
We actually had Amex _negotiate_ with us over a chargeback once. I had no idea this was even possible -- they actually said "So how about we'll agree to split the loss. We'll cover half, you guys cover half." I had no idea that was even an option.
I'm in the UK and this is not really my area, so you'd probably have a better chance of verifying that than me.
It's just like any cloned card - I can easily make a blank white card with a copy of my creditcard's magstripe, and technically it will work in a swipe POS-terminal, but any merchant is required to refuse such a card, and recommended to detain the card and me, if it's safe to do so, or call the cops.
If this becomes more widespread coin will have problems.
On the other side of it, I love the idea, and the only way to get merchants and card companies to begin changing their policies is for someone to be first through the door. This will not work for all situations at first, but if it proves popular it could easily sway these policies. Imagine some of the possibilities. Just as an example, imagine getting a pre-approved credit card offer in your email, then having the new, swipeable card instantly downloaded to this device after a few verification questions. Credit card companies that worked with Coin could gain an instant competitive advantage in the cut-throat credit card marketing business. This could also revolutionize the loyalty card business.
Typing in the last four on the coin completely bypasses this anti fraud measure since the last four will always match on the coin because the digits it displays come directly from the magnetic stripe data.
Cool product. I want it to work, but I fear it won't be widely accepted.
That said, if they were to license the visa and mastercard logos for it, that would probably be enough to get it accepted during most transactions by cashiers who aren't savvy or don't care.
If they want to book it as 'card present' transaction, then they have to follow the 'card present' guidelines - which, by coincidence, would require them to see the actual card, not just it's magstripe data in some fancy device.
Given your large average ticket, it makes sense to be extra paranoid and take an imprint (mostly to avoid scammers), but certainly doesn't apply to 99% of merchants.
I don't think this would be a roadblock for them. Unless, of course, Visa/MC/Amex finds some obscure legal clause (or technical way to detect the different card) to shut them down.
A more convenient way of handling credit cards is a useless idea to me. What we need is a safer and more reliable way to handle transactions. Preferably one that doesn't rely on politically motivated monopolists.
Thinking out loud here... could you make the use of the Coin card dependent on being within range of your bluetooth enabled cell phone. If the card knows that it is being swiped (not sure if it does)... then the in-range phone could know and send a msg to the CC company with the shared secret saying "yo, it's legit". Now a thief would have to steal both the phone and the card for it to work. I'm sure there are a million holes in this, but just putting it out there.
Similar concept could work regular CC's as well. CC company comes up with "card swiper 2.0!" and deploys them to merchants. I as a consumer get some incentive from the CC company to register my device with them. When my card get's swiped at a merchant... card swiper 2.0 tries to detect my device. If it sees it, great, lower chance of fraud. If it doesn't, give me a ring to see if I'm aware that my card was used or deny the charges. Might help the triage the sheer number of transactions out there for what's fraud and what isn't.
I have seen flat cards without numbers that would be impossible to imprint.
To me, this sounds like a big data play, except in this case the company is getting the user to cover the cost of acquisition. I imagine the actual cost of production on a card like this being well < $20 shipped (disclosure: I've been involved in shipping and starting up several physical products).
So now, I have something that collects and unifies data across multiple purchase vectors, sending that back to a single source. In other words, I've paid for the privilege of helping another company get the same sort of insight that mint.com was building, except that I'm also including loyalty data.
Colour me out.
No, Coin, I'm not going to store all of my credit and debit cards in a single spot on the Internet.
Your app has to work without Internet, or it's a security risk.
Not only this but they're entire FAQ is vague and doesn't offer any concrete answers whatsoever. It's a half ass job.
Surprised (sort of) that this is a YC company with all the vetting, mentoring, perfecting and whatever else happens there. They have a lot of problems and a lot of holes.
Payments are HARD but this doesn't make them any easier. Quite the contrary.
I really think hard about whether these services are really worth forking over that much of my personal data, and as cool as this product is I don't think it's worth it. If vast amounts of my personal data weren't at stake I'd pre-order for sure :(
Their Echo card is exactly the same idea, with some minor variation in implementation. It has not yet launched.
As far as the concerns voiced here (accidental button presses, etc.), Chris Bartenstein, a Protean co-founder, has addressed some of that in the comments on this TechCrunch story: http://techcrunch.com/2012/08/02/the-protean-echo-reduces-al...
http://www.slideshare.net/balanon1/code-michigan-without-com...
Its not always the first product to ship that wins, its the best product that ships. I've seen the product evolve and the echo card is worth the wait.
I typically hand out a Google Voice # as a sort of DNS for phone calls so that I can change my device number at will.
Wouldn't this allow me to swap out credit cards in a pinch without having to carry new plastic? Or, as you suggest, if I lose my Coin do I have to get all new cards?
It's not obvious how to prevent that without affecting the UX.
The old method requires use of credit card blanks, a duplicating device, and the card itself doesn't look like the card when presented in person. In this case, as someone mentioned, Coin doesn't display the card #s on the front, so it's like a Card Not Present (CNP) transaction, but needs to be treated as if it was.
This doesn't bring anything new to the card skimming operation, but it simplifies, optimizes, and can in some ways facilitate it. They need some sort of ideally biometric authentication and/or a server that identifies when two Coin devices carry the same cards on it to avoid this sort of fraudulent use.
This device defeats all these human security measures by letting me use a startup bling device to try up to 8 cards at once without looking suspicious at all. "Declined? shit, my newfangled e-bling card must have messed up - try it again!" (while silently changing cards using the button). "No name on the card? Card isn't signed? You want my ID? But this is the hottest new toy! Promise it's fine!"
- Centralized location / evidence. A stash of blank cards and an ID printer have to go somewhere, and look suspicious to start with. The gear to skim cards and write them onto existing magstripe cards can be stored in a small space or on one's person and thrown away quickly; there's no centralized location. I believe hotel keycards are used because of their availiability. There was a sensationalized national news piece a few years ago about pimps giving women hotel keycards with credit cards written on them to buy gas with.
- Start-up cost. A couple thousand $$ in an ID printer is more than $0; that's what would divide street-level carders from professionals who probably wouldn't be passing overwritten cards at retail anyway.
So it sounds like if the name doesn't match, it won't work (you have to take a picture of the front).
Edit: And it's on the magnetic data, too.
Currently, one assumes you can take a picture of any card and store it for visual purposes. There's zero explanation of how they authenticate a physical card (photo) with the swipe data.
Online they make you provide information that is not written on it. With this you could easily copy a card and buy anything later on that day.
This thing should be outlawed
Dutch electronic payment (online or otherwise) always relies on "something you have" + "something you know" (which is secret and not shared with anyone ever). It's not airtight, but it's a lot safer than relying just on "something that can be stolen".
