Screwed by Square
alexshvartsman.com
alexshvartsman.com
This is the value of PayPal's Seller Protection Program, which people probably undervalue since they've never dealt with a real merchant account. If you sell with PayPal, and ship a tangible to the address on the buyer's PayPal account, and have proof of shipment, you have 100% liability protection. Someone charges back the payment, and it's PayPal's problem, not yours; even if they lose, you don't lose your money.
I'm not sure I understand why he thinks Square screwed him.
Even if Square is perfectly in the right based on their user agreements they may be throwing good money away, and chasing off good customers. It's not hard to understand why a retail business owner would appreciate a little notice before an account cancellation.
"We provide you with this disruptive new service that's really cool. Oh, it doesn't work for you? We also provide you with absolutely zero support."
Sometimes this means you lose business for a few days, realize you were dumb for building your business on top of a company that can't even be bothered to give you a phone number, and move on.
Sometimes the company takes the money out of your bank account and gives you absolutely no recourse.
If Alex had time and money, he could bring charges against Square. Not that he'd necessarily win, but he'd at least get himself on their radar (and hopefully get a settlement just to get him off their back). Thanks to Square, he has too little of both right now.
It's stories like this that make me realize how grateful I am for companies like Zappos, whose big selling point was (and still is, reputedly) "we're not jerks". I had to contact their customer service back when they were still independent, and I was very pleased with the experience. I still shop there, even when it feels like I'm paying a premium, because a company that treats me decently is worth it.
Due to this lopsided arrangement, banks and processors have no reason to change the system. We should force them to take the risk of fraud; it's the only way to make the system better for everyone.
If we get AVS check fails on billing address, we automatically reject the order. If AVS check passes but shipping address is different and based on some other criteria like order history, order amount; we have someone double check on the order.
I think every merchant should implement these basic checks. Not sure if it is possible with Square but I would assume they do provide something similar.
[1] http://en.wikipedia.org/wiki/Address_Verification_System
If not, why not?
That's part of it. The other parts are that unlike a PIN or password, people routinely tell others what those digits are, and that the system works as a pull (the merchant decides when to collect the money and informs the customer's bank via the payment processing system) instead of a push (the customer decides when and where to send the money and informs their own bank).
Most of the problems with security, fraud, chargebacks and related areas in the card payment industry ultimately start from this fundamentally flawed model.
The number of digits doesnt matter but CVV vs. no CVV does make a difference. CVV is the way to verify that you are allowed to use the given credit card number (its actually the second V in the initialization).
CVV is completely separate from the way the credit card number is generated. If someone else has your card number and CVV it implies:
Either your numbers were stolen directly from your card or your information was stolen from some third party server.
If your information was stolen from, say a merchant's server, it implies that they did not properly encrypt your credit number and that they stored CVV which should not even be in their database to begin with.
To the best of my knowledge, anybody taking a credit card will lose a chargeback if they don't have a signature. And you never have a signature in an ecommerce transaction, so you will lose all disputes. (I know the very large company I used to do the CC processing for routinely lost our chargebacks for ecommerce transactions, and at our volume we should have been able to find a system for not losing if one could be found.)
The only current "solution" is to do a good job of filtering up front and rejecting suspicious transactions, which can be helped by requiring AVS and CVV2 matches and phone calls for large orders - but there isn't really a good system for handling this at all. The best I've seen so far is a company that would verify new customers by calling and asking them a question about their neighborhood from google maps. And it's a shame that each individual merchant has to come up with something convoluted like this, and the payment processors don't provide technical help or financial guarantees for the transactions they authorize. But that's just how it is right now, and it isn't Square's fault.
It's not quite as simple as that. The customer authentication problem is what programmes like MasterCard SecureCode and Verified by Visa are supposed to solve. The trouble is, their implementations are so clunky that a lot of merchants/payment services don't use them, which in turn means a lot of end customers don't expect or understand them either, damaging legitimate conversions. I've heard that they are also not widely used in the US for whatever reason(s), though they're somewhat common here in the UK now.
In theory, these mechanisms should fix much of the underlying weakness in the current card payments model, because the end customer never gives the extra security information to others, only to their own bank/card provider. And there really are (or at least were the last time I checked) payment services that will eat the fees for chargebacks on transactions that were authorised using these kinds of 3-D Secure mechanisms given reasonable evidence that the merchant did provide whatever was being paid for. Unfortunately, I'm not aware that any of the new generation of online payment services offers 3-D Secure yet, which I expect to become a significant headache for them as more horror stories like the one we're discussing here come to light.
As a point of interest, much the same arguments apply to two-factor authentication schemes for cardholder present transactions, such as Chip-and-PIN, which has been almost universal in the UK for a long time now but again doesn't seem to have had as much take-up in some other countries. It's normal to consider a PIN-authenticated transaction at least as safe as one confirmed with a written signature. But again, these technologies don't seem to be universal in some other countries yet for whatever reason(s).
Sure, but be sure to empower consumers against the banks if you make the banks liable instead.
I've always found this case study from the classic "Why Cryptosystems Fail" fascinating:
In some countries (including the USA), the banks have to carry the risks associated with new technology. Following a legal precedent, in which a bank customer's word that she had not made a withdrawal was found to outweigh the banks' experts' word that she must have done [JC], the US Federal Reserve passed regulations which require banks to refund all disputed transactions unless they can prove fraud by the customer [E]. This has led to some minor abuse - misrepresentations by customers are estimated to cost the average US bank about $15,000 a year [W2] - but it has helped promote the development of security technologies such as cryptology and video.
