Poynt – Smart payment terminal
getpoynt.com
getpoynt.com
I like how the first guy puts his card in, takes it out AND THEN punches in his PIN, which is exactly how PIN & Chip doesn't work. I would have hoped they'd at least be familiar with the process.
It looks to me like a mobile computer strapped to a terminal. I'm not sure why this is better than having a terminal + iPad or something similar but I'm not the target demographic.
I see many other issues with it:
- Hardware development is hard and long. This looks to be little more than a physical mock-up. For example datasheet lists "Ethernet" is connectivity options but there is no ethernet port visible on the body.
- BLE & GSM antennas are exactly where you wouldn't put either of those. Here is tip: You can't put an antenna behind an LCD. They have metal backings.
- Shouldn't QR & Barcode Scanner be pointing UP? You have very limited field of view when it is pointing down.
- Getting EMV and FIPS certified are going to take a long long time. Granted they could buy that firmware off the shelf to accelerate the process.
An employee, above, said that it is for entering tip. Which would make more sense, but then the card would have to be inserted after the total amount I imagine but I can see how they would have a slightly different flow. Personally, I would want any terminal that I use to show me the final amount that I am going to pay before I put in my card. Lest I pay, walk away and the cashier adds her own tip.
The video was produced with a cosmetic device and with actors. You're right that the card has to be in the device during PIN entry. The scene you're referring to, however, is depicting tip entry.
The device does not have an ethernet port but we will be shipping with a separate charging dock that will provide wired connectivity.
I can assure you that all of our antennas are not behind LCDs. While compact, the device does have a number of non-LCD surfaces.
The customer facing camera is pointing horizontal. We'll continue to refine the angle (if needed) as we continue testing with our early adopters.
We did in-person demos with over a dozen news agencies. If you have any doubts about the existence of the device, please feel free to reach out to them for confirmation.
I am not doubting that you are building the product.
You/The company should probably put more effort in correcting the datasheet and the information you put out there. We can only judge by what is being presented. Your datasheet says Ethernet. It doesn't say Ethernet would be on a separate dock. It probably should.
If you are placing the antennas behind plastic surfaces, that is great. You should correct the diagrams.
Further to your point about tip entry, tip should be entered before the transaction is authorized right? So one would assume you'd enter tip then put in the card, and optionally enter a PIN or sign the screen.
I can appreciate that it may be just a video demo, but when you post it to a place like YN people are going to point out errors. Funny enough, that error was pointed out by a friend who was watching over my shoulder. She is not a technical person in any way and it jumped out at her.
Point taken about the errors. There are many things we can improve on all across the board. We made a conscious decision to not let perfect be the enemy of good. The video is done so we won't go back and change that but I will work with the team to fix all of our marketing material to be as accurate as possible. Thank you for pointing out or errors.
With regards to tip entry. Industry standard recommends gratuity be added before PIN but it is not mandatory and is a merchant preference. I can't find all the card network examples easily but I happen to have the AMEX EMV Acceptance Guide open and this is what section 4.2.7 states - "In certain Merchant categories such as restaurants, it is standard practice to enable customers to add a gratuity to the amount of the transaction. There are many different ways in which a gratuity can be added. American Express does not define any specific methods for adding gratuities..." it further goes on to say "American Express recommends that Terminal software enables the Cardmember to add the gratuity amount to the transaction before entering his or her PIN. This enables the transaction to be processed as a normal, “card present” transaction."
In any case, we've all appreciated the various comments on here and it has clearly been the most critical audience of the bunch.
With respect to the tip flow, with Chip & PIN you would need the final amount before authorizing the transaction so the tip would be added before just as your guide suggests. Chip & PIN terminals in Canada and Europe do just that. They present you with the tip screen (% or amount) before you enter your PIN & finish the transaction. For MSR, just like in restaurants today, they can change the amount after the initial authorization but they also often authorize for about 50% more (to allow for tip) and then do the capture once the server takes the bill from the table and "closes" it with the correct tip.
I can say from personal preference that I would do a double take if a device allowed me to put my card in and finished the transaction and then permitted a change to the charge amount. What is stopping the cashier from adding her own tip once I walk away.
That said, in the true Chip & PIN solution, once you ask for tip after PIN entry you as the merchant are opening yourself up to higher rates (Card Not Present) as well assuming liability for chargebacks. I don't know why a merchant would want to do that but as a platform we have chosen that use-case as an option.
Tamper-evident is likely baked into the device, instead. Make a circuit that trips when you open the thing up, wire that up to wipe the keys and brick the device until it goes back to factory.
Cheers!
Traditional carriers like Verifone or NCR, your costs are high (typically for enterprise) and implementation is anything but straightforward.
