4 ms·
Here's a list of the most common ways credit cards leak, from security journalist Brian Krebs: -Hacked main street merchant, restaurant... -Processor breach..
by mapgrep 10y ago
Here's a list of the most common ways credit cards leak, from security journalist Brian Krebs:
-Hacked main street merchant, restaurant...
-Processor breach...
-Hacked point-of-sale service company/vendor...
-Hacked E-commerce Merchant...
-ATM or Gas Pump Skimmer...
-Crooked employee...(Most frequently committed by restaurant workers)...
-Lost/Stolen card...
-Malware on Consumer PC...
-Physical record theft [from] Merchant, government agency...
https://krebsonsecurity.com/2015/01/how-was-your-credit-card-stolen/ https://krebsonsecurity.com/2015/01/how-was-your-credit-card...
So of Krebs' top nine sources of leaks, Final addresses at most three. No thanks!
UPDATE: Re the downvotes, Maybe someone should tag posts about YC companies so we know when it's unacceptable to engage our critical faculties.
- Flott 10y agoIMHO if three sources of leaks are fixed, it is a giant step forward. Not event trying to fixe anything doesn't seem like a better alternative at all.
- jonursenbach 10y ago> So of Krebs' top nine sources of leaks, Final addresses at most three. No thanks! I mean, sure, but three is still better the status quo.
- fragmede 10y agoPerfect is the enemy of the good. Unless your startup you haven't told anybody about solves all 9 issues, I'll take those 3 all the way to the bank! If they get enough traction with this MVP, they may move onto mailing out monthly physical credit cards which would handle a couple more on that list, but how about letting them learn to walk first?
- mapgrep 10y agoI guess as a consumer I feel like I already have this option. Bank of America and Citi both offer disposable CC numbers for online purchases. I happen to be at BofA (not a fan of them, but I needed a national bank), and, Googling just now, it looks like I can log on to my online banking and get a disposable number right now, without even signing up for anything. https://www.bankofamerica.com/privacy/accounts-cards/shopsafe.go https://www.bankofamerica.com/privacy/accounts-cards/shopsaf... I was hopeful a "credit card built for the 21st century" would offer something genuinely new. I guess this has push notifications about charges, which is nice. And it can go in a digital wallet, but digital wallets are supposed to refrain from giving out CC #s anyway (or at least Apple Pay does that). To be clear, I'm not casting judgment on Final's prospects as a business, just pointing out why I as a consumer would not want to go to the trouble of signing up. I do think the mission is a great one and hope they succeed (seriously).
- arfrank 10y agoWe seriously appreciate the thoughtful feedback. Email me, aaron@getfinal.com, if you want to learn/discuss more about why we made some of the decisions we made day one. It really comes down to resources and a team of 12 working against incumbents with teams of 1200+.
- xoa 10y agoThanks for being here and your responsiveness in this thread. A small team is actually itself something of a concern for a core life financial product, but the flexibility and responsiveness is a much appreciated strength as well. Regarding mapgrep's post, I also have one of my accounts with Bank of America, and I have used the virtual card generation feature (in BoA branding it's "SafeShop") constantly for years (and regretted it wasn't more widespread). Nevertheless your implementation looks significant superior, and I think implementation improvements are usually far more significant in the context of a product like a credit card then "genuinely new". BoA's feature is clunky, available only through a tiny (and I mean that literally, it's a 467x300 fixed size window) Flash-based tool with a mediocre UI and poor virtual CC management. It has zero presence on mobile (despite that being the obvious way to use it, particularly combined with Touch ID), no notifications, etc. Despite that the advantages of a fixed limit virtual CC are great enough to make it worth it, but you doing a better job (and one that folks less paranoid then me might be willing to use more often) is a very strong feature for your product in my opinion. One thing I may have missed on your site that I'd like to see for financial interactions in general: do you cryptographically sign your email communications (or at least allow customers to have that be a preference in their accounts)? I do see you list PGP keys for people to communicate with your security team specifically as is good practice, but I'd love to see more general use of at least signing email, which could dramatically reduce the ability of spammers, phishers and other malevolent actors to spoof legitimate sources. S/MIME at least has widespread native support without anyone needing to do anything else. PGP would probably need to be a selected option as it requires the installation of additional tools, but would be a nice bonus. You could even allow the customer to supply/request you fetch their own PGP key, thus allowing email to be encrypted as well as signed. While PGP support on mobile unfortunately looks to remain poor, since you have your own app for securely communicating in that area it shouldn't be as much of a problem. Someday hardware mediated scheme's like Apple Pay or Google Wallet or whatever will hopefully make some of this redundant, but I suspect the old CC system will stick around as legacy for a long, long time, and better ways to securely make use of it will remain valuable. Best of luck to you!
