5 ms·
I went to buy lunch today, and the shop was like "we are only taking cash right now." I didn't have any cash, so I went to a different place across the street.
by dlevine 3y ago
I went to buy lunch today, and the shop was like "we are only taking cash right now." I didn't have any cash, so I went to a different place across the street. That place was only taking cash because their Square machine was down as well. I mentioned to the guy that the place across the street was down. I saw him go to the place next door and ask if their Square machine was down too.
Kind of crazy how one company's outage can bring down most of the places on a block. Everyone just relies on Square for their payments.
- raincole 3y agoHow does VISA credit care actually work? (genuine question) Like is there a single point of failure of credit card transactions? Can a cybro-terrorist shut down credit card by DDoS VISA's server or something?
- paulddraper 3y agoFrom my understanding, yes, but they have rock solid uptime.
- chrisco255 3y agoThere's usually at least two single points of failure, the merchant processor (Square in this case, but other retailers use different processors) and the card issuer (Visa, MC, etc) responsible for approving/declining a transaction.
- lelanthran 3y ago> How does VISA credit care actually work? (genuine question) Full answer at the bottom. I hope this answers your question. > Can a cybro-terrorist shut down credit card by DDoS VISA's server or something? No. There's some nuance though[2]. You can't shutdown VISA globally, but you can probably target a set of customers for a particular bank, or a set of customers in a particular suburb. In a single card transaction there are multiple parties (none of whom trust any other party): the acquirer, the issuer, the merchant bank, the cardholder, the cardholder bank, the PoS and the transaction switch. The transaction flows through some or all of these parties. 1. The acquirer[1], the issuer, the merchant and the merchant bank will all configure the terminal for when to go online and when to approve offline (using the card information and the cardholder information). Whose settings take preference depends. This means, in effect, that small transactions (like your lunch) are approved offline and so even when the issuer service is offline for 16 hours, most people won't notice. 2. When the transaction is forced online it isn't going to VISA anyway. It's going to a switch (probably hosted by the merchant's bank, or a party that the bank hired to switch transactions). 3. The transaction is then switched to a bank, and the bank approves or declines the transaction. It may be the merchant's bank that approves it and reconciles with the cardholder's bank at midnight. It may (depending on the risk evaluation of that transaction) go straight to the cardholder's bank. 4. The bank verifies the transaction against a secure security service (Frequently called the HSM - Hardware Security Module) which is provided by VISA (or if provided by someone else, has to be certified by VISA/MC/Europay). The HSM decrypts the encrypted 38-byte payload from the card and verifies if the cardholder and card are genuine. 5. The bank hosting the HSM can then decide to either approve or decline the transaction. If the transaction is approved then the bank will reconcile with VISA at some later point (generally once a day at midnight, or similar). 6. In very rare cases, the bank might decide to ask VISA to approve the transaction. I've never heard of this happening (because I never worked on the backend side of things past the bank). If this happens, it's a relatively new thing (in the last 20 years or so). So, the answer is "no", you cannot shutdown VISA cards by shutting down VISA's entire network. If VISA goes down the vast majority of online transactions will still work, and every single offline transaction will still work. You have to DDoS every single switch at every single bank to make online-only VISA transactions fail. Bear in mind that a single bank hosts multiple switches to handle the load, as well as spreading the transaction load across multiple third-party switches too. The entire global card network is handling billions of transactions per second, and is set up so that a peak of double the current load doesn't break it. Even if you managed to globally pwn every single desktop computer currently powered on with internet access, there may still not be enough resources to overload the global network to such an extent that you knock out card transactions globally. The best you can do is probably hit a single bank or a single group of banks (which still wouldn't make a difference to most merchants as most have more than one bank anyway), or take down all internet in a single area (knock out fibre, copper and cell towers all at the same time). The system is built for resilience and poor networking infrastructure, by adding in risk of fraud. People tend to forget that, for 4 decades, credit card transactions where a 24x7 0% downtime service. Well before 99.999% uptime on HA cloud providers were a thing, transactions were working just fine, just with an added cost to cover the fraud and only localised downtime (a single bank, a single suburb going down, not the entire network). This is also why crypto-currencies bring no value to the transaction/payments space in terms of resiliency. [1] Acquirer includes recent things like those USB/BL card-reader dongles you buy for android phones that are EMV certified with the app they come with. [2] I may be misunderstanding, or even misremembering some of the details, and some of the details may have changed in the years since I first worked on this stuff.
- raincole 3y agoWow, thank you so much. I didn't expect for such an elaborated answer!
- lelanthran 3y ago> Wow, thank you so much. I didn't expect for such an elaborated answer! Don't worry, I'm sure someone will post a reply pointing out all the things I got wrong :-) Read their replies too.
- orwin 3y agoThe 'favorite comment' is missing on HN. I really want to save it for later.
- hiatus 3y agoClick the timestamp of the comment and you can favorite it.
- silisili 3y agoAre you going to consider carrying cash going forward? Maybe it's where I live more than anything, but it seems bizarre to read this thread that so many people carry no cash at all anymore. I advised my wife to always have $40 on her. When she asked why, I said what my Dad said to me 20 something years ago..."you never know when you're gonna need it." Sure enough, at least a few times a year...whether from down POS systems/phone lines or a yard sale or some side of the road trinket seller, it does come in handy.