I'm still constantly appalled and amazed at US/international online payments relying on something as outdated and backwards as just a string of numbers and some other public information.
You actually increase the chances of fraud/loss/theft/errors with Coin.
It creates more problems than it solves (which is unfortunate, since it does have the "cool" factor going for it) That only goes so far.
The product/fit questions have already been asked, but there's still this: Why is Coin taking pre-orders several months in advance just to raise $50k? I can't help but wonder why a YC company wouldn't just raise the needed $50k from investors?
If this is an attempt to test the market, are you sure that a crowdfunding approach is the best image for a financial company? I want any company dealing with my financial data to be rock solid and reliable, and crowdfunding is the exact opposite of that.
Also, why aren't you collecting shipping addresses? I read your answer in the FAQ, but that makes me twice as concerned. You say, "A lot can happen between now and Summer 2014. For example, you could move. To reduce confusion, we’ll get those details from you once we get a little closer to getting you your Coin."
This is a problem for two reasons: (1) you are emphasizing that the ship date is far in the future, and (2) it comes across as though Coin is run by young founders who move around a lot and don't see value in long term planning. That's the wrong mindset for a company handling financial data.
See the FAQ, It doesn't. It's designed to be standalone with only periodic checkins (once a day probably) with the phone to make sure you still have the card.
Q. Can someone accidentally change which card is selected on my Coin?
A. We’ve designed the button to toggle cards in a way that makes it difficult to trigger a "press" unintentionally. Dropping a Coin, holding a Coin, sitting on a Coin, or putting the Coin in a check presenter at a restaurant will not inadvertently toggle the card that is selected.
Seriously though, they did a fantastic job with the overall experience of the landing page/video. The product, however, is not that great.
I carried my wallet in my back pocket from 16yrs of age to 34 and always ended up with broken or bent cards. After taking a cruise outside of the US, I started carrying my wallet in my front pocket for security purposes and started researching minimalist wallets to reduce the bulk. I've backed 2 of those on kickstarter and am eying a 3rd, because the first two don't allow me to acces my cards quickly enough when I have more than 2 or 3.
For me, this solves multiple problems: it makes the minimalist wallets out there that much for functional because now I only need my coin card, my ID, my insurance card and perhaps a backup credit card for any merchants I run into that won't take the coin. 4 cards down from 9, not including any rewards cards which could push it up to 16 easily sounds like a good deal to me. It also keeps me from forgetting lesser used rewards cards and credit cards at home because they're either in the coin already or in the iPhone app and can be switched into the coin when needed.
So much so that I don't carry them, and it costs me money.
The wallet is: photo ID, transit card, and 1 or 2 ccs, depending on if I need my biz cc that day.
Wallets are a pain - though it must be said less so than, keys or phones. All of which dig into me an inopportune moments (usually going around corners on the bike) get dropped, or left on the counter... I'm probably just much to forgetful and clumsy for modern life, but all this /stuff/ is constantly annoying.
I carry Discover, MC (as backup) a bank debit for Mom's care, business debit, DL, Work ID card, medical, dental, and a couple paper cards like voter registration. No vendor loyalty cards, I give 'em my phone number and if that's not good enough, they can't track my purchases. Business should recognize ME when I walk in. Not the other way around.
Q. Can a Coin be used to skim cards?
A. No. You can only add cards that you own to your Coin.
Ummmm... I hate to be pedantic [1], but the question is using the "is it possible" meaning of "can", but the answer seems to be using the "am I allowed to" meaning. There's a line in the previous question about how "As an additional safeguard, the Coin app will only allow you to add cards you own," but no detail on the mechanism of this magical authentication process.[1] Who am I kidding? I love being pedantic.
Back in 2009, I was (apparently) the first person to use the chip+pin machine in one of the biggest bookstores in Toronto - the cashiers got excited and all gathered round to watch. It was a little bit bizarre.
I eventually just gave up and got my cards reissued as Chip+PIN.
I only understood that after a week and maybe ten or so places had told me "your card doesn't work", when some hotel tenant called her daughter to translate things, and she knew about chip and pin and was excited to see how it worked.
I'm pretty sure all the other places just saw some message they didn't really understand, and just thought "the card doesn't work", when in fact they probably just had a pad somewhere that was waiting for my input.
Just before that, we had stayed in Taiwan and used the same card pretty much everywhere with absolutely no problem.
It's been more of a problem in places in Thailand and Singapore where they're not really equipped to hand over the card terminal and sometimes I have to go behind the desk or something.
Then a few hotels and ryokans mostly around Nagano and Toyama. The 7/11 ATMs worked fine though (but the card didn't work to pay directly, it did at Lawson though, IIRC) so we just used cash everywhere, but I liked to keep trying to use the card, as I was really not sure what was happening.
It's in a small hotel in Obama that I finally understood what was happening, after the woman first asked me to "write my secret code" on a piece of paper (she didn't know the keypad was attached to a long cord and that she was supposed to let me enter the PIN myself, her daughter figured - or knew - that).
I don't really remember but I think we just didn't have many issues afterwards, once in the larger cities of the Kansai.
It was kind of a pain to have to use cash so much because my card had a rather low limit on cash withdrawal at foreign ATMs (of course, my other card had been mailed by mistake by my bank to my former place just before I left). I just didn't expect at all that it would be so difficult in Japan.
In a perfect world...
Where's that?
This also stops the frequently problem mentioned about a waiter changing your card because you'd need to validate the purchase via pin on a POS terminal.
The downside is that you're vulnerable to shoulder surfing and people stealing your pin (at which point they really have the keys to the kingdom), but given that signature checks are rarely that stringent in the US I think it's a moot point.
Magstripes still work, but many stores in the UK have stopped accepting it as a payment method if the card fails.
I'm surprised to see no mention of NFC in this thing, that would work in Europe in plenty of stores.
- less liability for the merchant
- either the transaction was explicitly approved or wasn't
- sense of security for the user
- card never leaves you
- if you ever lose the card it doesn't matter
- there's no reason to sign anymore (less opportunities for fraud)
I can't quite put my finger on it but it does change the dynamic between wait staff & consumers when you're out dining - it just makes things simpler & you have to wait a lot less when you decide to leave.EDIT: It seems as if it's different at restaurants. Here, we give the card to the waiter/waitress and they return with a receipt to sign.
http://www.enterpriseefficiency.com/author.asp?section_id=10...
It won't be long before most swipe terminals are themselves augmented with wireless transceivers, making the "CoinCard" a redundant middleman-device. That is, your phone could just send archived magstripe details, after your onscreen-app confirmation of payment-intent, to the retailer's terminal.
