981 karma · joined March 20, 2007
http://johncollison.ie
https://stripe.com/jobs & jobs@stripe.com
Edit: I'm using the words seller and recipient interchangeably: https://stripe.com/docs/api#update_recipient
We hope that people new to web security can solve the first few levels with some work and inspection, and the later levels with hints from others or a significant amount of research into the topics.
At the end of the day, the point of the exercise is to expose realistic vulnerabilities for fun and education. We try to make them similar to how they'd be in the wild.
We certainly believe that the approach is sustainable, and the data so far strongly supports this.
Observer (http://observer.no.de) seems like a good new solution.
You should probably still use Stripe in this case. (Some people already are.) We scale up pretty well. Everything that you get with a merchant account (correct statement text, money held in your name), you get with Stripe.
Additionally, there are some advantages for large businesses that would make Stripe more attractive than a merchant account: transfer reporting and detailed reconciliation tools make a big difference to people doing high throughput.
Since Groupon's investment and revenue strategies are known to all, this would be closer to a pyramid scheme than a Ponzi scheme.