5 ms·
Paypal and Authorize.net: Help End the Credit Card Hostage Situation
- browser411 16y agoBraintree is one of the most forward thinking payment providers out there. A good number of startups on HN have integrated with them (we have, too). They have an excellent policy about porting customer data (e.g., stored credit card numbers) when moving to a different provider. Amazing customer service overall.
- slantyyz 16y agoSadly, Braintree's letter is not going to have much impact. Most of the bigger providers care more about their own interests than those of their customers.
- hga 16y agoI'm not sure Braintree is being all that different. I've heard nothing but good things about them ... except that their minimum transaction level is high enough many/most/all??? startups can't meet it. So the latter obviously go to Paypal and when/if larger Auth.net. Braintree is asking those companies to make it easier to "graduate" to Braintree. Since Braintree provides one of the highest quality services in this field, they're obviously not worried about too many customers defecting, or at least not until they get so big they bring it in house. Which in the current startup capital climate is going to be very rare, I suspect.
- bshep 16y ago>> Braintree is asking those companies to make it easier to "graduate" to Braintree. I think you hit the nail on the head. I just looked at their pricing and we cant afford them, so we are stuck with paypal for now. By the time we grow enough we will be locked into paypal.
- slantyyz 16y ago@bshep: A bit offtopic, but how has your experience been with PayPal so far? I'm investigating payment gateways for a SAAS offering (I'm based in Canada), and despite all the negativity surrounding PayPal, it seems to be the easiest way to go. I can't afford to go with Braintree, and I'm not quite sure they even deal with Canadian companies.
- thechangelog 16y agoFWIW I've been quite pleased with PayPal, both standard and "pro." They get a bad rap (somewhat deserved), but for ease of setup and low barriers to entry, they're the best I've found. For one customer (a music festival) I set up paypal integration for ticket sales three years ago and haven't had to change anything since.
- what 16y agoHave you ever integrated PayPal in a way that requires a PayPal account for purchase (ie: turning the "PayPal account optional" setting off)? How many people bounce when they have to pay with their PayPal account? I was looking into their Adaptive Payments API, but it requires both sender and receiver(s) to have a PayPal account. I'm not sure if that's a good idea.
- thechangelog 16y agoI'm not brave enough for that. Everything we do is about reducing friction.
- bshep 16y agoI've also had a good experience with paypal. I've also tried google wallet (much cheaper) but google does not allow for subscriptions which I need for my business. The only thing with paypal is that if they decide your business is somehow in a legal gray area they will take your paypal balance and you have very little recourse. At least this is what I have always heard in Paypal horror stories.
- 16y ago
- bryanjohnson 16y agoWe (Braintree) now work with companies of all sizes, including a lot of startups, and have no volume requirements. In the past we did have volume requirements. We were a smaller company then and were trying to balance maintaining a high quality of service when working with more leads than we could handle. We'll be blogging about this in greater detail.
- nkohari 16y agoSeconded. Braintree is probably the best vendor I've ever worked with.
- andrevoget 16y agoUnfortunately, Braintree's services are only available to US companies.
- wizard_2 16y agoTheir open letter on the other hand is relevant to the entire credit card industry.
- steveklabnik 16y agoAnother happy BrainTree user here. Their backing bank was a bit of a pain, but BrainTree themselves were great. I'm glad to see them trying to make moves like this. It's one of the reasons that our business is with them.
- bkrausz 16y agoThey also require a 3 year contract where if you go out of business before then they require you to pay thousands in monthly minimums (read the ENTIRE contract before signing up). They claim to be very startup-friendly, but really their terms are not that great. I've heard great things about their service, but I found CDGCommerce to have much better terms.
- bryanjohnson 16y agoWe (Braintree) have no contracts and no termination fees. Merchants can leave whenever they want and for whatever reason without penalty. Some of our sponsoring banks unfortunately have cancellation fee language (that we don't control and are trying to get removed) but we provide an addendum to every customer that states they will never be responsible for any cancellation fees.