Coin's real strategy may be for that world - the hardware will fall away like a first-stage-rocket at some point... even faster, say, than Netflix moved from DVDs-through-mail to pure-network-delivery.
If it is because of the "tradition problem", it's not much better than Square Wallet either: In more than one place I've been to the cashier was supposed to manually enter the last four digits of CC# manually for the transaction to get through. You'll have to carry a backup card with either Square or Coin.
I like the vision of completely ditching the credit card far better, and the marginal compatibility benefit does not seem good enough for this to get anywhere in its current shape.
Of course, things can change.
(BTW, wasn't Google doing the same thing with a physical card for Google Wallet and ended up abandoning it?)
They abandoned it.
http://www.kickstarter.com/projects/loop/pay-with-loop
Personally, I like the idea of using my phone over the coin thingy.
Also, I'm curious about how sturdy this thing is. Maybe it's my wallet or maybe I just shop too much, but I tend to wear out my debit card really quickly (< 1 year).
For what it's worth, my cards last have lasted indefinitely in my wallet.
I can't see the banks being happy about customers cloning their own cards. In fact, it will probably be a convenient excuse for them to absolve themselves of all liability in the case of loss, theft, or misuse. Some, if they found out, might pitch a fit and close the account.
This also is going to pose a lot of problems when used with non-domestic cards, as they point out in their FAQ. It's possible to use an EMV-based card with just the magstripe, but it's a pain in the butt and the bank may well be aware that all your meatspace transactions are not using the EMV-chip. They may assume that your card is broken or (quite correctly) cloned and block it. A call from the fraud department may well lead to a fit being pitched.
From wikipedia: "Magnetic stripe cloning can be detected by the implementation of magnetic card reader heads and firmware that can read a signature of magnetic noise permanently embedded in all magnetic stripes during the card production process." [0] Oops, now your card is blocked.
Retailers might also get skittish if they figure out this isn't actual bank-issued plastic. They may well refuse it because of the risk of fraud. I would. I really wouldn't want to be running someone's cloned card, even if the cardholder was the one that did the cloning. In fact, it might jeopardize a retailer's merchant account if the acquiring bank found out the merchant were running cloned cards!
The best way to counter a bulky wallet is to not add bulk in the first place. How many credit cards and debit cards does one need to carry on a daily basis? I carry maybe two or three cards, some ID, my Oyster card, and a Costa rewards card that I use daily. I also have a backup wallet that contains a second set of cards in case I lose the first. The bulk of my wallet is receipts that accumulate, but even when I carried way more my life wasn't burdened by a whalelike wallet.
It'd also be a pain in the butt to use this with some rewards cards. For example, my Costa rewards card is swiped at the same time as I'm paying. Would I really want to fumble through pressing a button to find the right rewards card, give that to the cashier, have it handed back so I can fumble through pressing buttons again so I can pay? Certainly not, and even less so the impatient people in line behind me.
Sorry to promulgate the Hater News stereotype, but it's just too easy to poke holes in this idea. It has superficial appeal but I really wouldn't pay $100 for so many potential problems, especially as it would only make my wallet a few mm thinner.
I was looking at my wallet the other day, and wondering why i can't slim it down even further to carry one digital card instead of multiple. i even thought it would make a good startup. and here we are.
the only drawback in my mind's eye regarding coin as a business is that there will be no reason to have "swipes" anymore if you can just scan a smartphone, as with the starbucks card.
however, the widespread use of scan technology is years away, whereas the swipe is ubiquitous now.
ergo, IMHO, coin will be a success if they can execute on the product.
Yay? In any case, it does seem odd to build a business around something that is virtually guaranteed to be extinct in a few years time.
I'm not being a hater, this is just an occurrence where this might not work well. I still think it's an awesome idea though, and I'd like to get one.
It's probably like a gas station authorizes your card for a certain amount before pumping, but then actually charges the specific amount you pumped at the end.
In all seriousness, most bars hold a CC and ID for a tab.
Add another item to the list of problems.
EDIT: What the person above me said =)
EDIT: More details from the FAQ:
Q. Can someone accidentally change which card is selected on my Coin?
A. We’ve designed the button to toggle cards in a way that makes it difficult to trigger a "press" unintentionally. Dropping a Coin, holding a Coin, sitting on a Coin, or putting the Coin in a check presenter at a restaurant will not inadvertently toggle the card that is selected.
I can imagine multiple ways they can handle this, all of them fairly trivial.
Now I can keep as many rewards cards as I want, without having to stuff my wallet full of junk I don't need 99% of the time.
The money I save from rewards cards I wouldn't normally carry would probably pay for the price of a Coin, even if I don't use it for any of my credit or debit cards.
If I had this I could see myself using this for rewards cards only. But then again, I don't have a lot of rewards cards that are fattening up my wallet.
Looking in my wallet to pick the silver card on the middle right and the brown card on the top left is so much easier. People can pick out location and color far faster because of our evolutionary history.
"I go to pay at the checkout counter. Oh wait! I suddenly remember I have a rewards card here. Good thing I carry it in my wallet along with the other 10 rewards cards I have...shoot, which pocket did I put it in? Maybe it's here? no wait...oh shoot, now I have to take all the cards out. I know it's a red card, but so is my Target and Walgreens card. Now all my cards are out all over the place. People behind me in line are getting pissed off with how much time I'm taking. Now all I have to do is collect all my cards from the counter, reorder them, and put them back in my wallet. I wish I just had one card in my pocket that could work for everything."
With Coin, you have to find the cards serially, no matter how much lead time you have.
I'm not sure how every corporate card works, but I have accidentally made purchases on a Corporate Amex before and it's not a problem. I just pay that part off myself and don't mark it to be expensed. Don't see this as a problem.
If it's not, then we're assuming a shared account, which increases the risk exposure for normal loss, theft, etc. by the number of people using that account. Can you afford to have your organization's payment ability severely hampered because a field rep got mugged?
Many Amex cards look very similar, for instance. I and others I know have accidentally handed the corporate amex over instead of the personal one. I've also had the case where, a company (in this particular case, a rental car company) had saved my corporate card, and automatically billed that when I went for a personal purchased.
> I wonder how this would fare in an ATM. What happens if the ATM accidentally presses the card selection button?
This might be solvable by making it a capacitance-based button.
Just saying...
What's your point? If you're not allowed to clone your business credit card, and you do, of course there will be disciplinary action. That would be true if you used this "coin" or any other method to create the clone.
RED FLAGS:
* Coin is in the process of earning a PCI certification. This should have been done before launch. Also, what level? * Coin uses 128/256bit for security but HOW and WHERE? * Coin essentially skims cards (through the reader) to playback for terminals. I don't see how they can say with a straight face that it is less susceptible to the same techniques. * Adding what are supposed to be funny Q&As to a FAQ trivializes what are supposed to be important questions for people thinking about using this. * I understand the love of "the cloud" but I wish people would also consider scenarios for a disconnected model. These are solutions that do not necessarily require a full time connection.