In Britain, the regulators and courts have not yet been so demanding, and despite a parliamentary commission of enquiry which found that the PIN system was insecure [J1], bankers simply deny that their systems are ever at fault. Customers who complain about debits on their accounts for which they were not responsible - so-called `phantom withdrawals' - are told that they are lying, or mistaken, or that they must have been defrauded by their friends or relatives.
The most visible result in the UK has been a string of court cases, both civil and criminal. The pattern which emerges leads us to suspect that there may have been a number of miscarriages of justice over the years.
* A teenage girl in Ashton under Lyme was convicted in 1985 of stealing £40 from her father. She pleaded guilty on the advice of her lawyers that she had no defence, and then disappeared; it later turned out that there had been never been a theft, but merely a clerical error by the bank [MBW]
* A Sheffield police sergeant was charged with theft in November 1988 and suspended for almost a year after a phantom withdrawal took place on a card he had confiscated from a suspect. He was lucky in that his colleagues tracked down the lady who had made the transaction after the disputed one; her eyewitness testimony cleared him
* Charges of theft against an elderly lady in Plymouth were dropped after our enquiries showed that the bank's computer security systems were a shambles
* In East Anglia alone, we are currently advising lawyers in two cases where people are awaiting trial for alleged thefts, and where the circumstances give reason to believe that `phantom withdrawals' were actually to blame.
Finally, in 1992, a large class action got underway in the High Court in London [MB], in which hundreds of plaintiffs seek to recover damages from various banks and building societies. We were retained by the plaintiffs to provide expert advice, and accordingly conducted some research during 1992 into the actual and possible failure modes of automatic teller machine systems. This involved interviewing former bank employees and criminals, analysing statements from plaintiffs and other victims of ATM fraud, and searching the literature. We were also able to draw on experience gained during the mid-80's on designing cryptographic equipment for the financial sector, and advising clients overseas on its use.
What I don't get is why you can't do something much more simple.
Wouldn't 99% of these problems be fixed by something as simple as a credit card companies just requiring transaction approval from the card holder?
It could be handled by text message or an app and show up as on your phone within 5 seconds of running your card.
Swipe, okay it on your phone, done, forget giving everyone new cards with some sort of complex PIN # system.
Heck, you could even go a step further and make a barcode on your smartphone scan as a credit card at checkout, and then hit okay on your phone to complete the transaction.
Get an alert for something you aren't buying? Hit deny, it doesn't go through. No fraud, everyone's happy.
I'm guessing the reason there's not a system like this is that most credit card terminals are too archaic and dumb to have a live link to the Internet to handle something like this in real time? (Or the more obvious reason of not being able to use it without a cell phone?)
For e-commerce you need to enter a password after you enter all your CC details. It's called Verified by Visa or Mastercard Securecode, depending on what card you have.
The downside is that apparently the user agreement states that if your password gets stolen (as well as your credit card details) then all liability is on you.
And you don't have to sign up for the whole POS system to get the card-reader for your phone/iPad. Their mobile app (available to any Shopify shop owner) ships out a free reader. http://www.shopify.com/blog/11013977-introducing-shopify-mob...
I had a similar problem with eBay and the only way to get them to respond in a timely fashion was a similar rant that made it to the front page of Hacker News.
Customer support via blog post. Not the most effective method I can think of.
No - but the only one where a manager will have his job on the line.
(unfortunately)
Do they try to differentiate themselves via customer service?
Okay, that made me laugh. :)
They're also not a PayPal that's willing to provide buyer or seller protection. They just facilitate the transaction. The responsibility for verifying the transaction falls entirely on the vendor.
He never mentions following up with them or how he took them up on their offer and what their response was.
> A Google search unearthed a number, but it was literally nothing but a recording, directing the listener to go to their web site.
> So to the website I went, sending them the following message through their web form
> When I came into work on Monday, one of the first things I did was to fill out their chargeback response form again
> I received none of the “updates throughout the process” that they promised
So, he's followed their rules, and used their channels of communications. Their response was an automated "we cannot divulge the reason for your account termination ... our decision is final."
Past articles from people who encountered the same problems have posted the response to challenging these to be "stop contacting us, your account is closed, our decision is final".
To them "high-risk" often means "you put too many questions" or "we don't have time to actually support you properly". By simply banning you they get rid of businesses that require more attention instead of hiring more capable people. That list of capable people should grow along with the customers list but they stop at some point and that's when they can't deal with you.
It's good that stripe is not available in my country because I really wanted to pick them after Paypal nightmare. I think I would have killed myself at round 2 with this type of support and bans they throw at you when you need help.
Also, reminds me of this post a while back - http://elliotjaystocks.com/blog/good-riddance-paypal/
"PayPal have all the power of a bank and yet none of the responsibility."
If this is so obvious, why doesn't Squaree explicitly spell this out in a help page? Is this some magical knowledge that can only be learnt first hand, and never officially stated?
Square screwed him over by not being more transparent with their policies.
And while it's ok to cancel an account that has a high proportion of fraud, it's wrong to do that AND take the money back.
Yeah, but for a shipped physical good, only being able to ship to the original cardholder's address doesn't do you much good. That $1800 package isn't going to you, unless you are physically close enough to steal it off their doorstep which is pretty risky.
So either it's the correct address, which points to the cardholder defrauding, or it's a different address, which should be caught by the processor. Or they shipped to a different address than the billing address, which would be totally the fault of the seller.
These are/ should be normal precautions when shipping expensive equipment
If I had a small business with large dollar amount purchases, it certainly doesn't seem worth the risk to allow it. One bad transaction and you are out a lot of money.
One thing I learned is that I should also contact the vendor next time. I am not sure who lost in my case, but after the information I heard today I think it is Dell.
Dell still thinks I am a good customer. I can't get them to stop sending promotional junk mail since the incident.