3 ms·
The worst part for small businesses is that Square's offline payments mode (where you can accept credit cards without live authorization, at risk of later decli
by cypherpunks01 3y ago
The worst part for small businesses is that Square's offline payments mode (where you can accept credit cards without live authorization, at risk of later declines when they post) has been unreliable historically. With some Square outages, customers have been logged out, and then unable to enter offline mode to accept credit cards. Not enough attention has been paid to this critical feature unfortunately, it does not seem to activate properly in many situations. I hope it worked OK for businesses yesterday and cards were able to process today.
- rossdavidh 3y agoMy understanding is that it did not.
- djmips 3y agoAnecdata - a local farmers market weren only taking cash payments yesterday AFAIK - it sounded like a big deal
- Scoundreller 3y agoGood reason to always carry a bit of cash with you. Yeah yeah, you’re losing $5 per $100 a year, but situations like this won’t affect you. If visa or Mastercard go down, I could say ATMs being emptied out.
- altairprime 3y agoLatch and Luxer One are two other apps that log you out if any HTTP error code returns - but instead of locking you out of your payments service, they lock you out of your apartment building. Apparently the lazy way to code “access terminated” these days is “if http.ok is false”.
- ebiester 3y agoThis is a much larger problem. Fail open and you potentially let someone who has been evicted with a relatively unsophisticated method. Fail closed and you lock someone out. Now, if you are going to say you are solving the problem, it means you have to think deeply here. However, all of the existing solutions have had unpleasant tradeoffs in degraded cases.
- altairprime 3y agoTrusting the client to be permitted to reauth is a guaranteed failure scenario, because then they can just put their phone in airplane mode and disable background updates. Issuing time-restricted certificates to the client that expire after an interval is the only way to be certain, other than the property manager simply walking to the lock in question and using the lock app on it to force out your client. Interpreting “No route to host, as various mobile networks do when your only cellular connection is Emergency Only, as “Purge the current session” is not beneficial to anyone’s security, and results in angry tenants trapped without cellular service in your parking garage, that then call emergency services via the elevator to get out. (This is not a theoretical example.) I assume the core problem is that they only refresh their session once a month when the previous session expires, and if that refresh fails, you’re locked out — because they didn’t code it to update the session expiration each time it successfully phones home your lock’s status when used, and so when the monthly interval is up, it logs out because it incompetently manages the OAuth session.