I could see using this for pre-paid gift cards but not for my actual credit cards.
And then really, while I'm dreaming....I just want my phone or an app on my phone to deal with paying because carrying around a card just feels so 2000s.
This is a slick implementation, though.
I'm also more worried about actual merchants refusing to take something like this.
Or, maybe only allow switching within a foot or two of your smartphone.
That would eliminate the concern people have about where the waiter accidentally pushes the button and switches the active card.
Q. Does Coin support chip and pin (EMV)?
A. Coin is currently designed for the U.S. market and does not support chip and pin (EMV), however, future generations of the device will include EMV.
Heck, they're running a kickstarter for funding, while even dreaming about being a card issuer would require to start with posting multimillion security deposits.
Unfortunately cross-bank and cross-scheme cooperation has never been there to the extent that this has been possible so far.
I see it on every terminal I use here in France, so it seems to somewhat work already here.
I've been out of the payments game a few years now (going back in on Monday though) but in EMV speak an 'application' is usually something like Visa, or Mastercard or something along those lines. Some cards I looked at in the past had a few on them for local schemes, for instance we had "Switch" cards here in the UK that were the equivalent of "Maestro" in Europe, but were different enough that a lot of UK debit cards had both applications on them.
If "pay in three installments" is a sort-of credit facility provided by your card issuer(?) then I suppose it could be coded as an on-card application. In fact if you wanted to give your customers that choice on every single transaction I can't think of a better way.
Would get damn annoying...
You would need some cooperation from the card issuer to clone the card, or some sophisticated technical equipment to open up the chip and read it.
In the EMV process the private key should be unique to the card (if you make a replacement card with the same number, it's a different key); the private key shouldn't exist anywhere outside the chip after the card is made; and there aren't supposed to be any ways to read the key. Well, cutting the chip and scanning with a electron microscope works, but it's impractical.
I'm not saying that there aren't any bugs in the implementation, but I'm quite sure that there are no known bugs that allow simply to get the key; even full control of the HSM which holds the bank's private key should allow you only to make/sign new fake cards, but not recreate an existing card.
> Magnetic stripe cloning can be detected by the implementation of magnetic card reader heads and firmware that can read a signature of magnetic noise permanently embedded in all magnetic stripes during the card production process. This signature can be used in conjunction with common two factor authentication schemes utilized in ATM, debit/retail point-of-sale and prepaid card applications. -- http://en.wikipedia.org/wiki/Magnetic_stripe_card
It might work like a bunch of tiny electromagnets appropriately arranged on the back of the card, like pixels on your screen. These electromagnets can probably be polarized in a particular way to match the original card.
The TV show White Collar's pilot has a cool depiction of Neil Caffrey copying a guard's magnetic stripe badge using a tape deck by recording it to tape, then playing it back through the record (write) head on the other side of the tape player while he slid a new card through. It would be hard to get the timing right, but there's no reason this shouldn't work.
It's incredibly primitive technology, as is simple RFID - the cloning process isn't much more difficult. Fortunately my university uses HID iCLASS contactless smart cards - there is actually a cryptographic handshake between the reader and my student ID which is resistant to replay attacks. If implemented correctly, it's impossible to copy the electronic access control portion of a student ID without the university's private keys. (The same access control infrastructure that's on my dorm's main entrance also guards healthcare information, nuclear and virology labs, etc. so that makes sense.)
Best I can find so far is this website which kind of describes what is going on:
This is more of the way it works:
This was a crude first pass, which is evident from the fact that the shim is a sawed off kitchen knife. In principle if you make the electromagnets smaller you could fit three. Make them adequately decoupled and you're away.
If these guys have an alternative approach I would be interested to read about it, but as far as I can tell they don't describe the method anywhere.
As a consumer I'd love to have something like this but it will never fly. Stores will lose liability protection since there is no security. Unless they partner with card issues to provide some kind of secure card verification it will end up being banned by merchant agreements. No store in their right mind would accept it.
Not to mention the fact that now one service has all of my cards and their information? Coin better know what they're getting into. I'd prefer the hassle of many sites than one with everything, just not worth it to me.
I'm from the UK and EMV (Called Chip & PIN) has been around for years now. No-one issues non-EMV cards anymore, except perhaps for cards designed exclusively for use in ATMs. Something like Coin would not be possible and, frankly, I'm happy this is the case. While having to carry multiple cards around is not an optimal solution I'd much prefer this over the ability for my cards to be trivially cloned.
Aside from the security issues how would this work in relation to fraud with your card issuer? I'm not sure if it is different in the US but if you are the victim of fraud and you were not seriously negligent (i.e stored your PIN in the same wallet as your card) then the issuing bank will refund any money fraudulently taken/spent. Assuming something similar operates in the US, would using this service give the issuing banks a excuse to hold you responsible for fraud? I'd also wonder if you were breaking any agreements you have with your bank in relation to your use of the cards they issue you with.
The first one I ever heard about was back in 1999, PocketVault from Chameleon Networks. They lingered with a website that was updated every couple of years promising a release soon.
Next came the iCache. That one did a Kickstarter and actually made it out to market... sorta. I have one, but the company ran into huge manufacturing issues and folded under very odd circumstances.
A few others I've kept an eye on are:
Dynamics, Inc. Card 2.0 -- Was supposed to come out with exactly this product.. ended up doing a very reduced feature set that lets you just select A or B rewards.
Protean Echo -- Same concept. Originally promised 2013 but recently updated saying they weren't ready yet.
There was another that was a similar concept company/site, but I can't find a link to it or remember the name at the moment. :/
There is also a recent company that had a successful Kickstarter: Loop. Rather than a programmable credit card, they are hacking the magnetic readers themselves by making a mobile phone case or dongle that emits a magnetic field that tricks the reader into registering a card swipe. Pretty neat stuff to compete with the struggling NFC solution, but unfortunately, it isn't 100% compatible with all swipe readers, and totally incompatible with dip readers.
But this changed after the CIA got their hands on the technology through in-q-tel acquisition of the french company gemplus then world n°1 company in the business. Then cards with chips were coming the US and it was expected for the rest of the world to get backdoors with their US issued chip cards, years later the french government finally bought back control of the company but way too late.
Now that they have the technology, I'm surprised the switch has not happened yet, even more so since cloning and other kind of fraud is quite easy with magstripes (not that it is that much harder with chips, see yescards).