- eeeeeeeeeeeee 10y agoYou are being downvoted because you completely dismissed something that people worked hard on because it apparently didn't completely solve all credit card fraud instantly. You also didn't even say which three issues you think Final solves, making discussion about the issue even more difficult.
- mapgrep 10y agoFirst off, this company makes a really big claim, "The credit card was broken. We fixed it." Super sweeping, no? Then they say "The next time you hear about a big credit card breach, you can relax." Both of those statements clearly aren't true, IMO, so if I was harsh, it was partly in reaction to their over the top hype. Don't claim you solved the problem of credit card fraud when you really just made a disposable number generator that's already available from two big national banks, and didn't do anything new to address the issue of physical card use and all the associated forms of fraud. Anyway, in terms of constructively mentioning more specifics, I was thinking it can solve: -Hacked E-commerce Merchant... [since they get a virtual number] -Malware on Consumer PC... [since you would not be storing/entering the actual number any more] Less so, now that I think about it: -Physical record theft [from] Merchant, government agency... [Kinda - if you pay all government agencies and merchants virtually, you're fine, although those you pay physically are still vulnerable to theft] (Processor breach is still going to catch your physical purchases, but using virtual numbers online could reduce the attack surface of that particualr vector... So I guess it's two clear solves and two half solves... depending how much online purchasing you do vs physical) Also, anyone who thinks i'm completely dismissing the company is reading too much into my comment. By "no thanks!" I just mean it doesn't solve any problems for me right now. That's not a dismissal of the company's long term prospects, just because, IMO, the MVP is weak, for me. (As I said in another comment, I happen to bank at a national bank that offers free disposable CC numbers to all customers through standard online banking web login... not everyone has that, so maybe they'll sign up.)
- anonymous19711 10y agowhat national bank is that?
- zekevermillion 10y agoIt seems like a modest improvement on the way plastic is currently issued. The annual fee and interest rate make this specific card uninteresting for me, but those are largely dependent on the card issuing bank so I would not consider that a ding against the technology per se. I wonder though if the reduction in fraud through this technology, however modest, would benefit the issuer more than the consumer. Banks usually eat the cost of fraud in the interest of lowering friction for consumers, making it up on volume essentially. I wonder if given the benefits of security-improving tech, such a company could convince a more progressive banking partner to subsidize the costs of the card for consumers. That is in the long run, this card should really be cheaper than the alternative, not more expensive.
- pkulak 10y agoIf you give a new number to a merchant, with a strict limit, doesn't that solve every single one of these apart from "lost/stolen"?
- 0xffff2 10y agoYou only give a new number to merchants where you type in a card number. For all physical card transactions, it looks like you still use a physical card with a fixed card number.
- kylebenzle 10y agoWhy are we even taking time to critique startups like this when 9 out of 9 of these problems are already solved with cryptocurrencies that have been around for 10 years? I struggle to see why this is even a product at all?
- eterpstra 10y agoUnfortunately mainstream consumers still love credit cards, and think "Bitcoin" is some sort of criminal activity.
- smsm42 10y agoUnfortunately, if you look at real usage patterns, they are not completely wrong either. At least from the POV of a mainstream non-technical person not visiting obscure meetups but reading newspapers.
- andirk 10y agoNowadays we know banks get criminal legislation in their favor. That's pretty criminal. Bitcoin doesn't get much legislation, which is a good thing.
- bjapel 10y agohttps://hbr.org/2016/07/the-goldilocks-theory-of-product-success https://hbr.org/2016/07/the-goldilocks-theory-of-product-suc...
- mfringel 10y agoHave you tried answering that question yourself? If so, what answers have you found?