- bkrausz 16y agoI see on your application page that you have that addendum. I'm sorry for the incorrect statement, the rep I worked with last year didn't do a good job of communicating requirements (also was very inflexible with monthly fees). I will be sure to keep Braintree in mind for my next venture
- merrick33 16y agoBraintree has gone out of their way to help my company out, they are extremely startup friendly. My customer service rep at Braintree handles regular billing inquiries and has also helped me with some coding issues - that speaks volumes in my book.
- deleted 16y ago[deleted]
- staunch 16y agoIt seems kind of lame to beg the incumbents to make it easy for you to poach their customers. The big evil guys have their customers by the balls. It's safe to assume there's no way they're going voluntarily let go. They need angry former customers to do the talking. Maybe this raises awareness a bit, but what really resonates is horror stories. A few high profile former Authorize.net/PayPal customers that are angry and willing to tell people about it would probably go much further. The sweet begging approach isn't likely to work.
- mseebach 16y agoThe addressees of an open letter are seldom the intended recipients.
- staunch 16y agoYeah no doubt. And maybe this is really the best way to get things started. It definitely isn't enough though. Anymore than The Gimp guys asking the CEO of Adobe to make Photoshop save files in XCF format.
- hannibalhorn 16y agoI'm one of those angry former customers. You can yell at PayPal all you want but you won't get that data. Honestly, I think there needs to be some regulation here, since there's just no incentive for the large incumbents to change. From a security perspective, it's a huge disservice to the consumer. It's a great thing to not worry about storing card details in your application. The auth.net/paypal policies incent anyone using those providers to store those details anyway to ensure portability.
- thinkcomp 16y agoOr just forget about credit cards and use FaceCash! http://www.facecash.com http://www.facecash.com (My startup.) Seriously, the industry has no incentive to change. They make a killing. Merchant contracts are strict and likely forbid alternative standards such as the one being proposed here.
- stephen 16y agoAgreed, the industry makes a killing, but you're still charging a percentage. How about a flat $0.25 per transaction? http://dwolla.org/dwollak/questions/16/Advantages http://dwolla.org/dwollak/questions/16/Advantages
- sachinag 16y agoThis is cute. Not even Chargify or Recurly support[1] the "standard" (as far as I know), and they have vaults! Show me a list of other gateways that support the standard, and then maybe you can get the big boys on board. I used to work in politics. This is the sort of poke-the-giant thing that longshot candidates do, and it actually ends up reflecting more negatively on Braintree than anyone else. It's a tone-deaf PR move from a great company. EDIT: Looks like Chargify sends the CC details to the gateway and they don't have their own vault: http://chargify.com/features/pci-compliant-security/ http://chargify.com/features/pci-compliant-security/
- isaachall 16y agoJust to clarify, we at Recurly will gladly return your credit card data to you (in a secure fashion) if you decide to migrate away. I've been burned before by Authorize.NET holding my business' credit card data hostage and I wouldn't wish that on anyone. We'll be posting more on this shortly. I'm really happy that Braintree is pushing this forward. I've seen it hurt several companies when they need to switch gateways or merchant accounts. Isaac Recurly, CEO
- cryptnoob 16y agoI got frightened by all the PCI DSS fear that permeates this board. I assumed you guys had it all figured out, and to a man, you seem to all be of the same mind on this issue. Fear, fear, fear. When I actual Read the F----ing Manual about this ...., actually read that what was required was peanuts compared to the thousands of posts and comments I've read here pontificating on how to safely store a freaking password to a dating site, I am perplexed. How can a group of people who can talk your arm off for two hours about salts, rainbow tables, hashes, and password entropy, be frightened of PCI? https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml https://www.pcisecuritystandards.org/security_standards/pci_... I store my own credit card info. Exactly how I do it is none of your business, as, while I don't rely on obscurity for my security, I'd be foolish to deny myself it's added protection. I don't just meet PCI standards, which are easy, I greatly, greatly, exceed them. Why anybody would use a third party billing company is not mysterious, but why somebody who reads HN would do so, is strange to me. I already know the comments I'll get for uttering such blasphemy. I would respectfully request that you actually spend 10 minutes reading actual PCI DSS guidelines before doing so, however.