The coin introduced here seems anachronistic to my european eyes which have not seen a card being swiped in the last 30 years and a great opportunity for fraud. Better use than reducing the number of card in a wallet is obviously to charge other people for your expenses by cloning their cards.
Never heard of that before, interesting.
I used programmable test cards when doing EMV and did wonder what would happen if I made such a card but (as the wikipedia page says) they're of very limited utility as they don't have the right keys to do anything but low-value offline transactions.
Cloning chip cards is still pretty hard, IMHO, though that is interesting.
They asked him for proof, as an engineer he gave them proof by buying metro tickets and sending them the tickets, the receipt and the card used to exploit the vulnerability. The GIE CB then went on pressing charges and using those as evidence of the crime and Humpich was sentenced to prison, the flaw was not fixed and the whole story got in the media.
Then yes cards started to appear all over France and Europe and people would draw money directly from atms with yes cards, until all ATMs were replaced by fixed version gradually over a few years.
The amount of fraud related to yes cards and subsequent iterations was never disclosed, but it was estimated to be in the tens of billions euros per year.
In 2001 a network of gas stations got exposed for copying the magstripe of chip cards which were then sent to be cloned in other countries and the same CBCarbon surfaced, a software dedicated to cloning chip cards issued after 1999 (those including the crypto bump from 320bits to 768bits)
I suppose this is not the low hanging fruit of getting the money from ATMs as the current method is a physical attack based on making them explode using gas but I sincerely doubt chip cards are really secure nowadays, probably just not as easy as it used to be.
The mag stripe thing is a weakness in mag stripes. The effectiveness of EMV is amply demonstrated by the fact that the numbers had to be sent to othe countries to be useful.
And yes cards in an ATM? The ATM software was not up to the standards that are required by the banks for third parties then. Implementation bugs, nothing more.
It is surprising, however, that all of them received a significant amount of upvotes.
http://www.theverge.com/2013/11/14/5103820/coin-electronic-c...
[1]:http://static.macquarie.com/dafiles/Internet/mgl/com/furnitu... [2]: http://tess2.uspto.gov/bin/showfield?f=doc&state=4807:8dpjzg...
Ideally, it'd be something like:
* Entering your key keeps exactly one card decrypted for up to 2 minutes * Changing cards requires a reentry of the key
You could even go crazy and do things like allow different cards to have different passkeys. Not sure how useful that would be though
One more thing that crossed my mind is, what happens if you give this to the waiter, the waiter goes away to handle your payment and it happens to be outside of reach of your bluetooth ping; then you will most likely become worried that the waiter ran away with your card, or you will start ignoring it when it notifies you that it is outside of reach.
While talking about the waiter, what happens when the waiter accidentally clicks the "change card" button and takes the personal lunch on your business card? You might not notice until it's too late and people start asking questions..
Paying by card here happens either by using a mobile card reader, or by just getting up and walking to the cash register before leaving. Much safer.
I was surprised to see in Quebec City that all the stores/restaurants had portable card machines they brought to you. That does make a lot more sense to me.
In Sweden restaurants have started to come out with portable devices and you even have to put in the amount you want to pay (because they want tip which is already included in the price..). I find this really good but at the same time less convenient because I don't want to fiddle with their device.
I would feel much better if I had my cards stored "securely" in my phone and could do "Tap to Pay" over NFC instead and have the waiter bring over an NFC device to tap against my phone.
Just having to enter a pin in Australia is going backwards.
I would maybe pay $50 for the beta card because I think it's super cool and I love trying new tech, but definitely not a price point I would pay to solve a problem that is hardly a problem at all. (to be fair, this might be one of those problems that you don't realize how bad it is until you solve it.)
I can't see myself paying more for this than I would spend on a wallet, which is less than $20.
Moreoever, I'd rather have my smartphone do it all, and by all I mean all: cc, id, insurances... Most places I care about now accept IC cards and RFID, which means I should be able to pay directly by pointing my phone at something while punching an sending a encripted 4-digit pin.
Using Google Wallet, Paypal, Square and others would be even better. It's coming and the pace is just accelerating...
Have a good one!
It would be useful for things like gift cards and reward cards - but is it worth it for that?
Here's how it works. Users register their cards on the company Web site and upload the information into the iCache. When they want to use it, they activate the device with a fingerprint on its biometric strip, scroll through a list of cards on its screen and choose one. Out pops a plastic card with a magnetic stripe, temporarily loaded with the chosen card's data. Just swipe the card and pop it back into the iCache. After one use, the information on the card disappears. The device even works with loyalty cards, such as those handed out by supermarkets.
http://money.cnn.com/2007/08/23/technology/one_credit_card.b...
The hardware technology is certainly more advanced, but I'm of the opinion that the true endgame is going to be a scannable or NFC "card" stored entirely on the user's device (ala Passbook), not using a physical middleman.
My iCache is now sitting in a drawer with a bunch of other "good tech gone old," but, I've had issues with servers understanding what my iCache card was, had Enterprise Rent-A-Car flat-out refuse to rent a car unless they could see the raised digits on a card, and a shit-ton of other things.
I was lucky -- I didn't have any issues with the actual encoding on the card (apparently, there were some folks from kickstarter who couldn't use it at all), but, I'll deal with the five cards in my wallet and generally be happy about it.
i really would love to see a one-card-for-all tho that supports chip + nfc, but my understanding is that card issuers are eager to ensure that this will not happen.
However - if you're looking for the future, I think I've got something interesting - feeless payments bank to bank by oAuthing consumers directly into their online banking. Completely secure - merchants never get the personal information, they just get paid. Better: I've built it, and we have beta customers. I'm posting a couple comments on HN to start the conversation, because anyone who cares about payments or accepts them online - I'm trying to talk. You'll be hearing more from me in the coming weeks and months - and it's going to be exciting. We're going to kill credit card fees, because we don't need them anymore.
If you want to talk, email me @ tommy@thecityswig.com and let's just chat. I'm not selling anything - we just need to know what hackers are thinking about payments. It's the most valuable info we can have.
Dead in the water - as much as I would personally like to see them succeed.
The biggest problems here are security.
() Merchants will hate it since there is no physical imprint / swipe of the bank-issued card. This will lead to chargebacks in favor of the customer. So this alone kills this company/product.
() Banks might change their terms forbidding customers to create digital copies / clones of their card. As per card holder agreements, if you (or Coin) has ever read one, you don't own your card. You're fully bound by the terms of the agreement.
() There is the issue of PCI-DSS compliance. They mention they're "in the process of earning" it but this is a lengthy, difficult and _costly_ process ($100 k). They're using a loophole to ensure consumer peace of mind but this won't last at all.
