4 ms·
Stripe's simplicity blows me away. Payments is one of those things I always hated dealing with--you could never provide a decent user experience for a reasonabl
by cloudwalking 15y ago
Stripe's simplicity blows me away. Payments is one of those things I always hated dealing with--you could never provide a decent user experience for a reasonable cost.
Stripe's solution is exactly what I want, so much so it's baffling that nobody had ever done it their way. And since I'm not planning on doing $50M+ revenue anytime soon, they're cheap too :)
- thematt 15y agoI agree, from a customer's point of view Stripe is a godsend. However, I wonder if that level of simplicity is sustainable for them going forward. The reason other payment providers have paperwork and approval processes is because of liability and the reality that there are unscrupulous merchants out there. Is Stripe assuming an increased liability because of the ease at which anybody can just sign up?
- dangrossman 15y agoI was somewhat surprised that when signing up I was not asked to agree to any terms, and there wasn't even a link to any on the signup form. When I did find them after signing up I see they require you to comply with PCIDSS, but by neither asking me to agree to this nor pushing it in their documentation at all, it's unlikely their users are going to actually do so. How many Stripe users are paying SecurityMetrics or ControlScan for their quarterly compliance scans? How many have even filled out the self-assessment questionnaire? So then comes the problem -- Stripe is encouraging developers, regardless of experience with security or payment systems, to set up direct credit card payment forms on their website (to be processed by Stripe's javascript). Lots of these servers probably have outdated services, CMS's and other packages with gaping security holes -- any of which would allow someone to hijack the form to silently send customers' credit card data somewhere else. In the end, who is Visa going to be able to get its half million dollar fine for a data breach by a site not in compliance with PCIDSS from? The merchant it has signed contracts with (Stripe via their underwriting banks) or the lone developers that have no funds to meet the security requirements, let alone pay fines on the resulting losses? I think Stripe's pitch deck would be an interesting thing to see.
- nilsbunger 15y agoWhat are the PCI-DSS compliance requirements when you're using Stripe?
- dangrossman 15y agoEverything except the parts about storing payment data. In a nutshell: - Install and maintain a firewall - Lock down system users, groups, passwords and default settings of your services - Use encryption - Use and update anti-virus software - Restrict access to your systems and have auditable logs of all access to your systems, physical and digital - Have unique identifiers for all people with access to your systems, so that those audits are meaningful - Log and monitor all network access to your systems - Have, distribute, and regularly test your physical, network and information security policies - Fill out a self-assessment questionnaire attesting you meet all these requirements - Have your server scanned by a 3rd party compliance company every 3 months To pass the compliance scans, you will have to maintain all services on your servers at the latest versions or provide evidence that you have applied patches covering all known security flaws, among other things. The scans are not cheap and have to be made by a provider approved by PCI. SecurityMetrics charges $699 per year to do them quarterly. By signing up with Stripe you are agreeing that you're taking care of this already. > You agree that at all times you shall be compliant with the Payment Card Industry Data Security Standards (PCI-DSS) and the Payment Application Data Security Standards (PA-DSS), as applicable. You agree to promptly provide us with documentation evidencing your compliance with PCI DSS and/or PA DSS if requested by us. You also agree that you will use only PCI compliant service providers in connection with the storage, or transmission of Card Data defined as a cardholder’s account number, expiration date, and CVV2. You must not store CVV2 data at any time. Information on the PCI DSS can be found on the PCI Council’s website. It is your responsibility to comply with these standards. https://stripe.com/terms https://stripe.com/terms It's also important to realize that you can't meet all the requirements on shared or cloud hosting -- except Amazon EC2, which is AFAIK the only PCIDSS approved cloud. You really need your own server to be in compliance.
- nilsbunger 15y ago