What other payment product that is not a dongle solves these varied payment problems for hosted solutions like vend, lightspeed, shopkeep, etc and is plug and play?
All the payments (EMV/NFC/MSR), secure key (including acquirer keys) management, P2PE encryption, EMV/PCI, etc. are handled by the secure processor. There are no other applications that can run on this secure processor other than the signed and certified applications.
On the Android side, Poynt's Secure service is the only service that's capable of communicating with the Payment Processor to initiate card reading (EMV/NFC/MSR/others) and pass through the encrypted data it receives to the merchant's acquirer. All the 3rd party applications run independent of the Poynt's Secure Service and when they need to collect a payment, they do so through our Poynt Payment Fragments to facilitate the Payment flows. (See here for information on how it works: https://getpoynt.com/developers/terminal#2.3 Poynt Payment Fragments).
So as you can see, we are able to keep the security domains separate and thereby able to handle PCI certification in a much more graceful way. Obviously they are some complexities but choosing a certifiable payment processor board was one of many ways we are able to deliver a secure solution.
Cheers!
I'm nervous about the Android part of this product. I've seen some poor implementations of devices that want to use Android because it's 'easy' to get a lot of features up and running but then struggle with the quality of the middleware layers or Android-specific UI patterns that they try to strip out.
Otherwise, I think the dual screen and industrial design looks good! I hope the LCD looks as good as the renderings.
I think there was a lawsuit filed against him and Google by PayPal the day of Wallet's launch, claiming Google stole their secrets. No idea how that turned out; though I imagine it was a PR move on PayPal's part.
> Does the Smart Terminal accept payments by Apple Pay?
> Yes, the terminal accepts Apple Pay since the iPhone securely communicates with the terminal through NFC. We here at Poynt made our first Apple Pay payment with our Smart Terminal on the morning the software was released to the world. It was a very exciting moment for us!
Probably not the best idea to launch with a name identical to another start-up that also has apps on all major platforms...
https://play.google.com/store/apps/details?id=com.poynt.andr...
Aside from that one would hope that they aren't storing PII or financial data on the device itself.
To begin with, while our terminal is Android based we have taken numerous steps to lock this device down. Side loading apks is not possible nor is arbitrary access via adb. On top of that, we take great lengths to protect consumer data. In addition to full PCI compliance data is fully encrypted on the device. And if that's not enough, there are several anti-tamper mechanisms that will trigger and lock down the device even further upon physical instrusion.
In terms of physical theft we are actively looking into an option to physically secure the device (think kensington). Our plan is to have a good solution for this before our merchants go live.
The transaction data (amounts, items, transaction statuses, etc) is managed by the PoyntOS (owned by Poynt). That data has the necessary authentication and authorization around it to prevent just anyone with the device from having access to it. Only a merchant user logged into the app and with the appropriate level of privilege will be able to access the data.
Finally, 3rd party applications will go through a strict vetting process and will be signed. Therefore, it will not be possible for some fake app to work on the device. Also, PCI requires us to constantly monitor the installed application for any kind of tamper.
With respect to anti-tamper mechanism, are you FIPS-140-2 certified or plan to be?
Our security subsystem is being built to be FIPS 140-2 Level 3. Complete with tampers seals, switches and a security mesh that will destroy sensitive keys when triggered.
Opening the video with the phone held vertically and then rotating the phone once the video loads works fine, however.
Yes wifi.
So that the secure element(yeah right) that's on your plastic or your phone only communicates with OSes and HW that limits the ID-ing of the cx and provides the strict minimum of info to your POS is the critical part, in my view.
1) near immediate payment resolution
2) fraud protection
3) insurance against bad products and vendors - you can almost always get your money back if something goes wrong
4) credit accounts
5) points/miles/cash-back, at the expense of the vendor
What is the risk of fraud or of bad product and or bad vendors when both ends know each other? Why introduce a 3rd party in those transactions that gives back a fraction of its fee to the payer? (5) Instead why not reward repeat business with preferential pricing? (not directly possible but attempted via loyalty programs that cost a lot to deploy)
The credit is provided by the issuing bank (4). It can exist independently of the credit card network.
And with any electronic means, 1 is pretty much a given.
Credit 3rd parties still have a reason d'être if a solution that shortcuts VISA and MC when both ends know each other catches on. A Credit 3rd party is needed as an insurance policy when two unknown parties do a transaction; that insurance is bound to cost more than today given less volume; but it could be efficient if pricing would be market driven instead of diluted in 100-1 day to day transactions.
Thanks to the down voters, BTW. Again HN is showing openness to look at things from a totally non conventional angle. I think I'll log off for good. So long, and thanks for all the fish!