() Adding a card seems flawed. You're asked to take a picture of the physical card after swiping to "prevent fraud" ok but unless Coin uses some advanced image processing/OCR to validate the card with the swiped data, you can take a picture of any card. So big fail here.
() Coin seems to access a cloud service. Another major reason that this simply isn't going to work. If you've paid any attention to the NSA situation within the past 6-months, ordinary/average consumers (not the HN crowd) are becoming weary of cloud/hosted service. Not to mention, Coin will never ever work outside of the US (or San Francisco for that matter).
Practical usability problems:
() Most users are totally fine with credit cards and big wallets. It's actually empowering to them. I spoke to a guy who loves the fact that he has every color Amex card! So in essence, this is geared towards a micro-niche of tech savvy SF/NY/LA crowd.
() Selecting a card by tapping the button - great. What if the waiter taps the same button? Or someone you're paying does? So many issues with this button here.
"We’ve designed the button to toggle cards in a way that makes it difficult to trigger a "press" unintentionally" -- yeah, well most of the time, credit card fraud is an intentional act. What a stupid response. And quite frankly, offensive to anyone with half a brain.
() The obvious issue of losing Coin and losing everything. People like backups. It's a mindset.
() Battery issues with digitizing a non-battery product (credit card). Be in no doubt that more than half of users will forget to charge their credit card (as if we don't have enough things to charge). So you'll see people having lunches and presenting a dead Coin. And since you don't have any plastic, well, now you're screwed.
Products are supposed to make life better, easier, more intuitive.
Conceptually, it sort of makes sense. But the execution is flawed in so many ways.
You're being sold a product that now requires more steps than you did before. And that is the killer fellow HN'ers.
I don't want to have to sync, take photos, select a card by pushing a button, make sure it's within range to my device, update the app when needed for it to work, deal with merchants who won't take it, CHARGE my credit card (!), deal with issues because I tapped/selected the wrong card - vs - take out and swipe. Done.
Fuck that.
The product is inherently flawed
Quite the opposite. The HN crowd is becoming wary of cloud services, ordinary/average consumers aren't even aware of the NSA relevations.
Companies like AT&T have dedicated rooms for the NSA with spliced fiber to dumb daily terabits of data to. For decades. This is nothing new.
with regards to payments and consumer awareness of breaches and security issues, well, consumers today are becoming more AWARE of these facts brought on primarily by the Snowden leaks. Sure, a lot are still clueless and that won't change but there is still an inherent reluctance to trust new products/services/technologies especially when it comes to banking and finance.
The status quo are not early adopters. Never have been, never will be. The mainstream products are the success. When you sign up for an Amex or a Chase card or whatever bullshit they're selling on TV, they sell a sense of security, confidence, TRUST.
The problem with a startup like Coin (aside from the dozen or so issues mentioned above by me and a few others reading the thread now) is a narrow focus. They aren't really solving a problem, rather they're creating many more.
They've created a product that a handful of people in the SF Mission district will use to buy a $7 coffee and a croissant while they Tweet about it (from the Coin app hopefully). But this focus forgets the rest of the world (which is a big and lucrative place).
I think this is the problem with a lot of Bay Area startups. They're so caught up in the YC dinners, the SF startup scene, the networking, and the conferences that they limit their focus to a very narrow audience.
Apparently this criticism is not valid, since physical imprints / swipes are rare in Europe.
Perhaps learn/read about how the payments process with respect to credit card transactions and chargebacks work in the US before commenting.
Additionally, read about Coin, which doesn't work in Europe and doesn't support EMV.
:facepalm:
I fail to see how Coin is a lack of backups. If having two copies of a card isn't 'having a backup' what is?
It's about losing all of your cards when you lose one. And most people aren't going to spend money ($100) on one - yet alone TWO - cards vs. the free cards they get from their banks 24/7. If I lose my Amex, I can walk into an Amex office and get a free card in under an hour. Or have it overnighted for free.
Clearly you didn't read the site. Maybe you should pay more attention to things you criticize.
What's your point? None
I actually forgot to add something to my original critique: if your device (iPhone) dies, and Coin isn't authenticated you can't use your card(s)!! Haha
Can't believe I missed this. There's another bullet of flaws to add.
Their FAQ is vague and doesn't really answer any questions, especially the important ones. They attempt to give clever and confronting responses to serious questions and most people can see right through that. Comments on their FAQ like "Should last" and "a lot can happen between now and Summer 2014" - get out here. If you want customers to pay (a premium) for an experimental product - be concrete and firm.
They quite clearly state the usage pattern for the 2 year figure. From said FAQ site (https://onlycoin.com/support/faq/)
Q. How do you figure that a Coin will last 2 years? What constitutes
normal usage?
A. Here’s how we modeled typical usage. On a daily basis, we assume
you’ll toggle which card you want to use and swipe your Coin 10-20 times
a day. In addition, you may adjust which cards you want to store on your
Coin a few times a week. Initially when you’re getting to know your Coin
you will likely be syncing often. Over time we find that most people
sync much less frequently once his or her cards are on a Coin. If you
swipe and sync more frequently on a consistent basis, your Coin’s
battery will drain more quickly.I disagree. I sent the Coin video to my technology phobic parents in the midwest. They are hesitant to use most smartphone apps and online banking but they were really excited about Coin and could see themselves using it. It really appeals to them that 1) it's only slightly more complicated to use than a regular credit card (whereas, say, online banking requires you to learn a relatively elaborate user interface) and 2) keeps them from having to actively worry about leaving a card or wallet behind.
When you make a user interface a slight variation of something the user is already very familiar with, you can draw in the less tech-savvy because it's less intimidating. It's the same reason why my parents are avid Dropbox users but it's hard to get them to try new web apps.
Adding a card seems flawed. You're asked to take a picture
of the physical card after swiping to "prevent fraud" ok
but unless Coin uses some advanced image processing/OCR to
validate the card with the swiped data, you can take a
picture of any card. So big fail here.
Why do you expect them not to do image processing and OCR? Credit cards have standardized, highly OCR-able fonts. I would be very surprised if they didn't OCR it. Most users are totally fine with credit cards and big
wallets.
I'll have to disagree with that. There may be a few people out there who appreciate the physicality of the cards, but based on personal experience, I'll bet a lot more would love to streamline it. In fact, I would love to not carry a wallet at all, just maybe a billfold and a single card or my phone. The problem is this doesn't go far enough; it only eliminates a few cards from the wallet, it does nothing about all of the health insurance cards, rewards cards, drivers license, membership cards, subway cards, etc that clutter people's wallets. The obvious issue of losing Coin and losing everything.
People like backups. It's a mindset.
According to their video and FAQ, the cards are backed up to your phone. If you lose it, you can just get a new one and transfer your cards to that. And your phone will warn you when you lose it. Actually, one of the big draws are those two features together. Much less anxiety about leaving your card behind. Battery issues with digitizing a non-battery product
(credit card).