- modoc 16y agoI respectfully suggest that you undergo a 3rd party Type 1 PCI audit.... The amount of legal and policy documentation you are required to have is by itself a massive undertaking. The 3rd party audit will cost $150,000-$300,000 and a huge amount of man hours.
- cryptnoob 16y agoOne in every crowd, isn't there?
- modoc 16y agoOne what? One person who's actually undergone multiple type 1 PCI audits? :) Encrypting the credit card is the smallest part of it (although the number of people who actually pull off the encrypted key, key pieces kept by different people/systems, etc... is low). The networking, server, secure audit/logging to a dedicated server, patch within 90 days, policy documents, and so on are the hard parts.
- jacquesm 16y agoI'm not aware of how exporting the credit card data stored in the databases of these companies could ever be valid under PCI compliance rules. They say it is, but I don't think it is up to braintree to say that it is, it would be up to the issuers to say that it is, and as long as they don't come out on the subject nobody is going to risk getting fined 10 million bucks or so by VISA or MC (or worse, to get shut down) to find out. Braintree should probably do it's best to lower the barrier to entry to their services rather than to try to create a portability layer with competitors that don't care. And then braintree could give the right example by allowing merchants to take their data with them to other providers of payment services. Note that just as you can't 'export' from Paypal or authorize.net you also can't simply 'import', the reason for that is that bulk import with random 3rd parties is extremely risky, it bypasses all the safeguards that have been installed to prevent all kinds of fraud.
- Judson 16y agoThe problem: not many people actually switch payment processors. Once you get with Auth.Net, you spend a lot of time negotiating better rates with different companies, but your Auth.Net gateway stays the same. I could see data portability being an issue in the long run, but for now, with Auth.net being basically one of two gateways, not enough moving around happens for their to be a "call for portability" (that will actually be heard). I do, though, applaud a forward-thinking move like this. It may be looked back on as the small spark that got the fire going.
- mattmaroon 16y agoIf I'm one of the mentioned CEOs, here's what I just read: "Dear guys who are bigger than me: please make it easier for me to steal your customers."
- vishaldpatel 16y agoI have fun questions: Who is the target audience for this letter? What is it trying to achieve? How effective is this letter in its current state in a) reaching the target audeience and b) achieving its goals?
- conanite 16y agoAt some point, your customer's card expires, and you need to ask them to re-enter their details. New details -> new provider. It might take two years to migrate most of your clients - even if it isn't ideal, it's not like you're locked in forever.
- sachinag 16y agoNot true. Dirty little secret - you can roll forward the expiration on a credit card with impunity. The expirations are because the magnetic strips wear, not for any security.
- quellhorst 16y agoI have tried this before with my processor, and the transactions were denied because of no match on the expiration date.
- bryanjohnson 16y agoNot directly related, but we (Braintree) recently blogged about credit card expiration dates. Here is a snippet: "If you run a transaction in our gateway and enter a date in the past for the credit card expiration date, you may be surprised to discover that we don't validate it. We run the transaction knowing that the card is expired. Why do we do this? The short answer is that financial institutions will still approve transactions with expired expiration dates." http://www.braintreepaymentsolutions.com/blog/credit-cards-arent-like-milk---theyre-still-good-after-expired http://www.braintreepaymentsolutions.com/blog/credit-cards-a...
- isaachall 16y agoBraintree is great for bringing this issue to light. I've personally been hurt by the lack of portability and have seen it affect several other companies. Here is Recurly's response: http://blog.recurly.com/2010/05/credit-card-portability/ http://blog.recurly.com/2010/05/credit-card-portability/
- quellhorst 16y agoIf braintree cares this much about this, why don't they allow people who use authorize.net currently to store their credit cards in the braintree vault?