They explicitly state that the battery is non-chargeable and non-replaceable. You don't charge it. According to their usage model (which includes much heavier usage than I use any of my cards, I generally use a card once or twice a day, maybe 4 or 5 times on a weekend), it will get two years life.While I share the same concerns about privacy, compliance, card not present, and so on, I feel like you went out of your way to pick out problems, ignoring several things that were obvious from their FAQ.
I think you're mistaken. There is a swipe. It perfectly mimics the magnetic strip of the bank-issued card. The issuer wouldn't even know you didn't use the real card.
It wouldn't work for physical imprints, but neither does my Chase Sapphire Visa card. Point being even card issuers are comfortable EOL'ing physical imprints at this point. And it's not used for anti-fraud these days (real-time authorizations of swipes have replaced that); it's just a backup for when merchant systems are down.
Yeah I know right, this is why I can never buy anything online, oh wait.
> () Banks might change their terms forbidding customers to create digital copies / clones of their card. As per card holder agreements, if you (or Coin) has ever read one, you don't own your card. You're fully bound by the terms of the agreement.
The bank that does not enforce these agreements will have my business. Bring it on.
> () There is the issue of PCI-DSS compliance. They mention they're "in the process of earning" it but this is a lengthy, difficult and _costly_ process ($100 k). They're using a loophole to ensure consumer peace of mind but this won't last at all.
Every startup has to start somewhere.
> () Adding a card seems flawed. You're asked to take a picture of the physical card after swiping to "prevent fraud" ok but unless Coin uses some advanced image processing/OCR to validate the card with the swiped data, you can take a picture of any card. So big fail here.
I've used the camera to accurately scan my card data into 3 different apps in the past week.
> () Coin seems to access a cloud service. Another major reason that this simply isn't going to work. If you've paid any attention to the NSA situation within the past 6-months, ordinary/average consumers (not the HN crowd) are becoming weary of cloud/hosted service. Not to mention, Coin will never ever work outside of the US (or San Francisco for that matter).
Just... stop.
> () Most users are totally fine with credit cards and big wallets. It's actually empowering to them. I spoke to a guy who loves the fact that he has every color Amex card! So in essence, this is geared towards a micro-niche of tech savvy SF/NY/LA crowd.
You talked to one guy who loves that he has every color Amex card, and then came to this conclusion?
> () Selecting a card by tapping the button - great. What if the waiter taps the same button? Or someone you're paying does? So many issues with this button here.
I've had my card charged twice before, so what you are telling me is that the same thing that happened to me before might happen to me again? Thanks.
> () The obvious issue of losing Coin and losing everything. People like backups. It's a mindset.
You mean like how people lose their wallets?
> () Battery issues with digitizing a non-battery product (credit card). Be in no doubt that more than half of users will forget to charge their credit card (as if we don't have enough things to charge). So you'll see people having lunches and presenting a dead Coin. And since you don't have any plastic, well, now you're screwed.
So once every 2 years, I might have to ask my wife or a friend to pay for my meal at a restaurant, and I trade that for the convenience of not having to carry a wallet? Where do I sign up?
> Products are supposed to make life better, easier, more intuitive.
If everyone was using Coin, and then you introduced me to the concept of a wallet, it would be downright laughable.
Where can I sign up?
U.S.-based customers: Coin will work overseas, but we recommend that you bring a backup card when you travel.
Customers located outside of the U.S.: Coin does not support EMV yet. If the country you live it requires it we recommend holding off your purchase for now."
Found this in FAQ
It also appears that the Coin is programmed over Bluetooth. Why bother swiping to steal when you can run a smartphone app and take all of the cards on all of the coins in range?
If this takes off and fraud goes up, credit card companies will drop the discount vendors currently get by swiping. Maybe vendors that currently swipe will start entering CVVs? Will Coin then start storing CVVs per card?
Vendors might refuse to accept Coin in the first place (there's already a comment here from one who won't). Or credit card companies will have Coin outlawed as a counterfeiting tool. I can see how this seems like a good idea, but I don't think it will work out.
Because it doesn't broadcast credit card data over Bluetooth.
Does this happen to anyone else? It has happened with the last two wallets I've owned.
Clearly you need a better wallet >_>
At the time of account creation, create means by which both the web site and the user can prove unequivocally at a transaction later, that they are the same person who was there when the account was created.
Nothing about "who" they are, or "what" or "where", but just that the person or entity doing this transaction right now, is exactly the same as the person who created the account.
If I have to use this card, do I also have to have my cell phone with me all the time? If I go downstairs to get a Bagel in the morning, I need to take my phone, or else no Bagel for me? And it seems from the "Iphone will alert you using Bluetooth" facility, that I need to have Bluetooth on all the time, which I normally do not, to save battery life (adds an hour or so on my Iphone4). To me this is a functional gridlock.
Does it also need to be connected to some data network or the other to work?
If I lose this Coin card, then is it same as losing all my cards? If my assumption is true that this needs to be paired with a phone always, then will it not be possible to nullify the card, using the app on the phone, in case I lose the Coin card?
Thanks
However this feels like an awkward stop-gap between the current card-payment system and online payments. I don't want to give a waiter a piece of plastic and get a little paper receipt back, give me some kind of abstracted account ID and I'll transfer you the money from my phone/laptop/smartwatch/glass (/whatever we'll all have by the time a new payment method is sufficiently penetrant to be useful).
I have 2 cards, only one is actually credit, but that's because I am expat, so I still keep one card from my home country.
Someone mentioned owning 16 or 9 cards, which sounds so unbelievable to me.
Coin could even take this idea one step further and allow you to store your credit card, but when you swipe their card it provides the merchant with a randomized credit card number useful only for a one-time purchase. Now that'd be cool.
How would the terminal know it's debiting your account?
Where would the authentication take place?
Where would the randomization take place? And what would this be based on?
Credit cards are actually very simple in nature (and why there are billions of dollars of fraud occurring every year). It's simply an account number printed on a piece of plastic. But this account numbers is solely responsible for the transaction behind the scenes.
Who does this random number now? I've been studying payments for years and have never heard of this.
Obviously this only really works for online transactions that don't require a physical card - and even then introduces a ton of complexity to things like refunds. But the idea is interesting.
But this doesn't answer the question of how the terminal/processing system knows it's your account being debited?
The whole concept of randomization with payments (or anything for that matter with respect to authentication) is impossible. There will ALWAYS have to be some sort of static identifier in order for this to work. Common sense I think.
The idea is interesting but I'm not sure exactly what the idea is!! :)
If you have an AMEX and you randomize the account number on each transaction, AMEX still has to IDENTIFY your account with something? A name? A PIN? A unique ID? AKA an account number.
It doesn't. It debits an account that is signified by the randomly generated account number. The connection between that number and your actual account would be done by AMEX/in the backend somewhere. In fact, the whole point of such a system would be that the terminal would be blind to it.
There would always be a static identifier, but the key is taking that identifier away from the end user. That's where the card details get duplicated.
But IIRC the rules allow such virtual cards to be used only in online transactions, not for normal 'card present' sales.
The problem is that in Finland there is very few places that uses the "swipe" your card and sign method anymore. Back some 2-3 years ago it was a custom, but for security reasons (anyone can swipe a stolen card and sign it, the law does not require an ID unless the amount being paid is over 100 euros) it was abandoned and now you simply enter your PIN and that that.
Im not sure about other countries, but atm this is the norm in Finland.
Q. My soufflés keep collapsing! What can I do?
A. In order for the meringue to peak properly we suggest adding a little lemon juice to the béchamel. This strengthens the mixture and prevents tragedy.
As a consumer I have a few suggestions:
1. Make the card switch/activation button detect the fingerprint of the owner. (The merchant or waiter sliding the card could press the button accidentally and switch to a different card)
2. Show me that a tap-scanning tool can't take the data for all of my cards. (from hackers to accidental taps)
3. Can a magnet disable this card?
4. What happens if someone steals my coin? Can I disable it remotely with the app? Can it happen automatically?
Good luck!
That might not end well. But I guess that has been an open security hole for a long time now, hopefully has been addressed.
Even though Coin doesn't solve this problem, especially since it doesn't have EMV which is required in Europe, I'd love to have all off them one card. I have another boatload of cards at home that are rarely / never used because I never have them on me when I could use them.
So basically: very cool idea, needs some more thought for the european market though.
Personally I only have one card, so I don't really have that problem :D
I was really thinking of buying one but $100 every two years is too much for this.
This wouldn't be able to replace my wallet, so I'd still be carrying two things around with me.
So the card would be like Coin's but would have fixed credentials. Then when you open an account you'd provide your ID for the bank to register (or sign the registration with your public key); that account would be added to your card as an option.
I know this oversight can happen and it sucks, but the two are in the same industry (Macquraie has a global presence and quite a substantial US one), so it might come under some sort of copyright infringement. Just a heads up!
of course with the exception of it altering you if you left it at home, however that is a bit creepy, and, well let's just say I won't be getting a coin for my wife anytime soon
Alas, I'm afraid that kind of disruption cannot be brought forth in a market context...
Coin looks like a device that replaces my existing cards, which is a problem I want help with. I don't want to close my business bank account or get rid of my credit cards, I just want a lighter wallet.
That would mean the company gets a log of all transactions.
Though it only supports a maximum of 4 cards, at scale it would cost ~500x less.
I call it "penny." Here's my prototype: http://imgur.com/49auKC4
(reposted from https://news.ycombinator.com/item?id=6733584)
Now if you could get my phone to be as slim as that Coin that would be pretty sweet too.
Question: what kind of BLE technology goes in a card that thin? Looking into some applications of BLE myself and I haven't seen anything like that. I'd love to know what's in the card and how I could build a similarly small bluetooth device.
What happens when merchants/banks start offering the ability to make purchases using your smartphone? Doesn't that render this product obsolete? (if I'm not mistaken, you need a smartphone to set it up)
I know of an alternative that I bookmarked a long time ago. Have just submitted a link to their landing page, they're practically doing the same, but allow more card types to be fused and it's a mini-computer. They were on the market much earlier than Coin and it looks very prestigious & elegant.
The alternative card can be found here: https://news.ycombinator.com/item?id=6736606
(A post, because I'm curious how the Echo is worse or better, without interrupting the Marketing of the Coin, on this board)
I am not sure how to think about this in general, but @nlh has really good points. I agree with him that he needs the imprints, but to be honest, those imprints don't guarantee security.
EDIT:
http://www.chrisenns.com/2010/02/square-introduction-video/ http://lonelysandwich.com/
Q. Which is better; Tiger or Monkey style Kung Fu? A. Depends on the terrain.
If you're a photo sharing / blogging app, sure that kind of tongue in cheek humor is okay and acceptable.
However if I'm supposed to give you access to my credit cards, that is entirely unacceptable.
If this happens with Coin then I guess I'm screwed and embarrassed.
I agree wholeheartedly - the idea is good
I'm pretty obsessed with keeping the wallet light & thin - this seems to help out with that.
I wonder if this could potentially store other cards in some way as well? Gift cards etc - would be super convenient.
Incredible to squeeze that much tech in such a thin form factor - would love to see the internal hardware
At $50/card, with anywhere from 5 to 15 cards, it quickly adds up...
>A. Your Coin account is password protected and the mobile app requires that you type in your password before you can access sensitive card details.
There is no way in hell I would trust a single password to protect all of my debit, credit, loyalty, or gift cards.
http://allthingsd.com/20131114/finally-a-new-way-to-pay-in-s...
And referral: https://onlycoin.com/?referral=lvCn3taa please use it :)
Sounds cool, then you think about it, then it turns out pretty useless if they don't partner with everyone.
The demo is very, very good though. Nicely done.
Sorry, but I really don't see what this is saving me/doing for me? Whats the problem this solves?
From what I understand...there is some sort of memory chip on the card that stores the credit card numbers and info for every card, right?
So what is to stop some chip from bypassing the OS that manages the multiple cards and just reads the raw data?
Sure, it may be 128-bit encrypted, but if they have the raw dump - then it's just a matter of brute forcing it to eventually crack it...no?
What am I missing here?
No comment.
Remember, the difficulty goes up EXPONENTIALLY for every bit you add.
Just that it is much easier to do that - when you can set computer power to it locally. i.e. you can download all the credit card data onto your local hard disk and throw computing power at it....as opposed to trying to compromise a remote server that may be monitored.
I'd much rather have my financial data stored on my phone as I keep the device encrypted and can erase it remotely.
however, $100 is way too much for what is basically a very minor convenience. $50 is too much. For $20, I'd consider it.
from a business perspective, I wonder if they have deals with the banks. I wouldn't be surprised if they get slapped with some cease n desists just because the megabanks want their shiny pieces of plastic on display at all times.
Needs chip support for Canada and perhaps the rest of the world.
What a product, I love it, and I love this guy's quirkiness. Love. Love. Love.
I just wish my phone did all stuff related to money.
The big card issuers then are warranting the card as a token and allowing others access to verify the token holder. Seems like the way forward to me.
It's great to see that someone actually brought this to life!
There is a huge window of opportunity in the altcoins market right now.